
From local kindergartens to internationally renowned higher education institutions, schools are a prime target for cyber-attacks due to a combination of valuable data, lack of cyber risk awareness, and significant, widespread vulnerabilities. Such data includes names, addresses, emails, phone numbers, social security, loan info, medical records, and more.
By some estimates, schools see fifty times more attacks than financial institutions. In just one month, more than eighty percent of all cyberattacks targeted public schools within the U.S.,
Here are some further details explaining why schools get cyber-attacks.
Lack of Cybersecurity & Awareness
The education sector is one of the slowest adopters of modern cybersecurity solutions, typically due to a lack of funding, causing limited resources, outdated technology, and more. Cybersecurity is often deprioritized in K-12 education in favor of staff salaries, school resources, and infrastructure upgrades with their limited budgets.
The most common way cybercriminals get such credentials is via a successful phishing attempt. With the personal data acquired during a phishing attempt, cybercriminals can target more high-profile individuals with spear phishing and whaling attacks.
People working in the education sector also tend to be less aware of cyber risk than other sectors. They are likelier to have an open attitude that inspires learning, collaboration, and sharing. Therefore, identifying phishing attempts and scams tends to be more challenging for individuals working in education.
Use of Personal Devices
During the COVID-19 pandemic, many schools and universities turned to remote working and remote learning to minimize the impact on their students. With hybrid and fully remote learning, it is easier than ever for cybercriminals to attack frequently unvetted personal devices using unvetted connections.
Whether they are accessing resources via smartphones, sending assignments via their laptops, or bringing USB drives to campus, students and teachers introduce many potentially vulnerable endpoints to the system daily.
Heavy Dependence on Third Parties
From virtual learning platforms to student information systems, schools rely on a growing list of technology vendors. Each integration introduces additional tech openings and attack surface. These outside parties maintain sensitive student, staff data, and personal information. Students are also spending more time online than ever before, using technology to complete homework, communicate with peers, and engage with teachers and school staff that might not have the right cyber security in place or prioritized.
With so many ways cybercriminals can get into school technology and devices, it can be hard to put procedures in place to keep educational data safe. Some ways schools can help protect themselves could be monitoring risk management with third-party partners, hold cyber-attack awareness seminars with both students and teachers to mitigate phishing attempts, and standardizing cybersecurity within the school. Schools can also leverage government and nonprofit resources such as threat intelligence alerts, implantation guides, and recommendations to assist school security and harden defenses.
Is your institution commonly attacked by cybercriminals? Let us know in the comments!
Resources
https://www.upguard.com/blog/education-sector-cyber-attacks
https://securityscorecard.com/blog/why-education-is-a-growing-cyber-target