Compliance
What districts are actually required to do.
The part that is settled federal law, the part that varies by state, and the part that is not law at all but still decides whether your insurance renews.
Federal
The three that apply almost everywhere.
FERPA
Protects student education records and governs who may see them. It shapes how records systems are accessed, who holds administrative rights, and what happens when data is exposed.
CIPA
Ties internet filtering and a written safety policy to E-Rate eligibility. If you take E-Rate discounts this is not optional. It is a compliance obligation, not a security control.
COPPA
Governs collection of personal information from children under 13, which reaches into the classroom apps teachers adopt, often without IT being asked first.
Worth being clear: CIPA is about filtering and policy. Passing it does not mean an attacker cannot get in. The two get conflated constantly in vendor material.
State
This part genuinely varies.
State requirements for school cybersecurity have expanded quickly and they are not consistent.
- Breach notification. Every state has one and the clocks differ. Tennessee, for example, requires notification within 45 days of discovery.
- Incident reporting. Some states require districts to report to a state education or cybersecurity agency, separately from notifying individuals.
- Vendor and student-data agreements. Several states impose specific contract terms on anyone handling student data.
We will not quote your state statute at you. Requirements change, they differ by state, and getting one wrong in a sales conversation is worse than useless. Tell us which state you are in and what you have been asked to satisfy, and we will scope to it.
Not law, but decisive
Your cyber insurer asks harder questions than your state does.
Is anyone monitoring after hours?
Guardian is the answer on the renewal form: 24/7 analysts with the authority to isolate a machine.
Do you train staff and test them?
BlueHook: simulations, training completion by name, and the record of real threats removed.
When was your last penetration test?
Red Team: a dated assessment with a retest, and a posture score that moves between renewals.
Get started
Tell us what you have been asked to satisfy.
Your state, the questionnaire, the audit letter. We will tell you which program produces the evidence, or that none of them do.
Reply within one business day. No sales sequence, no mailing list.
