Another Cyberattack on Michigan Schools – Districts Need to Be on High Alert
Summary
TL;DR:
- Recent ransomware attacks on Michigan schools highlight the severe operational, financial, and reputational damage caused by reactive security postures, urging districts to become proactive immediately.
- Cybersecurity risk must be treated as a strategic priority by making it a standing agenda item at all board and executive leadership meetings.
- Since over 80% of successful breaches stem from social engineering, ongoing staff training is essential to transform employees from a security risk into a first line of defense.
- Schools must establish and practice a formal Cybersecurity Incident Response Plan so that leadership and IT teams know exactly how to react and recover during an attack.
- Districts should institute a strict policy requiring that all security patches be installed within 24 hours of release to close vulnerabilities before they can be exploited.
- To ensure recovery from ransomware without paying demands, critical data must be backed up daily to a separate network or a cloud service designed specifically for isolation.
The Jackson County Intermediate School District was hit with a ransomware attack this past week, adding to the growing list of cyberattacks on schools resulting in canceled classes and major disruption. The cyberattack locked district accounts in schools in both Jackson and Hillsdale Counties.
The impact of this cyber incident has far-reaching implications including:
- Missed school days – Students lost valuable instruction since virtual classes were not an option. Email and other critical systems that educators, students and families use to communicate were halted.
- Ransomware – Payment demands could be in the millions—at the taxpayer’s expense.
- Major inconvenience/uncertainty for educators and the school community – Teachers didn’t have access to valuable student data. Parents had to take time off work and stay home with their children.
- Negative press – A cyber incident brings negative, unwanted attention to the district.
- Lost confidence – The school community (educators and families alike) need to be confident that their personal information is not in the wrong hands.
A similar incident happened in the South Redford School District in September , and even higher education isn’t immune, as seen when a cyberattack takes the University of Michigan completely offline. The district was a victim of a malicious cyberattack that closed schools and impacted more than 3,000 students and their families. Earlier this year, Federal agencies had warned that back-to-school cyber attacks would escalate, highlighting what businesses, parents, and schools need to know.
School districts, both public and private, should be on high alert. These cyberattacks serve as a grim reminder that schools must be proactive (instead of reactive) about their cyber hygiene and diligent about improving their cybersecurity posture to help mitigate future attacks.
The following are cybersecurity recommendations from the SensCy team:
- There’s no magic answer. Cybersecurity is a risk that needs to be managed and included in your strategic planning. As with any other risk, cybersecurity should be visible at the top of the organization.
Recommendation: Make cybersecurity risk a standing agenda item at board meetings and executive leadership meetings.
- 80%+ of successful cyber breaches are the result of social engineering. Your employees are your greatest risk, but they can also be your first line of defense with ongoing education.
Recommendation: Invest in your employees by educating them on how to recognize these attacks.
- Visibility at the top + Education throughout your organization = An Active Cybersecurity Culture. An active cybersecurity culture is better protected from an incident, better prepared to respond to an incident, and able to recover and stay open should an incident occur.
Recommendation: Ensure you have a Cybersecurity Incident Response Plan. Make sure the leadership team and the IT team understand it, know how to activate it, and have practiced doing so.
- Security patches cannot be ignored. They are released because a vulnerability has been identified. Every day you wait to install them puts you at greater risk.
Recommendation: Institute a policy that ensures security patches are installed within 24 hours of release. Ensure your team is accountable for doing so.
- Backing up your data is critical to ensuring you don’t fall victim to Ransomware.
Recommendation: A successful recovery from a Ransomware incident requires that your data is backed up on a separate network or in a cloud service designed for this purpose. Back up your data daily!
To learn more about these recommendations, read You’ve Been Hacked! Now What? by Raj Patel. With more than 25 years of experience helping clients with their cybersecurity, Raj’s insights will get you thinking the right way about your cyberhealth.
Want to find out how vulnerable your organization is to a cyberattack?
Your SensCy Score is a good indication of your organization’s cyber hygiene and preparedness. It is like a credit score for your cyberhealth. We can generate your score in less than 30 minutes—at no cost or obligation to you. Click here to get your free SensCy Score or visit www.senscy.com to learn more.

The SensCy Solution
We provide an affordable, easy-to-understand, sensible solution specifically tailored to each client. Our clients tell us that they are thrilled with the value that they derive for the price they pay. Schedule a consultation with one of our experts.

Your SensCy Score® is a good indication of your organization’s cyber hygiene and how prepared your organization is against cyber threats. We can generate your score in less than 30 minutes—at no cost to you!
Recent Posts
