K-12 IT and Cybersecurity for Texas School Districts
Texas districts face ransomware, FERPA and Texas Student Privacy Act duties, TEC 11.175 reporting, 1:1 MDM sprawl and E-Rate funding gaps. Here is the August checklist.
Introduction
August is when districts stage devices, onboard staff, and push enrollment through a student information system about to carry its heaviest load of the year. Attackers read the school calendar too. The 2025 CIS MS-ISAC K-12 Cybersecurity Report, drawn from more than 5,000 K-12 organizations between July 2023 and December 2024, found attacks surge during high-stakes periods like the start of the school year.
Here is what gets hit, which Texas statutes bind your district, what E-Rate will not pay for, and a checklist you can finish before students walk in. For the service view, see our K-12 education IT services page.
Why Texas School Districts Sit Near the Top of the Target List
Districts carry a mid-sized enterprise's risk profile on a public agency budget. Three structural factors do most of the damage:
- Enormous attack surface per dollar. One district runs dozens of campuses, thousands of student devices, HVAC and bell controllers, cafeteria point-of-sale, and a dozen instructional SaaS platforms on one funding envelope.
- Downtime with a hard public deadline. A district that cannot take attendance, run buses, or serve meals makes the evening news. Comparitech's tracker of US school and college ransomware puts average downtime near 10.7 days across 491 attacks from 2018 through July 2024, which hit 8,054 institutions and exposed over 6.7 million records.
- Data that stays valuable for a decade. A student record carries a clean, unmonitored Social Security number belonging to someone who will not check credit for years, which is why exfiltration now accompanies encryption. Comparitech counted 180 ransomware attacks on education worldwide through the first three quarters of 2025, 95 of them in the US, averaging a $444,400 demand and 2.6 terabytes stolen.
The same report is blunter on cause: attackers targeted human behavior at least 45 percent more often than technical vulnerabilities, and 82 percent of reporting K-12 organizations took a cyber threat impact. The control that pays best is rarely an appliance.
Two Texas Statutes Every District Should Have Wired In
Two state requirements are already law and get audited in practice.
- Texas Education Code Section 11.175. Each district must adopt a cybersecurity policy securing district cyberinfrastructure, determine cybersecurity risk, and implement mitigation planning. The superintendent must designate a cybersecurity coordinator as liaison to the Texas Education Agency. Districts must report a breach involving student information to the agency as soon as practicable after discovery, and the coordinator must notify affected parents.
- Texas Government Code Section 2054.5191, from HB 3834, signed June 14, 2019. Cybersecurity training must come from a program certified by the Texas Department of Information Resources. The coordinator completes it annually, board members annually as elected officials, and other employees as the district determines, with compliance certified through DIR.
The failure mode here is ownership, not ignorance: the coordinator role goes to whoever is available, the policy is adopted once and never revisited, and nobody keeps the evidence that makes a TEA conversation short. A recurring vCIO and IT strategy cadence prevents that decay.
Student Data Privacy: FERPA Plus the Texas Student Privacy Act
Districts sit under two overlapping privacy regimes, and vendors often address only one. FERPA (20 U.S.C. 1232g, 34 CFR Part 99) governs personally identifiable information in education records. The provision that matters most for outsourced technology is the school official exception: a district may disclose PII to a contractor performing a service it would otherwise perform in-house, but that contractor must be under the district's direct control, may use the information only for the purpose of the disclosure, and may not redisclose it without consent. FERPA also carries no breach notification mandate; that duty comes from Education Code 11.175 and state breach law.
The Texas Student Privacy Act sits at Education Code Sections 32.151 through 32.153. Section 32.151 defines an operator as one running a website, service, or app it knows is designed, marketed, and used primarily for a school purpose, and defines covered information broadly: educational records, names, addresses, email, discipline records, test results, special education data, biometric information, and geolocation. Section 32.152 prohibits targeted advertising based on that information and prohibits selling or renting it.
Every instructional app should clear three gates before it touches a roster: a written FERPA school-official designation with direct-control language, an explicit Section 32.152 representation, and a documented deletion timeline.
