The New School Safety Perimeter: Where Cybersecurity Meets Physical Security
Key Highlights
- Physical and digital security systems in schools are often managed separately, creating vulnerabilities when digital credentials are compromised.
- Current funding frameworks focus on hardware without ensuring integration, leaving critical interfaces unmonitored and unowned.
- Effective school safety requires deliberate, audited interfaces between physical access controls and digital identity systems, with clear ownership and protocols.
- Regular audits and real-time response protocols are essential to detect and mitigate breaches quickly, minimizing physical security risks.
- Policymakers should adopt practices from critical infrastructure sectors, including comprehensive inventories, defined ownership, and accountability measures for integrated security systems.
At many institutions, the student ID number exposed in a data breach is the same number that unlocks dorm doors, sits behind classroom badge readers, controls laboratory access, and authenticates into building automation systems. The badge in a student's wallet is keyed to that database. When that database is compromised, every physical system running on top of it becomes a question: who can we still trust?
The administrator who commissioned that system in 2016 was buying hardware: cameras, locks, badge readers, items on a procurement list, signed off at handover. The administrator commissioning one today is buying a platform: the same hardware, plugged into network infrastructure, identity databases, cloud services, and incident-response protocols that determine whether any of it functions when something actually happens.
State funding has kept pace with the hardware. It has not kept pace with the platform underneath, or with the audit framework needed to verify that the two work together. The recent Canvas breach made that gap visible in a way that should change how state funding frameworks think about school safety.
What the Canvas Breach Exposed
In May, attackers exfiltrated student records, names, email addresses, and student ID numbers from 8,800 institutions and roughly 275 million users. What concerned us at Acre wasn't just the breach itself. It was what it meant for the physical systems running on top of that identity infrastructure.
At institutions where student IDs are integrated with physical access control, and in our experience deploying these systems, that's more common than most administrators realize; the exposure doesn't stop at the data breach. The lockdown protocol, when activated, pulls from that same database. The campus security system treats that number as the identity it trusts.
Once a credential is exposed at that scale, every physical system that uses it becomes a question of trust. Not because attackers will necessarily walk into a building with a cloned badge, but because the institution can no longer prove that they cannot. And the standard incident response, "rotate credentials", runs into the physical limit that you cannot reprint 30,000 student IDs over a single weekend.
What we see across our deployments is the predictable outcome of treating physical and digital security as separate accountability frameworks; separate budgets, separate audits, separate owners, in an environment where they stopped being separate things years ago.
How the Funding Frameworks Haven't Caught Up
State school safety funding has grown across the country. Texas has doubled its school safety allotment. Colorado runs a statewide School Security Disbursement program. Michigan committed $321 million in school safety grants after Oxford. The visible side of the work has, finally, become a priority.
But almost all that funding goes to physical hardware, and almost none of it requires districts to show the hardware is integrated with the systems behind it. The funding pays for the camera. It does not pay for the integration between the camera, the access control system, and the identity provider that decides who is allowed to be on screen. It pays for the badge reader. It does not pay for the framework that decides what happens to that badge reader when the identity provider has been compromised.
Physical security is funded through one bucket and audited (where it is audited at all) by one inspector. Cybersecurity is funded through another bucket and audited by a different one, if at all.
In our experience, it's because the accountability infrastructure that would require integration doesn't yet exist, and no one in the current funding framework has asked what lives between them. Physical security is funded through one bucket and audited (where it is audited at all) by one inspector. Cybersecurity is funded through another bucket and audited by a different one, if at all. The thing that lives in between the integration, the interfaces, the protocols that link physical to digital- does not have a clear owner in most state funding frameworks. It also does not have a clear owner in most district org charts.
That gap needs closing. It will not close on its own.
What Integrated School Safety Actually Looks Like
The districts we work with that get this right share a few characteristics.
Their access control systems are connected to their identity infrastructure through deliberate, audited interfaces, not by accident. When a credential is compromised in the digital system, the physical side knows about it within hours, not weeks, and the response is automatic rather than dependent on someone in another department remembering to call. Their security teams cover both estates: someone is named owner for what happens to physical access when our identity provider has a breach, and someone is named owner for what happens to digital systems when a key is physically stolen. Vendor and contractor access, often an afterthought in credentialing, is managed through the same integrated framework, not a separate spreadsheet.
Their training reflects integration. Staff is taught not just what to do in a lockdown, but how to recognize the early signs of compromise: an unfamiliar badge attempt, a system showing an authorized entry at a time the student is known to be off-site, a maintenance account logging in from a location it should not be.
And, most importantly, someone is responsible for measuring the integration itself. Not the physical estate. Not the digital estate. The interface. That role does not exist in most state funding frameworks. It rarely exists in district org charts. But the districts that have built it are the ones with a defensible answer to the question that is coming: what did your safety budget actually buy?
What State Funding Should Require Next
My children do lockdown drills at their school in Austin. So do millions of children in every state. The drill teaches them how to respond when the physical system is challenged. It does not prepare anyone for what happens when the digital system has been compromised in a way that makes the physical system unreliable. The next generation of school safety frameworks needs to close that gap, district by district.
● A single inventory that documents both the physical and digital systems in a school, and the interfaces between them. Not two lists, one connected list.
● A named owner at the district level for the integrated security posture, not just "the cameras" or "the firewall," but the interface between them.
● A regular audit, not just an installation receipt. The question is no longer whether we installed the system. It is: does the system still do what it was funded to do, given the conditions it now operates in?
● A protocol that defines what happens, on the physical side, when the digital side reports a credential compromise, and vice versa.
● A reporting requirement back to the state on what specifically the funding bought, integrated against what.
These are not radical asks. They are the standard practices of critical-infrastructure sectors that figured this out a decade ago: power generation, transportation, hospital systems, and that school districts can borrow from without reinventing.
The Accountability Question, Restated
The Canvas breach was a warning, not a one-off. The accountability question that follows from it is not whether schools should spend more on cybersecurity. It is whether what they are already spending on physical security can be measured against the digital reality those systems now operate inside.
The next school safety debate will not be about dollars. It will be about whether the dollars bought a connected system. The time to build that case is now, not after.
About the Author
Kumar Sokka Kumar Sokka
CEO of Acre Security
Kumar Sokka is CEO of Acre Security, a global provider of integrated physical security solutions serving more than 100,000 customers across 25 countries. Acre works directly with higher education institutions on the challenge at the center of this piece, building security infrastructure where physical and digital systems operate as a single accountable framework.
