K-12 cybersecurity, run for you
Cybersecurity for K‑12 school districts.
Phishing defense that removes the email. Monitoring that stops the attack at 2 a.m. Testing that proves what is exposed. All of it run by us, none of it handed to your technology team.
What we do
Four programs. Pick one, or take all four as one agreement.
Plain name first. Product name under it. Every one is a complete managed service with a printed overview you can hand to a board.
Phishing defense
Staff report a suspicious email with one click. We remove it from every inbox in the district.
See how it works Guardian24/7 monitoring & response
Analysts on every device and the network edge, all night and all summer. We isolate, not just alert.
See how it works Red TeamPenetration testing
Every device found, every finding proven, a retest to show it is closed. A short list, not a 400-item scan.
See how it works Credential watchDark web monitoring
A district password leaks somewhere else. We tell you before an attacker logs in with it.
See how it worksHow it works
One team. Nothing for you to run.
Every inbox, device, building and your domains on the dark web. 24/7/365.
A real analyst confirms it is genuine. You never work an alert queue.
Email pulled from every inbox. Machine isolated. Hole found and closed.
Plain English, evidence attached. Nothing lands on your technology team.
BlueHook phishing defense · Guardian 24/7 monitoring · Red Team pen testing · Dark web monitoring — compare all four.
BlueHook
simulation · training · email threat removalStaff report a suspicious email with one click. We investigate it, and we remove it from every inbox in the district.
- Simulations built for school roles. Payroll changes, vendor invoices, “the principal needs a favor.”
- Training at the moment of a click, thirty seconds long, for staff and students.
- One action removes the real thing from every mailbox it reached. Outlook and Gmail.
Guardian
security operations center for districtsAnalysts watch every device and the network edge around the clock, and stop an attack while it is still happening.
- Nights, weekends and breaks covered. A third of what we catch arrives outside school hours.
- We isolate the machine, kill the process and block the address. Minutes, not tickets.
- Reported per building, in plain English, with the evidence and the action already taken.
- 02:10Detected
- 02:11Analyst paged
- 02:13Confirmed genuine
- 02:14Host isolated, process killed, address blocked
- 07:30Technology director briefed
Why it matters
Districts get attacked like enterprises and are funded like schools.
of district technology leaders say they do not have enough cybersecurity staff.
CoSN, U.S. State of EdTech 2026 · sourceof principals reported a compromised business email account, the most common incident.
RAND principal survey, 2024 · sourcedays of instruction a district can lose after an attack. Recovery runs two to nine months.
U.S. GAO-23-105480 · sourcefall in US K-12 ransomware in the first half of 2026. The trend is going the right way.
Comparitech via GovTech, 2026 · sourceBuilt for K-12, not adapted
A district is not a small business with lockers.
Everything here is scoped to how a school district is actually staffed, funded and scheduled.
Timed to the school year
Testing and cutovers land in breaks. Simulations land on school days. Nothing on a testing week. Winter and spring break, when the buildings are empty, are when we watch hardest.
Reported per building
Guardian is organised the way a district is, by school, so a principal sees their own building and a board sees the whole district on one page.
Works with what schools run
Microsoft 365 and Google Workspace, Outlook and Gmail. The report button goes where your staff already are. Nothing to install on a Chromebook cart.
What you will be asked to show
Districts do not buy security. They buy an answer.
Somebody is going to ask. Here is who, what they ask, and which program hands you the evidence.
A one-page monthly report, per building, with what was caught and what was done.
Guardian · BlueHookMonitored endpoints, training completion by staff member, a dated pen test with a retest.
Guardian · BlueHook · Red TeamTraining records, remediation logs, findings tracked to closure, a posture score that moves.
All four, exportedAn assessment, a remediation plan with dates, and documentation a reviewer accepts.
Red Team · GuardianWhat we are actually covering
Move the slider to your district.
A district is not one network. It is thousands of accounts and devices, and every one is a way in.
Typical district ratios, not a measurement of yours. Tell us the real numbers and we will scope and price to them, in writing.
Paying for it and proving it
The two questions every business office asks.
Funding: E-Rate covers a basic firewall. Not much else.
What E-Rate Category 2 actually pays for, what the FCC Cybersecurity Pilot pays for, and how districts put monitoring, phishing defense and testing on a budget line.
How districts pay for this →Compliance: FERPA, CIPA, COPPA, and the rules that vary by state.
What is settled federal law, what changes at the state line, and what is not law at all but still decides whether your cyber insurance renews.
What districts are required to do →Questions we get first
Before you call
Do you only work in Tennessee?
No. The K-12 programs are delivered remotely, to districts in any state. On-site business services are limited to the Tri-Cities area of Tennessee.
Can we take one program rather than the whole package?
Yes. Most districts start with BlueHook, because email is where incidents begin. Guardian follows when an insurer asks who is watching after hours. Red Team comes first when there is an audit to satisfy.
Does this work with Google Workspace?
Yes. BlueHook works with both Microsoft 365 and Google Workspace, with the report button in Outlook or Gmail. Guardian watches endpoints and the network regardless of which platform you run.
Can E-Rate pay for this?
Mostly no. Under E-Rate Category 2 only a basic firewall is eligible. Districts selected for the FCC Cybersecurity Pilot can use pilot funds for monitoring, endpoint protection and identity.
How do you price?
Per program, fixed, in writing before anything starts. Tell us your student and staff numbers and we will give you a figure.
Will you work with our existing technology team?
Yes, and that is the normal arrangement. Your team keeps ownership. We cover what you do not have the hours or tooling for.
What do you need from us to get started?
What you are being asked to prove, your student and staff numbers, and who is asking. That is enough to scope and quote.
Get started
Tell us what you are being asked to prove.
An insurance renewal, a state review, a board question. We will tell you which program answers it, or that none of them do. Straight answer, fixed quote, from the engineer who would do the work.
Reply within one business day. No sales sequence, no mailing list.