Segment the Student Information System From Everything Else
The highest-leverage decision in a district network is keeping the SIS off the same broadcast domain as anything a student touches. Flat networks are how one compromised Chromebook becomes a district-wide encryption event.
- Four zones minimum: student devices, staff devices, guest and community wireless, and administrative systems such as the SIS, finance, HR, badge, and camera platforms.
- Deny by default between zones. Student VLANs reach the internet and approved instructional SaaS, nothing else. Guest wireless reaches the internet only, with client isolation on.
- Separate the OT. HVAC, bell systems, door controllers, and cameras rarely need to reach a workstation VLAN, though their vendors will ask for flat access.
- Administrative SIS access should require phishing-resistant MFA and should not be reachable from student subnets at all.
If nobody has diagrammed your segmentation against what the switches are actually configured to do, that gap is worth a network security audit. A sloppy SSID structure quietly reunites zones you thought were separated, so see campus WiFi solutions and firewall management too.
1:1 Device Fleets, MDM, and the Summer Drift Problem
A 1:1 program is a fleet management problem disguised as an instructional initiative. Devices spend ten weeks off-network, out of policy, and often with someone other than the enrolled student.
- Enrollment must be automatic. Zero-touch enrollment through Apple Business Manager, Windows Autopilot, or Chrome Enterprise means a reimaged device re-enrolls itself rather than escaping management.
- Reconcile the fleet against the roster in August, not in May. Any device that has not checked in for 60 days is lost, broken, or being used off-policy, and all three answers require action.
- Push the compliance baseline before day one: disk encryption, screen lock, a patch level floor, CIPA-compliant content filtering, and conditional access blocking non-compliant devices from district data.
- Staff devices need their own baseline. Teacher laptops carry far more covered information than any student device and are usually managed less strictly.
Most districts already own the licensing through their Microsoft agreements. See Intune device management for how compliance and conditional access fit together, and endpoint security for what runs on the device.
Enrollment Season Is Phishing Season
August is the one month when unusual email is normal: new staff email unfamiliar names, HR sends real direct-deposit forms, vendors send real invoices, parents send real attachments. Attackers exploit that noise floor.
- Payroll diversion is the classic district BEC: a message appearing to come from a teacher, asking HR to update direct deposit before the first pay run.
- Vendor invoice fraud spikes with the fiscal year, when purchase orders move and the business office is busiest.
- Substitute and new-hire onboarding creates a window where an attacker's account request looks identical to fifty real ones.
Two process controls beat any filter. Require out-of-band verbal verification against a known-good number for every banking change, with no exception for urgency. Then run a baseline phishing simulation in the first two weeks, so DIR-certified training aims at real weaknesses.
E-Rate and the Cybersecurity Pilot: What Actually Gets Funded
E-Rate is the largest funding lever most districts have and the most widely misunderstood. It funds connectivity, not security.
- Category One covers data transmission and internet access, the circuits themselves.
- Category Two covers internal connections, managed internal broadband service, and basic maintenance: switches, access points, cabling, and basic firewall services and components.
- What the FY2026 Eligible Services List left out. The FCC again declined to make advanced or next-generation firewall features eligible under Category Two, and declined to expand eligibility to standalone cybersecurity tools. Threat protection, intrusion detection, endpoint security, and managed detection and response are not Category Two eligible.
Advanced security sits instead in the FCC's Schools and Libraries Cybersecurity Pilot Program, a separate three-year program making up to $200 million available, with more than 700 schools, libraries, and consortia selected. Its eligible list names four categories: advanced and next-generation firewalls, endpoint protection, identity protection and authentication, and monitoring, detection, and response.
Treat any award as acceleration, not as the plan. It is a pilot studying whether universal service funding should support cybersecurity permanently, and disbursement has been deliberate: industry trackers reported roughly $28 million committed after the second wave of decisions in late January 2026, about 14 percent of the budget. Your security line stays a general fund or grant line.
Backups That Survive a District-Wide Event
Districts routinely have backups and still lose two weeks. The backup server is domain-joined, so the credential that encrypted the file servers also deletes the restore points. Microsoft 365 retention gets mistaken for backup. Nobody has read the SIS contract for the real RPO and RTO. And restoring one file proves nothing about restoring 40 servers over a weekend.
