Business Continuity Plan for School Districts: Start Here
A practical guide to building a business continuity plan for school districts: RTO/RPO tiering, restore testing, downtime costs, and CIRCIA reporting.
A business continuity plan for school districts answers one question that a backup job cannot: at 7:15 a.m. on a Monday, with the student information system unreachable and buses already rolling, who does what?
Districts run on a fixed calendar. There is no catch-up quarter. When attendance, transportation routing, food service, or phones stop, instruction and operations stop with them — and the clock keeps running whether or not anyone has written down the recovery steps.
This is an awareness-stage primer for superintendents, CTOs and CIOs, business officials, and the one- and two-person IT departments that keep most districts online. It covers what belongs in the plan, what the current research says, and which items you should verify locally before making decisions.
What is a business continuity plan for a school district?
A business continuity plan is the document that describes how the district keeps teaching and operating during a disruption — not how it rebuilds servers. It names people, decisions, and workarounds: who declares an incident, how attendance gets taken on paper, how families are notified, how payroll runs if the HR system is unavailable, and how long each of those manual workarounds can realistically hold.
A continuity of operations plan for schools is only useful if it is specific to your systems and your calendar. A generic template with vendor logos on it will not tell a transportation director what to do at 6:40 a.m.
What is the difference between business continuity and disaster recovery for schools?
Three different plans answer three different questions, and districts often collapse them into one:
- Business continuity: how do we keep teaching and operating while systems are down?
- Disaster recovery (a k-12 disaster recovery plan): how do we get the systems back, in what order, from what copies?
- Incident response: who do we call, what do we preserve, and what do we have to report?
You need all three. Most districts have a partial version of the second one and nothing written for the first or third.
How much does ransomware downtime cost a school district per day?
The most quotable figure comes from Comparitech data reported by K-12 Dive, covering 2023: the K-12 and higher education sectors lost an average of 12.6 school days to ransomware that year, with downtime calculated at roughly $548,185 per day — framed in that article as the equivalent of about 123,744 school lunches for a single day.
Two caveats worth stating plainly. Those are 2023 figures, not current-year data. And they are sector averages, not a prediction for your district. Use them the way a board uses them: as a rough order of magnitude for what lost days cost, which is a more actionable number than any ransom demand.
How long does it take a school district to recover from a ransomware attack, and what does it cost?
Recovery costs in education fell sharply in the most recent Sophos research, and preparation appears to be why.
Sophos’ State of Ransomware in Education 2025 reports that mean recovery costs excluding ransom payments fell from $3.76 million to $2.20 million in lower education, and from $4.02 million to $0.90 million in higher education — with higher education the joint lowest across all industries surveyed. K-12 Dive’s write-up of the same study notes that lower education still reported the highest recovery costs of any sector.
Important context: Sophos’ figures come from a global survey of 441 institutions across 17 countries that were hit by ransomware, and the responses are self-reported. They are not US district averages and not an incidence rate.
The more interesting number in the same coverage: K-12 Dive reports that 67% of global lower education providers said they stopped an attack before their data was encrypted. That is a preparation outcome, not luck — and it is the core argument for a written, tested plan.
Meanwhile, the threat side has not eased. Acronis’ Cyberthreats Report H1 2025 reports that the number of global ransomware victims increased 70%, and that social engineering and business email compromise attacks rose from 20% to 25.6% when comparing January–May 2025 with the same period in 2024. Acronis also reports that February 2025 was the peak month with 955 victims, largely driven by Cl0p, which accounted for 335 cases — a 300% month-over-month increase. Acronis’ H2 2025 report, published February 18, 2026 and based on telemetry from over one million global endpoints, reports that attacks across email and collaboration platforms surged and ransomware activity continued to grow, with attackers using AI to scale attacks that already work rather than to invent new ones.
Two takeaways. First, initial access still runs through people and email, so a continuity plan should assume compromise rather than assume prevention. Second, ransomware is campaign-driven and spiky — recovery capacity has to exist before a mass-exploitation campaign arrives.
