Introducing KyberOS — Digital safety + Physical security in one platform.Learn more →
Back to Blog

Federal Swatting Guidance Landed. Your Filter Owns One Narrow Piece of It.

The ED and DOJ issued joint guidance on school swatting threats on September 25. A web filter does not stop a swatting call — but four specific things sit in the filtering and monitoring layer, and most districts have configured about half of them.

September 29, 2026By KyberGate TeamSchool SafetyK-12 PolicyThreat AssessmentStudent SafetyIT Admin GuidesIncident Response
Federal Swatting Guidance Landed. Your Filter Owns One Narrow Piece of It.

On September 25, the U.S. Department of Education and the U.S. Department of Justice jointly issued guidance on swatting threats against schools and colleges. The agencies called swatting a "crisis." The guidance is voluntary, and it lands on the same desk every safety directive lands on: yours.

Before we go further, the honest sentence that most vendor blog posts about this news will avoid:

A web filter does not stop a swatting call.

Swatting is a phone call to 911 from someone who is very often not on your network, not on your device, and not in your state. No proxy, no SSL inspection, no category list touches that. Any vendor who tells you their filter is an anti-swatting product is selling you something.

So why write this at all? Because the guidance asks schools to do five specific things, and two of them quietly become configuration work on your stack — and because the part filtering does own is small, real, and mostly unconfigured in the districts we talk to.


What the guidance actually says

The joint ED/DOJ document recommends that schools and colleges put in place:

  • Staff training on the typical characteristics of a swatting event, so false threats are identified sooner
  • Partnerships between on-campus officials and external law enforcement, with clear communication lines established before an incident
  • Training exercises that familiarize leaders with emergency decision-making protocols in advance
  • A multidisciplinary threat assessment team that can assess and address anonymous threats
  • A designated point person who leads campus-wide communications, notifies law enforcement, and evaluates threat level

The agencies also stated the operating rule plainly: all threats should be treated as credible when they are received. Under Secretary Nicholas Kent and Associate Attorney General Stanley Woodward Jr. wrote that "staff preparation is key and should be the foremost priority."

Note what is not on that list. There is no technology mandate. No filtering requirement. No software to buy. The guidance is about people, procedure, and rehearsal — which is the correct emphasis, and which is exactly why the technology conversation has to be scoped honestly rather than inflated.


The numbers: improving, not solved

Reporting from K-12 Dive, citing analysis from the Educator's School Safety Network, puts the trend in useful perspective:

School yearRecorded K-12 swatting incidents
2022-23446
2023-24158
2024-25124

That is a 72% decline from the 2022-23 peak, and a 22% decline year over year. The network's analysis found it difficult to isolate why the drop was so steep, though increased prosecution of offenders appears to be a factor.

Read that table carefully before you relax. A 72% decline still leaves 124 incidents in a single school year — each one triggering a lockdown or shelter-in-place, each one consuming a law enforcement response, each one costing instructional time and leaving trauma behind in a building full of children. The federal agencies noted swatting costs taxpayers millions in personnel, equipment, lost classroom time, and property damage.

Declining is not the same as rare. The odds your district sees one this year are not zero, and the guidance exists because the cost per incident stayed high even as the count fell.


The narrow piece that is genuinely yours

Here is the part of swatting response that does live in the filtering and monitoring layer. It is four things. It is not more than four things.

1. Threats composed on school-managed accounts

A meaningful share of school threats — not swatting calls themselves, but the bomb threats, shooting threats, and "don't come to school tomorrow" messages that trigger the same lockdown machinery — are typed on a district-issued device, in a district Google account, during the school day.

That content is inside your perimeter. It is visible to you in a way a burner VoIP call never will be. KyberPulse monitors student Google Workspace content — Docs, Gmail, Slides, Chat — for violence and threat language, using contextual analysis rather than keyword matching, so a history essay about a school shooting does not generate the same alert as a student drafting one.

The guidance asks for a threat assessment team that can "assess and address anonymous threats." A team with no data source is a meeting. This is one of the few data sources you actually control.

