Why schools are prime targets
Attackers follow value and weakness, and education offers both. Institutions store vast amounts of personal data, yet often run on tight budgets, legacy systems and small security teams. Add thousands of users - students, staff, parents - with varying security awareness, and a large, soft attack surface emerges.
The consequences are serious: ransomware can shut down an entire district's operations, and breached student data - especially of minors - can enable identity theft that goes undetected for years, because a child's identity isn't being actively monitored.
What data is at risk
Educational data is unusually sensitive because it concerns children and follows them for life. A breach can expose:
- ✓Personal identifiers: names, addresses, dates of birth, and government ID numbers.
- ✓Academic records: grades, transcripts, disciplinary and special-education records.
- ✓Health and wellbeing data: medical notes, counselling records, and accessibility needs.
- ✓Behavioural and biometric data: platform activity, location, and increasingly biometric identifiers.
The laws that apply
A patchwork of regulations governs student data, and both institutions and edtech vendors must comply. Knowing the main ones is essential:
- ✓FERPA (US): protects the privacy of student education records and gives parents/students rights over them.
- ✓COPPA (US): governs the online collection of personal information from children under 13, requiring verifiable parental consent.
- ✓GDPR (EU): a broad data-protection law with strict rules on consent, minimisation and rights, applying to any service handling EU residents' data.
- ✓Regional and national laws worldwide impose similar duties - so vendors serving multiple markets must meet the strictest applicable standard.
How to protect student data
Security is layered - no single control is enough. The practical priorities for institutions and the edtech vendors they choose:
- ✓Vet vendors: review any edtech tool's security practices, data handling and compliance before adopting it - the school is accountable for what its tools do.
- ✓Minimise data: collect only what's needed, keep it only as long as necessary, and limit who can access it.
- ✓Encrypt and control access: encrypt data in transit and at rest, enforce strong authentication (including MFA), and apply least-privilege access.
- ✓Train people: most breaches start with a human - phishing awareness and basic security hygiene for staff and students prevent many incidents.
- ✓Plan for incidents: maintain backups, and have a tested response plan so a breach or ransomware attack is contained, not catastrophic.
