Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

Pen testing · Public sector & education

Penetration Testing for School Boards & K-12 Schools

Penetration testing shows a school board how its student information system, parent portal and network would actually hold up against the techniques used in real K-12 breaches, and it produces the evidence maturity assessments, insurers and trustees increasingly ask for. Boards typically book testing for the July-August window so exploitation work never touches a live school day, with findings remediated before September registration opens.

Reviewed by the Privacy Horizon team · Last reviewed

What you're protecting

The board systems a test needs to reach

K-12 attack surface is wider than most boards assume, and the highest-value targets are the ones facing parents and vendors, not just staff.

SIS web front ends and portals

The interfaces where parents check attendance and students see marks are internet-facing doors into OSR-derived data, so authentication, session handling and authorization between accounts get close attention.

Payment and fee systems

School-cash platforms take card payments from thousands of families, and a test probes both the application and how it connects back into board finance systems.

Remote-access and support channels

VPNs, vendor support connections and administrative back doors are tested the way the PowerSchool attacker used PowerSource: with valid-looking credentials and patience, checking whether MFA and access windows would have stopped them.

The internal network between schools

From a foothold in one school, how far can an attacker move toward payroll, the SIS database or backups? Segmentation testing answers the question TDSB's testing-environment incident posed.

Wi-Fi, BYOD and device fleets

Student Chromebooks, personal devices on school Wi-Fi, classroom AV and building automation share the environment, and testing checks whether a hostile device in a classroom is contained or catastrophic.

Regulatory map

Where testing fits in a board's compliance picture

No statute orders a board to run a penetration test, but three current instruments make test evidence the practical way to demonstrate what they require.

O. Reg. 51/26 program evidence

The cyber program and the recurring maturity assessments both need proof that controls work, and independent test results are among the strongest artifacts a board can put in front of an assessor or the Ministry summary.

Primary source →

MFIPPA's safeguard standard

The s. 30(5) duty arriving January 1, 2027 asks whether measures protecting personal information are reasonable, and a finding you fixed last summer is far easier to defend than one an attacker finds first.

Primary source →

The IPC's vendor-testing recommendation

The PowerSchool report tells boards to demand security evidence from edtech vendors, penetration-test results included, and boards that test their own estate are in a much stronger position to insist.

Primary source →

BC's reasonable-security duty

For boards of education under FOIPPA, s. 30 requires reasonable security arrangements, and testing the MyEducation BC integration points and local systems is a direct way to check them.

Primary source →

What goes wrong

Attack paths proven against Canadian K-12 targets

We scope board tests around techniques with a K-12 track record rather than generic checklists.

  • Credential abuse on support portals

    One subcontractor password on an un-MFA'd portal exposed roughly 5.2 million Canadians in the PowerSchool breach, so our testing hammers credential paths: password spraying, MFA gaps, and what a single compromised account can actually reach.

    Source →

  • Ransomware staging from weak footholds

    Board incidents like TDSB's began away from crown-jewel systems and spread, which is why we test lateral movement and privilege escalation, not just perimeter entry.

  • Long-dwell data theft

    WRDSB's 2022 intrusion exfiltrated years of student cohorts including OENs and IEP status before detection, so we assess what your logging and alerting would have noticed at each stage of our own attack chain.

    Source →

  • Abuse of parent and student accounts

    Portals authenticated by minors and families invite account-takeover, enumeration and authorization flaws, and a student reaching another student's record is a reportable incident all by itself.

Our pen testing for school boards & k-12 schools

What a board penetration test covers

The parent service's exploration, response observation and improvement guidance are scoped here to the systems and calendar of a school board.

Portrait of beautiful African American nursing student in her first class
  1. External testing of internet-facing assets

    Portals, remote access, mail and web infrastructure across the board's ranges, mapping what an anonymous attacker anywhere can see and exploit.

  2. Application testing of the SIS and payment flows

    Authenticated testing of the student information system, parent portal and school-cash integration, focused on access control between parent, student, teacher and admin roles.