2. The anonymity tooling that makes an on-network threat untraceable

If a student can reach a VPN, a web proxy, an anonymous text-sending service, or a burner-number site from a school device, then a threat that originated in your building becomes a threat that appears to originate anywhere. You lose attribution on the one incident class where you had it.

This is straightforward category work, and it is frequently half-done: districts block "VPN" and never touch web-proxy mirrors, browser-integrated VPNs, or the free burner-SMS sites that sit in no obvious category at all. We wrote about the mechanics of that in VPN detection and bypass prevention. Applied here, it is not about content policy — it is about whether your threat assessment team can ever answer "who sent this."

3. Logs that survive the incident

When law enforcement arrives, the questions are specific: which device, which account, what time, what did it reach. If your filtering logs have a 7-day retention window and the investigation starts on day nine, you have nothing to hand over.

Check your actual retention setting before you need it. Not the marketing page — the setting.

4. The harassment and doxing surface

Swatting is usually the endpoint of a targeting campaign, not a random act. The doxing sites, harassment forums, and address-lookup services that supply a swatter's target details are ordinary filterable categories. Blocking them on school devices does not stop an adult at home. It does remove one path by which a student-to-student conflict escalates into a police response at a classmate's house.


Mapping the guidance to configuration

Two of the five federal recommendations translate directly into work on your stack.

"A multidisciplinary threat assessment team that can assess and address anonymous threats" — the team needs inputs. Decide now, in writing, which systems feed it: filtering alerts, Workspace monitoring alerts, device logs, SIS discipline records. Decide who has query access at 6 a.m. on a Saturday. A team that has to file a ticket to get a log export is not an incident-response capability.

"A point person who leads efforts to publish campus-wide communications, notify law enforcement and evaluate the level of threats" — that person needs a console login and standing permission to use it. If your named point person is a principal who has never opened the filtering dashboard, the account exists but the capability does not. Our broader take on this gap is in the school incident response plan guide.

The other three — staff training, law enforcement partnerships, rehearsal — are not IT deliverables, and you should resist being handed them because you were in the room.


Where alert fatigue will sabotage this

There is a failure mode specific to doing this well.

Turn on threat monitoring, wire it to a response team, and instruct everyone that all threats are treated as credible — and you have built a system whose volume determines whether anyone still reads it in March. We have watched districts configure aggressive keyword alerting, generate several hundred flags a week, and functionally stop triaging by the second month.

The federal guidance says to treat every threat as credible. It does not say to manufacture threats out of false positives. Those are different instructions, and a keyword-matching monitor cannot tell them apart. Contextual classification and a real triage path are what keep the first instruction survivable — the reasoning is in our alert fatigue and triage guide.


A short list for this month

  1. Pull your filtering log retention number. Write it down. If it is under 90 days, raise it or document why not.
  2. Test the anonymity categories yourself. On a real student device, try to reach a web proxy, a browser VPN, and a free anonymous-SMS site. Do not check the toggle — check the result.
  3. Name the systems that feed your threat assessment team, and confirm each named member can actually log into each one.
  4. Confirm your communications point person has console access, and has used it once.
  5. Check whether threat-language monitoring is on at all for student Workspace accounts, and who receives those alerts outside school hours.

None of these require a purchase. All of them are things a district discovers it skipped on the morning it matters.


The bottom line

The federal swatting guidance is a people-and-procedure document, and it is right to be. Filtering is not an answer to swatting, and we are not going to pretend otherwise to sell a product.

What the filtering and monitoring layer owns is narrow: threats composed inside your perimeter, attribution on devices you control, logs that outlive the incident, and the harassment surface that precedes the call. That is a real contribution to the threat assessment capability the guidance asks for, and it is worth configuring properly precisely because it is the part you can actually control.

Everything else on that list is drills, relationships, and training. Do those first.


KyberPulse surfaces violence and threat language in student Google Workspace content with contextual analysis, not keyword matching. KyberFilter handles the anonymity and harassment categories at the network layer, with logs that survive an investigation. Together they cover the slice of student safety that genuinely belongs to IT.

Start a free 30-day pilot and see what your current stack is and is not capturing today. Or view pricing — per-device, no hidden fees.

Ready to protect your students?

Deploy KyberGate in under 30 minutes. No hardware required.

Request a Demo