Podcast: How to Secure Your School Data Investment

EduJedi Report Podcast: K–12 Information Security — Big Picture Insights

In this episode of the EduJedi Report Podcast, host LeiLani Cauthen, CEO of the Learning Counsel, speaks with Cisco security expert Doug Walsten to provide a broad, practical overview of information security challenges facing K–12 schools and districts. The conversation focuses on how student and staff data exists across many environments — on local devices, in school networks, and throughout cloud services and third‑party applications — and what leaders need to understand to manage risk effectively.

Widespread Data: At Rest and In Motion

Walsten explains the two fundamental states of data that every education leader should consider: data-at-rest (stored on servers, desktops, laptops, tablets, USB drives, or cloud storage) and data-in-motion (data moving across networks, between devices, or between systems and cloud services). Both states present unique vulnerabilities. Data-at-rest can be exposed by unsecured devices, weak access controls, or inadequate encryption. Data-in-motion can be intercepted if network traffic is unencrypted or if poorly configured services allow unauthorized access.

Why K–12 Environments Are Particularly Vulnerable

Schools and districts often rely on a large and diverse ecosystem of applications and systems. From learning management systems and state reporting platforms to teacher-created spreadsheets and third‑party apps used in classrooms, personally identifiable information (PII) about students and staff is widely distributed. This fragmentation increases the attack surface and complicates oversight: administrators may not always know which apps have access to sensitive data, how that data is stored, or how vendors handle privacy and security.

Regulatory and Legal Considerations

Cauthen and Walsten stress that information security in education is not only an IT issue but also a compliance and governance challenge. School leaders must account for federal and state student privacy regulations and district policies when selecting and managing technology. Ensuring contractual protections and data‑processing agreements with vendors, applying strong access controls, and maintaining clear inventory and accountability for apps and services are essential steps to meet legal obligations and protect students.

Practical Risk Mitigation Strategies

The discussion covers practical approaches that districts can adopt to reduce risk without disrupting instruction. Key recommendations include:

  • Maintaining an up-to-date inventory of all applications and systems that access student data, including the permissions each app requests.
  • Applying encryption for both stored data and network traffic to reduce exposure if devices or connections are compromised.
  • Implementing multi-factor authentication and robust identity management to limit unauthorized access.
  • Establishing vendor risk assessments and contractual safeguards that define data usage, retention, and incident response obligations.
  • Providing ongoing training for teachers, staff, and administrators so they recognize common threats and follow security best practices.

Real-World Stories and Lessons

Throughout the episode, Walsten shares anonymized, real-world examples from American school districts that illustrate how simple misconfigurations, overlooked apps, or unprotected endpoints can lead to data exposure. These stories underline the importance of proactive measures — routine audits, centralized visibility into systems, and clear policies governing app adoption and data access. While no single solution eliminates risk, the right combination of policy, technology, and training can dramatically reduce vulnerability.

Why This Conversation Matters

As schools continue to adopt digital tools and cloud services to support teaching and learning, the amount of sensitive information stored and transmitted grows. That makes informed leadership essential: district decision-makers must balance the educational benefits of technology with the responsibility to protect student privacy and secure district systems. The podcast episode offers a concise, informed perspective that helps leaders prioritize actions and better understand where to apply resources.

Click Here to Listen

This episode is a valuable resource for superintendents, technology directors, school administrators, and anyone involved in K–12 technology procurement and governance who needs a clear, actionable overview of information security issues affecting schools today.