At ESET, we’ve long advocated for multilayered security solutions that turn reactive security into a proactive one through a prevention-first approach. It’s logical—you don’t want even an inch of an adversary’s foot inside your systems since who knows what kind of evasive techniques or persistence they’ll employ. 

With investments in the correct platforms, problems should just disappear, right? However, while platforms do reduce impact, they don’t eliminate incidents, as outcomes depend on operational readiness and response, not tooling alone. Still, institutions like schools are persistently troubled by both, owing to their often-underfunded IT security resources. 

Major cyber-attacks against education continue globally, but these cases don’t seem to move the needle with regards to budgeting for security at all. Why is that, and what can be done to raise the right points for budget holders? Read on.

Key points of this article:

  • Globally, education has become a prime target of cyber-attacks, with further and higher education facing data breaches and systemic disruptions.
  • Attackers are both advanced threat groups (focusing on higher education), but also insiders, with pupils ordering or committing attacks themselves.
  • The reason schools are targeted by external attackers (such as ransomware groups) can be attributed to eCrime, but it’s just as likely that these groups seek access to lots of proprietary research data or student records.
  • ESET’s 2026 SMB Cyber Readiness Index provides some answers to how ready educational organizations are to face cyber threats.
  • The forces that be demand readiness, but said demands aren’t formed as absolutes. Regulations are merely minimal due diligence measures by which resilience standards are raised across the line, the journey to which is taken by means applied on a case-by-case basis.
  • As outlined in ESET’s Cyber Resilience by Design framework, resilience rests on three equally important dimensions: technology, processes, and people. Schools often focus on tools first, but resilience only works when all three evolve together.
  • The end of the resilience journey is not a given destination, but an environment, a lifecycle based on learning. 
  • If educational institutions can apply the same sort of commitment they have provided to their students and colleagues toward security, each successive security step will come at a lower cost and higher return on investment.

Schools: Ticking cyber time bombs

In the past, a typical school used to be just a collection of classrooms and teachers’ chambers, with most documentation written on paper, archived within a school building for a set period of time before disposal. 

Now, with the advent of cost-accessible computing, schools have largely digitized much of this work. Gradually, a similar transformation has also occurred within classrooms, with classes requiring online work for essays, presentations, and even lectures. Projectors and smart boards have become mainstays in modern classrooms, and student grading has also gone digital because of the shift toward “smarter” teaching.

However, digitization is a double-edged sword.

Testing school security

Threats increasingly target schools:

  • The UK’s Cyber Security Breaches Survey 20251 reports how schools are more likely to experience a breach than other organizations overall (43%), including facing a wider range of attack types. Of these, higher education institutions are the most targeted.
  • In the EU, major cyber-attacks against institutions like La Sapienza University in Italy, Eindhoven University of Technology in the Netherlands, or the University of Warsaw in Poland confirm this trend. With internal systems offline, teaching activities cannot continue. 
  • In Asia, education service conglomerates are also targeted, such as in South Korea, where one attack is estimated to have impacted 9.6 million user accounts.
  • In the US, the Center for Internet Security’s 2025 report detailed how 82% of reporting K-12 schools experienced a cyber-attack, with most focusing on exploiting the human element (via social engineering). This is supported by the 2026 Verizon Data Breach Investigations Report2, with top attack patterns being system intrusion, miscellaneous errors, and social engineering, representing around 83% of all breaches.
  • Ransomware attacks are surging (supported by ESET telemetry), where groups also tracked by ESET like Clop, RansomHub, Akira, and Qilin penetrate institutional defenses and ask for ransom payments ranging from hundreds of thousands to millions of dollars.
  • But it’s not just schools, as ransomware actors are also likely to target the education sector’s digital supply chains, including major education SaaS platform owners, who harbor multitudes of partner institution data points, falling into their crosshairs as well.

We need to go deeper

There’s also something to be said about internal threats. In Estonia, the Central Criminal Police have recently identified around 1,600 young people who used an online platform to order cyberattacks against their schools and/or their websites. Similar stories have also emerged in the UK and Japan, where students pit their IT skills against school networks, or cause an insider cyber-attack in some manner.

Why are schools targeted?

