Skip to main content
Has your work email already leaked?Run the 10-second check
State, local and education

A district cannot hire five analysts. It can buy the shift.

Public sector affordability is rarely solved by a discount. It is solved by knowing which pot the money comes out of and which contract lets you buy without a nine-month solicitation. This page is about both, because that is what actually blocks the purchase.

The short version

SLED means State, Local and Education: the public sector outside federal. It is a procurement grouping rather than a technical one, because these buyers share funding mechanisms, purchasing rules and budget cycles.

The security problem is the same one every mid-market organization has, with two differences. The budget cannot absorb a staffed 24/7 rotation, which is several full-time salaries. And the purchase is governed by procurement rules that decide the timeline more than the requirement does.

So the practical answer to "how does a district afford a SOC" is usually which funding route it uses and which contract vehicle it buys through, not what the service costs per endpoint. Vijilan sells directly to districts and agencies, and white-label behind the education-focused MSPs that already serve them.

Three buyers, one label

Grouped by how they buy, not by what they run.

K-12 school districts

The most targeted and least resourced segment in the sector. Thousands of identities turning over every semester, a network deliberately open to students, and almost never a security team. Coverage has to arrive as a service because the alternative does not exist at district budgets.

Higher education

Research data, federal grant obligations, a population that changes annually, and departmental IT that predates central control. The security problem is usually less about tooling than about how many separate estates there genuinely are.

State and local government

Counties, municipalities, utilities and agencies running services residents cannot do without, frequently on a single IT team covering everything from payroll to water treatment. Public-records and breach-notification duties apply regardless of headcount.

Why the sector

K-12 is hit roughly three times as often as higher education.

In the United States in 2025, K-12 institutions recorded around 96 ransomware attacks against higher education’s 34. Across confirmed attacks in the sector, roughly 3.9 million records were exposed, about 27% more than the 3.1 million of the year before, while the number of attacks stayed broadly flat.

Flat volume with rising exposure is the more concerning of the two shapes. It means the attacks that land are reaching further, which is what happens when there is nobody watching between the initial compromise and the exfiltration.

Figures from Comparitech, reported via GovTech, covering calendar year 2025. They are not Vijilan’s measurements and are attributed here for that reason.

How it gets paid for

Four routes, and how reliable each one is.

Written with the caveats attached, because a funding page that omits the oversubscription rate is not helping anybody plan.

FCC Schools and Libraries Cybersecurity Pilot

K-12 districts and libraries

A three-year, $200 million pilot using Universal Service Fund money, separate from the existing E-Rate categories so it does not consume that budget. Support is scaled to the applicant’s discount rate, from 20% to 90%, weighted toward low-income and tribal applicants.

In practice: Substantially oversubscribed. Roughly 614 applicants submitted around $1.35 billion in funding requests against $200 million available, so participation is selective rather than automatic.

State and Local Cybersecurity Grant Program

State, local and tribal government, sometimes passed through to districts

Appropriated $1 billion across four years under the Infrastructure Investment and Jobs Act covering 2022 to 2025, administered through CISA and FEMA with state pass-through to local entities. Periods of performance run into FY2029.

In practice: Its future beyond the original appropriation is not settled. Check your state administering agency for the current cycle rather than assuming a window is open, and do not build a multi-year plan on it alone.

State-level cybersecurity programs

Varies by state

Several states fund district cybersecurity directly, through the state education agency, a statewide service cooperative, or a shared services model. These are frequently the most reliable route and the least publicized.

In practice: Entirely state-specific. Your regional service agency or educational cooperative usually knows more about what is actually available than any national source.

Cooperative purchasing

All of SLED

Not funding, but the thing that usually determines how fast a purchase can happen. Buying through an existing cooperative contract can remove a competitive solicitation cycle from the timeline entirely.

In practice: Ask us which vehicles we can be reached through before you scope a solicitation, because the answer changes what the process has to look like.

Grant programs change every cycle and application windows open and close. Nothing above is a guarantee of availability, and we have deliberately not printed application deadlines here rather than risk showing you one that has passed. Ask us and we will tell you what is genuinely open.

And when there is no grant.

Most districts buy this without one, so it is worth saying what makes it affordable in the ordinary case. A staffed 24/7 rotation is several full-time salaries plus the training to keep them current, and no district is hiring five analysts. The service is cheaper than the thing it replaces because the cost is shared across every organization the SOC covers.

Two things beyond that matter for a public budget. ThreatRespond™ wraps the tooling the district already owns, so an existing EDR investment is not written off. And ThreatLog™ is index-free, which means retention for compliance does not carry a per-gigabyte bill that grows every time coverage improves.

Questions

Asked by superintendents and county IT directors.

What does SLED mean?

State, Local and Education: the public sector market outside federal. It is a procurement term rather than a technical one, and it groups these buyers together because they share funding mechanisms, purchasing rules and budget cycles, not because their networks look alike.

How can a school district afford a 24/7 SOC?

Usually not out of the general fund, which is why the honest answer to affordability in this sector is about which pot the money comes from rather than about a discount. The realistic routes are the FCC cybersecurity pilot if the district is a participant, state-level programs administered through an education agency or service cooperative, and buying through an existing cooperative contract to avoid a solicitation cycle. Beyond that, a managed service is simply cheaper than the alternative, because a staffed 24/7 rotation is several full-time salaries and no district is hiring five analysts.

Is the E-Rate cybersecurity funding guaranteed?

No. The FCC pilot is $200 million over three years and was substantially oversubscribed: roughly 614 applicants requested about $1.35 billion. Participation is selective, weighted toward low-income and tribal applicants, and it should be treated as a possible accelerant rather than the basis of a plan.

How bad is the threat to K-12 specifically?

In the United States in 2025, K-12 institutions recorded roughly 96 ransomware attacks against higher education’s 34, close to three times as many, and confirmed attacks across the sector exposed about 3.9 million records, up around 27% on the previous year. Attack volume was broadly flat year on year while records exposed rose, which is the more concerning shape of the two. Figures from Comparitech, reported via GovTech, covering calendar 2025.

Do you work with districts directly or through an MSP?

Both. Many districts already have an education-focused MSP and we run white-label behind them; we never compete with our partners for their clients. Where a district or agency buys direct, we sell direct. Those are not in tension, and anyone telling you a provider must be one or the other is describing their own constraint.

What about student data privacy and FERPA?

FERPA obligations and state student-privacy laws apply whether or not a district has a security team, and the practical gap is usually evidence rather than controls. What a managed service produces, an incident timeline, access logging, retained audit trail, is the material those obligations actually ask for. The compliance services page covers how that maps to a framework.

Our procurement requires a competitive process. Where does that start?

With scope, and earlier than most solicitations start. We would rather help you write a specification that describes what you actually need, including the questions that separate providers, than respond to one that has already been written around somebody else’s datasheet. The RFP tool is a faster first pass if you want a draft to react to.

We're online · book a SOC walkthrough today

Tell us the district
and the fiscal year.

The useful first conversation is about which funding route is genuinely open to you and what your procurement rules require, not about endpoints. We will be specific, including when the answer is that you should wait for a cycle.