school children on laptops

Cyber Liability for School Districts: Protecting Student Data Under FERPA

By Poms & Associates Insurance Brokers, LLC ·

A school district holds a concentration of sensitive information that few organizations of comparable size can match: student identification numbers, health and special education records, disciplinary histories, family contact and financial details, and the personnel and payroll data of every employee. That information is held by an organization that typically operates with constrained technology budgets, a distributed network of campuses and devices, and a heavy reliance on third-party software vendors. The combination makes districts an attractive target, and it makes a cyber incident an exposure that boards and superintendents cannot treat as a purely technical matter.

What FERPA Does and Does Not Address

The Family Educational Rights and Privacy Act, commonly known as FERPA, governs the privacy of student education records at institutions that receive federal education funding. It gives parents and eligible students rights over access to those records and generally restricts disclosure without consent. Districts routinely cite FERPA when discussing student data protection, and understandably so.

What FERPA does not do is function as a complete framework for responding to a cyber incident. It is primarily an access and disclosure statute, enforced administratively through the U.S. Department of Education, with the theoretical consequence of lost federal funding. It does not itself prescribe a detailed cybersecurity standard, it does not establish a breach response process, and it does not create the full range of legal exposure a district faces after a data compromise.

That wider exposure comes from other sources. State data breach notification laws impose notification obligations and timelines. State student privacy statutes can add requirements specific to student data and the vendors that handle it. Families affected by a breach may bring claims under state law alleging negligence in safeguarding their children's information. A district that frames its cyber risk solely around FERPA compliance is therefore addressing a fraction of the exposure it actually carries.

Why School Districts Face Elevated Cyber Risk

Valuable data held for long periods. Student records often include information that remains sensitive for decades, and records of minors are particularly valuable because identity misuse can go undetected for years.

Ransomware aimed at operational disruption. Districts depend on their systems for instruction, transportation, food service, payroll, and safety communications. An attack that halts those systems creates acute pressure to restore operations quickly, which is precisely the leverage ransomware actors seek.

Heavy dependence on outside vendors. Student information systems, learning platforms, and other educational technology are frequently operated by third parties. A vendor breach can expose district data even when the district's own network was never compromised, and responsibility for the response can be difficult to untangle.

Limited security resources. Many districts operate with small technology teams and tight budgets, which can leave gaps in the controls that carriers and attackers alike pay attention to.

A broad and changing user base. Thousands of students, staff members, and visitors connecting through personal and district-issued devices expand the number of potential entry points.

What Cyber Liability Coverage Should Address

A cyber liability program is generally structured around two categories of loss, and a district should confirm that both are present and adequately limited.

First-party coverage responds to the district's own costs following an incident. This typically includes forensic investigation to determine what occurred, legal counsel guiding the response, notification of affected individuals, credit or identity monitoring services, data restoration, crisis communications, and the costs of responding to a ransomware demand. It can also include business interruption, which compensates for lost revenue or extra expense when systems are down.

Third-party coverage responds to claims and proceedings brought against the district. This includes liability for the failure to protect personal information, regulatory defense and, where insurable, penalties, and claims from affected families alleging harm from the disclosure of student data.

Because the number of affected individuals in a district can be very large, and because notification and monitoring costs scale with that number, the adequacy of limits and sublimits deserves direct scrutiny rather than acceptance of a standard form.

Where Districts Commonly Find Gaps

Ransomware sublimits and coinsurance. Some policies cap coverage for ransomware events well below the aggregate limit, or require the district to share a percentage of the loss. A district that sees a seven-figure limit on the declarations page may discover that the exposure it is most likely to experience is covered at a fraction of that amount.

Security control requirements. Carriers increasingly condition coverage and pricing on specific controls, including multi-factor authentication, endpoint detection, tested and segregated backups, and employee training. A district that has represented controls on an application that are not actually in place can face a coverage dispute at the moment it needs the policy most.

Vendor and dependent business exposure. Coverage for an outage or breach at a third-party provider is often narrower than coverage for the district's own systems, and it is frequently overlooked. Contracts with technology vendors also deserve review for indemnification and insurance requirements, since the allocation of responsibility in those agreements affects who ultimately bears the loss. This is the same principle that applies to indemnification obligations in commercial contracts: the contract and the coverage must be reviewed together.

Social engineering and funds transfer fraud. Fraudulent payment instructions, impersonation of vendors, and business email compromise are common in public entity settings, and coverage for them is often sublimited or placed in a separate policy.

Policy structure and timing. Cyber policies are typically written on a claims-made basis, which makes the retroactive date and the reporting requirements important. An incident that began months before it was discovered can create questions about which policy responds if the program has changed carriers or terms.

Overlap with pooled or other district coverage. Districts that participate in a risk pool or joint powers arrangement sometimes assume cyber exposure is handled within that program. The scope and limits of pooled cyber coverage vary, and the relationship between pooled coverage and any standalone policy should be understood before an incident, not during one.

What Leadership Should Confirm

  • Are the cyber coverage limits and sublimits, particularly for ransomware, notification, and business interruption, sized against a realistic scenario involving the district's actual number of student and employee records?
  • Do the security controls described in the insurance application match the controls actually operating across the district today?
  • Does coverage extend to incidents originating at third-party vendors that hold student data, and are vendor contracts aligned with that coverage?
  • Is coverage for fraudulent payment instructions and social engineering included, and at what limit?
  • Has the board been briefed on an incident response plan that identifies who makes decisions, who must be notified, and how coverage is triggered?

The Bottom Line

A cyber incident at a school district is a governance event as much as a technology event. FERPA is one part of the legal landscape, but the financial and reputational consequences of a breach reach well beyond it. Poms & Associates works with districts to evaluate cyber exposure alongside the rest of the program, starting from the same risk assessment approach behind every program we build, and treats it with the same seriousness as other exposures that boards cannot afford to assume are covered, such as sexual abuse and molestation claims. Assumptions about cyber coverage are best tested before a loss, when changes are still possible.

If your district has not reviewed its cyber program against its current systems, vendors, and student data footprint, talk to a Poms & Associates advisor before your next renewal.

Frequently Asked Questions

Does FERPA require school districts to carry cyber liability insurance? No. FERPA governs the privacy and disclosure of student education records but does not mandate insurance. Districts carry cyber liability coverage to address the financial consequences of a data breach or ransomware event, which extend well beyond FERPA compliance.

What does cyber liability insurance cover for a school district? A well-structured policy generally includes first-party coverage for incident response costs such as forensics, legal counsel, notification, credit monitoring, data restoration, and business interruption, along with third-party coverage for claims and regulatory proceedings arising from the compromise of personal information.

Is a district covered if the breach happens at a software vendor? It depends on the policy. Coverage for incidents at third-party providers is often narrower than coverage for the district's own systems, and the allocation of responsibility in the vendor contract also matters. Districts should confirm both rather than assume that a vendor breach is covered.

Why do insurers ask about multi-factor authentication and backups? Carriers use specific security controls to evaluate the likelihood and severity of a loss. Districts that cannot demonstrate controls such as multi-factor authentication, endpoint detection, and tested backups may face higher premiums, reduced coverage, or difficulty obtaining coverage at all.

What is the risk of relying on a risk pool for cyber coverage? Pooled programs may include cyber coverage, but its scope and limits vary and may not match the district's actual exposure. Districts should understand what the pool provides and whether a standalone or excess policy is needed to fill gaps.