TriVigil Free Consultation
Why TriVigilWhat actually makes us different Our ServicesTwelve domains, one agreement Education Small & Medium Business Investors & Portfolio Companies About UsOur story Leadership Team News & Resources Contact Schedule a Free Consultation
Home  /  Who We Serve  /  Education

Security leadership for campuses that have everything except a security department.

TriVigil started in education, and education is still most of what we do: colleges and universities are the larger part of the practice, K-12 districts the rest, and the same team serves both. We know what a cabinet or a school board needs to hear, what an auditor will ask for, and how to run a program alongside your existing IT staff without getting in their way.

53%
of higher-education institutions hit by ransomware said a lack of detection expertise was a factor. Across all sectors the figure is 35%.
Sophos, State of Ransomware in Education 2026
85%
of ransomware attacks on education used an identity-based technique such as a stolen or phished credential.
Sophos, State of Ransomware in Education 2026
52%
of U.S. school districts reported a cybersecurity incident in 2025. In 2023 it was 31%.
Clever, Cybersecure 2026 Report
Colleges & universities

What a campus has to protect

A campus runs a clinic, a financial aid office, student housing, and a research operation, and each one answers to different rules. We take on the parts your security team does not have the hours for, and we report to the people who have to sign.

GLBA Safeguards, owned by someone

Title IV institutions have to designate a Qualified Individual, keep a written risk assessment current, and report to the board every year. Our vCISO serves as the Qualified Individual and owns that calendar, including the report your auditors look for.

Research data and the grant clause

Federal awards increasingly carry NIST SP 800-171 language, and DoD work brings CMMC. We scope the research enclave with the PI and the research office, then write the system security plan before the sponsor asks for it.

Vendors, HECVATs, and the queue

Every department buys software, and every purchase arrives with a HECVAT to review. We take the inbound assessments off your desk, maintain the vendor risk register, and turn the one-off reviews around in days instead of weeks.

The lines between FERPA and HIPAA

Student health and counseling records sit on the boundary between the two laws, and the answer changes by office. We map which records fall under which rule and write policy the registrar, the clinic, and the counseling center can all follow.

Decentralized by design

Academic units run their own systems and hire their own vendors, and central IT finds out later. We build governance that fits that reality: a standard baseline, and a practical way for units to meet it.

Monitoring with analysts behind it

Round-the-clock detection across endpoints, identity, and cloud, with people reviewing what the tooling raises. For a two-person security office, it means someone is reading the overnight alerts and calling you when one matters.

K-12 districts

What a district has to protect

A district holds Social Security numbers, health records, family financial data, and years of behavioral history on minors, and the team defending it is usually smaller than the front office. We have worked with districts since the company started, and the superintendent's board packet is a document we know well.

Student data, FERPA, and CIPA

A student's identity stays clean until they apply for their first loan, which is why student records sell at a premium. We review how student data moves through your SIS, your assessment platforms, and your vendors, and we write the policy that keeps FERPA and CIPA obligations in one place.

The monitoring gap

MS-ISAC moved to paid membership in October 2025 when its federal funding ended, and federal grant dollars can't be used to pay the dues. Many districts lost round-the-clock monitoring as a result. We provide it, priced for a district budget, with people reviewing the alerts.

The board, the insurer, and the audit

A risk assessment a superintendent can take to the board, controls documented the way a cyber insurer wants to see them at renewal, and Google Workspace or Microsoft 365 hardened before the next audit finds what was left on default.

The retainer

How the engagement runs

HIGHER EDUCATION

Colleges & universities

We work alongside your existing IT organization. The retainer covers a named security leader, the compliance calendar, board and cabinet reporting, and a tabletop exercise with the people who would be in the room during an incident.

  • Virtual CISO and GLBA Qualified Individual
  • Safeguards Rule risk assessment and board report
  • NIST 800-171 and CMMC readiness for sponsored research
  • HECVAT triage and vendor risk management
  • Penetration testing and cabinet tabletop
K-12 DISTRICTS

Districts & charter schools

A named security leader on call for the superintendent and the technology director, policy that survives an audit, staff training that fits in a professional development day, and monitoring that replaces what MS-ISAC used to provide.

  • FERPA and CIPA alignment
  • Student data privacy review
  • Google Workspace and Microsoft 365 hardening
  • 24/7 monitoring to replace the MS-ISAC gap
  • Board-ready reporting
WHEN IT'S URGENT

Transitions & incidents

Two moments bring most institutions to us: the security leader just left, or something has already happened. We hold the seat while you hire. In an incident, we stay through disclosure, the insurance process, and the rebuild.

  • Interim CISO and CIO coverage
  • Incident response and containment
  • Insurance and legal coordination
  • Communications support for students, families, and staff
Buying it

Cost and procurement

A public institution needs a number it can put on a requisition and a path through procurement. Here is how that works with us.

The assessment is a fixed-price project and the retainer is a monthly fee scoped to the size of the institution. We put both in writing, on letterhead, before any work starts, so the quote can go straight into a requisition. Retainers run month to month after an initial term.
Ask us which vehicles apply in your state. Where a cooperative purchasing contract fits we will use it, and where it doesn't we can provide the documentation a sole-source or small-purchase process needs.
Core E-Rate pays for connectivity and basic firewall, and does not cover most security services. The FCC's Cybersecurity Pilot is closed to new applicants. If you are a district in the Pilot, we can help you use the commitment. Otherwise, state cybersecurity grant programs and general fund technology allocations are where this work usually gets funded, and we will say so up front rather than let an application go nowhere.
Yes, and that is the normal arrangement. Central IT keeps running the environment. We take the security program, the compliance calendar, and the reporting, and we stay out of the operational decisions that belong to your team.

The unexpected loss of our IT Director was more than just a vacancy; it felt like losing a friend and a vital member of our community. In those moments of vulnerability, we realized we needed more than just a service provider; we needed a trusted partner. That's when we turned to TriVigil.

Brent KoontzSuperintendent, Pioneer-Pleasant Vale Schools

Bring us the question you're stuck on.

Whether it is an auditor asking who your Qualified Individual is or a board asking about ransomware, start there. The first conversation is free and takes about half an hour.