The endpoint detection & response product running on staff and student devices. Single biggest predictor of whether ransomware detonates or gets quarantined at first execution.
Which platforms have EDR deployed today.
Who watches the EDR alerts after hours. If your EDR vendor also provides 24/7 SOC monitoring, name them here.
How staff and student devices are enrolled, configured, and pushed updates.
How OS and third-party patches reach endpoints.
Good = staff users are standard, IT uses just-in-time elevation. Acceptable = standard with local admin password solution (LAPS).
Whether staff, student, IoT/OT, and guest traffic are isolated from each other at L3.
Hard finding · Flat network
A flat network is the single biggest blast-radius multiplier in K-12 incidents. One compromised user device can reach servers, IoT, OT, and student data without crossing a control. This is a top finding regardless of other strengths.
The firewall captured here is pulled from your tech stack inventory.
If your firewall handles IDS/IPS (Field 9), select that option.
CIPA filtering is a federal funding requirement for E-rate participation.
Exploited remote access is a top-two K-12 breach root cause.
HVAC, access control, video, paging, and bell-system vendors with persistent remote access. The K-12-specific worst-offender path — if IT doesn't know about it, no other control can apply.