Now, why would criminals target education? The answer is relatively simple. Educators possess the skeleton keys to a treasure trove of sensitive data… the importance of which grows the higher up the chain we go:

  • Preschools, elementary schools, and high schools: These institutions own pupil data (so addresses, dates of birth, etc.), financial data (obviously), and potentially, access to some official governmental data due to their connection to state oversight boards/ministries.
  • Colleges and universities: The same as above, but with more considerable financial assets as well as research and access to wider interinstitutional networks, including work with major partners such as government entities and private companies. In other words, R&D and IP are also of interest to the attackers.

We’re talking about data that’s worth at least millions of dollars or more in some cases. A collective estimate3 from the UK puts the economic cost of cyber-attack-sourced IP theft in the billions. This is unsurprising, as the UK is a major generator of “smarts” as an asset, owing to its robust and storied higher educational sector, which is deeply intertwined with other economic activity across its vast industrial landscape. So, a loss in one sector can create a wave across the entire economy.

Putting on a security lens: Schools x healthcare

The previous paragraph is worth exploring deeper as it’s the key to understanding the importance of education as a critical sector in need of resilience. So, for example, let’s consider medical schools and universities. 

These institutions do far more than train future clinicians: they produce original research, develop new medications and medical devices, and function as the engines of healthcare innovation.

This work does not occur in isolation. Academic medical research is conducted in constant partnership with hospitals, medical device manufacturers, and health ministries. As a result, large volumes of sensitive data are generated, transmitted, and stored—while a rotating population of interns, researchers, contractors, and senior staff move in and out of these environments.

When the mean expected development cost of a single therapeutic complex medical device (such as an MRI machine) exceeds $500 million4, compromising the developers rather than replicating the research might become justified in the eyes of those that would rather skip the research effort.

The state of resilience in education

It is undoubtable that the education sector is rich in expensive data ready to be exploited or sold. But has the sector reconciled itself with this knowledge?

ESET’s 2026 SMB Cyber Readiness Index finds that in the education sector5:

  • Around 75% are concerned about cyber-attacks in the coming 12 months, with 37.1% being very or quite concerned, and 37.9% slightly concerned.
  • 43.3% are slightly confident about their cybersecurity posture, while 29% are neutral, and 11.1% are not confident.
  • Nearly 50% employ advanced measures such as endpoint protection, secure access, and use some security management tools such as patching. While this is great, there are large differences in the maturity spectrum in-between those surveyed, from mature in-house resources to fully outsourced—36.2% have an SOC + security specialist, 32.1% use generalist IT admins, and 31.7% outsourced (both partial and full).
  • Budgets seem to be sufficient (63.8%), but 21% expect an increase in the coming year, with 36.2% seeing their budgets insufficient.

This sector-specific take tracks with the general trends ESET has found, but this doesn’t absolve the education sector, chiefly due to its designation as critical infrastructure in the US, for example, or as an important entity covered under “research” within NIS2 in the EU.

The forces of resilience

Aside from helpful regulations like NIS2 in the EU, the upcoming CSRB in the UK, or the SEC’s final rule on Cybersecurity Risk Management and Incident Disclosure, it looks like resilience is shaping up to be a major talking point. Sensitive data security acts like FERPA in the US (also worth mentioning are grant/funding based conditions), along with the GDPR in the EU, present strong resilience-demanding forces.

Related reading: Cyber resilience strategy in 2026: A practical guide for modern businesses

The point of these regulatory acts isn’t to stop cyber-attacks, they’re merely the means to standardize basic controls. I’m sure that by now, this blog has probably led the reader to believe that cyber-attacks MUST be stopped. The problem with that takeaway is that they can’t be—they’re inescapable—but are not unavoidable. 

What is avoidable is catastrophic failure. It’s akin to receiving a “U” grade, where for all intents and purposes a pupil’s passed, but not without some deficiencies.

Organizations can function despite weaknesses, provided those weaknesses are understood and actively managed:

  • Hardware: Smart devices are now virtually in every classroom/research lab, whether that’s projectors, laptops, desktops, tablets, or smartboards. Hardware can be stolen or manipulated, so it’s best to keep that fact in sight.
  • Software is what opens hardware to external threats. Aside from physical exploitation (malicious flash drives), the OSs running on work/student computers, the apps in use, and most importantly, anything that communicates via the internet, is vulnerable.
  • Data, especially, is in a vulnerable position. As education produces a vast amount of data with the churn of students and research, safe storage of said data is imperative. 
  • Cloud services/platforms: Services like Microsoft 365 and Google Workspace, including their respective email modules, represent a threat surface that goes beyond a school’s premises. Securing these requires proactive measures and a form of comprehensive governance where the cloud’s extended threat surface is internalized as an in-house issue.
  • Edge devices: Edge devices are systems positioned at the boundary of a network that handle, inspect, and control incoming and outgoing traffic. Examples include routers, firewalls, IoT gateways, and VPN gateways. They play a critical role in protecting the network perimeter, helping to reduce the risk of unauthorized access by external threat actors.

