Tex. Education Code § 11.175
This is the official text of Tex. Education Code § 11.175, part of Texas’s Education Code — governs public schools and universities in Texas.
Not legal advice. This page reproduces the official text of a government statute for reference only. Laws change, and how a statute applies depends on your specific facts. For advice about your situation, consult a licensed attorney in your state.
§ 11.175. SCHOOL CYBERSECURITY.
Official statutory text
(a) In this section:
(1) "Breach of system security" means an incident in which student information that is sensitive, protected, or confidential, as provided by state or federal law, is stolen or copied, transmitted, viewed, or used by a person unauthorized to engage in that action.
(2) "Cyber attack" means an attempt to damage, disrupt, or gain unauthorized access to a computer, computer network, or computer system.
(3) "Cybersecurity" means the measures taken to protect a computer, computer network, or computer system against unauthorized use or access.
(b) Each school district shall adopt a cybersecurity policy to:
(1) secure district cyberinfrastructure against cyber attacks and other cybersecurity incidents; and
(2) determine cybersecurity risk and implement mitigation planning.
(c) A school district's cybersecurity policy may not conflict with the information security standards for institutions of higher education adopted by the Texas Cyber Command under Chapters 2059 and 2063, Government Code.
(d) The superintendent of each school district shall designate a cybersecurity coordinator to serve as a liaison between the district and the agency in cybersecurity matters.
(e) A school district or open-enrollment charter school shall report to the agency or, if applicable, the entity that administers the system established under Subsection (g) any cyber attack or other cybersecurity incident against the school district's or open-enrollment charter school's cyberinfrastructure that constitutes a breach of system security as soon as practicable after the discovery of the attack or incident.
(f) The district's cybersecurity coordinator shall provide notice to a parent of or person standing in parental relation to a student enrolled in the district of an attack or incident for which a report is required under Subsection (e) involving the student's information.
(g) The agency, in coordination with the Department of Information Resources, shall establish and maintain a system to coordinate the anonymous sharing of information concerning cyber attacks or other cybersecurity incidents between participating schools and the state. The system must:
(1) include each report made under Subsection (e);
(2) provide for reports made under Subsection (e) to be shared between participating schools in as close to real time as possible; and
(3) preserve a reporting school's anonymity by preventing the disclosure through the system of the name of the school at which an attack or incident occurred.
(h) In establishing the system under Subsection (g), the agency may contract with a qualified third party to administer the system.
(h-1) Notwithstanding Section 2063.103, Government Code, only the district's cybersecurity coordinator is required to complete the cybersecurity training and the artificial intelligence training under that section on an annual basis. Any other school district employee required to complete the cybersecurity training and the artificial intelligence training shall complete the training as determined by the district, in consultation with the district's cybersecurity coordinator.
(i) The commissioner shall adopt rules as necessary to implement this section.
(1) "Breach of system security" means an incident in which student information that is sensitive, protected, or confidential, as provided by state or federal law, is stolen or copied, transmitted, viewed, or used by a person unauthorized to engage in that action.
(2) "Cyber attack" means an attempt to damage, disrupt, or gain unauthorized access to a computer, computer network, or computer system.
(3) "Cybersecurity" means the measures taken to protect a computer, computer network, or computer system against unauthorized use or access.
(b) Each school district shall adopt a cybersecurity policy to:
(1) secure district cyberinfrastructure against cyber attacks and other cybersecurity incidents; and
(2) determine cybersecurity risk and implement mitigation planning.
(c) A school district's cybersecurity policy may not conflict with the information security standards for institutions of higher education adopted by the Texas Cyber Command under Chapters 2059 and 2063, Government Code.
(d) The superintendent of each school district shall designate a cybersecurity coordinator to serve as a liaison between the district and the agency in cybersecurity matters.
(e) A school district or open-enrollment charter school shall report to the agency or, if applicable, the entity that administers the system established under Subsection (g) any cyber attack or other cybersecurity incident against the school district's or open-enrollment charter school's cyberinfrastructure that constitutes a breach of system security as soon as practicable after the discovery of the attack or incident.
(f) The district's cybersecurity coordinator shall provide notice to a parent of or person standing in parental relation to a student enrolled in the district of an attack or incident for which a report is required under Subsection (e) involving the student's information.
(g) The agency, in coordination with the Department of Information Resources, shall establish and maintain a system to coordinate the anonymous sharing of information concerning cyber attacks or other cybersecurity incidents between participating schools and the state. The system must:
(1) include each report made under Subsection (e);
(2) provide for reports made under Subsection (e) to be shared between participating schools in as close to real time as possible; and
(3) preserve a reporting school's anonymity by preventing the disclosure through the system of the name of the school at which an attack or incident occurred.
(h) In establishing the system under Subsection (g), the agency may contract with a qualified third party to administer the system.
(h-1) Notwithstanding Section 2063.103, Government Code, only the district's cybersecurity coordinator is required to complete the cybersecurity training and the artificial intelligence training under that section on an annual basis. Any other school district employee required to complete the cybersecurity training and the artificial intelligence training shall complete the training as determined by the district, in consultation with the district's cybersecurity coordinator.
(i) The commissioner shall adopt rules as necessary to implement this section.
Status: in_force · Read it on the official government site
Need a lawyer in Texas?
Find a Texas lawyer
About this page: Statute text is reproduced from official government publishers via the
Open US Law dataset
(Vaquill AI, snapshot v2026.08, CC BY 4.0). Primary legislative text like this is public domain under the government-edicts doctrine
(Georgia v. Public.Resource.Org, 2020). We link every section back to its official source so you can verify it independently.