On August 12, the Cybersecurity and Infrastructure Security Agency released the K-12 Cybersecurity Foundations Resource Package, a free collection of guides, videos, and quick-reference materials built specifically for schools and districts. It is not another high-level warning about the threat landscape. It is a set of working documents with named objectives, associated practices, and enough structure that a district technology director can turn it into a project plan.
For Montana districts, the timing is useful. School starts in a few weeks. Budgets for the year are largely set. And the free federal supports districts leaned on in past years have gotten thinner, not thicker.
Here is what is in the package, what it is worth, and what a Montana district should do with it between now and the first day of school.
The package has two guides at its center, plus supporting material.
The Getting Started Guide is written for superintendents, business managers, principals, and other non-technical leaders. It covers the threats schools face and walks through four foundational steps a district can take regardless of size, budget, or in-house expertise.
The Implementation Guide is the deeper document, written for the people who will actually do the work. It organizes practices around eight objectives:
Alongside the guides is a six-part video series (two sets, one per guide) and quick-reference material for navigating the package. CISA says it developed the resources with input from K-12 stakeholders and cybersecurity practitioners, and aligned them to the NIST Cybersecurity Framework and its own earlier K-12 guidance.
Everything is free. There is no registration wall, no vendor attached, and no procurement required to start reading.
Access the package here: cisa.gov/topics/cybersecurity-best-practices/K12cybersecurity/foundations
You will see two contradictory framings of K-12 cyber risk this month. Both are partly right.
The encouraging read. Ransomware attacks on the education sector dropped 13 percent globally in the first half of 2026, from 120 in the back half of 2025 down to 104, according to Comparitech's H1 2026 education roundup. In the United States specifically, researchers logged 34 attacks across K-12 and higher education combined, a 44 percent decline from the 61 recorded in the second half of 2025. K-12 attacks worldwide fell 26 percent.
The less encouraging read. That decline was not evenly distributed. Attacks on higher education rose more than 8 percent over the same period. And the attacks that did land were expensive: the median ransom demand across the education sector climbed to roughly $420,620, up 53 percent from about $275,000 six months earlier. Of the 104 attacks tracked, only 36 were confirmed by the targeted organizations, which means the real number is a floor, not a ceiling. Districts frequently do not disclose.
There is also a structural change worth naming. The Multi-State Information Sharing and Analysis Center, which many districts relied on for free threat intelligence and incident response support, lost its federal funding and has since lost roughly 70 percent of its membership, including dozens of states and more than 10,000 local jurisdictions. CISA itself saw its workforce cut by close to a third during the first half of 2025.
So the practical situation for a small Montana district is this: the odds of being hit may have ticked down slightly, the cost of being hit went up, and the free help you used to be able to call has largely gone away. That is the context this new CISA package arrives in, and it is a fair reason to take it seriously rather than filing it.
You do not have to look to Texas or Minnesota for a relevant example.
In early April 2026, Belgrade School District No. 44 in Gallatin County, which serves more than 3,200 students across five schools, experienced a malware incident that disrupted network systems. The district notified families on April 6 that it was working to repair systems. Parents later reported that the disruption affected routine school operations, including lunch processing and assignments.
On April 17, trustees authorized $750,000 for network security and restoration services connected to the incident. That figure prompted community speculation about a ransom payment, and Superintendent Dede Semerad clarified publicly that the money was for restoring system functionality and preventing future incidents, not a ransom. By May 18 the district said its review had found no evidence of unauthorized access to Infinite Campus, its student information system, while review of other systems continued. Restoration work was expected to run into June. The district has not publicly confirmed ransomware, a ransom demand, or a threat actor.
Belgrade handled the incident the way you would want a district to handle it: isolate, respond, investigate, communicate. But the number to sit with is $750,000, in a district that was simultaneously working through a budget deficit. That is what an incident costs before anyone has proven data was stolen.
Statewide, the direction of travel is not subtle either. Montanans reported a record $53 million in losses to cyber crime in 2025, up from $31.6 million the year before, with losses quintupling since 2021 according to FBI Internet Crime Complaint Center data.
Rural and small does not mean invisible. Among the U.S. districts that confirmed ransomware attacks in the first half of 2026 were Wagon Mound Public Schools in New Mexico, a district of a few dozen students, along with Delano Public Schools in Minnesota, Denmark School District in Wisconsin, and Alcorn School District in Mississippi. Attackers are not filtering by enrollment.
The CISA package is genuinely good, and it is also not a security program. It is a description of one.
