Oliver Page

Choosing & Implementing

July 22, 2026

Questions Every IT Director Should Ask Before Signing a Security Awareness Contract

You have a shortlist of security awareness vendors. Demos are scheduled. Before you sign anything, you need a set of questions that separate platforms built for school districts from those built for a different market and relabeled. The eight questions below are designed to surface that difference. Take them into every demo.

What Questions Should Schools Ask Cybersecurity Training Vendors?

School districts should ask cybersecurity training vendors eight specific questions covering K-12-native design, simulation methodology, threat removal capability, behavior-change measurement, deployment speed, compliance alignment, district-wide scalability, and pricing structure. These cybersecurity vendor questions schools need answered will reveal whether a platform was built for K-12 from the ground up or adapted from an enterprise product after the fact.

Each question below targets a specific failure point that districts encounter during vendor evaluation. A platform can demo well and still fail your district if its underlying design assumptions do not match K-12 realities: lean IT teams, seasonal staffing changes, shared devices, constrained budgets, and a user base that includes both staff and students. The right vendor will answer each of these with specifics. The wrong one will offer workarounds.

Was This Platform Built for K-12, or Adapted from an Enterprise Product?

A platform built for K-12 from the ground up will have school-specific phishing scenarios, training for both staff and students, directory integration with Google Workspace and Microsoft 365, and an administrative model designed for IT teams of one to three people. A platform adapted from enterprise will have corporate phishing templates rewritten for schools, no student-facing training, and an admin workflow that assumes dedicated security staff.

This is the most important question on the list because it determines everything downstream. School districts operate with shared devices, seasonal staff turnover, substitute teacher pools, and no dedicated security operations center. Enterprise platforms assume stable headcounts, individual workstations, and IT teams with bandwidth to configure campaigns manually. When a vendor says their platform "serves education," ask what percentage of their customer base is K-12 and whether the product was originally built for corporate environments. The answer shapes how much ongoing work falls on your team.

Is the Phishing Simulation Continuous and Automated, or Run in Batches?

Phishing simulation should run continuously and adapt automatically to each user's demonstrated skill level. A platform that runs quarterly or monthly batch campaigns with manual configuration leaves long gaps where staff are not being tested, and attacks do not arrive on a predictable schedule.

The CIS/CoSN 2025 K-12 Cybersecurity Report found that 82% of reporting K-12 organizations experienced cyber threat impacts, with attacks targeting human behavior at least 45% more frequently than technical vulnerabilities. Those attacks arrive daily, not quarterly. Continuous, AI-adaptive simulation means the platform adjusts difficulty based on each individual's click history: a staff member who repeatedly identifies phishing receives progressively harder scenarios, while someone who clicks receives targeted reinforcement. Ask the vendor whether campaigns run automatically after initial setup or whether your IT team must build and schedule each campaign manually. If the answer is manual, factor that administration time into your total cost of ownership.

Training Alone Leaves Threats Sitting in Inboxes

The strongest security awareness platforms combine phishing simulation and training with real threat removal in a single platform. If a vendor offers training only, every malicious email that a trained staff member correctly reports still sits in every other inbox across the district until someone manually removes it.

Ask whether the platform includes the ability to remove a confirmed phishing email from every inbox district-wide with a single action. CyberNut's Active Threat Manager provides exactly this: when a staff member reports a suspicious email, the IT director can investigate the message's reach using Advanced Threat Search and then remove it from every inbox in seconds. Without integrated threat removal, a district needs a separate email security tool and a manual process to stitch training and response together. That fragmentation costs time during active incidents and increases the window of exposure. For a deeper look at how detection, training, and removal connect, see Email Threat Management for School Districts: From Detection to Removal.

Behavior Change Is the Metric That Matters

Protection should be measured by whether staff actually click less on phishing emails over time, not by whether they completed a training module. Ask every vendor for phishing click-rate reduction data from their K-12 customers, segmented from their enterprise base.

A platform that reports only completion rates is measuring compliance, not protection. Microsoft's Digital Defense Report 2024 identified education as the second most-targeted sector globally at 21% of all attacks. The U.S. Government Accountability Office documented K-12 financial losses of $50,000 to $1 million per cyber incident, with recovery timelines of 2 to 9 months. Against that threat landscape, the only metric that demonstrates a return on your investment is measurable behavior change. CyberNut districts see a 75% average reduction in phishing click rates, a result driven by continuous simulation and gamified micro-lessons that build a culture of awareness rather than a one-time compliance event. When a vendor quotes completion rates without click-rate trend data, ask why.

How Long Does Deployment Take, and What Does Ongoing Admin Look Like?

Target a platform that deploys within the first week, runs automated phishing campaigns within two weeks, and requires no more than 1 to 2 hours of IT staff time per month for ongoing oversight. Anything beyond that competes with the rest of your workload and will lose.

Ask the vendor to walk through the deployment timeline step by step: directory integration, user provisioning, first simulation launch, and full automation. Then ask what your team is responsible for each month after go-live. A platform built for K-12 should auto-provision users from your directory, auto-schedule simulation campaigns, auto-deliver training when someone clicks, and auto-generate reports. If the vendor describes monthly campaign configuration, manual roster uploads, or a dedicated administrator role, the platform was designed for a larger IT team than most districts have. For a detailed breakdown of what fast deployment looks like in practice, see Implementation in Days, Not Months: What Fast Deployment Actually Looks Like.

