CISA and MS-ISAC explicitly name K-12 as a primary ransomware target. The PowerSchool breach (Dec 2024) exfiltrated millions of student records — months later, individual TX districts received targeted follow-on attacks using the stolen data. The Canvas LMS breach (Jan 2025) hit 8,000 institutions. FERPA, HB 18/SCOPE Act, CJIS v6.0, and SB 820 create a four-framework compliance stack for Texas ISDs.
CISA and MS-ISAC name K-12 as a primary ransomware target — particularly Phobos and RaaS variants optimized for SLTT
Key attack patterns for Texas K-12: (1) Phishing emails to staff — credential harvesting via fake Office 365 login pages is the #1 entry vector; (2) Student data platforms — PowerSchool and Canvas LMS breaches gave attackers a massive dataset of student PII to weaponize for follow-on attacks; (3) Shared credentials across devices — same login for student Chromebooks, teacher laptops, and admin systems creates a wide, weakly defended surface; (4) Underfunded patching — many TX ISDs still run Windows 7 and Server 2012 with no security updates available; (5) Vendor-linked attacks — a compromised EdTech vendor can cascade into every district using that vendor.
Four frameworks simultaneously govern TX school district data security
| Framework | Scope | Status | Key Requirement |
|---|---|---|---|
| FERPA Family Educational Rights and Privacy Act |
All public schools receiving federal funding | Active — federal | Protect student education records; breach notification to parents, U.S. Dept. of Education; up to $100/violation per instance |
| HB 18 / SCOPE Act Effective September 1, 2024 |
TX digital service providers with student data | Active — TX state | Data minimization, parental consent, privacy notice obligations for vendors processing minor student data; districts must ensure vendor compliance |
| CJIS v6.0 Full compliance: Oct 1, 2027 |
ISDs with School Resource Officer (SRO) programs / campus PD | Active audit / Oct 2027 deadline | 13 CJIS security policy areas; FBI audit scope for campus law enforcement systems; criminal justice data protection requirements |
| SB 820 (TX 88th Leg.) TX Education Code §37.083 |
All Texas school districts | Active — TX state | Designate a cybersecurity coordinator; report cybersecurity incidents to Texas Education Agency within 48 hours; maintain cybersecurity policies |
Key protection layers for K-12: Phishing defense with anomalous link detection and fake Office 365 login page blocking (stops the credential harvesting that precedes most ransomware), SIS/LMS activity monitoring for unauthorized access to student records (FERPA breach detection), summer and holiday attack prevention (the most common ransomware timing for K-12 is when IT staff is minimal), and SB 820 incident documentation that satisfies the 48-hour TEA notification requirement. CoreRecon maps all FERPA, HB 18/SCOPE Act, CJIS v6.0, and SB 820 requirements to SOC monitoring evidence packages that can be provided to auditors and the Texas Education Agency.
30-minute security posture assessment for Texas K-12 ISDs. We'll identify your FERPA exposure, student data system vulnerabilities, and the gaps between your current protection and what a breach-ready defense looks like. No obligation, no sales pressure.