The Canvas incident and a Cybersecurity Checklist for 2026
In early May 2026, a security incident at Instructure took the Canvas LMS offline for several hours and exposed names, email addresses, student IDs, and messages for an unconfirmed number of users across schools and universities. Instructure detected the intrusion, brought in outside forensics help, and restored service.

SafeShare Editorial Team6 min read
On this page
Here we present a checklist to run, regardless of whether Canvas is in your stack, K-12 districts are a genuinely frequent target, and most of what actually reduces risk is neither expensive nor exotic.
Quick Takeaways
- K-12 schools saw 96 ransomware attacks in 2025, more than any other education subsector tracked, and 116 districts were hit in 2024, affecting an estimated 2,275 individual schools (Comparitech data via K-12 Dive).
- Multi-factor authentication is the single highest-leverage fix available: Microsoft reports it blocks more than 99% of phishing-based account compromises (EdTech Magazine), and one district, IDEA Public Schools, saw a 90% drop in compromised accounts within months of requiring it.
- K-12 MFA adoption jumped from roughly 40% of districts in 2022 to about 72% by 2024, meaning a meaningful share of districts are still exposed on the easiest fix to make (EdTech Magazine).
- Free, K-12-specific resources exist for almost every item on this checklist: CISA's K-12 program, K12 SIX's Essential Cybersecurity Protections, and MS-ISAC membership.
How Often Do K-12 Districts Actually Get Hit?
Often enough that it's a "when," not an "if," for a district of any size. A 2025 Center for Internet Security survey found 82% of K-12 schools experienced at least one cyber incident between July 2023 and December 2024, totaling more than 9,300 confirmed incidents across roughly 5,000 institutions. Ransomware specifically stayed roughly flat year over year in raw attack count through 2025, but with more records exposed per incident, and average ransom demands around $556,000 in early-2025 education-sector attacks (NBOA).
That framing matters for budget conversations. This isn't a hypothetical risk a board needs convincing exists. It's a documented, recurring cost category, and the checklist below is about reducing the odds and the blast radius, not eliminating a risk that isn't real.
What's the Single Highest-Leverage Fix?
Multi-factor authentication, by a wide margin. It's the one item on this list that's both cheap and dramatically effective. Microsoft's own data puts MFA at blocking over 99% of phishing-based compromise attempts, and the real-world numbers back that up: IDEA Public Schools required MFA for staff in 2021 and saw a 90% reduction in compromised accounts almost immediately.
District adoption has been moving in the right direction, from around 40% of districts using MFA to protect network access in 2022 to about 72% by 2024, but that still leaves roughly a quarter of districts without it on their most exposed accounts. If your district has one item to knock out this month, this is it: enforce MFA on staff email and admin systems first, then extend it outward.
What Should Be in Your District's Cybersecurity Checklist?
Treat this as a starting list, not a complete audit. Each item maps to something a district IT team, even a small one, can act on directly.
Identity and access
- MFA enforced on staff email, admin consoles, and any system with student data
- Role-based access reviewed at least annually, so departed staff and over-provisioned accounts get caught
- Shared/generic logins eliminated where individual accounts are feasible
Backups and recovery
- Backups exist that are offline or otherwise isolated from the network a ransomware attack would encrypt
- Backup restoration has actually been tested, not just configured
- A written incident response plan exists and has been walked through at least once, not just filed
People and process
- Staff receive recurring phishing-awareness training, not a single onboarding session
- A clear, low-friction process exists for staff to report a suspicious email or link without fear of blame
- Leadership knows who to call first (legal, insurance, forensics, law enforcement) before an incident happens, not during one
Vendor and data risk
- Every vendor with access to student data has a signed data processing agreement specifying breach notification timelines
- For each vendor, someone can answer "what specific data does this tool actually need to function, and what happens if that data is exposed"
- Tools that don't need to store sensitive data. A video-sharing tool is a useful example: SafeShare doesn't require a student account to view a link and doesn't collect or store enrollment records or message history, since a clean video link has no reason to touch either. That's not a claim that any vendor is breach-proof; it's the same "audit what each tool actually needs" question applied to one specific, common category of ed-tech tool.
Where Do the Free Resources Come In?
You don't have to build this from scratch. Several federally- and community-backed resources exist specifically for K-12 districts, most of them free.
CISA's K-12 Cybersecurity program publishes a Getting Started Guide, an Implementation Guide, and a short video series aimed at districts without a dedicated security team (CISA).
K12 SIX's Essential Cybersecurity Protections series, updated for 2026, gives districts a concrete list of baseline defenses, an implementation rubric, and a self-assessment tool built specifically around what K-12 districts actually face, not generic enterprise security advice (K12 SIX).
MS-ISAC (the Multi-State Information Sharing and Analysis Center) offers no-cost membership to K-12 districts, including threat alerts, free security tools, and 24/7 incident assistance (CIS/MS-ISAC).
Between those three, a district with limited security staff has a real starting framework, not just a list of things to worry about.
Frequently Asked Questions
We're a small district with no dedicated IT security staff. Where do we actually start?
MFA on staff email and admin systems, then a tested offline backup. Those two items address the two most common ways districts actually get hit, and both are achievable without a security specialist on staff. CISA's Getting Started Guide is built for exactly this situation.
Is MFA really worth prioritizing over other items on this list?
Given Microsoft's figure that MFA blocks over 99% of phishing-based compromises, and that phishing remains the most common entry point for ransomware, yes. It's the highest-return item on this checklist relative to the effort required.
How do we evaluate whether a vendor's data practices are actually a risk?
Ask what specific data the tool needs to function, and what would happen if that exact dataset were exposed. A tool that needs full enrollment sync and years of message history carries different risk than one that only ever touches a video URL for a few seconds. Your signed DPA should specify breach notification timelines regardless.
Does joining MS-ISAC or using K12 SIX resources cost anything?
Both are free for K-12 districts. MS-ISAC membership and K12 SIX's Essentials series don't require a security budget to access, just staff time to implement.
We hope this was helpful!
Btw, do you need to start sharing videos safely and avoid distractions for your students?
SafeShare is the right tool for you!
We hope this was helpful!
Btw, do you need to start sharing videos safely and avoid distractions for your students?
SafeShare is the right tool for you!
One short email a month.New posts, no noise. Unsubscribe anytime.
Comments
Loading comments…