Each service below addresses a specific threat vector or compliance gap in the the Charlotte area private school IT environment. We do not sell technology for its own sake. We solve the specific problems that cause the Charlotte area schools to get breached, fail to meet North Carolina notification obligations, or lose cyber insurance coverage at the worst possible time.
SentinelOne EDR
Endpoint Detection and Response for School Networks and Administrative Workstations
SentinelOne provides AI-driven behavioral detection on every administrative and staff endpoint — detecting ransomware behavior, lateral movement, and credential misuse in real time, before encryption begins. Unlike traditional antivirus tools, EDR monitors process behavior rather than file signatures, catching novel ransomware variants and fileless attacks that signature tools miss. For the Charlotte area private schools, every workstation that accesses the student information system, processes tuition payments, stores payroll data, or connects to the school’s administrative network is in scope. SentinelOne’s rollback capability can reverse ransomware damage within minutes of detection — turning a potential catastrophic data loss into a contained and recoverable incident without paying a ransom.
What it prevents: successful ransomware encryption of student records and administrative data, silent lateral movement across school networks, and the extended dwell times that allow attackers to map and exfiltrate student information before triggering visible damage.
Without it: the student information system ransomware scenario above unfolds exactly as described — a school’s entire administrative database encrypted on the Friday before tuition invoices went out, with no forensic evidence to support the North Carolina breach notification response. EDR closes both the detection gap and the evidence gap simultaneously.
Microsoft Defender + DMARC
Email Security and Phishing Protection for Faculty and Business Office Staff
Microsoft 365 Defender for Education provides pre-delivery detonation of malicious attachments, URL rewriting for phishing links embedded in faculty and business office emails, impersonation protection for head of school and administrator accounts targeted in BEC attacks, and behavioral anomaly detection for compromised accounts — the control that would have flagged the attacker’s silent email monitoring in the tuition payment scenario within hours rather than three weeks. We enforce DMARC, SPF, and DKIM on every school client’s domain so attackers cannot send spoofed emails to families appearing to come from the school’s official address. For schools communicating tuition instructions, payment details, and sensitive information by email, domain protection is a direct financial safeguard.
What it prevents: credential phishing against faculty and business office accounts, domain impersonation targeting families, BEC attacks redirecting tuition payments and payroll, and unmonitored compromised account activity that runs for weeks before detection.
Without it: the average BEC attack runs for weeks before detection, during which time multiple payment runs can be redirected and substantial student data exfiltrated. Most the Charlotte area private schools have no alerting capability for compromised-account behavior that does not involve visible malware symptoms.
Immutable Backup
Ransomware-Resistant Backup for Student Records and Administrative Data
We deploy immutable, offsite backup with tested recovery that does not depend on paying a ransom or negotiating with an attacker. Immutability means backup data cannot be encrypted, deleted, or modified even if an attacker gains administrative credentials on the school’s primary network. Recovery testing is documented and performed regularly so that when a ransomware event occurs, recovery time objectives are known quantities. For the Charlotte area private schools that cannot afford enrollment data loss, financial record destruction, or extended administrative downtime, the backup architecture is what separates a recoverable incident from a crisis. The student information system database, payroll records, financial files, and enrollment data are specifically scoped into the backup program and tested independently.
What it prevents: the irreversible data loss in the SIS ransomware scenario above, where years of enrollment and financial records were unrecoverable because the school’s backup had not been tested and was itself encrypted during the attack.
Without it: the ransom note becomes your recovery plan. Schools with tested immutable backup recovered within a week without paying ransom in Sophos’s 2025 data. Schools without it faced prolonged downtime, data loss, and the financial and reputational pressure of an extended breach response during the academic year.
Cisco Meraki / CIPA
Content Filtering and Network Security for CIPA Compliance and Student Safety
We implement Cisco Meraki content filtering across all campus network access points — wired, wireless, and guest networks — enforcing age-appropriate filtering on all student-accessible internet connections and meeting CIPA requirements for schools receiving E-rate funding. Meraki’s filtering applies across every device connecting to the school network, including student Chromebooks, staff laptops, and classroom devices. For private schools with separate academic and administrative networks, we implement network segmentation preventing student-side network access from reaching administrative systems, student information systems, or payroll infrastructure. Filtering policies are documented to support E-rate certification and can be adjusted by grade level or device category.
What it prevents: student access to age-inappropriate content on campus networks, malware downloads through unsecured web browsing, and lateral network access that allows a compromised student device to reach administrative infrastructure.
Without it: schools applying for E-rate funding cannot certify CIPA compliance, making them ineligible for discounts on internet access. And without network segmentation, a Chromebook compromised through a malicious website becomes a direct pathway into the same network segment as the student information system.
