AccuSights
PartnersBlogAbout
Book my 30-minute demo

Blog / The data you hold

The data you hold

Private Schools, Tutoring Centers and the Shared Link: Student Data When IT Is One Person Who Also Teaches Robotics

Private school student data and FERPA: what schools hold, which rules apply when you take no federal funds, and the 56 safeguards one IT person can run.

Sam KhanSam Khan The Cyber ExpertFounder and CEOJanuary 11, 2027 · 6 min read

The link that was still open

The director of technology at a 420-student independent K-8 school outside Charlotte also teaches the middle-school robotics elective on Tuesdays and Thursdays. That is the whole IT department. Two hundred Chromebooks, forty staff laptops, a student information system, a fundraising database, and a Google Workspace that has been accumulating documents since 2016.

In the second week of January she is cleaning up shared drives before the re-enrollment mailing. She opens a spreadsheet last edited in 2023 by an admissions assistant who left the following summer.

It has 380 rows. Student names, dates of birth, home addresses, allergy notes, the counselor's shorthand about two learning plans, a column for family financial aid status, and the last four digits of the card each family used for the deposit. Sharing is set to anyone with the link.

She checks the link history. It went into an email thread with a summer camp vendor, a photographer, and a parent volunteer's personal address.

Nobody did anything wrong on purpose. Somebody needed the list, the fastest way to send it was a link, and the link outlived the person, the vendor and the school year. Her next thought is the one every school leader eventually has: how many more of these are there, and who would tell us if one of them left the building.

What the heck does this mean

Student data is a mixed pile with different rules attached to different parts of it.

The education record is the school's file on a student: grades, discipline, counselor notes, learning plans. FERPA, the Family Educational Rights and Privacy Act, governs those records at schools that receive funds under applicable Department of Education programs. Many independent schools do not, which is why FERPA is quoted at private schools more often than it applies.

State student-privacy laws are the ones that catch you anyway. They follow the student's residence and they reach the vendors you share data with, which for a school is a long list of learning apps.

GLBA Safeguards obligations arrive with Title IV federal student aid, because family financial information turns a school into an institution handling consumer financial data.

And the enrollment contract is a rule too. Whatever the handbook promises parents about privacy, a court will read it as a commitment.

The numbers that matter

Vulnerability exploitation was the leading initial access route in education and the public sector at 34 percent, according to the Verizon 2026 Data Breach Investigations Report. Old systems, small teams, long summer to-do lists.

Ransomware appeared in 88 percent of breaches at small and medium businesses in the Verizon 2026 report. A school running admissions, billing and attendance on one platform is a small business with a hallway.

Implementation Group 1 of the CIS Controls defends against 77 percent of attack techniques overall and 78 percent of ransomware techniques, according to the Center for Internet Security's Community Defense Model v2.0. IG1 is 56 safeguards, which is a school-year project, not a career.

What to do this week

  1. Run a sharing audit on the whole shared drive and turn off every "anyone with the link" document that holds a student name. Do the noisy one first: the spreadsheet with 380 rows. Then set the default for new files to restricted. (CIS 3 Data Protection)
  2. Remove accounts for everyone who has left. The departed admissions assistant, the 2024 long-term substitute, the board member who needed access once. Then set a rule that offboarding happens the same week, tied to the payroll change, not to a memory. (CIS 6 Access Control Management)
  3. Put multi-factor authentication on the student information system, the fundraising database, the business office email and every administrator account. Staff email next. Students last, and only where the platform makes it workable. (CIS 6 Access Control Management)
  4. List the apps teachers actually use, including the free ones a teacher signed up for in September, and check what each one collects. Every free tool with a student roster in it is a vendor holding education records without a contract. (CIS 3 Data Protection)
  5. Test a restore of the student information system and the fundraising database, and write down how many hours it took. A school can survive a week without email. It cannot survive losing attendance and enrollment records in March. (CIS 11 Data Recovery)
  6. Spend twenty minutes at the January faculty meeting on one scenario: the email from the head of school asking for the family financial aid list, sent at 7:40pm from an address that is one character off. Give people permission to check by phone. (CIS 14 Security Awareness and Skills Training)

Where AccuSights fits

We assess schools the way we assess any business that holds sensitive records on people who cannot consent: find the data, find who can reach it, put the fixes in order. Our team implements the controls at a reasonable rate, from data loss prevention that stops a roster leaving by link to multi-factor authentication, encryption, scanning and protection of the machines in the front office. Our education page shows the work in a school's terms. Take the three-minute Cyber Hygiene Test, then spend 15 minutes with an engineer who will tell you which safeguards to do before spring.

Questions people ask

Does FERPA apply to a private school that takes no federal funds? Often it does not. FERPA attaches to schools receiving funds under applicable US Department of Education programs, and many independent K-12 schools do not. That is not the relief it sounds like. State student-privacy laws apply based on where the student lives, your enrollment contract and handbook make promises you have to keep, and a school with Title IV federal student aid picks up GLBA Safeguards obligations on top.

What is GLBA doing in a school? The Gramm-Leach-Bliley Act Safeguards Rule covers institutions that handle consumer financial information, and a school participating in Title IV federal student aid handles exactly that: family income, tax returns, account details. Those schools are expected to run a written information security program with a named responsible individual, access controls, encryption and vendor oversight. Most tutoring centers are outside Title IV, and most still hold parent payment data that deserves the same treatment.

Where should a one-person IT department start? With Implementation Group 1 of the CIS Controls v8.1, which is 56 safeguards written for organizations with limited staff and budget. The Center for Internet Security's Community Defense Model v2.0 found IG1 defends against 77 percent of attack techniques overall and 78 percent of ransomware techniques. Fifty-six is a list a teacher who also runs IT can work through across a school year.

Parents hand you their children and their tax returns on the same afternoon. Guard the second one like you guard the first.

Controls this post maps to

CIS 3 Data ProtectionCIS 6 Access Control ManagementCIS 11 Data Recovery

CIS Controls v8.1. These are the same controls our assessment scores and the console watches.

Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →

Where AccuSights fits

Our team implements these controls at a reasonable rate, from DLP to scanning to protection of assets.

Thirty minutes with an engineer, your environment on the screen, and a fixed-fee scope before the call ends. Prefer to see where you stand first? The hygiene test takes three minutes.

Compliance is not security. The audit is not the exam; the attacker is.