CISA Just Released a Free K-12 Cybersecurity Toolkit. Here's What Montana Districts Should Actually Do With It.

On August 12, the Cybersecurity and Infrastructure Security Agency released the K-12 Cybersecurity Foundations Resource Package, a free collection of guides, videos, and quick-reference materials built specifically for schools and districts. It is not another high-level warning about the threat landscape. It is a set of working documents with named objectives, associated practices, and enough structure that a district technology director can turn it into a project plan.

For Montana districts, the timing is useful. School starts in a few weeks. Budgets for the year are largely set. And the free federal supports districts leaned on in past years have gotten thinner, not thicker.

Here is what is in the package, what it is worth, and what a Montana district should do with it between now and the first day of school.


What CISA actually released

The package has two guides at its center, plus supporting material.

The Getting Started Guide is written for superintendents, business managers, principals, and other non-technical leaders. It covers the threats schools face and walks through four foundational steps a district can take regardless of size, budget, or in-house expertise.

The Implementation Guide is the deeper document, written for the people who will actually do the work. It organizes practices around eight objectives:

  1. Protect login credentials for students and staff
  2. Safeguard student and staff devices and assets
  3. Perform, verify, and test backups
  4. Develop and exercise a cyber incident response plan
  5. Use available cybersecurity training and awareness campaigns at all levels
  6. Protect sensitive data
  7. Prioritize near-term investment in alignment with CISA's Cross-Sector Cybersecurity Performance Goals
  8. Develop a customized long-term cybersecurity plan aligned to the NIST Cybersecurity Framework

Alongside the guides is a six-part video series (two sets, one per guide) and quick-reference material for navigating the package. CISA says it developed the resources with input from K-12 stakeholders and cybersecurity practitioners, and aligned them to the NIST Cybersecurity Framework and its own earlier K-12 guidance.

Everything is free. There is no registration wall, no vendor attached, and no procurement required to start reading.

Access the package here: cisa.gov/topics/cybersecurity-best-practices/K12cybersecurity/foundations


Why the threat picture is more complicated than the headlines

You will see two contradictory framings of K-12 cyber risk this month. Both are partly right.

The encouraging read. Ransomware attacks on the education sector dropped 13 percent globally in the first half of 2026, from 120 in the back half of 2025 down to 104, according to Comparitech's H1 2026 education roundup. In the United States specifically, researchers logged 34 attacks across K-12 and higher education combined, a 44 percent decline from the 61 recorded in the second half of 2025. K-12 attacks worldwide fell 26 percent.

The less encouraging read. That decline was not evenly distributed. Attacks on higher education rose more than 8 percent over the same period. And the attacks that did land were expensive: the median ransom demand across the education sector climbed to roughly $420,620, up 53 percent from about $275,000 six months earlier. Of the 104 attacks tracked, only 36 were confirmed by the targeted organizations, which means the real number is a floor, not a ceiling. Districts frequently do not disclose.

There is also a structural change worth naming. The Multi-State Information Sharing and Analysis Center, which many districts relied on for free threat intelligence and incident response support, lost its federal funding and has since lost roughly 70 percent of its membership, including dozens of states and more than 10,000 local jurisdictions. CISA itself saw its workforce cut by close to a third during the first half of 2025.

So the practical situation for a small Montana district is this: the odds of being hit may have ticked down slightly, the cost of being hit went up, and the free help you used to be able to call has largely gone away. That is the context this new CISA package arrives in, and it is a fair reason to take it seriously rather than filing it.


The Montana case study nobody wants to be

You do not have to look to Texas or Minnesota for a relevant example.

In early April 2026, Belgrade School District No. 44 in Gallatin County, which serves more than 3,200 students across five schools, experienced a malware incident that disrupted network systems. The district notified families on April 6 that it was working to repair systems. Parents later reported that the disruption affected routine school operations, including lunch processing and assignments.

