Dallas ISD (Aug 2022) — RansomHouse published 2,000+ SSNs, student IEP records, and staff credentials. Athens ISD paid $50,000 to recover district systems in 2022. PowerSchool (Dec 2024–Jan 2025) exposed historical student and teacher data across 6,500+ districts nationwide, including multiple Texas LEAs. Cleveland MetroSchools (Dec 2024) lost student records for 18,000+. Your district is next on the list — or it already happened and you don't know yet.
K-12 districts are uniquely vulnerable because the threat surface extends from campus HVAC controllers to PowerSchool vendor portals to the SRO's CJIS terminal. Texas K-12 SIX data and CIS MS-ISAC reporting confirm that education is the highest-growth ransomware sector — with summer dwell time as the primary attacker strategy. Districts don't discover the compromise until the September bell rings.
/IEP/,
/504/ directories.
Texas K-12 districts face more compliance obligations than most mid-market healthcare organizations — with a fraction of the IT staff. FERPA, HB 18/SCOPE Act, SB 820 TEA coordinator requirements, CJIS for SRO programs, and Texas Government Code 2054 stack on top of each other. Here's every framework in scope and what CoreRecon covers.
| Requirement | Effective / Status | Key Obligations | Penalty / Consequence | CoreRecon Coverage |
|---|---|---|---|---|
| FERPA | Active — ongoing | Protect student education records; breach notification; restrict third-party data access; data privacy agreements with vendors | Loss of federal Title funding; OCR investigation; mandatory corrective action plan | Sentinel Data access monitoring, breach detection, 72-hr notification support, audit logging |
| IDEA Confidentiality | Active — ongoing | IEP/504 records treated as education records; strict access controls; parent rights to records | OCR investigation; IDEA complaint resolution; loss of IDEA Part B funding | Sentinel Sensitive data classification, privileged access monitoring for IEP system access |
| TX Ed Code §38.027 (Breach Notification) | Active — ongoing | Districts must notify TEA, affected individuals, and law enforcement of security breaches involving student PII | TEA corrective action; parent/community trust damage; media exposure | Sentinel Breach event documentation, IR playbook, notification timeline support |
| HB 18 / SCOPE Act — Minors' Data | Eff. Sep 1, 2024 | Digital service providers must: data minimization for minors, parental consent for sensitive data, no behavioral advertising, privacy notice disclosures; districts must enforce via vendor agreements | AG enforcement; fines up to $7,500/violation/day; reputational damage; parent lawsuits | Fortress SCOPE Act vendor assessment, data privacy agreement review, vendor data use mapping |
| SB 820 — TEA Cybersecurity Coordinator | Active — TEA reporting required | Each district must designate a cybersecurity coordinator; complete TEA-approved training; file annual cybersecurity reports to TEA; report cybersecurity incidents | TEA corrective action; accreditation risk; state funding conditions | Fortress Coordinator reporting cadence support, incident documentation, TEA report templates |
| CJIS Security Policy v6.0 (SRO Programs) | v6.0 audit active Oct 2025 | All 13 CJIS policy areas: physical protection, personnel security, mobile devices, incident response, auditing & accountability, access control, identification & authentication, configuration management, media protection, systems & comm. protection, formal audits, security awareness | Loss of NCIC/TCIC access; FBI audit findings; federal criminal justice funding risk | Command Full CJIS v6.0 — 13 policy areas, SRO environment scoping, audit-ready evidence packages |
| TX Gov. Code §2054 (State-Funded Entity Cyber) | Active — DIR oversight | State-funded entities must: maintain cybersecurity programs aligned to Texas Cybersecurity Framework (TCF), participate in statewide threat intel sharing, report cybersecurity incidents to DIR within required timeframes | DIR audit findings; state funding conditions; mandatory remediation timelines | Fortress TCF-aligned security posture documentation, DIR incident reporting support |
* COPPA applies to districts using online services for students under 13. CIPA/E-Rate compliance applies to E-Rate Category Two recipients (internet safety policy, content filtering). Both covered at Sentinel tier.
A hypothetical based on actual K-12 ransomware patterns in Texas. The events are composite — the attack surface, timing, and recovery costs are drawn from confirmed 2022–2025 Texas district incidents.
Aligned to the TEA cybersecurity coordinator reporting calendar and SB 820 obligations. Cooperative contract execution (TIPS/BuyBoard/DIR) can happen in parallel with Phase 1 deployment.
CoreRecon's K-12 pricing covers staff workstations, servers, and administrative infrastructure — not 1:1 student device fleets. Typical endpoint counts by district size: small (200 students, ~40 staff endpoints), mid (1,500 students, ~200 staff endpoints), large (8,000+ students, ~800–1,200 staff endpoints). Month-to-month. No minimums. Procurable via TIPS, BuyBoard, and DIR cooperative contracts.
| Tier | $/Endpoint/Month | What's Included | Best For |
|---|---|---|---|
| Sentinel | $89 | 24/7 TX-resident SOC, EDR deployment, FERPA breach detection, anomalous access monitoring, attack surface management, CIPA policy posture, monthly reports, cyber insurance Letter of Engagement | Small-to-mid districts (no SRO program); FERPA + COPPA baseline; basic insurance requirements; budget-constrained procurement |
| Fortress | $109 | All Sentinel + SIEM, firewall management, network segmentation, vendor risk monitoring (PowerSchool/Skyward/Frontline), SCOPE Act / HB 18 vendor assessment, TX Ed Code §32.151 documentation, SB 820 TEA coordinator reporting support, DIR §2054 posture documentation | Mid-size districts with active EdTech vendor stack; SB 820 TEA coordinator compliance; SCOPE Act obligations; E-Rate eligibility |
| Command | $129 | All Fortress + full CJIS v6.0 (all 13 policy areas), SRO program security architecture, annual CJIS audit support, TX DPS coordination, CJIS audit-ready evidence package, ESSER III procurement documentation, tabletop exercise included annually | Districts with SRO programs (CJIS in scope); large ISDs; maximum insurance coverage; ESSER III-funded deployments requiring full documentation |
* Staff endpoints = workstations, servers, network appliances, administrative infrastructure. Student 1:1 devices (Chromebooks, iPads) excluded. Endpoint count confirmed during free assessment — no surprises before contracting. Cooperative contract numbers available for TIPS, BuyBoard, and DIR on request.
Most K-12 breaches aren't discovered until ransomware detonates. Average attacker dwell time in Texas education networks is 8 weeks. Our free assessment maps your endpoint exposure, identifies active compromise indicators, benchmarks against FERPA and CJIS requirements, and delivers a prioritized remediation plan with ESSER III documentation if applicable. Procurable immediately via TIPS, BuyBoard, or DIR.
Request your free assessment →Delivered within 14 days • No credit card • Cooperative contract procurement available • SDVOSB