Back to School Cybersecurity Advice

0

Schools are entering the 2026–2027 academic year, and as they do, they are facing a radically different security landscape. One shaped by AI‑driven attacks, expanding third‑party ecosystems, and rising pressure on already resource‑strapped IT teams. In an Action1 Cybersecurity in Education Report for 2025-2026, two-thirds of school IT Leaders rated their cybersecurity posture as moderate, and over 85% experienced at least one incident.

The expert commentary that follows makes one theme unmistakably clear: identity, access, and vendor governance now define the frontline of school cybersecurity. From phishing campaigns supercharged by GenAI to EdTech platforms that can amplify a district’s blast radius, these insights outline the practical, urgent steps schools must take to protect students, staff, and critical operations in an era where attackers move faster, automation raises the stakes, and every connection introduces new risk.

Third-Party Risk Comes From Access

Third-party risk is about access, not brand size. Schools should establish what sensitive information a supplier handles and what access it requires. They should also check whether MFA is enforced, privileged accounts are controlled, vulnerabilities are patched promptly, and recognised standards such as Cyber Essentials or ISO 27001 can be evidenced. Crucially, vetting must continue after procurement through regular reviews, audits and access checks, because third party risk changes as systems, permissions and threats evolve.

Jennifer Williams, Managing Director, Secarma

Achieving Good Security With Budget Constraints

Districts with limited budgets are likely to assume good security must involve investing in expensive systems – and therefore ignore it as a core issue that needs priority and be added into their budget – I am advocating this thought process has to change. The easiest wins are the unglamorous things: multifactor authentication everywhere, robustly tested offline backups and an incident response plan schools have actually practised, not just filed away and forgot about it. What I would add that people rarely consider is that the cheapest way for a high cyber safety score is simply by getting the answers to “the worst-case scenarios”- not what you would prefer to save, but what you would inevitably end up losing; you prioritise a system based on its loss impact, not necessarily its value from a price perspective, such an approach ensures your school is far more secure with the same budget than simply ignoring it. Remember too, you do not need a huge team of experts for this. Even a few individuals with a strategic mindset can carry out significant improvements, but that demands support and budget for consistent training courses. What people miss usually though, with time technology advancements. Remember the days you used a Nokia in a world that transitioned to iPhones: this does not need to be you in your systems nor the process of updating all devices/programs/softwares because they do not have to be!

Rafay Baloch, CEO and Founder, REDSECLABS

Determine the Blast Radius

Schools need to vet the potential blast radius of an EdTech vendor, not just the vendor’s security claims. Before approving a platform, IT leaders should know exactly what student or staff data it collects, where that data is stored, who can access it, what third parties or subcontractors can touch it, and whether MFA, SSO and least-privilege access are supported. They should also establish breach-notification requirements, data retention and deletion policies, and a clear process for exporting or recovering critical information if the vendor becomes unavailable. No vendor can guarantee it will never be breached, so the goal is to make sure one compromised provider cannot become a single point of failure for an entire district.

Bryan Sevener, Founder & CEO, ValorTech

Phishing Warning Signs

GenAI has made it significantly easier for threat actors to craft convincing phishing emails. Poor grammar, once a hallmark of these campaigns, can no longer be relied on as a phishing red flag. Attackers don’t need strong writing skills or even fluency in the target’s language, as GenAI enables them to produce polished, personalized messages that mimic the style and tone of students, faculty, or administrators. What’s more, the technology can draft these emails in a matter of seconds, facilitating sophisticated phishing attacks at scale.

Schools and universities need to be cognizant of these risks and ensure the entire community is aware of phishing warning signs. Any message that pressures recipients to act immediately should be viewed with suspicion, particularly if it’s asking people to click on a link, open an attachment, verify personal information, or transfer money. Another red flag is a mismatch between the sender’s proclaimed identity and the email address, domain, phone number, or handle communicating the message. Often these are very small details—for example, a few extra numbers in an otherwise legitimate-seeming district or university domain.

Finally, any request that seems unusual for the person or institution should give people pause. Would the superintendent really be asking for gift card donations via a text? When in doubt, the best approach is to hold off on any action until you’ve verified the message independently through a separate channel.

Mike Greene, CEO, Enzoic

Map Where Your Data Lives

IT teams should be mapping exactly what data lives where and before introducing new tools, verifying that vendors have real evidence of secure practices like SOC 2 Type II compliance, cyber insurance, and contractual breach-notification and audit rights.