On April 17, trustees authorized $750,000 for network security and restoration services connected to the incident. That figure prompted community speculation about a ransom payment, and Superintendent Dede Semerad clarified publicly that the money was for restoring system functionality and preventing future incidents, not a ransom. By May 18 the district said its review had found no evidence of unauthorized access to Infinite Campus, its student information system, while review of other systems continued. Restoration work was expected to run into June. The district has not publicly confirmed ransomware, a ransom demand, or a threat actor.

Belgrade handled the incident the way you would want a district to handle it: isolate, respond, investigate, communicate. But the number to sit with is $750,000, in a district that was simultaneously working through a budget deficit. That is what an incident costs before anyone has proven data was stolen.

Statewide, the direction of travel is not subtle either. Montanans reported a record $53 million in losses to cyber crime in 2025, up from $31.6 million the year before, with losses quintupling since 2021 according to FBI Internet Crime Complaint Center data.

Rural and small does not mean invisible. Among the U.S. districts that confirmed ransomware attacks in the first half of 2026 were Wagon Mound Public Schools in New Mexico, a district of a few dozen students, along with Delano Public Schools in Minnesota, Denmark School District in Wisconsin, and Alcorn School District in Mississippi. Attackers are not filtering by enrollment.


The honest limitation of free guidance

The CISA package is genuinely good, and it is also not a security program. It is a description of one.

The gap between reading the Implementation Guide and satisfying its eight objectives is staffing, tooling, and sustained attention. Objective two asks you to safeguard devices and assets. That presumes you have a current, accurate inventory of every device on your network, who has it, what is on it, and whether it is patched. Objective three asks you to perform, verify, and test backups. Most districts do the first part. Far fewer do the second and third. Objective four asks for an incident response plan that has actually been exercised, not one that exists as a PDF on a shared drive.

This is where districts stall out. Not because the guidance is unclear, but because there is no one whose job it is to own it.

If your district has no dedicated security staff, the useful way to read the package is as a gap-assessment instrument, not a to-do list. Score yourself honestly against each objective, identify the three or four gaps that would hurt most in an actual incident, and fund those first.


What to do in the next 30 days

A realistic sequence for a Montana district before school ramps up:

Week 1: Read and score. Download the Getting Started Guide and Implementation Guide. Have your technology director or IT partner score the district against all eight objectives on a simple scale: in place, partial, absent. This is a two-hour exercise, not a two-week one.

Week 2: Close the credential gap. Multi-factor authentication on staff email and administrative accounts is the single highest-return control on the list. If MFA is not enforced on your Google Workspace or Microsoft 365 tenant, on your student information system, and on any remote access path into the network, that is the first fix. Review privileged accounts while you are in there and remove standing admin rights that no longer belong to anyone's current job.

Week 3: Prove your backups. Do not confirm that backups are running. Restore something. Pick a real system, restore it to a test environment, and time it. If you cannot state your recovery time for the student information system in hours, you do not have a tested backup, you have a backup job.

Week 4: Write and walk through the incident response plan. It needs names, phone numbers that work when district email is down, a decision path for who talks to families and media, your cyber insurance carrier's notification requirements, and a defined threshold for when you call law enforcement. Then run a 60-minute tabletop with your leadership team before the first bell.

Ongoing: Vendor access. Most districts have more third-party access into their environment than they realize, and the education sector's largest recent breaches have come through vendors rather than direct attacks on districts. Inventory every vendor with a login or a network path into your systems, confirm each one still needs it, and confirm each one has MFA enforced.


What your board needs to hear

Boards do not need the Implementation Guide. They need four things, in a one-page summary at the next regular meeting:

  1. Where we stand. Our score against CISA's eight objectives, as a simple count: in place, partial, absent.
  2. What an incident would cost us. Not hypothetically. Reference a comparable Montana district and the real recovery figure.
  3. What we are asking for. The two or three funded items that close the largest gaps, with dollar amounts.
  4. What we are accepting. The risks we are consciously choosing not to fund this year, documented.

