Playbooks

Twelve scenarios. Written for the way K-12 districts actually run.

Each playbook gives you one scenario, a first-hour checklist, a decision tree, and the regulators to call — in plain language, no vendor pitch.

Ransomware mid-school-day

Encryption hits during classroom delivery — transportation routing, lunch accounts, IEP accommodations, or state testing.

Open

Student Information System compromise

PowerSchool, Aspen, Infinite Campus, Skyward, or Synergy account takeover, grade tampering, or credential-stuffing.

Open

Teacher email / BEC

Compromised teacher mailbox — gradebook variant (transcripts) and the payroll-redirect variant (paycheck reroute).

Open

Student Google Workspace / Microsoft 365 takeover

Compromised student account — and the triage 'is this a real compromise or a student prank?' decision tree.

Open

Family communication after a breach

Templates by severity tier — SIS down one day, vendor PII breach, ransomware affecting operations, sextortion involving a student.

Open

Lunch, payment, and fundraising system compromise

MySchoolBucks, SchoolCashOnline, RevTrak, LINQ Connect — customer-data plus payment-processing implications.

Open

Transportation / bus routing system compromise

Tyler Transportation, Bytecurve, Versatrans — continuity-of-pickup, parent comms, safety implications.

Open

IEP / 504 / special-education data exposure

Extra-sensitive PII, extra-sensitive notification obligations. FERPA + IDEA + state-law overlay.

Open

Sextortion or intimate-image incident involving a student

Mandatory-reporting overlay. Coordinated with the hackfirstaid.com personal-tier sextortion playbook.

Open

Social-media incident involving a student or teacher

Doxxing, AI deepfakes of teachers made by students, coordinated bullying campaigns crossing platform and school lines.

Open

Insider threat — staff or contractor

Particularly access to grades, finance, or student data. Departing-employee overlay (mid-year vs end-of-year).

Open

Vendor / EdTech supply-chain compromise

PowerSchool's 2024-2025 incidents are the archetype. Generalizes to any SIS / LMS / payment / transportation vendor.

Open