Recent conversations about technology in schools have centered around one main question: Are students spending too much time on screens?
Now, this debate has expanded to include issues like AI, a ban on cellphones and/or tablets, and the broader role of digital learning. While the concerns are legitimate, for schools’ technology leaders, these questions are incomplete.
The most urgent concern is not determining how many devices belong in classrooms; it is understanding how schools intend to govern the digital ecosystems students are using, across school-issued and personal devices. Those advocating for stricter limits on classroom technology have learned to recognize this distinction.
As the American Federation of Teachers recently outlined new recommendations on student technology use, President Randi Weingarten pointed out that she was “not calling for a ban on AI or a bonfire of Chromebooks.”
The issue is no longer whether technology belongs in classrooms. It’s whether schools have the operational maturity to manage it responsibly, and that is a responsibility that extends far beyond the device itself.
Modern school perimeter lives in the cloud
School-issued laptops or tablets are only one part of a student’s digital learning environment. Student identities, cloud storage, collaboration platforms, browser sessions, and third-party applications are the new learning infrastructure. And this is also where most cybersecurity risks emerge.
Cybercriminals do not need access to a district-issued device to compromise a student account. Because Microsoft 365 and Google Workspace can be accessed from virtually anywhere, weak or stolen credentials can give attackers easy access to accounts that lack adequate monitoring.
Attackers can then send phishing emails from trusted school addresses, making recipients more likely to click malicious links or disclose sensitive information. These attacks can compromise additional accounts and expose student, staff, and financial data.
Without appropriate monitoring, governance and security controls, restricting managed devices does little to reduce a district’s exposure.
In other words, removing “managed” devices doesn’t remove digital risk. It transfers that risk into environments where school technology teams have less visibility and fewer opportunities to intervene.
This shift has fundamentally changed what K-12 cybersecurity looks like. Protecting endpoints is still important, but it is no longer sufficient.
Visibility is a K12 cybersecurity requirement
Schools cannot secure what they cannot see. Visibility must now extend beyond networks and devices into the cloud services students use.
Shared documents, email accounts, collaborative workspaces, and third-party applications are all potential attack surfaces that traditional network controls are not designed to monitor.
One Wisconsin district discovered this reality during a routine security review when administrators found a Google Doc containing more than 7,000 links to proxy websites intended to bypass the school’s web filter. This activity wasn’t occurring on the district network; students had organized and distributed the document entirely within their Google accounts.
This particular incident isn’t simply about students circumventing rules. It demonstrated how cloud-native activity can create operational and security blind spots if schools focus only on devices rather than digital identities and online collaboration environments.
As more instructional resources migrate to cloud platforms, such as Google Workspace and Microsoft 365, identity and account governance will need the same attention schools have historically given to endpoint security.
Governance should enable innovation
Technology governance is viewed as synonymous with restriction. In reality, however, effective governance is what makes innovation possible.
School IT teams should establish security guardrails that protect student data, maintain compliance and reduce operational risk. Within those guardrails, educators must have the flexibility to adapt technology to different instructional goals, based on the requirements of each course.
The most successful technology implementations are often the least noticeable. Security operates quietly in the background, allowing educators to focus on teaching while students experience technology as a learning tool rather than an obstacle.
The objective isn’t to monitor every action. It’s to establish clear, predictable guardrails that allow digital learning to happen safely and efficiently.
AI raises the stakes for digital governance
Artificial intelligence has accelerated the need for stronger governance as it has already become an integral part of teaching and learning. The challenge now is to ensure AI adoption aligns with the schools’ policies on student privacy, academic integrity, and responsible technology use.
This requires governance models that evolve as cybersecurity cannot remain focused on devices when instructional environments increasingly depend on cloud applications, AI services, and digital identities that extend beyond the traditional school network.
A school’s technology strategies should therefore be evaluated not by the number of devices deployed, but by how effectively they govern the systems supporting digital learning.
Schools that approach cybersecurity, instructional innovation and technology governance as interconnected priorities will always be better positioned to adapt to the future. In today’s education environment, resilience depends less on limiting technology and more on building policies and governance frameworks that allow it to be used with confidence.





