Most school district IT departments are small; some are one or two people. And yet, they’re responsible for protecting thousands of student and staff accounts against threats that have grown considerably more sophisticated in recent years.
ManagedMethods, a Boulder, Colorado cybersecurity company that focuses exclusively on K-12 schools, is releasing a new product meant to address that imbalance: Email Threat Intelligence, an expansion of its existing Advanced Phishing offering.
The scale of the problem isn’t in dispute. CIS and MS-ISAC published a report in 2025 drawing on data from more than 5,000 K-12 organizations, collected between July 2023 and December 2024; 82% of those schools had experienced a cyber threat impact of some kind, and researchers logged nearly 14,000 security events and 9,300 confirmed incidents over that period.
Comparitech’s own research puts a number on the financial side of it: 251 ransomware attacks against schools, colleges, and universities worldwide in 2025, and close to 4 million records confirmed breached – up 27% from 2024.
Much of that risk starts in the inbox. ManagedMethods isn’t claiming Email Threat Intelligence catches more phishing attempts than its existing product; the company’s argument is narrower than that. What it’s trying to fix is what happens after detection – specifically, whether an understaffed IT team can actually do anything useful with the alerts it’s already receiving.
“Phishing remains the leading entry point for ransomware, account compromise, and data breaches, but simply detecting suspicious emails is no longer enough,” said Charlie Sander, ManagedMethods’ CEO.
“Email Threat Intelligence gives school districts the context they need to make smarter security decisions instead of reacting one email at a time.”
The product centers on a new analytics dashboard built on top of the company’s phishing detection engine, which in turn has been tuned to K-12 specific attack behavior rather than repurposed from broader enterprise security tools – which tend to assume a different kind of user base entirely.
Districts get a live view of phishing volume and how sophisticated the campaigns hitting them have become. The dashboard flags which staff and students are targeted most often, and it sorts incoming threats by method, including credential harvesting, business email compromise, brand impersonation, and platform abuse.
It also tracks activity over time, which can help a district notice, for example, that phishing attempts spike every August when a new school year starts.
One additional metric compares malicious to legitimate inbound email volume, which is less meant as a threat feed and more a diagnostic – a way for a district to check whether the email defenses they already have in place are actually working.
When something warrants closer investigation, the dashboard surfaces the most-targeted users, flagged senders, and daily trends rather than requiring staff to dig through logs manually.
“Our goal has always been to bring sophisticated cybersecurity capabilities within reach of every school district,” Sander added. “Email Threat Intelligence reflects that vision by giving K-12 IT teams the AI-powered email security toolkit they need to better protect students, staff, and district data.”
The company describes the release as one step toward a longer-term shift it wants districts to make, away from responding to individual phishing incidents and toward using the data those incidents generate to plan ahead.
Districts interested in a demonstration can find more information at managedmethods.com.
Featured image: via ManagedMethods

Disclosure: This article includes a client of an Espacio portfolio company.