Wizer Free Security Awareness Blog

Back-to-School Cybersecurity Checklist | Wizer

Written by Wizer Team | Aug 11, 2026, 5:38:50 PM

Quick Answer: A back-to-school cybersecurity checklist covers three groups — staff, students, and parents — each with a short, specific list of habits to set before the first bell rings. Skip the 40-slide policy deck and focus on passwords, MFA, social media, and spotting a scam text.

  • Staff: MFA and phishing awareness before students arrive
  • Students: passphrases, social media privacy, one trusted adult to tell
  • Parents: device setup and lookalike-text awareness

Most districts still run this as a single staff meeting in August. That's also why most of it is forgotten by October.

Why Back-to-School Week Is a Cybersecurity Moment

August 15 is National Back to School Prep Day, and most checklists built around it are about supplies and schedules. Cybersecurity belongs on that list too.

New devices, new logins, and thousands of new inboxes and social accounts all activate in the same two weeks. That's a lot of fresh attack surface at once, and it lands right when staff are busiest.

In its guidance for the sector, the Cybersecurity and Infrastructure Security Agency describes K-12 schools as "target rich, cyber poor," and says cyber incidents there now average more than one per school day. Districts hold sensitive student and staff data with a fraction of the security budget of a comparable business. Back-to-school week is when that gap gets tested first, usually by a realistic-looking email rather than a sophisticated attack. If you want the plain-language version of how that gets tested safely ahead of time, see what a phishing simulation actually is.

What Belongs on a Back-to-School Cybersecurity Checklist

For Staff and Teachers

  • Turn on MFA for every school account before students arrive, not after an incident.
  • Learn to spot the "urgent schedule change" text and the gift-card email — two lures that show up in school inboxes every September.
  • Keep student data off personal devices and personal email.
  • Use the same reporting button every time, so reporting becomes a habit instead of a judgment call.

For Students

  • Use a passphrase, not a password — something long and easy to remember beats "P@ssw0rd1."
  • Treat a text or DM claiming to be "the school" the same way you'd treat a stranger asking for your locker combination.
  • Set new social accounts to private before posting, not after.
  • Know one adult to tell if something online feels off — no shaming, just a name.

Cyberbullying deserves a place on this list too, not just phishing. Most schools already have a policy for it; the gap is usually practice, not policy, kids need to know exactly where to report it and trust that reporting won't backfire on them.

For Parents

  • Set up parental controls on any new device before it's used unsupervised.
  • Watch for lookalike "school portal" texts asking for a login or a payment.
  • Have one privacy conversation before a new social account exists, not after a problem shows up. Wizer's guide to apps parents should know about is a fast way to see what's actually on the phone.
  • Know exactly who at the school to contact about a cybersecurity or cyberbullying concern.

The Trap vs. What Actually Works

The trap What works
One 45-minute assembly in August Short lessons spread across the semester
A password reset email and nothing else MFA turned on before the first login
Cyberbullying covered once in health class A reporting path students actually use, repeated often
Parents get a flyer Parents get one specific action before day one

A Checklist You Can Actually Use Before the First Day

  •  MFA is on for every staff and admin account before the first day of school.
  •  New student and staff accounts are provisioned with unique, non-default passwords.
  • Staff get a short phishing refresher during pre-service week, documented for the board.
  • Students get one age-appropriate lesson on social media privacy and spotting scams.
  • Parents get one specific email on device setup and lookalike-text warnings, not just a flyer.
  • One named reporting path exists for suspicious emails, texts, and cyberbullying — and staff actually know it.

See what a training program built for a school budget looks like →

Make Back-to-School Training Something Your Staff and Students Finish

Wizer's cybersecurity awareness training replaces the annual assembly with short lessons staff actually complete, and Wizer for Students brings the same approach to the classroom. Education pricing is built for a district budget, not an enterprise one.

Book a 15-minute walkthrough for your district →