The gap between reading the Implementation Guide and satisfying its eight objectives is staffing, tooling, and sustained attention. Objective two asks you to safeguard devices and assets. That presumes you have a current, accurate inventory of every device on your network, who has it, what is on it, and whether it is patched. Objective three asks you to perform, verify, and test backups. Most districts do the first part. Far fewer do the second and third. Objective four asks for an incident response plan that has actually been exercised, not one that exists as a PDF on a shared drive.
This is where districts stall out. Not because the guidance is unclear, but because there is no one whose job it is to own it.
If your district has no dedicated security staff, the useful way to read the package is as a gap-assessment instrument, not a to-do list. Score yourself honestly against each objective, identify the three or four gaps that would hurt most in an actual incident, and fund those first.
A realistic sequence for a Montana district before school ramps up:
Week 1: Read and score. Download the Getting Started Guide and Implementation Guide. Have your technology director or IT partner score the district against all eight objectives on a simple scale: in place, partial, absent. This is a two-hour exercise, not a two-week one.
Week 2: Close the credential gap. Multi-factor authentication on staff email and administrative accounts is the single highest-return control on the list. If MFA is not enforced on your Google Workspace or Microsoft 365 tenant, on your student information system, and on any remote access path into the network, that is the first fix. Review privileged accounts while you are in there and remove standing admin rights that no longer belong to anyone's current job.
Week 3: Prove your backups. Do not confirm that backups are running. Restore something. Pick a real system, restore it to a test environment, and time it. If you cannot state your recovery time for the student information system in hours, you do not have a tested backup, you have a backup job.
Week 4: Write and walk through the incident response plan. It needs names, phone numbers that work when district email is down, a decision path for who talks to families and media, your cyber insurance carrier's notification requirements, and a defined threshold for when you call law enforcement. Then run a 60-minute tabletop with your leadership team before the first bell.
Ongoing: Vendor access. Most districts have more third-party access into their environment than they realize, and the education sector's largest recent breaches have come through vendors rather than direct attacks on districts. Inventory every vendor with a login or a network path into your systems, confirm each one still needs it, and confirm each one has MFA enforced.
Boards do not need the Implementation Guide. They need four things, in a one-page summary at the next regular meeting:
That fourth item matters more than it looks. Cybersecurity is a governance decision, not just an IT decision, and documenting accepted risk is what turns a board from a bystander into a participant. CISA's own framing in this release is that K-12 cybersecurity has moved past being an IT department concern and belongs alongside physical safety and security.
Any conversation about paying for K-12 cybersecurity in Montana runs into E-Rate.
On June 25, 2026, the FCC voted to open a broad review of the E-Rate program, adopting a combined Notice of Proposed Rulemaking and Further Notice of Proposed Rulemaking (FCC-26-41) under WC Docket No. 26-133. Among the many questions raised is whether the program should be narrowed or reoriented, including whether it should be limited or sunset.
The FCC has pushed back on characterizations of this as a plan to end the program, stating that it did not vote to eliminate E-Rate and that no school or library loses support as a result of the June vote. Education groups including CoSN and the SHLB Coalition read the proposal as a serious enough risk to organize advocacy around it.
Either way, the procedural facts matter for planning: the proposal was published in the Federal Register in August, comments are due October 13, 2026, and reply comments are due November 12, 2026. If your district depends on E-Rate discounts for connectivity or internal connections, this is the window to file, and it is worth a line item in your fall board packet regardless of which reading you find more persuasive.
We work with Montana school districts and nonprofits that mostly do not have a dedicated security staff, and often do not have a dedicated IT staff either. The CISA package is a good fit for exactly that situation, because it is designed to be implemented by generalists.
What we can do with it:
If you want to start with the free version, start with the free version. Download the guides, score yourself, and see where you land. If the gaps are bigger than your team can close before students arrive, get in touch and we will work through it with you.
Is the CISA K-12 Cybersecurity Foundations package free? Yes. All components, both guides, the six-part video series, and the supplemental materials, are published free on CISA's website with no registration required.
Does our district need dedicated IT security staff to use it? No. The Getting Started Guide is written specifically for district leaders without technical backgrounds, and its four foundational steps are designed to work regardless of district size, expertise, or funding level.
How is this different from CISA's earlier K-12 guidance? The earlier material was primarily a report on the threat landscape with high-level recommendations. This package is implementation-oriented: named objectives, associated practices, and instructional video walking through each one. CISA states the package builds on and aligns with its earlier guidance and the NIST Cybersecurity Framework.
Are ransomware attacks on schools getting better or worse? Both, depending on the measure. Attack volume against U.S. education fell substantially in the first half of 2026, while ransom demands rose sharply and support resources for districts contracted. Lower probability, higher consequence.
What should a small Montana district do first? Enforce multi-factor authentication on staff email, administrative accounts, and the student information system, then test a real backup restore. Those two items address the most common entry point and the most common recovery failure.