S-5098-119
Read twice and referred to the Committee on Homeland Security and Governmental Affairs.
Sponsored by Marsha Blackburn (R-TN)
What it does
This bill would direct the Director of the Cybersecurity and Infrastructure Security Agency (CISA) to create three new programs for K-12 schools: (1) a publicly accessible website called the School Cybersecurity Information Exchange to share best practices, training, and funding opportunities; (2) a voluntary registry where schools can report cyberattacks to help track trends nationwide; and (3) a K-12 Cybersecurity Technology Improvement Program to deploy cybersecurity tools, services, and training directly to elementary and secondary schools. The bill would authorize $10 million per year for fiscal years 2027 and 2028.
Who benefits
K-12 students whose personal and academic data would be better protected from breaches. School administrators and IT staff who would gain access to free or subsidized cybersecurity tools, training, and a centralized funding database. Parents concerned about student privacy. Smaller and rural school districts with limited IT budgets that cannot currently afford robust cybersecurity. Cybersecurity vendors and Information Sharing and Analysis Organizations (ISAOs) that would partner with CISA to deliver services. State and local educational agencies that would receive guidance and resources.
Who is hurt
Private cybersecurity firms that currently sell services to schools may face reduced demand if free federal alternatives are made available. Taxpayers would bear the $20 million cost over two years. Schools that experience cyberattacks and choose to report them to the voluntary registry may face reputational risk or increased scrutiny, even though participation is voluntary and data is de-identified in public reports. Federal agency staff at CISA would absorb new administrative responsibilities.
Supporters argue
Supporters argue that K-12 schools have become a primary target for ransomware and data breaches — the K12 Security Information Exchange documented over 1,300 publicly disclosed school cyber incidents between 2016 and 2021 — and that most districts, particularly small and rural ones, lack the resources to defend themselves. They contend that centralizing threat intelligence, best practices, and funding information through CISA would give under-resourced schools access to the same level of protection that larger institutions can afford, protecting sensitive student data and preventing costly disruptions to learning.
Opponents argue
Opponents argue that education is constitutionally a state and local function, and that creating a federal cybersecurity infrastructure for schools — even a voluntary one — risks drawing districts into dependency on federal programs that may come with future conditions or data-sharing obligations. They contend that $10 million annually is insufficient to meaningfully address the scale of the problem across roughly 13,000 school districts nationwide, amounting to less than $800 per district per year, and that the funds would be better directed as block grants to states rather than administered through a federal agency with no direct education mission.