
School Ransomware Lessons for SMBs and Nonprofits
When ransomware hits a school district, the headlines sound distant if you run a clinic, a manufacturer, a church, or a 40-person firm. They should not. The way attackers get in is almost never a Hollywood zero-day aimed at "education." It is the same three doors that small and mid-sized organizations leave open every week.
In July 2026, April Mardock, CISSP - a cybersecurity veteran and current CISO of WSIPC - published field notes from conversations with IT leaders at twenty-four school districts that had already paid the price. She asked one narrow question: forget the recovery story and the ransom note - how did attackers get in the first time? The answers collapsed into three buckets. Not a dozen. Three. You can read her full piece here: I Asked 24 Ransomed School Districts How the Attackers Got In.
Her caveat matters: this was not a formal research study. It was honest post-incident talk. It still deserves a boardroom minute because nothing in those conversations contradicts years of breach reporting for businesses of every size. It puts a face on patterns most leaders half-know and still underfund.
The three doors (and the SMB / nonprofit version)
Door one: An internet-facing system that was not patched fast enough
In the districts, that meant a VPN appliance, a firewall management page left on the open internet, aging on-prem email or file-transfer gear, or a departmental web app nobody remembered owning. The patch existed. The maintenance window did not.
For SMBs and nonprofits, swap the labels: a "temporary" remote desktop rule from 2019, a firewall admin portal reachable from anywhere, a vendor appliance in the closet, a line-of-business server with a public IP, an old VPN that never made the change list. Attackers do not need your industry. They need a scanner and a slow clock.
April's working standard - roughly two weeks for internet-facing systems, faster for known-exploited flaws - is aggressive for busy seasons. It is also realistic for how quickly edge bugs get weaponized. Internal print servers can wait a beat. The unlocked front door cannot.
Door two: Phishing, plus too much privilege on the machine that clicked
Someone clicked. Teachers open parent attachments. Your office manager opens invoices. Your development director opens "updated grant forms." Someone will always click. Training lowers how often. It does not make humans perfect.
What decided the damage was what happened next. The account that clicked had local administrator rights. In several districts, the same local administrator password was reused across many machines from an old imaging process. One bad email became credential theft, disabled security tools, and a key that worked on the next laptop and the next.
Small businesses and nonprofits live this with different excuses: "the accounting package needs admin," "the donor database installer fails without it," "the founder's laptop is also the file server." Shared local admin passwords from a one-time setup years ago are still common. That is not a user problem. That is a privilege and identity problem.
Door three: Remote access without multi-factor authentication
Staff VPN. Remote desktop gateways. And, repeatedly, vendor access.
Nothing exotic was required. A valid username and password were enough. From the network's point of view, someone simply logged in. Stolen passwords are cheap - harvested by infostealer malware, reused from personal accounts, sold in dumps. If remote access does not demand a second factor, you have already answered the only question that mattered.
April's most consistent gap was vendors. Districts that hardened staff MFA still left standing access for student systems, transportation software, HVAC, copiers, and alarm support - often on shared accounts, often without MFA, because "we did not want to break support."
If that made you think of your MSP remote tool, bookkeeper login, payroll vendor, CRM support account, or building controls contractor, you understood the point.
Why this mirrors SMBs and nonprofits so closely
School districts and small organizations look different on paper. Operationally they rhyme: thin IT capacity, calendars that block change (testing season, busy season, gala week, grant closeout), heavy vendor dependence, leadership that "knows about MFA" but has not enforced it everywhere it counts, and commodity ransomware economics - scanners and kits, not boutique genius aimed at your brand alone.
Published breach data has said for years that smaller organizations absorb ransomware at high rates when they are hit. The entry path is rarely unique. What is unique is how little margin you have when email, billing, donor records, or scheduling go dark for a week.
Where the mirror is imperfect - student privacy law versus customer or donor data, free government scanning eligibility, fleet maturity - the leadership lesson still holds. The hard part is not knowing the control exists. The hard part is governance: who owns the risk, who signs the exception, and who can tell a powerful vendor or long-tenured power user that the old way is closed.
What you can do in about ninety days
You do not need a fortune. You need decisions above the help desk.
- Get an outside view of what faces the internet. Inventory reachable systems from the attacker's perspective, not last year's diagram. Decommission what should not be there. Put management interfaces (firewall pages, remote desktop, device consoles) behind controlled access - not on the open internet "just in case."
- List every remote path in and mark MFA. Staff VPN, remote desktop, cloud admin portals, and especially vendor and MSP access. Unmarked rows are the project plan. Prefer stronger factors where you can. Kill shared vendor accounts; use named, limited, time-boxed access and turn it off between engagements. Keep awareness training, but fund controls that assume someone will still click.
- Fix local privilege before the next click. Unique local administrator passwords per machine (Windows LAPS or equivalent), no standing local admin on everyday accounts, and separate day-to-day identity from highly privileged admin identity. Start with a pilot group if a fleet-wide mandate will stall - but start.
- Write the patch clock and get it signed. Internet-facing systems get a short SLA. Known-exploited issues get a faster one. A written exception process turns future arguments into past decisions when someone wants to wait until "after the busy season."
- Practice the boring detections. A successful remote login at odd hours, from a strange place, on an account that never works remotely, is often your last cheap warning before encryption or extortion.
Key takeaways
- Twenty-four ransomed school districts described three initial-access doors: slow edge patching, phishing plus over-privilege, and remote or vendor access without MFA.
- Those doors map cleanly onto SMB and nonprofit environments under different labels.
- Attackers in these stories were not uniquely sophisticated. Defenses that matter are known and mostly inexpensive in dollars.
- The expensive part is leadership: winning the politics of privilege, vendors, and maintenance windows.
- A ninety-day plan focused on exposure, MFA paths, local admin, and a signed patch SLA beats a binder of unused policies.
How Executive Solutions can help
Stories like April's are useful because they shrink a noisy threat landscape into decisions owners and executive directors can own. That is the work of a virtual CISO (vCISO): baseline what is really exposed, score risk in business language, and build a roadmap you can fund and follow - without hiring a full-time security executive on day one.
Executive Solutions works with small and medium-sized businesses and nonprofits that need that leadership coverage. If you want a clear-eyed read on your internet face, remote and vendor access, privilege on endpoints, and what to fix first, start a conversation or learn more about cybersecurity leadership services.

