K-12 Cybersecurity Information Exchange

Full Title:
Enhancing K–12 Cybersecurity Act

Summary#

This bill would require the Cybersecurity and Infrastructure Security Agency (CISA) to set up a School Cybersecurity Information Exchange, a voluntary cyber incident registry, and a K–12 Cybersecurity Technology Improvement Program. The goal is to help elementary and secondary schools, local and state education agencies, and educational service agencies improve their cybersecurity, share lessons, and get help with threats like ransomware. The bill authorizes limited federal funding for two years to carry out these activities.

  • Main changes: create a public website with best practices and tools for K–12 cybersecurity; create a voluntary registry of school cyber incidents and publish an annual de‑identified aggregate report; create a program to deploy cybersecurity tools, services, and training for K–12 schools.
  • Who must act: CISA (the agency) must run the programs, partnering with information sharing organizations and consulting other federal agencies and state/local education leaders.
  • Privacy rule: incident data published must be de‑identified and aggregated and must follow federal and state privacy laws.
  • Funding: the bill authorizes $10 million for each of fiscal years 2027 and 2028.

What it means for you#

  • Schools, school districts, and state education agencies

    • Could use a public website with K–12‑specific cybersecurity guidance, training, and lessons learned.
    • Could search a database listing cybersecurity tools and services funded by the federal government and those recommended for state/local purchase.
    • Could search and apply for funding opportunities aimed at improving school cybersecurity.
    • Could receive cybersecurity services, tools, and training through the Technology Improvement Program.
  • School IT staff and administrators

    • May have access to tailored strategies and tools for preventing and responding to ransomware and other threats.
    • May be invited to report cyber incidents to a voluntary registry, which could help with shared learning but would not be mandatory.
  • Students and parents

    • The bill aims to improve protection of school IT systems and student online privacy through better practices and technical defenses.
    • Annual public reports on incidents will be de‑identified and aggregated, which is meant to protect personal privacy.
  • Vendors and cybersecurity organizations

    • May be engaged as partners, consulted as subject‑matter experts, or listed in databases of tools and services.
  • Federal and state agencies

    • CISA will consult with the Department of Education, NIST, FCC, NSF, FBI, and state/local education leaders in building the programs.

Expenses#

Estimated public cost: The bill authorizes $10,000,000 for each of fiscal years 2027 and 2028.

  • Direct funding: $10 million available in FY2027 and $10 million in FY2028 to carry out the Act.
  • Other costs: The bill does not provide a detailed fiscal note showing how the funds will be spent, how much will go to grants or services, or whether additional federal or state funds will be needed.
  • Administrative costs: CISA will need staff time and partner resources to build and run the website, registry, databases, reports, and the Technology Improvement Program; the bill does not detail those staffing or technology costs.
  • No information is given about grants to individual schools, matching requirements, or ongoing funding after 2028.

Proponents' View#

  • The bill appears intended to improve cybersecurity in K–12 schools by giving schools tailored guidance, shared lessons, and access to tools and services.
  • It could increase awareness and preparedness among schools by collecting and analyzing incident data and publishing de‑identified annual findings.
  • The Technology Improvement Program could make cybersecurity tools, services, and training more available to schools, helping them prevent or respond to threats like ransomware.
  • A central public website and searchable databases could make it easier for school leaders to find recommended tools and funding opportunities.

Opponents' View#

  • One concern is that the funding is limited to $10 million per year for two years; it is unclear whether that amount is enough to meet cybersecurity needs across all U.S. K–12 schools.
  • The incident registry is voluntary and the bill lets the Director decide what incidents are included; this could limit how complete or representative the collected data will be.
  • Although the bill requires de‑identification and aggregate reporting, it does not give detailed rules on how privacy will be protected in collected incident reports, which may raise implementation questions.
  • The bill leaves many operational details unspecified: how funding or services will be allocated, who is eligible for direct assistance, whether schools must apply or meet criteria, and how partnerships with private vendors will be managed. These gaps make the practical effect on individual schools uncertain.