During the COVID-19 pandemic, educators, parents, and students moved to remote and hybrid learning environments in order to slow the spread of disease. However, this shift to remote learning made existing vulnerabilities within K-12 cybersecurity systems more apparent. Even after returning to in-person learning environments, threat actors are still exploiting these vulnerabilities. A report published by Cybersecurity and Infrastructure Security Agency (CISA) emphasized the need for education and technology leaders to come together to defend K-12 schools from ransomware attacks and improve overall cybersecurity efforts.
The CISA report explores the significant increase in the number of ransomware attacks against schools. In the past, schools have often relied on backed up files to avoid paying a ransom in order to have their stolen files decrypted or restore access to them. In light of this, threat actors have upped the ante and now threaten to leak personal information in attempts to coerce schools to pay a ransom. If school districts refuse to pay it can often have devastating consequences, with threat actors selling the sensitive information of students, educators, and faculty members.
In a recent webinar, Fadi Fadhil, Palo Alto Networks’ Field Chief Technology Officer, discussed the rise of ransomware attacks on schools. “When it comes to that cybersecurity conversation, what has worked before is not working anymore,” Fadhil explained. “Not just from an operational or tool standpoint, but also from the threat itself is not the same… [Ransomware] tactics are not static, [threat actors] have evolved their tactics and techniques and procedures… They’re adopting prolific ransomware-as-a-service business model, which gives anyone who wants to make attack [the ability to] go and hire those folks to attack your district… [and] pressure the victims to pay more and pay faster.”
One of the biggest challenges schools face when trying to improve cybersecurity efforts is a lack of resources because of budget and workforce limitations. Often times, IT workers wear multiple hats performing tasks that typically require a multi-person team to implement.
In the report, CISA stated that to overcome the challenges presented by the cyber threat landscape, K-12 leadership and faculty must come together. “Change must come from the top down. Leaders must establish and reinforce a cybersecure culture. Information technology and cybersecurity personnel cannot bear the burden alone.”
To achieve this, CISA laid out three key insights and recommendations for K-12 school leaders.
- Overcome Limited Resources
Cybersecurity needs to be considered a top priority for superintendents and administrators. To overcome funding challenges K-12 leadership should be creative in finding additional resources. This can include migrating to a secure cloud environment, leveraging grant programs, and working with technology providers to use low-cost cybersecurity services and products.
- Prioritize the Right Cybersecurity Tools
Rather than trying to implement everything all at once, start by investing in the tools that will have the biggest impact. Priorities should include: multi-factor authentication (MFA), identifying, mitigating known vulnerabilities, implementing and testing backups, exercising incident response plan, and implementing a cybersecurity training program.
- Create a United Front through Collaboration
There is power in numbers. Collaborating with other school districts creates a united force to increase awareness of cyber threats, improve cyber resilience, and defend K-12 schools from ransomware attacks. K-12 schools should participate and contribute to information sharing forums such as K12 Security Information eXchange (K12 SIX) or Multi-State Information Sharing and Analysis Center (MS-ISAC).
“The whole goal of an IT department is to be able to support the safe and effective delivery of curriculum, resources, and services so that students can learn and grow,” said David Cumbow, Palo Alto Networks’ Principal Architect. “You’re not in this alone and you shouldn’t be expected to be the expert and have to understand all the threats that are coming at you… [Work with] trusted partners to help you get these devices implemented properly. That way, once they’re implemented, you can focus more on day-to-day operations and advancing your cybersecurity posture instead of putting out the fires.”
The cyber risks threatening schools should not be taken lightly. In order to improve cybersecurity efforts, school leadership should take action using the guidance from CISA to defend K-12 schools from ransomware attacks. By doing so, they will create a safer cyber space for students to learn and thrive.
Learn more about ways to defend K-12 schools from ransomware attacks here.