Tiffany Shogren, Senior Director of Service Enablement and Education, Optiv

Three-fold Threat Defense

Generative AI fundamentally shifts the attacker economics. The techniques themselves haven’t changed much, but AI has made them faster, cheaper, and hyper-individualized. To oppose it, quite a few security controls are required in addition to generic threat awareness. The viable defense is three-fold: Least Privilege Management at the account level, strict role-based access between departments, and offline authorization on high-value transactions. MFA should be a must-have control for anything related to credential changes. Any demand to do something outside of usual processes, especially high-value financial transactions, should be authorized only using an offline four-eyes principle. If attackers speed up, slowing down is what actually stops a compromised admin account from cascading into district-wide IT disaster.

Dirk Schrader, Resident CISO (EMEA) and VP of Security Research, Netwrix

What To Look For When Evaluating Vendors

When a breach involves the personal data of minors, the severity and the stakes escalate significantly. Unlike a compromised credit card or a rotated password, a child’s name, date of birth, institutional records and private communications cannot be replaced. That exposure follows them. For institutions and the students they serve, the consequences can persist for years through identity fraud, targeted social engineering and other scams long after the headlines fade.

For any follow-on actors who acquire or purchase this data, that longevity is the value. A dataset with hundreds of millions of student records spanning multiple countries and age groups is extraordinarily monetizable – not just once, but repeatedly. Attackers know that educational platforms aggregate identity data across a lifetime of users who are unlikely to monitor their own exposure. That makes this type of breach particularly consequential.

Accountability in third-party breaches rarely falls cleanly on one party. Instructure is responsible for the security of the platform and the data entrusted to it, and two incidents involving the same attacker targeting the same environment raise serious questions about whether the remediation after the first breach went far enough. Those are questions Instructure will need to answer.

But organizations, schools included, cannot treat vendor selection as a full transfer of security responsibility. Institutions that store sensitive data through third-party platforms have an obligation to understand how that data is protected, to ask tough questions during procurement and ongoing reviews, and to ensure contractual accountability exists. Too often, those decisions are made on functionality and price, with security treated as a secondary priority or neglected altogether.

When evaluating any vendor that handles sensitive personal data at scale, institutions should be looking for recognized security certifications as a baseline: ISO 27001 for information security management, ISO 27017 for cloud security controls and ISO 27018 for protection of personally identifiable information in cloud environments. FedRAMP Authorization is the relevant benchmark for federally-funded programs, while GovRAMP covers state and local public institutions including school districts and universities. These certifications don’t guarantee a breach won’t happen, but they signal that a vendor has subjected its security practices to independent scrutiny and meets a defined standard for protecting the data in their custody. These standards will help prevent successful attacks, and significantly limit the impact of a breach, if one occurs.

Schools, districts and universities must pressure their vendors on access governance, incident response obligations and breach notification timelines – not just at contract signing, but continuously.

Darren Guccione, CEO and Co-founder, Keeper Security

School Identity Weaknesses

Generative AI has industrialized identity attacks. Criminals can rapidly create convincing district login pages, personalized emails, text messages, and voice calls impersonating a superintendent, help desk technician, or trusted vendor. Their goal is often to steal a password, capture a session, persuade someone to approve an MFA request, or convince support staff to reset an account and enroll a new authenticator.

Schools are especially exposed during seasonal onboarding, when thousands of students, employees, contractors, and devices are being added or reactivated. Attackers hide inside that volume and use legitimate access to reach student records, financial systems, and backups before deploying ransomware.

The numbers make the priority clear. Unit 42 found that identity weaknesses played a material role in nearly 90 percent of its 2026 incident investigations. Sophos found that 79 percent of ransomware attacks began with an identity based approach. Ransomware is now fundamentally an identity problem.

Kevin Surace, CEO, TokenCore

Three Things Districts Should Require Before Adopting AI Tools

The biggest compliance pitfall as schools integrate new AI classroom tools is adopting them before anyone documents what student data the tool ingests, where it is processed, and who can retrieve it later. Districts should require three things before any AI tool touches a classroom: a data inventory naming exactly which student records the vendor receives, an auditability requirement so every AI output can be traced back to which model, which inputs, and when, and a written bias and fairness review completed before launch rather than after a complaint. None of this requires new budget. It is contract language and a checklist, and it turns an unmanageable vendor risk into something a resource-strapped IT department can actually enforce.

Sepehr Sisakht, President, AIDOLS Group

How Attackers Are Using AI

Attackers are using AI for deep-fake voice manipulation; They will impersonate trusted individuals, like the Superintendent or CBO, and try to obtain valuable information or credentials. As an example, they may dial the District’s IT help desk and impersonate a teacher to obtain a password reset. Once they have valid credentials, they can access the District’s VPN, file servers, email, and other applications.

AI is also helping attackers create convincing phishing emails to district purchasing and accounting teams. Attackers might use AI to comb through the District’s board meeting minutes and identify current construction projects. The attacker can then craft a convincing email to the purchasing team requesting a wire transfer to pay for some aspect of the project. These emails usually come with a sense of urgency (i.e. The District must wire funds within the next two hours or the project will be halted).

