Building a Statewide Cybersecurity Program Through Managed Vulnerability Management

Executive Summary

Students using computers in a K-12 school protected by managed vulnerability management

Facing rising cyber risk, tight budgets, and limited staff, a U.S. State Department of Education partnered with Pellera to design and operationalize a statewide cybersecurity program protecting K-12 school districts at scale. Built on Tenable One, the program turned fragmented, tactical vulnerability management into a centralized, measurable service and within the first 90 days, districts achieved a 74% reduction in identified vulnerabilities.

The Challenge

K-12 school districts face a persistent cybersecurity gap driven by limited expertise and staffing, expanding attack surfaces across endpoints, cloud services, and student devices, and severe budget constraints. The State Department of Education needed to provide consistent, auditable support across districts, reduce risk rapidly without overwhelming local IT teams, and create a repeatable, scalable operating model.

Disconnected tools, decentralized management, and ad-hoc remediation were failing. Pellera reframed the problem with a simple talk track: give us the hardest thing you’re struggling with, and let us take it off your plate and turn it into a strength.

The Approach

Building on a long-standing partnership that spanned multiple leadership changes, Pellera co-developed a statewide program from the ground up and deployed a Managed Vulnerability Management Service anchored by 600,000 Tenable One licenses — enabling the state to run an MSSP-style model for its districts.

The Solution

The service combined a unified platform, a standardized district rollout, and hands-on managed support:

01

Tenable One Platform

Unified visibility across endpoints, applications, identities, and cloud assets, with risk-based prioritization and per-district dashboards at statewide scale.

02

District Deployment Model

Standardized onboarding, credentialed scanning, scheduled assessments, and alerting centrally orchestrated to state security standards.

03

Pellera Managed Services

Program governance, scan tuning, vulnerability triage, weekly prioritized reports, and optional fully managed operations for districts with limited staff.

The Results

Over three 30-day remediation sprints, participating districts saw dramatic risk reduction:

74% fewer vulnerabilities

A 74.31% total reduction in identified vulnerabilities across participating districts.

22,154 vulnerabilities found

Identified across districts and systematically remediated.

84% drop in critical vulnerabilities

Critical-severity vulnerabilities reduced by 84%.

91% drop in high vulnerabilities

High-severity vulnerabilities reduced by 91%.

The program focused on high-impact, low-disruption updates, standardized remediation across districts, and centralized compliance reporting without adding to district workloads which are currently graded B+, with a clear path to A+ as adoption expands.

Conclusion

By partnering with Pellera, the State Department of Education shifted from reactive tooling to a problem-solving, outcomes-driven cybersecurity program. Turning one of education’s greatest vulnerabilities into a sustainable strength. Schedule a consultation.