There’s always room for improvement. Resilience is a journey, and each organization has a different experience, therefore, forces pushing for a change can’t pretend that there’s a one-size-fits-all approach, not to any of the above points for sure. But where there’s a will, there’s a way.

How to build cyber resilience in education

Cyber resilience can’t be bought as a single solution. But the right technologies can strengthen the stages of the resilience lifecycle.

If an organization has built a rock-solid baseline, then their resilience, when put to the test, will save their bottom line. To get to that foundation, organizations, both less and more mature ones, are likely looking at months of incremental modifications to their postures, which sounds worse than it actually is (see the example below):

A cyber resilience roadmap example by ESET

The extent of the resilience lifecycle depends on an organization’s infrastructural needs (size/scope/existent measures). In other words, an elementary school doesn’t need enterprise-grade security unless its size demands it, nor would a university survive on measures fit for a preschool.  So, let’s look at some of the steps the sector can take to start its resilience journey:

Begin with an audit > Anticipate

Every resilience measure build-up should start with an audit to map the extent of an organization’s threat surface. Are there any errant printers? To what degree can students/employees access systems and how? Is the Wi-Fi running the latest security protocols? And so on. Without this, IT just can’t be sure what needs protection. 

Tech such as external surface mapping, curated threat intelligence, and identity‑risk monitoring provide early visibility, while processes like business‑aligned risk assessments and realistic tabletop exercises prepare teams for credible scenarios. 

Eliminate your vulnerabilities > Resist

Found some weaknesses? Get rid of them. Proactively scour the audited systems and services that are in use and configure the attack surface to work for you. Reducing systemic exposure can profoundly lower one’s risk.

Multiple authentication layers, various identity-based access policies, cloud security posture management and other processes, including configuration standards, regular patching, and SaaS security focus help ensure continuous business integrity.

Elevate visibility > Expose

Even secure systems can have hidden gaps. Resilience eschews the myth of 100% protection in favor of durability, meaning that if something gets bypassed (like one’s firewall) then the security admin needs to know that this happened, how, and why. 

While early telemetry visibility informs quick security decision-making, telemetry is useless without a proper SOC-like workflow that makes use of it. Human analysts are essential in exposing malicious activity, but not every school can have access to such capabilities. It’s one reason why Managed Detection and Response (MDR) services are so useful, turning your telemetry into actual outcomes, fast.

Telemetry from across the organization that connects identity sources, endpoints, and cloud-native services in an OpenXDR or MDR console, supported by processes tuning detections to frameworks like MITRE ATT&CK, with a dash of skilled human analysis transform telemetry into action for future incident response.

Automate and act > React

It is critical to get the most out of incident response with early automation. When an incident occurs, response time makes all the difference as in the end, when controls fail (due to omissions in audits and similar), it is quick detection and response that saves the day.

Immediate response via SOAR or XDR action that isolates compromised assets, elevates authentication requirements, and has a solid backup plan are worth their weight in gold. For organizations without an SOC or means of automation, similar abilities can be unlocked via MDR/MSSP services that provide continuous monitoring with expert-led investigation. 

Get back to normal > Restore

Recovery demonstrates whether resilience works. Can you restore what was lost? And how fast can business continuity be reestablished? All these questions are relevant, as resilience is more about surviving an encounter, rather than the assumption that the chance of an incident happening is zero thanks to all the protective layers installed.

However, we can’t forget about the human aspect of recovery, as restore success equally depends on cross-functional coordination between legal, PR, and leadership roles having established well-rehearsed decision-making while under pressure. If a business wants to maintain continuity, both systems and decision chains (maintaining critical operations and minimizing disruption to teaching during a crisis, for example) need to work.

Backups, tested restore paths, cloud failover options and periodic integrity checks of internal and supplier security, as well as having regulation-aligned risk management strategies with individually set responsibilities and response hierarchy are what define the restore stage.

Repetition is the mother of wisdom > Go On

Learn from mistakes. Working dynamically with past incident data can better inform more efficient decisions in the future, sanding away the edges of future incident response into something that can be more easily handled.