That fourth item matters more than it looks. Cybersecurity is a governance decision, not just an IT decision, and documenting accepted risk is what turns a board from a bystander into a participant. CISA's own framing in this release is that K-12 cybersecurity has moved past being an IT department concern and belongs alongside physical safety and security.


The funding question hanging over all of this

Any conversation about paying for K-12 cybersecurity in Montana runs into E-Rate.

On June 25, 2026, the FCC voted to open a broad review of the E-Rate program, adopting a combined Notice of Proposed Rulemaking and Further Notice of Proposed Rulemaking (FCC-26-41) under WC Docket No. 26-133. Among the many questions raised is whether the program should be narrowed or reoriented, including whether it should be limited or sunset.

The FCC has pushed back on characterizations of this as a plan to end the program, stating that it did not vote to eliminate E-Rate and that no school or library loses support as a result of the June vote. Education groups including CoSN and the SHLB Coalition read the proposal as a serious enough risk to organize advocacy around it.

Either way, the procedural facts matter for planning: the proposal was published in the Federal Register in August, comments are due October 13, 2026, and reply comments are due November 12, 2026. If your district depends on E-Rate discounts for connectivity or internal connections, this is the window to file, and it is worth a line item in your fall board packet regardless of which reading you find more persuasive.


How K12 Montana fits in

We work with Montana school districts and nonprofits that mostly do not have a dedicated security staff, and often do not have a dedicated IT staff either. The CISA package is a good fit for exactly that situation, because it is designed to be implemented by generalists.

What we can do with it:

  • Run the assessment with you. We will score your district against all eight CISA objectives and give you a written gap report with a prioritized remediation list and rough costs, so the conversation with your board is grounded in specifics rather than adjectives.
  • Close the device and asset gap. Objective two is where most districts score worst, because nobody has a reliable inventory. Our K12 Panel platform gives districts a live view of devices, assignments, and status, which is the precondition for satisfying that objective rather than guessing at it.
  • Own the ongoing work. Our managed service tiers (CORE, MSP-12, MSP-24, and MSP-48) exist so that patching, backup verification, monitoring, and incident readiness have a name attached to them instead of falling to whoever has time.
  • Get you incident-ready. Plan development, tabletop exercises, and a documented escalation path, including who to call at 6 a.m. when email is down.

If you want to start with the free version, start with the free version. Download the guides, score yourself, and see where you land. If the gaps are bigger than your team can close before students arrive, get in touch and we will work through it with you.


Frequently asked questions

Is the CISA K-12 Cybersecurity Foundations package free? Yes. All components, both guides, the six-part video series, and the supplemental materials, are published free on CISA's website with no registration required.

Does our district need dedicated IT security staff to use it? No. The Getting Started Guide is written specifically for district leaders without technical backgrounds, and its four foundational steps are designed to work regardless of district size, expertise, or funding level.

How is this different from CISA's earlier K-12 guidance? The earlier material was primarily a report on the threat landscape with high-level recommendations. This package is implementation-oriented: named objectives, associated practices, and instructional video walking through each one. CISA states the package builds on and aligns with its earlier guidance and the NIST Cybersecurity Framework.

Are ransomware attacks on schools getting better or worse? Both, depending on the measure. Attack volume against U.S. education fell substantially in the first half of 2026, while ransom demands rose sharply and support resources for districts contracted. Lower probability, higher consequence.

What should a small Montana district do first? Enforce multi-factor authentication on staff email, administrative accounts, and the student information system, then test a real backup restore. Those two items address the most common entry point and the most common recovery failure.


