AccuSights
PartnersBlogAbout
Book my 30-minute demo

Private Schools & Tutoring · Cybersecurity, compliance and GRC, in plain English

Sixty years of trust, protected every night.

A school holds the most sensitive files a small organization can: grades, health forms, custody orders and the notes a teacher writes when a child is struggling. Extortion crews post those first. We scope every vendor and contractor login, encrypt the devices that go home, protect the staff inboxes and watch the student information system so the school’s name stays out of the news.

Built for independent schools and tutoring centersVendor review includedSee your score immediately

The test is scored against CIS Controls v8.1 IG1 and the CIS Community Defense Model. You see your score immediately, then we talk if you want to.

A story we hear too often

The morning a school’s student files showed up in a parent’s inbox

the head of a 300-student private K-8 school and its after-school tutoring program

Sister Anne has run the school on Ashland for fourteen years. Three hundred students, thirty staff, a tutoring program that fills the building until six. The student information system holds grades, health forms, custody orders and the notes teachers write when a child is struggling.

On a Wednesday in October a parent forwards an email. It is addressed to her by name, mentions her son’s reading plan and the family’s tuition balance, and asks her to pay a ‘late fee’ by gift card. Two more parents forward the same email by nine. The attacker did not guess; the attacker read.

In the version that goes badly, the export tool on the student system was used the week before with a contractor’s stolen password, every family’s data is gone, the custody orders are on a leak site, and the school’s reputation, built over sixty years, is a local news segment.

In Sister Anne’s version, the contractor’s login had been cut when it appeared from a country the school has never worked with, the export never ran, and the three emails came from an old parent-directory PDF a former staffer had kept. The engineer traces it in an hour. The school tells the parents the truth by lunch, and the truth is small.

The attacker did not guess; the attacker read.

What changes the ending

  1. Contractor and vendor access scoped, time-limited and watched, including the export tool (CIS Controls 15 and 6, Service Provider Management and Access Control)
  2. Student data encrypted, kept only as long as needed and never in a PDF on a home laptop (CIS Control 3, Data Protection)
  3. Login monitoring that cuts a session from the wrong country before the export runs (CIS Control 13, Network Monitoring and Defense)
Show me this running for my business

The questions owners are afraid to ask

Ask them anyway. Here are the answers.

If our student information system vendor is breached, is it our problem or theirs?

It is yours in every way that matters: the parents are yours, the notification is yours under state law and the trust is yours to lose. The December 2024 breach of a major K-12 platform reached about 62 million student records through one stolen support credential, so the assessment reviews your vendors’ access and your own copy of the data.

What if a teacher’s laptop with grades and health forms is stolen from a car?

If the drive is encrypted and the account has MFA, it is a lost laptop; if not, it is a breach notice to every family. Encryption, device inventory and remote wipe are day-one controls in the assessment.

We are a private school and FERPA does not cover us. Do we still have obligations?

Yes: state student-privacy and breach laws, COPPA for online services used by children under 13, PCI for tuition payments, your insurer’s conditions and the promises in your enrollment contract all apply. The assessment maps which ones and puts the controls behind them.

What you hold, and why someone wants it

Your data protection needs, by the data.

Student records: grades, health forms, custody orders, counseling notes

The most sensitive files a small organization can hold, and the ones extortion crews post first. Encryption, access limits and vendor control protect them.

Family financial and tuition data

Payment details, financial-aid forms and balances that make a phishing email convincing. Payment-page hardening and PCI controls protect them.

Staff and teacher accounts

Thirty mailboxes with access to every child. MFA and login monitoring protect them.

The student information and learning platforms

Vendors with export tools and support logins. Contract terms, access scoping and monitoring protect them.

Classroom and 1:1 devices

Laptops that go home with children and teachers. Device management, encryption and remote wipe protect them.

85%
of ransomware attacks on education organizations in the past year began with identity-based techniques such as phished or stolen credentials; recovery costs averaged $2.26 million
Source: Sophos, The State of Ransomware in Education 2026
5
cyber incidents per week on average across US school districts
Source: US Department of Education, K-12 Cybersecurity guidance, 2025
62M
student records taken from one K-12 platform through a single stolen support credential in December 2024
Source: BleepingComputer, reporting the PowerSchool breach and the Texas lawsuit, 2025

No regulator at the door, still rules that apply

What you are still on the hook for, in one page.

FERPA
US Department of Education
Applies to schools that receive funds from the Department; many private K-12 schools are outside it, while Title IV colleges are inside. Enrollment contracts and state law fill the gap.
COPPA and state student-privacy laws
FTC and state attorneys general
COPPA governs online services used by children under 13; most states have student-data privacy laws that reach private schools through their vendors.
PCI DSS v4.0.1 and GLBA Safeguards
PCI SSC and the FTC
Tuition and fee payments by card fall under PCI; institutions that participate in Title IV federal aid carry the Safeguards Rule.

Verified September 2026 from the regulators' own publications. We map all of it to one control set so evidence is produced once.

