2,000 users, a device for every student, and a network that trusted whatever connected.
A Montana K12 district grew from a few hundred devices to one per student. We implemented Zero Trust so connecting to the network no longer meant access to everything.

A K12 school district with around 2,000 users across multiple schools, running a one-to-one student device program alongside BYOD and vendor-managed building systems.
K12 Education
Zero Trust Networking, Network Segmentation, Multifactor Authentication, Continuous Monitoring
A Montana K12 school district with around 2,000 users across multiple schools had watched its IT environment grow for two decades. What started as a few hundred devices had become a one-to-one program, with a device for every student.
The network's security model hadn't kept pace with that growth. The district brought us in to rebuild it so that connecting to the network no longer meant automatic access to what was on it.
Before
The Challenge
A school network carries more kinds of devices than most business networks. Bring Your Own Device policies were hard to enforce, and shadow IT devices brought in by staff and students created entry points the district didn't know about.
Outside vendors also ran operational technology for building automation on the network, adding systems the district didn't directly manage and more access risk to control. Underneath it all, the network's design let any connection potentially reach every resource, so a single problem could put the entire district's data at risk. The result was constant strain on the IT team, a high risk of a breach, and the potential for serious disruption to learning.
The administration set four goals: implement Zero Trust networking to strengthen overall security, stop connections from automatically granting broad access, safely manage every device on the network including student BYOD and building automation systems, and protect sensitive student and staff information across all systems.
After
The Results
The district's security posture is fundamentally stronger, with greatly reduced risk of breaches and unauthorized access across all of its schools. The IT team shifted from constant firefighting to strategic work.
The network is more stable and reliable, and students and staff have uninterrupted, secure access to what they need. The IT team now has clear visibility into and control over the devices and activity on the network.
The district runs more efficiently, and its schools are a safer learning environment for everyone in them.
The Solution
Our engineers began by assessing the district's existing network, then designed a Zero Trust framework tailored to its needs and its multiple school sites.
We segmented the network to isolate critical assets and limit access by user role, which reduced the ability of an attacker or compromised device to move laterally. We enabled multifactor authentication at key access points so only authorized staff and students could reach sensitive resources.
We set up real-time monitoring and logging to detect and respond to suspicious activity. We enforced least privilege access, so users received only the access their roles required. And we required every connecting device, BYOD included, to meet compliance standards for security patches and secure settings, so non-compliant devices couldn't introduce vulnerabilities.
We guided the district through each step, then provided clear documentation and training so the IT staff could manage and maintain the new environment on their own. Daily operations at the schools continued without disruption throughout the rollout.
Getting onto the district network should not, by itself, grant access to anything on it.
Something here raise a question about your own setup?
Thirty minutes, no slide deck. If you're in decent shape we'll tell you that.
Schedule a call