Hold the line at immutable, credential-isolated copies plus one rehearsed full restore a year. Our backup and recovery page covers the architecture; if something is already burning, read the first 72 hours of a ransomware incident and see ransomware recovery.
The August Checklist Before Students Return
Work this in order. Most of it is verification, not procurement.
- Confirm the 11.175 basics: a named cybersecurity coordinator on file with TEA, a board-adopted policy reviewed this year, and a written notification procedure covering parents.
- Disable departed staff accounts and reconcile the identity directory against the current HR roster. Summer separations are the year's most commonly missed offboarding window.
- Enforce MFA on every administrative account, especially SIS, finance, HR, and the identity tenant itself. Verify no exclusions survived last year's rollout.
- Test inter-VLAN rules from an actual student device. Try to reach the SIS, the finance server, and a staff printer, and document what happens.
- Patch the edge first: firewalls, VPN appliances, and anything internet-facing. These are the initial access vectors attackers reuse most.
- Review every new instructional app against the FERPA and Section 32.152 gates before rosters sync.
- Run one restore test from immutable backup and time it honestly.
- Schedule DIR-certified training and send the baseline phishing simulation in the first two weeks.
Where to Start
If your district lacks an evidence-backed picture of its own exposure, that is the first purchase, not a tool. Start with a free IT assessment, then close the two or three findings carrying the most downtime risk.
Where an internal team is capable but out of hours, a co-managed IT arrangement usually beats a full outsource: your staff keeps instructional technology while the partner absorbs patching, monitoring, and escalation. Districts without dedicated security staffing more often need managed IT services with cybersecurity services and managed detection and response, so 24/7 automated monitoring covers overnight and weekend windows. LayerLogix provides business-hours support with after-hours emergency response, 100% Texas-based, backed by 20+ years of experience.
Frequently Asked Questions
Does FERPA require a school district to notify parents after a data breach?
No. FERPA carries no breach notification mandate. For Texas districts the duty comes from Texas Education Code Section 11.175, which requires reporting a breach involving student information to the Texas Education Agency as soon as practicable after discovery, and requires the district cybersecurity coordinator to notify affected parents.
What does Texas Education Code Section 11.175 require of a school district?
Each district must adopt a cybersecurity policy securing district cyberinfrastructure, determine cybersecurity risk and implement mitigation planning, and have the superintendent designate a cybersecurity coordinator as liaison to the Texas Education Agency. That coordinator also handles parent notification for reportable incidents involving a student's information.
Will E-Rate pay for a school district firewall?
Basic firewall services and components remain eligible under E-Rate Category Two. In the FY2026 Eligible Services List, however, the FCC again declined to make advanced or next-generation firewall features eligible, and declined to expand eligibility to standalone cybersecurity tools. Advanced firewalls fall under the separate Cybersecurity Pilot Program instead.
How should a district separate student and staff networks from the SIS?
Use at least four zones with deny-by-default rules between them: student devices, staff devices, guest and community wireless, and administrative systems including the SIS, finance, and HR. Student subnets should reach the internet and approved instructional platforms only, and administrative SIS access should require phishing-resistant MFA.
What should a Texas district do first when ransomware hits mid-year?
Isolate affected segments first and preserve logs rather than reimaging, then start the Education Code 11.175 clock by preparing the agency report and parent notification alongside technical recovery. Engage counsel and your cyber insurer early, since both often control which recovery vendors the policy covers.
Geographic Coverage
LayerLogix supports school districts, charter networks, and private schools across Texas from our headquarters at 2001 Timberloch Place in The Woodlands and our second office in Round Rock, serving Houston, The Woodlands, Conroe, Round Rock, and Austin. Greater Houston districts can reach us at 713-571-2390, DFW at 214-617-2370, and Central Texas at 512-829-1981.
Need Help With Cybersecurity?
LayerLogix provides expert cybersecurity solutions for businesses across Houston and nationwide.
Related Articles
Need Expert IT Support?
Let our team help your Houston business with enterprise-grade IT services and cybersecurity solutions.