K12 Six

More Events
Past EventsOn-Demand Events

Upcoming K12 Six Events

Purview in Practice: Stop Student Data From Walking Out the Door

Sep 22, 2026

Virtual / Online

K12 Six

Join us for a practical, K–12-focused session on maximizing your district’s security and ROI in Microsoft Purview by enabling key, often-overlooked features.

We will demonstrate how to gain deep visibility into where sensitive student and staff data resides across Microsoft 365—and how it’s used—without creating friction for educators. You will learn how enabling auditing, co-authoring, and native PDF support streamlines incident investigations, public records requests, and daily collaboration. Finally, we’ll walk through real-world K–12 scenarios using Content Explorer and Activity Explorer to surface hidden risks in SharePoint, OneDrive, and Teams, building a solid foundation for advanced Data Loss Prevention (DLP) policies.

Top 3 Actionable Takeaways:

  • Gain Full Incident Visibility: Enable Purview auditing across your tenant to maintain a clear audit trail of who accessed or shared sensitive student and staff data when security events arise.

  • Remove Collaboration Roadblocks: Enable co-authoring and native PDF support for encrypted files so educators and administrators can securely collaborate on IEPs and sensitive documents without breaking protection protocols.

  • Eliminate Data Blind Spots: Leverage Content Explorer and Activity Explorer on a quarterly cadence to track high-risk data across SharePoint, OneDrive, and Teams, ensuring your future DLP strategy is grounded in real environment usage.

Learn more

Sep 29, 2026

Virtual / Online

Phishing in K–12 succeeds because it exploits trust, not just technology. Messages that borrow the authority of a district leader, the urgency of a payroll or benefits notice, or the familiarity of a classroom tool consistently outperform technical defenses. Staff remain the foundation of this risk, but the same trust chain now reaches students. A single compromised staff account keeps its authentic address, contacts, and message history, which means the protections that close external student email do not close every path a trusted sender can travel. As AI makes these messages faster to produce and easier to personalize, the gap between filtering and human judgment is widening.

Drawing on anonymized data from CyberNut phishing simulations across more than 100 districts, this session examines how staff-targeted attacks work, how student-facing lures still arrive even in closed environments, and why the next step is moving from phishing training toward broader student cyber readiness that connects cybersecurity, digital and AI literacy, citizenship, and reporting.

In this session, we'll explore:

  • What CyberNut simulation data across 100+ districts reveals about how staff actually respond to phishing

  • How the same trust chain reaches students, even in districts that block external student email

  • Why AI is changing the scale, speed, and personalization of these attacks

  • How to move from phishing training to broader student cyber readiness, and five actions districts can take now

Oct 6, 2026

Virtual / Online

School districts run on email. It's how staff coordinate, how vendors get paid, and how families stay in the loop—and attackers know it. The threats causing the most damage in K-12 today rarely carry a malicious link or attachment. Instead, they impersonate a superintendent asking for a wire transfer, a vendor updating banking details, or an HR portal requesting a password. Because there's nothing technically "bad" to scan for, these messages slip past the filters most districts rely on.

This session walks through the attacks K-12 schools are actually seeing, using real examples of business email compromise, account takeover, and payroll fraud. Abnormal AI will break down how each attack works in plain terms, why traditional defenses miss it, and what school leaders can do about it right now. You'll leave with concrete steps you can put in place before the next attempt lands.

Join this session to see what's targeting your district and how to stop it.

Top 3 Actionable Takeaways:

  • The email attacks targeting K-12 districts and why standard filters miss them
  • The warning signs of impersonation, account takeover, and payroll fraud
  • The concrete steps school leaders can take to strengthen defenses right now

Oct 13, 2026

Virtual / Online

In today’s rapidly evolving digital environment, K-12 school districts remain primary targets for sophisticated cyber threats, ranging from disruptive ransomware and extortion schemes to complex data breaches. Defending school communities in 2026 requires more than isolated effort, it demands collective intelligence and proactive resilience.

Join the K12 Security Information eXchange (K12 SIX), the nation’s dedicated K-12 ISAC, to learn how school systems nationwide are staying ahead of emerging risks. Discover how our specialized threat intelligence, peer-driven collaboration, and purpose-built resources empower districts to proactively defend their networks within a trusted community built by and for K-12 leaders.

In this we’ll explore:

  • Real-Time Threat Intelligence: Stay informed on active attack vectors, emerging threat actor tactics, and K-12 specific vulnerabilities—paired with pragmatic, low-cost defensive strategies designed for immediate implementation.
  • A Dedicated Community of Practice: Connect directly with a nation-wide network of K-12 cybersecurity leads, CTOs, and IT staff who share your exact operational challenges and operational context.
  • Continuous Professional Development: Access expert-led sessions, tactical guidance, and emerging best practices designed to elevate your district's security posture and internal capability.

Oct 20, 2026

Virtual / Online

As AI becomes part of everyday teaching, learning, and school operations, K–12 leaders need a clear strategy for adopting it responsibly without putting sensitive student or organizational data at risk. This session will explore practical considerations for AI readiness, including FERPA, data governance, privacy, and security. Attendees will also learn how capabilities within Microsoft Purview can help districts better understand and protect sensitive information, manage data risk, and establish a stronger foundation for responsible AI adoption.

This session is designed for K–12 IT and security leaders, technology decision-makers, and others responsible for data protection, privacy, compliance, and AI strategy.

Top 3 Actionable Takeaways:

  • Establish AI governance before broad deployment:  Create clear policies for how AI tools can be used by staff and students.
  • Identify and protect sensitive data: Conduct a data inventory to understand where student, staff, and organizational information resides
  • Leverage Microsoft Purview to build AI readiness: Use Microsoft Purview to discover sensitive data, monitor data risks, and enforce protection policies.

Oct 27, 2026

Virtual / Online

K-12 networks face a constant barrage of threats—phishing, malware, spam, and other attacks that exploit the open, high-traffic nature of school environments. This session breaks down the most common network-side risks districts encounter today and what makes K-12 IT teams uniquely vulnerable.

In this we’ll explore:

  • Not All Network Threats Deserve Equal Attention: Learn to spot what's actually most dangerous for your district so you can focus resources where they matter most.
  • Resource Constraints as the Real Vulnerability: Limited staff and budget are often the real issue, not the attacks themselves, leaving IT teams overextended.
  • The Limits of Perimeter Defense: A locked-down network won't help if a stolen password gets someone in anyway, making identity protection critical.

Feb 17-19, 2027

Atlanta, GA

The 2027 K12 SIX National Cybersecurity Conference is a unique event designed exclusively for K-12 cybersecurity practitioners to share solutions and best practices to better defend school communities from emerging cybersecurity threats, such as ransomware, phishing, and data breaches. The fifth annual conference will be held February 17-19, 2027 in Atlanta, Georgia. 
View all