  3. Internal and segmentation testing

    Starting from an assumed foothold, we measure movement toward the OSR data stores, payroll and backups, and verify the school-to-board-office boundaries hold.

  4. Detection and response observation

    Throughout the engagement we track what your team or MSP noticed and when, giving the board a realistic read on monitoring, without turning the test into a surprise drill.

  5. Reporting for two audiences

    A technical findings package with reproduction steps for IT, and a plain-language summary the Superintendent of Business can take to trustees and the insurer.

  6. Remediation retest

    After fixes land, we re-verify the significant findings so the file shows closure, not just discovery, before the school year starts.

How the engagement runs

Testing around the school year, not through it

Scheduling is half the craft in K-12 testing, and we plan it with your IT lead from the first call.

  1. Step 1

    Scope and rules of engagement

    We agree targets, exclusions, test accounts and data-handling rules, including how we treat any student data encountered, and coordinate with vendors whose platforms are in scope.

  2. Step 2

    Schedule for the summer window

    Heavy testing runs July to August when classes are out, with any term-time work limited to low-risk reconnaissance and agreed maintenance windows.

  3. Step 3

    Test and communicate

    Daily check-ins during active testing, with an immediate stop-and-notify path if we find something already exploited or an exposure demanding an urgent fix.

  4. Step 4

    Debrief and prioritize

    Findings are walked through with IT and the senior contact, ranked by real risk to student data rather than raw severity scores.

  5. Step 5

    Fix verification before September

    A focused retest confirms the priority items are closed while the change window is still open.

What it costs

What drives penetration-testing cost for a board

Board test pricing scales with scope: how many external addresses and applications are in play, whether the SIS and payment testing runs against a test instance or carefully against production, the number of schools included in internal work, and whether you want detection observation and a retest bundled in. Vendor coordination, for example arranging authorized testing that touches a hosted SIS, adds planning time but not usually much cost.

A focused first engagement, external plus the parent portal, is a very different price from a full internal exercise across a large board. Share your target list and preferred window and we will return a fixed, per-scope quote your budget cycle can plan around.

School Boards & K-12 Schools: Pen testing questions, answered

Yes, and summer is exactly when we recommend it. July and August give us freedom to run exploitation and internal testing with no classes, no report-card runs and minimal portal traffic, and they leave the back half of August for fixes and retesting before registration. The one caution is that some staff and vendor contacts are away, so we lock in escalation names and vendor authorizations in June.

They should be near the top of the scope. The PowerSchool compromise came through a support portal credential with no MFA behind it, plus standing remote access into board data. We test what your vendors' access can reach, whether MFA and IP or time restrictions actually apply, and how the connection is logged, within whatever authorization the vendor contract allows. Where the vendor will not permit direct testing, we assess the board's side of the connection and flag the contractual gap for your next renewal.

Ask in the contract, not in an email after signing. The IPC's report backs boards demanding security evidence from vendors, so build a clause requiring an annual independent test summary or attestation letter, with findings-closure confirmation, into new agreements and renewals, including through OECM schedules where applicable. Most established vendors will provide a summary letter under NDA; a refusal is itself due-diligence information. We help boards word the ask and evaluate what comes back.

Designed correctly, no. Disruptive techniques are scheduled outside instructional time, denial-of-service is excluded unless explicitly requested against a test environment, and anything touching production student data runs under agreed guardrails with an abort path. In years of K-12-style testing the realistic risk is a noisy alert or a locked test account, and the rules of engagement cover both. That is also why we push heavy work into the summer window.

A sensible rhythm is a full test annually, timed to the summer, with targeted retests after major changes such as a new SIS module, a portal replacement or a network redesign. That cadence also matches the O. Reg. 51/26 cycle: a fresh test each year means every two-year maturity assessment has current, independent evidence behind its control claims rather than results from three summers ago.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

(647) 622-2644

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

We only use your details to respond to this request.