Schools Are a Cybersecurity Nightmare. What Can We Do About It?

Schools need to do more to improve cybersecurity as students move to remote learning.

Schools need to do more to improve cybersecurity as students move to remote learning. SHUTTERSTOCK/Maria Symchych

 

Connecting state and local government leaders

COMMENTARY | Educational institutions are alarmingly vulnerable to cyberattack. With schools across the country moving to more distance learning, it's time to change that.

Schools and universities in all 50 states, along with U.S. territories, have closed to prevent further spread of the novel coronavirus, resulting in a mass migration to online learning. As classes move online so are more of our students' information and records. 

The move to online instruction means that an increasing number of students also will be doing schoolwork from potentially unsecure networks like their home WiFi.

With faculty and administrators scrambling to make decisions to ensure minimal disruption to classroom instruction, this hasty decision making will result in a rush to install new software and applications as quickly as possible—without considering the cybersecurity of these systems.

This is an ideal scenario for cyberattacks.

Hackers know that in all the rush, many schools may adopt applications and software with vulnerabilities. While schools are being forced to implement changes quickly, cybersecurity must still be taken seriously and made a priority to keep students safe. 

Schools in the United States were already very far behind in cybersecurity. Falling short of acceptable standards in risk management, compliance, threat awareness and general security hygiene, a 2018 report ranked education last for cybersecurity prevention measures out of 17 industries. 

“The lack of resources and attention to cybersecurity in schools and universities should be a cause for serious concern among students, parents, school boards, and the education industry as a whole,” said SecurityScoreCard COO and co-founder Sam Kassoumeh. “Schools collect an incredible and vastly increasing amount of personal data about students. At the same time research universities house valuable IP. Securing these networks and protecting this information is essential to protect the future of innovation and privacy."

Malicious actors are very aware of the poor security practices of educational institutions and the troves of sensitive data they collect. It’s probably why cyberattacks on educational institutions are on the rise. In 2019, there were 301 reported attacks against schools, more than double the amount during the previous year. And those are just the ones we're aware of. 

Despite that, educational institutions still take an abysmally lax approach to securing the sensitive data they collect. It’s time to change that.

The problem is that most schools, like many other sectors, simply do not have the necessary resources for a well-trained, fully-staffed IT department. As infrastructure grows more complex and cyberattacks become more sophisticated, IT departments struggle to keep up.

While schools could use an increase in the IT budget and hire more cybersecurity professionals, in most cases, that’s not realistic. In the absence of increased funding, how can schools improve cybersecurity with existing resources? 

1. Keep software up to date 

The vast majority of successful cyberattacks are unsophisticated breaches that prey on human ignorance, target existing software vulnerabilities or both. An unpatched vulnerability is one that's easily exploited, and are the direct cause of at least a third of all cyberattacks

By ensuring your operating system and software is up to date, you can help mitigate the threat. School IT departments should configure the operating system of all computers within the institution to automatically update when a new security patch is available. Schools can work with virtual patching companies to automate software updates. Additionally, the IT department should schedule regular reminders for students and staff on how to keep their software up to date. 

2. Consider investing in automation

Seventy-three percent of security teams are understaffed. To address that, IT departments are increasingly turning to artificial intelligence and machine learning for automated network monitoring, threat detection, and attack mitigation solutions. This can take a lot of pressure off an IT staff, leaving them free to focus their efforts elsewhere.

While this requires some upfront costs, it will lead to cost savings and less risk over the long-term, as schools streamline the IT architecture, quickly pinpoint when to eliminate old systems and use fewer man-hours to secure IT systems.  

3. Promote awareness

The greatest cybersecurity threat in a school is its people. This is especially true given that more schools than ever are now handing out devices to students and teachers. While this enables more effective learning, the sheer number of potentially unmanaged devices connected to your network represents a significant risk.

You need to establish this risk and educate both students and faculty. Perhaps the most important takeaway is to teach students, faculty and parents the importance of cybersecurity and educate them on how to properly navigate online learning. take precautions and prevent themselves from becoming a victim of cybersecurity.

Devise and distribute a comprehensive set of security guidelines which include acceptable use for mobile devices along with password and email policies. Additionally, take the time to coach everyone on how to recognize and avoid common attack methods such as phishing emails.  

4. Maintain backups

It's safe to assume that most schools would be caught off-guard if they are attacked by ransomware. They will be forced to either pay the ransom or risk significant loss of data and systems. 

Data is a critical asset and schools should have at least two systems to back it up that are isolated from the core network. These backups should additionally be secured in the same way as your systems with strict access-controlled, secure firewalls and anti-malware tools.

While these are basic steps, they will go a long way in improving cybersecurity in schools and reducing the overall risk to public sector breaches.

X
This website uses cookies to enhance user experience and to analyze performance and traffic on our website. We also share information about your use of our site with our social media, advertising and analytics partners. Learn More / Do Not Sell My Personal Information
Accept Cookies
X
Cookie Preferences Cookie List

Do Not Sell My Personal Information

When you visit our website, we store cookies on your browser to collect information. The information collected might relate to you, your preferences or your device, and is mostly used to make the site work as you expect it to and to provide a more personalized web experience. However, you can choose not to allow certain types of cookies, which may impact your experience of the site and the services we are able to offer. Click on the different category headings to find out more and change our default settings according to your preference. You cannot opt-out of our First Party Strictly Necessary Cookies as they are deployed in order to ensure the proper functioning of our website (such as prompting the cookie banner and remembering your settings, to log into your account, to redirect you when you log out, etc.). For more information about the First and Third Party Cookies used please follow this link.

Allow All Cookies

Manage Consent Preferences

Strictly Necessary Cookies - Always Active

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data, Targeting & Social Media Cookies

Under the California Consumer Privacy Act, you have the right to opt-out of the sale of your personal information to third parties. These cookies collect information for analytics and to personalize your experience with targeted ads. You may exercise your right to opt out of the sale of personal information by using this toggle switch. If you opt out we will not be able to offer you personalised ads and will not hand over your personal information to any third parties. Additionally, you may contact our legal department for further clarification about your rights as a California consumer by using this Exercise My Rights link

If you have enabled privacy controls on your browser (such as a plugin), we have to take that as a valid request to opt-out. Therefore we would not be able to track your activity through the web. This may affect our ability to personalize ads according to your preferences.

Targeting cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.

Social media cookies are set by a range of social media services that we have added to the site to enable you to share our content with your friends and networks. They are capable of tracking your browser across other sites and building up a profile of your interests. This may impact the content and messages you see on other websites you visit. If you do not allow these cookies you may not be able to use or see these sharing tools.

If you want to opt out of all of our lead reports and lists, please submit a privacy request at our Do Not Sell page.

Save Settings
Cookie Preferences Cookie List

Cookie List

A cookie is a small piece of data (text file) that a website – when visited by a user – asks your browser to store on your device in order to remember information about you, such as your language preference or login information. Those cookies are set by us and called first-party cookies. We also use third-party cookies – which are cookies from a domain different than the domain of the website you are visiting – for our advertising and marketing efforts. More specifically, we use cookies and other tracking technologies for the following purposes:

Strictly Necessary Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Functional Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Performance Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Social Media Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Targeting Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.