And to be honest about targeting: Acronis reports manufacturing was the most targeted industry in Q1 2025, at 15% of recorded cases. Education is not the number one target. Education has the lowest tolerance for downtime, the leanest IT staffing, and some of the most sensitive minor-student data in any sector. That combination is the risk.
What should be included in a K-12 business continuity plan?
Start with a tiering exercise. Rank each system by how long you can live without it (RTO) and how much recent data you can afford to lose (RPO). Fill in the last two columns with your own district’s numbers — these are decisions for the cabinet, not for IT alone.
| System | What stops when it’s down | Your RTO | Your RPO |
|---|---|---|---|
| SIS / attendance | Attendance records, state reporting, gradebooks | ||
| Payroll and HR | Paychecks, substitute assignment, benefits | ||
| Transportation routing | Route sheets, driver assignments, special-needs transport | ||
| Food service and free/reduced-lunch eligibility | Meal service, eligibility records, reimbursement data | ||
| Door access and HVAC | Building access control, climate in occupied spaces | ||
| Phones and mass notification | Parent communications, emergency notification |
Then add the parts most plans skip:
- Manual workarounds for each Tier 1 system, printed and stored where staff can reach them without the network.
- A restore runbook with order of operations, dependencies, and known-good copies — including offsite and immutable copies, so a single compromised environment cannot take the backups with it.
- A named incident commander and a named reporter, with an after-hours contact tree.
- A communications kit: pre-drafted messages for families, staff, and the board.
- An evidence trail: what gets logged, preserved, and time-stamped, because reporting obligations require dates and details.
Does CIRCIA require school districts to report cyber incidents?
Possibly, and the timelines are tight enough to plan around now. K-12 Dive reports that CIRCIA is expected to take effect sometime in 2026 and that, under the proposed implementing rule, state education agencies and districts with more than 1,000 students would have to report a disruptive cyber incident to CISA within 72 hours and a ransom payment within 24 hours.
Treat that as directional, not final. Those details come from a proposed rule as reported in mid-2025, and federal rulemaking timelines and covered-entity thresholds shift. Verify current status, effective dates, and thresholds with CISA before you build a compliance statement on them. Separately, some states restrict public entities from paying ransoms or require reporting to a state agency — check your own state’s rules.
The planning point stands either way: a plan needs a reporting and communications workflow with a named owner, not just restore procedures.
It is also worth remembering that K-12 incident data is widely considered underreported, per K-12 Dive, because there is no national mandatory reporting system. You are planning against a picture that is likely worse than the published numbers.
Does E-Rate cover backup and disaster recovery for schools?
Do not assume it does. E-Rate Category 1 and Category 2 eligibility rules are specific and change over time, and the FCC’s Schools and Libraries Cybersecurity Pilot Program is a separate program with its own terms. Before you build backup, disaster recovery, or security spending into a funding plan, confirm eligibility against the current USAC and FCC eligible services list and pilot status. Budget from your general or capital funds until you have that confirmation in writing.
How often should a school district test its backups?
Often enough that a restore is boring. A backup you have never restored is an assumption, not a capability.
At minimum, tie testing to your tiering table: Tier 1 systems get a documented restore test on a defined cadence, with results, timings, and failures written down. Timed restores are what turn an aspirational RTO into a real one — and they are the evidence a board, an auditor, or an insurer will ask for.
Where palmiq fits
palmiq has worked with K-12 and SLED organizations since 2018, and our BCDR practice is built for districts where the whole IT department fits in one office. We are an Acronis Platinum partner, in the top 1% globally, and a Microsoft Gold partner. Our SOC runs 24/7 with a 15-minute response SLA on critical issues, and our MDR and EDR services neutralize 1,200+ threats monthly at a 99.9% threat neutralization rate.
For a lean team, co-managed continuity means someone else is watching backup jobs, running restore tests, and keeping the runbook current — so recoverability does not depend on one person’s memory or availability.
If you want a straight conversation about your tiering table, your restore evidence, and your reporting workflow, book a discovery call at https://palmiq.com/discovery-call.