Right-Sized Public Tech field kit

K-12 cybersecurity readiness

A bounded readiness session that turns broad cybersecurity concern into named owners, evidence, and the next exercise.

For district leadership, IT, communications, finance, legal, privacy, safety, and operational owners

Factual resources last verified August 26, 2026

Use this kit when

The workload is real, but the review path is not.

  • The incident response plan exists but has not been exercised with non-IT leaders.
  • Backup status is reported, but restore evidence is not routinely reviewed.
  • Security work competes with operational priorities and needs an executive decision record.

Minimum review packet

Bring evidence, owners, and open questions.

Packet item 1

Current incident response and continuity plans

Packet item 2

Named decision, technical, communications, legal, privacy, safety, and vendor contacts

Packet item 3

Critical-service and system inventory with owners

Packet item 4

Most recent backup restore-test evidence and unresolved gaps

Packet item 5

Current multifactor authentication, patch, and externally exposed service status

Packet item 6

Vendor incident duties, notification paths, and access dependencies

Working sequence

A 45-minute review.

  1. Set the decision boundary

    Choose one realistic scenario and the services, people, vendors, data, and facilities in scope.

  2. Walk the first hour

    Name who detects, confirms, contains, escalates, communicates, preserves evidence, and decides on service continuity.

  3. Test recovery assumptions

    Ask for evidence of the latest restore test, recovery priorities, dependencies, and who can authorize the recovery sequence.

  4. Record gaps without turning the session into an audit

    Capture missing owners, inaccessible contacts, untested assumptions, unclear vendor duties, and blocked decisions.

  5. Assign the next exercise

    Choose no more than three corrective actions, each with an owner, evidence target, due date, and next tabletop date.

Leave with

A decision record, not another discussion.

  • Named incident and recovery decision owners
  • Critical-service recovery order
  • Backup and restore evidence gaps
  • Vendor and communications dependencies
  • Three prioritized actions and a next exercise date

Local verification required

  • Do not place credentials, network diagrams, vulnerabilities, student records, personnel information, or incident details into this public worksheet.
  • Use your approved incident, legal, privacy, communications, insurance, and law-enforcement procedures for a real event.
  • This session does not replace a technical assessment, incident response service, or local legal and policy review.

Primary sources

What this kit relies on.

The NIST Cybersecurity Framework 2.0

National Institute of Standards and Technology. February 26, 2024. Last verified August 26, 2026.

A non-prescriptive set of outcomes across Govern, Identify, Protect, Detect, Respond, and Recover.

Data Security: K-12 and Higher Education

U.S. Department of Education Student Privacy Policy Office. Current resource hub. Last verified August 26, 2026.

Safeguarding student records, data security, data flows, retention, destruction, and online-service considerations.

No related JSTK product is presented for this lane.

The source-backed readiness work stands on its own.

Cut the next scope.

Turn this review into a bounded working brief.

Open the Scope Cutter