Google Admin + Intune
Chromebook and 1:1 Device Fleet Management
We manage Chromebook fleets and mixed device environments through Google Admin Console and Microsoft Intune — enforcing approved extension lists, blocking sideloaded applications, applying certificate-based authentication, setting content filtering policies that follow the device off campus, and configuring Admin Console alerts for unusual access patterns. Device policies apply whether the Chromebook is on the school network or on a student’s home network, preventing the configuration drift that enabled the summer credential-harvesting attack in the scenario above. For schools with BYOD programs, we implement network access control policies restricting what unmanaged personal devices can access on campus networks. Device inventory is maintained continuously so the school always knows which devices are enrolled and which have policy compliance issues.
What it prevents: unauthorized extension installation on student Chromebooks, credential compromise through home network exposure, Admin Console access by unauthorized parties, and the loss of student directory data through exploited Admin Console access.
Without it: a 1:1 Chromebook program without enforced Admin Console policies is a fleet of individually managed risks, each capable of becoming a network access point on the first day back from summer when students return with their devices.
KnowBe4
Security Awareness Training for Faculty and Administrative Staff
Annual security awareness training for all staff with access to student records, payroll data, or financial systems — delivered through KnowBe4’s training modules with documented completion records; simulated phishing campaigns targeting the specific social engineering techniques used against school business offices and administrators (credential harvesting, tuition-related BEC pretexts, payroll change requests); and training content specific to the school environment including FERPA obligations, COPPA awareness for teachers deploying educational technology with students under 13, and recognition of BEC attack patterns targeting school payment processes. Training completion records are maintained in a format that supports both North Carolina breach notification defense and cyber insurance carrier audits at renewal.
What it prevents: the initial credential-phishing access that enabled the tuition fraud and the SIS ransomware attacks above, and the procedural gap that allowed the payroll diversion to succeed because no one called to verify the account change by phone.
Without it: a faculty member who clicks a phishing link in a school email account — common, documented, and preventable — becomes the entry point for an attack that can compromise the entire school network. Training records also matter: without documented completion records, schools cannot demonstrate workforce training to carriers or regulators.
Vulnerability Management
Patch Management and Vulnerability Assessment for School Infrastructure
We maintain a complete inventory of every device on the school network — administrative workstations, staff laptops, classroom computers, network-connected printers, servers running the student information system, and any smart building or security technology with network connectivity — and enforce a documented patch management process applying security updates within defined timeframes by severity level. For school environments, patch management requires coordination with SIS vendors (Blackbaud, FACTS, Veracross, and others) to avoid breaking application compatibility when OS or browser updates are applied — a step generic IT providers often skip, creating either unpatched systems or broken administrative software. Our vulnerability management platform provides continuous vulnerability scanning to identify exposures before attackers do, with remediation tracking that documents the school’s patch management program for cyber insurance audits.
What it prevents: vulnerability exploitation through unpatched systems — the same attack vector used in the Chromebook Admin Console scenario where a known configuration gap was exploited — and the coverage gaps that result when schools cannot document their patch management processes during an insurance renewal questionnaire.
Without it: the 241-day mean breach detection time from IBM’s 2025 data means an unpatched vulnerability can be under active exploitation for months before any alert fires. Schools with older infrastructure and limited IT staff are specifically targeted by ransomware operators using automated vulnerability scanning tools.
IR Plan + Va. Code 18.2-186.6
Breach-Ready Incident Response and North Carolina Notification Workflow
A documented incident response plan aligned to North Carolina’s breach notification law (Va. Code 18.2-186.6) and FERPA breach procedures, including a breach risk assessment workflow, parent and guardian notification letter templates, North Carolina AG Computer Crime Section notification package, and a first-72-hours response checklist specific to school ransomware and data theft incidents. North Carolina requires notification “without unreasonable delay” and AG notification for every reportable breach regardless of how many individuals are affected. Civil penalties can reach $150,000 per breach. We also provide tabletop exercise facilitation so school leadership — heads of school, business managers, technology coordinators — understand the notification process and first-response sequence before executing it under pressure during an active incident.
What it prevents: the compounding violation of a breach plus a late or missing North Carolina notification — two independent liability categories. A school with a documented IR plan and tested backup executes a controlled response. A school without one improvises, misses notification timelines, and faces regulators and concerned families simultaneously without a communication framework.
Without it: when the ransomware note appears on a Friday afternoon, every decision — who to call, what to preserve, how to notify families — is made under maximum stress with no documented process. North Carolina’s “without unreasonable delay” notification requirement does not recognize “we did not know what to do” as a defense.