References

  1. Cybersecurity and Infrastructure Security Agency. "CISA Unveils New Cybersecurity Resources for K-12 Schools and Districts." August 12, 2026. https://www.cisa.gov/news-events/news/cisa-unveils-new-cybersecurity-resources-k-12-schools-and-districts
  2. Cybersecurity and Infrastructure Security Agency. "K-12 Cybersecurity Foundations." https://www.cisa.gov/topics/cybersecurity-best-practices/K12cybersecurity/foundations
  3. Cybersecurity and Infrastructure Security Agency. "K-12 Cybersecurity Foundations: Getting Started Guide Videos." https://www.cisa.gov/resources-tools/resources/k-12-cybersecurity-foundations-getting-started-guide-videos
  4. Cybersecurity and Infrastructure Security Agency. "K-12 Cybersecurity Foundations: Implementation Guide Videos." https://www.cisa.gov/resources-tools/resources/k-12-cybersecurity-foundations-implementation-guide-videos
  5. Dille, Grace. "CISA Rolls Out Cybersecurity Resource Package for K-12 Schools." MeriTalk, August 12, 2026. https://www.meritalk.com/articles/cisa-rolls-out-cybersecurity-resource-package-for-k-12-schools/
  6. Merod, Anna. "CISA issues K-12 cybersecurity guidance as schools' risks persist." K-12 Dive, August 14, 2026. https://www.k12dive.com/news/cisa-issues-k-12-cybersecurity-guidance-as-schools-risks-persist/827841/
  7. DataBreaches.Net. "CISA Unveils New Cybersecurity Resources for K-12 Schools and Districts." August 15, 2026. https://databreaches.net/2026/08/15/cisa-unveils-new-cybersecurity-resources-for-k-12-schools-and-districts/
  8. Moody, Rebecca. "Education Ransomware Roundup: H1 2026 stats on attacks, ransoms, and data breaches." Comparitech, July 22, 2026. https://www.comparitech.com/news/education-ransomware-roundup-h1-2026-stats-on-attacks-ransoms-and-data-breaches/
  9. Government Technology. "Ransomware Attacks on K-12 Trend Down, Higher Ed Trend Up in 2026." August 2026. https://www.govtech.com/education/k-12/ransomware-attacks-on-k-12-trend-down-higher-ed-trend-up-in-2026
  10. DysruptionHub Staff. "Belgrade, Montana, schools restoring systems after malware disruption." DysruptionHub, May 21, 2026. https://dysruptionhub.com/belgrade-montana-school-malware/
  11. Government Technology. "FBI: Powered by Crypto, Cyber Crime Cost Montana $53M in 2025." April 2026. https://www.govtech.com/security/fbi-powered-by-crypto-cyber-crime-cost-montana-53m-in-2025
  12. Federal Bureau of Investigation, Internet Crime Complaint Center. "2025 Internet Crime Report." https://www.fbi.gov/file-repository/2025_ic3report.pdf/view
  13. Cybersecurity Dive. "MS-ISAC enters uncertain new era after losing federal funding and thousands of members." June 2026. https://www.cybersecuritydive.com/news/ms-isac-membership-loss-states-federal-funding-cut/821984/
  14. Modan, Naaz. "FCC wants to know: Should the E-rate program be eliminated?" K-12 Dive, June 25, 2026. https://www.k12dive.com/news/fcc-wants-to-know-should-the-e-rate-program-be-eliminated/823813/
  15. CoSN. "FCC Opens Public Comment Period on Proposed Changes to E-Rate." August 14, 2026. https://www.cosn.org/cosn-news/fcc-opens-public-comment-period-on-proposed-changes-to-e-rate/
  16. Federal Communications Commission. "Report Cards and Diplomas: Progress in Meeting the Goals of the E-Rate Program." July 29, 2026. https://www.fcc.gov/news-events/blog/2026/07/29/report-cards-and-diplomas-progress-meeting-goals-e-rate-program
  17. National Institute of Standards and Technology. "Cybersecurity Framework." https://www.nist.gov/cyberframework

About the author

Jeff Patterson

Thank you for visiting the K12 Montana blog!