Sean White, Chief Technology Officer (CTO), NIC Partners

Vendor Security Can’t Be A One-Time Procurement Check

Schools are increasingly dependent on EdTech providers that may access student records, connect to core systems or introduce AI into the classroom, so vendor security can’t be treated as a one-time procurement check. Districts need a repeatable way to verify a supplier’s security practices, understand what information it can access, and regularly reassess that risk as the technology and relationship evolve. Standards such as ISO 27001 can help resource-constrained teams build that process into an information security management system, including categorizing suppliers according to the sensitivity of the data and systems they can access and applying controls accordingly. As schools adopt AI tools, ISO 42001 extends that discipline into AI governance by requiring organizations to establish requirements for suppliers and monitor their performance. Managing information security, data privacy and AI governance together gives schools greater visibility across their technology ecosystem and reduces the risk of gaps emerging between separate security, privacy and AI initiatives.

Sam Peters, Chief Product Officer, IO

Spend Attention Before Money

Resource-strapped districts should spend attention before money. Start with a reachability audit. It costs nothing. List everything the district has made reachable from the internet. Every forwarded port, every camera NVR, every door controller, every exposed login page. Automated scanners find each one within minutes of it going online. Most of that list never needed to be public. Remote access for a handful of staff does not need a public-facing door, so close what you can and move the rest onto a mesh VPN. Then spend the first real dollars on people. Most intrusions are let in, not broken in, and a short monthly email about entertaining high-profile security blunders keeps staff interested and suspicious. It’s better than any annual training module, because it keeps security top of mind all year, not for one afternoon.

Peter Carroll, Founder, Netrinos

Consider Which Technology Risks You Need to Own Directly

We advise higher education technology leaders to consider which technology risks their institutions need to own directly. Strategic use of hosted and SaaS solutions can shift portions of infrastructure management, security monitoring, patching, resilience, and recovery to providers with the scale and specialized expertise to manage them continuously. This does not eliminate institutional responsibility, but it can significantly reduce the operational burden and exposure associated with maintaining increasingly complex environments on campus.

For CIOs evaluating AI-enabled solutions, security and governance must be non-negotiable. We recommend partnering with vendors that provide strong safeguards for FERPA-protected data, utilize closed AI models to minimize data exposure, offer the ability to opt out of AI-driven features, enforce role-based access controls, and maintain comprehensive audit logs that track when generative AI is used to inform decisions. These guardrails help institutions embrace AI innovation while maintaining compliance, transparency, and trust.

Robert Wheeler, Vice President of Services, Jenzabar

The Extortion Surface

As both public and private sectors have become more resistant to paying ransoms, attackers have greater incentive to target environments where they can create enough pressure to make “I won’t pay” more difficult to sustain. Education is a strong example. Schools might not have the deepest pockets, but attacks –– such as the high-profile breach on EdTech vendor Instructure/Canvas –– can rapidly affect students, faculty, and critical operations, giving criminals several ways to build leverage. Security leaders should start thinking beyond attack surface to their “extortion surface,”: once an attacker gets in, how much sensitive data, disruption, and privileged access can they accumulate? Reducing standing privilege and limiting how far any one identity or third party can reach will help ensure a single foothold cannot be turned into an institution-wide extortion event.

Gal Diskin, VP of Identity Theft Products & Research, Delinea

Check The Data-Sharing Agreement

The data-sharing agreement buried under a new AI classroom tool gets way less scrutiny than the tool itself, and it should be the other way around. Educational institutions are onboarding new platforms faster than their legal or IT teams can actually vet them, and most vendor contracts default to collecting more than they need because nobody in the room pushed back. Before anything gets signed, ask point blank what student data they’re collecting, whether any of it trains a model somewhere, how long they keep it, and whether it ever ends up with a data broker – now or in the future. If the vendor gets vague on any of that, don’t let it slide – that’s your answer already. The schools staying ahead of this are the ones asking these questions at procurement, before any tool gets near a classroom. This is a growing issue in all educational facilities in the US, but the problem is exacerbated when students are adults with an already existing online profile and potentially leaked personal data.

Edvinas Sersniovas, CEO, HeyPolo

Related News:

Education IT Teams: Keeper Security’s Back-to-School Cybersecurity Guide

Oxylabs Analysis Reveals In-Demand AI Skills in Tech Hiring

Share.

About Author

Taylor Graham, marketing grad with an inner nature to be a perpetual researchist, currently all things IT. Personally and professionally, Taylor is one to know with her tenacity and encouraging spirit. When not working you can find her spending time with friends and family.