A note on authority: the regulator, auditor or certifying body has the final say on whether you comply. We help interpret the requirements, scope what applies, gap-assess against what is published today, and keep you compliance-ready and secure as the guidance evolves. We hold no regulatory authority and do not certify.

The threat picture

What actually goes wrong, and what we do about it.

  • A vendor or contractor login used to export every family’s records in one night.
  • Extortion emails to parents, written from the child’s own file.
  • A teacher’s unencrypted laptop with grades and health forms, left in a car.

It happened to businesses like yours

In December 2024 an attacker used a stolen support credential and a built-in export tool to take records on about 62 million students and 9.5 million teachers from PowerSchool, the largest US K-12 student information system; Texas sued in 2025.

December 2024 · BleepingComputer

After Minneapolis Public Schools refused a $1 million ransom in March 2023, the Medusa gang dumped more than 300,000 files online, including complete student sexual-assault case files, medical records and discrimination complaints.

February to March 2023 · Associated Press

Public incidents, listed to show the pattern, never to shame a victim.

Protect, for a education business

We protect your people, every device, the servers and the website. Day and night.

  • We protect every teacher and office inbox, where the fake tuition notice and the spoofed head-of-school request arrive.
  • Every staff laptop, office workstation and the classroom devices that go home.
  • The server and the file share holding health forms, custody orders and counseling notes.
  • The website and the online enrollment and tuition-payment pages.
  • The cloud apps: the student information system, the learning platform, email and payroll.
  • Day and night, with an AI agent that contains a threat in seconds and a named human engineer watching.

Think of it as a per-employee service, like payroll. Except that this is the one corner that, if you cut it, can empty the account and take the business with it. We have your back.

How Protect works →

Where we start

Cybersecurity and Data Protection Assessment for Schools

Built on the CIS Controls v8.1 IG1 and scoped from what a school stands to lose: the children’s files, the families’ trust and sixty years of reputation. It maps the student data, the vendors that can export it and the devices that carry it home, then ranks the fixes for a head of school, not an IT department.

  • Inventory of every staff device, classroom device, server and cloud platform, including the SIS and the learning tools (CIS Controls 1 and 2)
  • Student-data map: where grades, health forms and custody orders live, who can export them, and how long they are kept (CIS Control 3)
  • Vendor and contractor access review for the student information system and every platform with a support login (CIS Controls 6 and 15)
  • Account audit: MFA for staff, shared classroom logins, ex-employee and substitute access (CIS Control 5)
  • Backup and restore test for the SIS, the file share and the finance system (CIS Control 11)
  • Regulation map (state student privacy, COPPA, PCI, FERPA where it applies) and a ranked remediation plan
Start with the 3-minute test

Packages

Built for education businesses, with the price on the page.

Cyber and Data Protection Assessment

A complete read on your exposure: every endpoint, server, cloud account and identity inventoried, controls tested against CIS and NIST CSF 2.0, threats mapped to your industry, and a plan ranked by what would actually hurt.

Fixed feescoped in 30 minutes
1 to 3 weeks
Details →

Governance, Risk and Compliance (GRC), simplified

The discipline the largest institutions run, sized for a business that cannot hire a department for it.

Governance, Risk and Compliance is how a bank or a hospital system decides what to protect, proves it is protected, and shows a regulator the evidence. We ran it for those institutions. We now run it for the 30-person supplier, the medical practice and the defense subcontractor, because that is where the supply chain is thinnest and where a breach does the most damage, sometimes to more than one company.

Governance

Who owns security, which policies are real, and what the owner signs. One page, not a binder.

Risk

What could stop the business, ranked by likelihood and cost, refreshed as the threats change, not once a year.

Compliance

The evidence a regulator, a prime contractor or a customer asks for, produced once and kept current every day.

A defense contractor with 40 people is a link in a national supply chain. A breach there is not a small-business story; it is a national-security one. The same is true, at a smaller scale, for the accounting firm that holds 900 client returns and the clinic that holds 12,000 patient records.

Questions owners ask

Straight answers.

Does FERPA apply to private schools?
Only to schools that receive funds from the US Department of Education, which most private K-12 schools do not. State student-privacy laws, COPPA, PCI and your enrollment contract still apply, and parents expect the same care either way.
How do schools get hacked?
Mostly through people and vendors: a phished teacher password, a support contractor’s stolen login, a learning platform with an open export tool. Sophos found identity-based techniques behind 85% of education ransomware attacks in the past year.
What should a school do after a data breach?
Contain it, preserve the evidence, restore from backup, then notify families under state law with the facts rather than guesses. Schools with a rehearsed plan and a named engineer do this in days; schools without one do it on the news. The assessment writes and rehearses the plan.

People also search: cybersecurity for private schools near me · school IT security in Chicago · for a 300-student K-8 school · for a tutoring center with three locations · cybersecurity for a Catholic school · for a Montessori school · student data protection for independent schools · cybersecurity for a music or dance academy

Never too big or too small

Let's talk about your cyber anxieties. Thirty minutes with an engineer.

3-min test