Post-incident analysis, platform consolidation and upgrades, workflow retooling, and other updates of your security playbooks, including healthy management of responsible employees, ensures thorough improvements in resilience posture and governance.

Resilience is too big of an ask

Six stages, one lifecycle. Doesn’t sound like much, but these stages contain measures that might seem difficult to implement. However, missing know-how, experience, or technology can always be substituted with outsourcing, depending on what the internal capabilities and budgets are, as well as the level of enthusiasm regarding staying secure.

For example, access measures can stay in-house. Authentication, password strategies, things that even basic users can do aren’t resource-intensive to maintain, while threat intelligence or proactive threat hunting should probably be outsourced, if the budget allows their procurement at all. Again, not every organization needs these, but there are several doors to good security, such as via an MSP or MDR, which can serve to fulfill a lot of these stages on their own and without breaking the bank.

Did you know? The benefits of AI and automation

AI can also be useful. Automation is actively bringing breach costs down, while lowering the maturity required to enact complex manual security steps when facing advanced attacks like ransomware. Whether via baked-in AI-native detection engines or agentic assistance, it’s never been easier to stay resilient without having to go for a cybersecurity degree.

Step by step

Much like education itself, resilience is about creating the necessary foundations. You build structures that are strong enough to protect students, staff, and data, while remaining flexible enough to support innovation, collaboration, and growth. 

To wit, it’s not something you can buy off the shelf and roll out across every campus, classroom, and district. Every institution is different. A primary school with a handful of shared devices, a university running complex research networks, and a vocational college relying on cloud platforms all face very different risks and require different approaches.

Most importantly, cyber resilience in education is never “finished.” You don’t build it in a semester, and you don’t declare it complete at the end of a project. It’s a long-term commitment that evolves, and lessons learned from incidents—both big and small—are part of the process.

ESET_Cyber-resilience

Additional references:
1) Department for Science, Innovation & Technology and the Home Office, Cyber security breaches survey 2025: Education institutions findings, 2025. GOV.UK, https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2025/cyber-security-breaches-survey-2025-education-institutions-findings. Accessed 21.04.2026.
2) Verizon (2026), 2026 Data breach investigations report, pp.82-83, https://www.verizon.com/business/resources/reports/dbir/. Accessed 27.05.2026.
3) Alma Economics. (2025, July). Economic impact of intellectual property and knowledge assets theft from cyber attacks in the UK. Department for Science, Innovation & Technology. https://assets.publishing.service.gov.uk/media/691442809d50fc2fe8161635/Economic_Impact_of_IP_from_Cyber_Attacks_-_ALMA_ECONOMICS.pdf.  Accessed 21.04.2026. 
4) Sertkaya, A., DeVries, R., Jessup, A., & Beleche, T. (2022). Estimated Cost of Developing a Therapeutic Complex Medical Device in the US. JAMA network open, 5(9), e2231609. https://doi.org/10.1001/jamanetworkopen.2022.31609. Accessed: 27.04.2026
5) Based on proprietary analysis of the dataset underlying the report

Frequently Asked Questions (FAQ)

What encompasses “education” as such?

The education sector is comprised of institutions ranging from preschools, through universities, to complex research/innovation centers working in tandem with the public and private sector.

Why is education in danger?

Education is in danger for multiple reasons. As usual, personal data (of students/employees) to enable further attacks is a primary reason, but we also can’t forget about financial, intellectual property, or knowledge-related motivations.

What do you mean by “knowledge-related motivations”?

Universities produce lots of valuable research, some of it in close cooperation with state and non-state actors such as private companies. This R&D costs millions of dollars to generate, not to mention the manpower and time involved. Said proprietary data could sell for millions on the black market or help a competitor get ahead without the required investments involved.

What sort of danger to education are we discussing?

The means by which cyber-threat actors get ahead is largely via exploiting the human factor through phishing or social engineering. Through these mechanisms they can gather useful credentials or gain access to proceed with a ransomware or other attack, locking out students and staff from internal systems until a ransom is paid. 

How can education protect itself?

There’s not a one-size-fits-all answer here. Every institution is different, requiring unique security measures tailored to their own attack surface. Even then, security is not a given thing. It takes a complete cultural shift to the idea of cyber resilience, with a gradual and constant build-up/fitting of measures to promote continuity in face of adversity.