In September, as students across the nation readied themselves for the start of a new academic year, headlines were dominated by a startling concern – crumbling infrastructure in schools, posing a physical risk to the safety of students and staff.
However, amid the widespread awareness of the danger of ageing concrete, a lurking threat in the digital shadows remained relatively obscured – the ever-escalating cyber-threat to educational institutions.
During the same period, the National Cyber Security Centre (NCSC) issued a warning to schools and universities in the UK, urging them to fortify their defences against the growing menace of cyber-attacks.
Since that warning, several UK schools have fallen victim to attacks. This underscores a pressing need for the educational sector to bolster its cybersecurity posture, as the critical data of students, teachers, and other stakeholders is at risk.
Research from Comparitech has so far found 105 reported cyber-attacks on educational institutions across the globe in 2023. This is over a 517% increase from 2018, when they first started tracking the information.
Specifically, in the UK, official figures from last year revealed that attacks on secondary schools jumped from 58% in 2021 to 70% in 2022, exposing the sector’s vulnerability to cyber-crime.
In the face of this evolving threat landscape, education institutions need robust solutions to defend against attacks, such as ransomware and phishing. The industry needs zero-trust solutions and prevention-based technologies to play a crucial role in enhancing overall resilience against these threats.
So, how can the sector build up its resilience?
1. Public and private sector partnership
As bad actors become ever more sophisticated, public-sector leaders need to work more closely with the private sector, where much of the expertise resides, to strengthen the sector’s cybersecurity posture, as a critical first line of defence against cyber-crime.
Cross-sector collaboration will be a game changer for IT and SecOps teams, within the education sector, responsible for keeping cyber-attacks at bay. This collective knowledge strengthens the overall security posture of the entire cybersecurity community, as insights from one organisation’s findings can help others enhance the depth of their security measures.
It is critical that relevant authorities encourage cross-sector partnerships and incentivise the sharing of critical data to help cybersecurity experts build better solutions to stay ahead of future attacks.
2. Go threat huntingÂ
Our 2023 Threat Intelligence Trends report found that almost two-thirds of organisations said their threat intelligence programmes need improvement, and only 22% of surveyed respondents said they have fully mature threat intel programmes.
Malware is evolving and increasingly complex, allowing it to evade traditional defence systems. For instance, zero-day malware can easily bypass signature-based antivirus engines, limiting detection to only known threats.
Our report further found that phishing URLs and emails were identified as primary concerns for file type and delivery methods, with approximately half of the survey participants emphasising the significance of advanced security measures like Deep Content Disarm and Reconstruction (CDR), sandboxing and link reputation checks.
Education institutions must review their threat detection and scanning tools and ensure they have the most up-to-date solutions.
Recommended reading
- Report: FTSE 350 Cybersecurity Posture Has Improved
- 70% of IT Professionals Overwhelmed by Authentication Systems
- Edinburgh Napier University Recognised for Cybersecurity Work
3. Ransomware: To pay or not to payÂ
Unfortunately, the general perception among private and public sectors is that ransomware is still a consumer or small business issue and not a cause for concern. This is a dangerous assumption, as more and more organisations across all critical infrastructure sectors are becoming targets for malicious actors.
It can be tempting for organisations to pay the ransom as a quick solution to resume operations, but it’s not recommended. There is no guarantee that, after receiving the ransom, the attackers will decrypt the files, and you might open yourself to additional ransom demands. Furthermore, this could also be a compliance violation.
Instead, if your organisation is already infected, what should you do:
- Immediately disconnect or isolate the compromised systems from the network to prevent the ransomware from propagating to other networks and devices.
- Check to see whether you have healthy system restore points that can be used to retrieve files.
- If you have invested in a backup and disaster recovery solution, check with your support team to confirm if the data is recoverable.
- Sometimes, it might be possible to decrypt your files, so bring in the right experts.
- Report the incident to the relevant authorities immediately.
- After recovery, patch and update all systems to address vulnerabilities that may have been exploited by the ransomware.
- Prioritise cybersecurity awareness and training to ensure staff can identify suspicious links and files, and deploy zero-trust solutions to help eliminate the risk of human error.
The education sector needs to up its cybersecurity game, but it needs the support of experts to do so. More training and investment are required to ensure the industry can keep its systems safe and secure for the sake of students, staff, and other stakeholders.





