K-12 Cybersecurity Act of 2021 Launches Initiative to Combat Increasing Cyberattacks on Schools
Client Alert | 4 min read | 10.19.21
On October 8, 2021, President Biden signed the K-12 Cybersecurity Act of 2021 (the “Act”) that establishes an education cybersecurity initiative to equip elementary and secondary schools with strategies to combat cyberattacks. The Act directs the Cybersecurity and Infrastructure Security Agency (“CISA”) to collaborate with educational leaders and experts to produce a study of the cybersecurity risks facing K-12 schools and develop recommendations for educational institutions to address those risks.
The regimented approach outlined in the Act’s K-12 Education Cybersecurity Initiative to evaluate the systemic flaws that expose schools to an increased risk of ransomware and cyberattacks will take CISA nearly a year to complete, but could potentially result in a more robust, standardized strategy for educational institutions to address the issue. The approach includes:
- Cybersecurity Study. CISA has until February 5, 2022 (120 days from the law’s enactment) to complete a study evaluating the cybersecurity risks plaguing K-12 schools and assessing the obstacles schools face in securing and implementing cybersecurity protocols. The Act requires CISA to provide a Congressional briefing at the conclusion of the study.
- Cybersecurity Recommendations. By April 6, 2022 (60 days after completing the risk study), CISA must provide security recommendations, including cybersecurity guidelines for K-12 schools. Notably, these guidelines will be voluntary for K-12 schools to adopt.
- Online Training Toolkit. By August 4, 2022 (120 days after generating cybersecurity recommendations), CISA is required to develop an online training toolkit designed to educate school officials on CISA’s cybersecurity recommendations and provide strategies for its implementation.
- The completed study, recommendations, and online toolkit will be accessible to the public on the Department of Homeland Security’s website.
Some may question how the Act will be a value-add to the cybersecurity information currently available, particularly when the implementation of the final CISA work product – the cybersecurity recommendations – is voluntary. CISA already provides K-12 resources on its Stop Ransomware website; however, much of its content is reference materials and tip sheets for students, teachers, parents, and school district staff that serve as cybersecurity best practices without a more thorough analysis into the vulnerabilities in school districts’ information ecosystems across the country.
In a statement about the Act, U.S. Senator Jacky Rosen who co-sponsored the bill, recognized that “[c]ybersecurity can be expensive and debilitating, especially for small organizations or public entities.” The Act comes as a response to what is identified as a need for “an immediate federal response to improve cybersecurity” for school districts across the nation. The CISA recommendations could serve as more concrete guidance that schools may implement as a standard across their information security protocols, rather than on a user-by-user basis.
The result of CISA’s study could have far reaching implications at a time when cyberattacks on schools are on the rise. CISA’s study could identity the key systemic issues affecting school districts across the country, as well as shed light on the immeasurably inadequate resources certain districts may have to fight ransomware and other cyber threats. This would allow for better clarity on how school districts could fundamentally shore up their cybersecurity infrastructure to better protect student and employee information and keep up with the pace of evolving information security developments. Moreover, the results of the study could represent the first steps in the federal government being able to help avert and mitigate cyber incidents in K-12 educational institutions.
While educational institutions are given the option under the Act whether to implement CISA’s cybersecurity recommendations, cyber incidents are on the rise and many schools – both K-12 and higher education – will want to at least consider federally recommended guidelines. A 2021 report by the K-12 Cybersecurity Resource Center and the K12 Security Information Exchange identified 408 publicly-disclosed school cyber incidents in 2020. In the same year, there were 145 data breach incidents involving public schools, and most incidents involved both student and staff data. A State of Ransomware report outlined that, in 2020, 1681 schools, colleges, and universities were subject to ransomware attacks.
Educational institutions should consider how to best implement a strong privacy and cybersecurity culture across its staff and students, have strong incident response plans, and remain vigilant in pursuing resources to further their cyber priorities. All educational institutions, including independent schools, may want to consider leveraging the CISA recommendations since cyberattacks rarely discriminate between institution types. Exercising good cybersecurity hygiene can only further benefit schools in the long term.
Crowell & Moring is adept at navigating privacy & cybersecurity issues and has a robust education practice that includes counseling and training institutions on how to strengthen their security, develop and implement privacy and data protection programs, and comply with applicable laws. We have extensive experience managing the crises that can arise in the event of a breach, including those involving personal information, and other sensitive or proprietary information.
Contacts

Partner, Crowell Global Advisors Senior Director
- Washington, D.C.
- D | +1.202.624.2698
- Washington, D.C. (CGA)
- D | +1 202.624.2500
Insights
Client Alert | 5 min read | 12.12.25
Eleventh Circuit Hears Argument on False Claims Act Qui Tam Constitutionality
On the morning of December 12, 2025, the Eleventh Circuit heard argument in United States ex rel. Zafirov v. Florida Medical Associates, LLC, et al., No. 24-13581 (11th Cir. 2025). This case concerns the constitutionality of the False Claims Act (FCA) qui tam provisions and a groundbreaking September 2024 opinion in which the United States District Court for the Middle District of Florida held that the FCA’s qui tam provisions were unconstitutional under Article II. See United States ex rel. Zafirov v. Fla. Med. Assocs., LLC, 751 F. Supp. 3d 1293 (M.D. Fla. 2024). That decision, penned by District Judge Kathryn Kimball Mizelle, was the first success story for a legal theory that has been gaining steam ever since Justices Thomas, Barrett, and Kavanaugh indicated they would be willing to consider arguments about the constitutionality of the qui tam provisions in U.S. ex rel. Polansky v. Exec. Health Res., 599 U.S. 419 (2023). In her opinion, Judge Mizelle held (1) qui tam relators are officers of the U.S. who must be appointed under the Appointments Clause; and (2) historical practice treating qui tam and similar relators as less than “officers” for constitutional purposes was not enough to save the qui tam provisions from the fundamental Article II infirmity the court identified. That ruling was appealed and, after full briefing, including by the government and a bevy of amici, the litigants stepped up to the plate this morning for oral argument.
Client Alert | 8 min read | 12.11.25
Director Squires Revamps the Workings of the U.S. Patent Office
Client Alert | 8 min read | 12.10.25
Creativity You Can Use: CJEU Clarifies Copyright for Applied Art
Client Alert | 4 min read | 12.10.25
Federal Court Strikes Down Interior Order Suspending Wind Energy Development
