Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A U.S. school should activate its incident-response and communications plans, preserve evidence, determine which systems and information may have been affected, and report the intrusion to appropriate authorities. Separately, it must assess whether state or other applicable law requires notice to families. FERPA does not itself require a school to notify parents that education-record information was stolen or improperly released, and there is no single family-notification deadline established for every U.S. school.

What should a school do first?

Use the school’s incident-response plan and communications plan rather than improvising separate technical and public responses. Bring in the IT or security team, school leadership, relevant service providers, the insurer, and other stakeholders identified in the plan. Keep leadership informed as facts develop, and coordinate public statements with communications staff so updates remain accurate.

CISA recommends maintaining and exercising an incident-response plan with response and notification procedures for ransomware and data-extortion or breach incidents. Its #StopRansomware Guide, developed with the FBI and NSA, also emphasizes a communications plan.

Preserve evidence and establish what is known

Work with qualified incident responders and law enforcement as appropriate. CISA advises collecting relevant logs and malware or indicators, capturing system images and memory where appropriate, and preserving volatile evidence that could otherwise be lost. Avoid making changes that could destroy useful evidence unless needed to contain immediate harm.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For the notification assessment, determine which systems and records were affected; what categories of personal information may be involved; whose information may be implicated; and whether there is evidence of access, acquisition, or disclosure. A cyberattack alone does not establish that student records were accessed or released. The Department of Education’s guidance on unauthorized disclosure explains that whether a disclosure occurred depends on whether personally identifiable information from education records was made available to an unauthorized party.

How should a school report the cyberattack?

Report while the investigation is under way; the school does not need to wait until every fact is settled. CISA’s K–12 cybersecurity report urges schools to report every cyber intrusion to the U.S. government. The CISA K–12 report describes reporting through CISA and notes the FBI’s encouragement to report internet-crime victimization to IC3.

  1. Report to CISA: Use the reporting route identified in CISA’s #StopRansomware Guide or the Report to CISA webpage referenced in its K–12 report. The guide says organizations should report an incident to CISA and may request assistance.
  2. Contact the FBI: The guide identifies both a local FBI field office and the FBI’s Internet Crime Complaint Center (IC3) as options.
  3. Contact the U.S. Secret Service: A local Secret Service field office is another reporting or assistance option listed in the guide.
  4. Consider MS-ISAC support: CISA’s K–12 report describes support for eligible public K–12 entities, including 24/7 assistance. Confirm eligibility and current service details directly.

Provide the facts currently known and update reports as the investigation develops. The school’s response plan may specify who is authorized to make reports and how they are coordinated.

Does FERPA require the school to notify parents?

Not by itself when education-record information is stolen or otherwise released without authorization. The Department of Education’s K–12 parent guide to school data breaches, last updated in May 2021, says FERPA does not require a school to notify a parent in that situation, though the agency or institution must maintain a record of each disclosure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

That federal rule does not answer whether notice is required under other law. CISA advises organizations to ensure their breach-notification procedures comply with applicable state law. Requirements, recipients, and deadlines can vary by jurisdiction and incident, so a school should check the law that applies to its location and the data involved, along with relevant local policies, contracts, and insurance conditions. The sources cited here do not establish a universal U.S. deadline or a single set of recipients.

When and how should families be notified?

After assessing the facts and applicable notice duties, notify affected families when required or when appropriate under the circumstances. Do not equate an attack with confirmed exposure, but do not delay a legally required notice while waiting for certainty beyond what the law demands. Get jurisdiction-specific legal advice before announcing a deadline or deciding who must receive notice.

Make the notice useful and precise

CISA advises that a notice describe the type of information exposed, recommend practical steps to reduce misuse, and provide relevant contact information. A clear school notice should also:

  • Distinguish confirmed facts from matters still under investigation.
  • Explain who may be affected and what categories of information may be involved, without claiming more than the investigation supports.
  • Tell families what practical protective steps are supported by the facts, and how to contact the school with questions.
  • Give a realistic account of when the school expects to provide another update, if more information is not yet available.

The required timing and content still depend on applicable law. Coordinate the notice with communications staff and the response team so that it is consistent with what the school can substantiate.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What should parents do if a school reports an exposure?

Read the notice for the information categories involved, the affected period or group, any recommended account or identity-protection steps, and the school’s contact route. Ask the school whether the information was confirmed as accessed or disclosed, what remains uncertain, and when it expects to update families. Use only protective steps that fit the information and accounts actually implicated; a notice may not establish that every student’s records were exposed.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.