Compliance Means FERPA and CIPA, Not Enterprise Frameworks

Any cybersecurity awareness platform used in a school district must be FERPA compliant, with a signed Data Processing Agreement that governs how staff and student data is collected, stored, and processed. Platforms with student-facing modules should also support CIPA alignment for districts receiving E-Rate funding.

During evaluation, ask the vendor three compliance questions. First: can you provide a signed FERPA-compliant DPA before contract execution? Second: does the platform support student training that satisfies CIPA internet safety education requirements? Third: does your reporting format align with state-level cybersecurity training mandates? Enterprise vendors often lead with certifications designed for corporate procurement. Those certifications assess the vendor's internal security posture, which is useful, but they do not address the student data privacy obligations that fall on the district under FERPA. FERPA and CIPA are the relevant compliance frameworks for K-12 cybersecurity awareness platforms. If a vendor cannot provide FERPA documentation during the evaluation window, that is a disqualifying gap.

District-Wide Coverage Without Per-Building IT Lift

A platform that requires building-level administrators to manage training, upload rosters, or configure simulations does not scale for most districts. The right platform provides centralized, district-wide management from a single dashboard with automatic user provisioning from your existing directory.

Ask the vendor what happens when a new school joins the district, a staff member transfers between buildings, or a substitute teacher is added mid-semester. The answer should be: the directory sync handles it automatically. Also ask about support. A K-12-native vendor should provide onboarding assistance, responsive support from a team familiar with school district environments, and the ability to resolve issues without escalating through enterprise-tier support queues. CyberNut serves 400+ school districts, which means the support team understands the operational realities of K-12 IT, from Google Workspace directory structures to the timing constraints of deploying training during a school year. If support response times or expertise are unclear during the demo, ask for reference contacts who can speak to their experience.

Does the Pricing Model Fit a School District's Budget?

Pricing should be transparent and tied to your actual staff and student counts, with a predictable annual figure that fits public education budget cycles. Ask how the cost changes as enrollment and staffing shift from year to year, so a mid-year change does not trigger an unbudgeted true-up.

Ask the vendor how districts your size typically fund the platform, whether through Title IV-A, state cybersecurity grant programs, or general operating funds. Many districts still fund cybersecurity from general operating funds rather than dedicated grants, so a clean annual line item you can present during budget season and defend to the board matters more than eligibility for any single program. Keep the pricing conversation practical: what does this cost for a district your size, and how does it fit with how you actually purchase and fund technology?

How to Run the Evaluation: Take These Questions Into Your Next Demo

The strongest platform on your shortlist is the one that answers all eight questions with specifics, not promises. Take this list into every demo. Score each vendor's answers. Ask for documentation where the answer is a claim: FERPA DPA, K-12 click-rate reduction data, deployment timelines from reference districts, and a breakdown of monthly admin hours.

A vendor that cannot provide specifics during the evaluation process is unlikely to deliver specifics after you sign. For a complementary evaluation framework with a scored rubric, see What to Look for in a K-12 Cybersecurity Awareness Platform: A Buyer's Guide.

The best way to ground your evaluation in your own district's data is to know where you stand today. Run Your Free Phishing Assessment to establish a baseline click rate before you compare vendors. Takes 15 minutes. No commitment.

Frequently Asked Questions

How many vendors should a district evaluate before signing?

Three to five vendors provide a meaningful comparison without overextending your evaluation timeline. Include at least one platform built specifically for K-12 and at least one general-market platform so you can directly compare K-12 fit, admin burden, and pricing models. Use a consistent question set across all demos to make comparison straightforward.

Should I involve non-IT stakeholders in the vendor evaluation?

Yes. Bring at least one building-level administrator and, if possible, your CFO or business manager into a demo or reference call. Building administrators can assess whether the platform's training format fits the school day. The CFO can evaluate pricing structure and funding alignment. Superintendent and board involvement strengthens the purchase justification and prevents late-stage objections.

What if a vendor can't answer these questions during a demo?

A vendor that cannot provide specific, documented answers to questions about deployment timelines, ongoing admin hours, FERPA compliance, or K-12 click-rate data during the evaluation process is signaling that those answers either do not exist or are not favorable. Treat vague responses as a red flag, not a reason to schedule a follow-up call.

How do I compare vendor answers side by side?

Create a simple scoring matrix with the eight questions as rows and each vendor as a column. Score each answer on a 1 to 5 scale based on specificity and fit for your district. Weight the categories that matter most to your environment. For most districts, deployment speed and ongoing admin burden carry disproportionate weight. Share the matrix with your evaluation committee.

How should I evaluate a platform on my own district's data?

The most useful data comes from your own environment. Establish a baseline phishing click rate for your district before you compare vendors, then look for platforms that can show measurable click-rate reduction in K-12 settings similar to yours. A short baseline assessment takes minutes and gives you a concrete number to hold every vendor's claims against.

Sources

  1. Center for Internet Security & Consortium for School Networking. (March 2025). 2025 CIS MS-ISAC K-12 Cybersecurity Report: Where Education Meets Community Resilience. https://learn.cisecurity.org/2025-k12-cybersecurity-report
  2. Microsoft. (October 2024). Microsoft Digital Defense Report 2024. https://www.microsoft.com/en-us/security/security-insider/threat-landscape/microsoft-digital-defense-report-2024
  3. U.S. Government Accountability Office. (October 2022). Critical Infrastructure Protection: Additional Federal Coordination Is Needed to Enhance K-12 Cybersecurity (GAO-23-105480). https://www.gao.gov/products/gao-23-105480

Oliver Page

Some more Insights

Back