Beyond the Inbox: Protecting Staff and Students from Evolving K–12 Phishing
September 29th at 1:00 PM ET | In Partnership with CyberNut
Phishing in K–12 succeeds because it exploits trust, not just technology. Messages that borrow the authority of a district leader, the urgency of a payroll or benefits notice, or the familiarity of a classroom tool consistently outperform technical defenses. Staff remain the foundation of this risk, but the same trust chain now reaches students. A single compromised staff account keeps its authentic address, contacts, and message history, which means the protections that close external student email do not close every path a trusted sender can travel. As AI makes these messages faster to produce and easier to personalize, the gap between filtering and human judgment is widening.
Drawing on anonymized data from CyberNut phishing simulations across more than 100 districts, this session examines how staff-targeted attacks work, how student-facing lures still arrive even in closed environments, and why the next step is moving from phishing training toward broader student cyber readiness that connects cybersecurity, digital and AI literacy, citizenship, and reporting.
In this session, we'll explore:
What CyberNut simulation data across 100+ districts reveals about how staff actually respond to phishing
How the same trust chain reaches students, even in districts that block external student email
Why AI is changing the scale, speed, and personalization of these attacks
How to move from phishing training to broader student cyber readiness, and five actions districts can take now
Featured Speakers:
Andy Lombardo, Director of Technology, Maryville City Schools
Stephen Mirante, Chief Revenue Officer, CyberNut