Blog · Cyber security

Most attacks do not start at the firewall: they start with a password

When people talk about cyber security in a school, they usually think first of the firewall, the switches, content filtering or device protection.

Credentials are one of the main entry points

The firewall, switches and filtering are necessary, but a very large share of security incidents start somewhere much simpler: a user account and a password. A stolen credential, an account that is still active after someone has left the school or a password shared by several people can be enough for someone to get into systems they should not be able to access.

That is why protecting a school's network also means properly managing who can get in, what they can access and for how long. According to the report ‘The State of Ransomware in Education 2026’, published by Sophos and based on a survey of 226 technology leaders at schools in 17 countries, 85% of ransomware attacks on educational institutions used identity-related techniques.

These include malicious email, impersonation and the use of stolen or compromised credentials. Across all the sectors analysed by Sophos, the figure was 79%. In education, then, the weight of this type of attack was even greater.

The finding matters because it changes how security is approached. The firewall is still essential, but it cannot tell whether the person using a valid set of credentials is really their owner. If someone obtains the username and password of an account with access to email, the learning platform or certain school systems, from a technical point of view it may look like legitimate access.

So a fundamental part of security is reducing the chances of an account being misused and limiting what it can do if it does become compromised.

Shared accounts make it hard to know who did what

Schools can still have accounts used by several people. A shared school office account. A shared user in the staff room. A classroom computer that stays logged in to the same session all day.

These situations usually arise out of convenience and genuine day-to-day needs, not because anyone has decided to work insecurely. The problem comes when several people use the same account. If the system records that the user ‘office’ has accessed a student record, it is impossible to know which of the people using that account actually looked at it.

And this also affects the protection of staff themselves: if three people use the same credentials, it is not easy to prove which of them did not carry out a particular action either. So, wherever possible, each person should use their own account. As well as improving security, this provides something fundamental when an incident occurs: traceability, that is, being able to tell which user logged in, when and from which device.

Accounts belonging to people who are no longer at the school

Another common problem is accounts that remain active after a teacher, member of staff or supplier has stopped working with the school. It does not usually happen because someone has decided to keep them open. The departure can be processed correctly from an employment or administrative point of view, but there may be no procedure ensuring that the same removal is also applied to email, the Wi-Fi network, learning platforms and all the other systems.

In other cases an account is kept open for a few days to recover information or finish a task, and then nobody reviews it again. One particularly important case is access held by suppliers and former installers. A company that installed a system several years ago may have created an administrator account to carry out maintenance. If that account is still active after the relationship with the supplier has ended, it can keep elevated permissions for years without anyone at the school remembering it.

There is no need to assume any ill intent. The risk lies simply in keeping access that is no longer needed. Reviewing these accounts is also one of the simplest security measures a school can take.

It is a matter of getting the list of active accounts on each system, identifying who each one belongs to and checking whether that person still needs access. Accounts that no longer belong to anyone should be closed, and those with elevated permissions should be reviewed with particular care.

A shared Wi-Fi password sooner or later stops being private

Another common example is the Wi-Fi password. When the whole school uses the same key, that password can end up being passed around for years among teachers, pupils, families, suppliers and visitors. The problem is not just that many people know it. The problem is that all those people connect using the same credential.

If someone leaves the school, changing that password usually means changing it on every device that still needs to stay connected as well. For that reason, the change often keeps being put off. The alternative is for network access to depend on each user's identity.

With technologies such as WPA2/WPA3-Enterprise and 802.1X, each person can connect using their own school credentials. At PenwinEdu we implement this through PenwinIn, integrating Wi-Fi access with the directories the school already uses, such as Google Workspace or Microsoft 365. That way there is no need for a common Wi-Fi password shared among all users.

Each person uses their own identity and, when that account is deactivated, they automatically lose access to the network as well.

Knowing who is connecting changes how the network is managed

When each person uses their own account, the network no longer just records that ‘a device has connected’. It can link that connection to a specific identity and know which device was used, what time it connected and which access point it went through.

This considerably improves traceability if there is an incident. It also makes leavers easier to handle. If a teacher leaves the school or a device is lost, there is no longer any need to change a password everyone uses. Access can be withdrawn for that person or device alone.

Identity also makes it possible to apply different permissions depending on the type of user. Students, teachers, administrative staff or an external supplier do not need access to the same network resources. Identifying the user makes it possible to place each connection in the right environment and limit access to just the services it needs.

Two-factor authentication on important accounts

Some accounts are particularly sensitive because they allow much of the infrastructure to be administered. For these accounts, a password on its own provides insufficient protection. Two-factor authentication adds a second check. As well as knowing the password, the person has to confirm the login using something else, such as an authenticator app or a physical security key.

That way, even if someone obtains the password, they still need that second factor to get in. The exact same policy does not necessarily have to be applied to every account in the school, but accounts with administrator permissions should always have additional protection. The minor inconvenience of a second verification is far smaller than the impact of an administrator account being compromised.

These are the accounts that should always have that additional protection:

  • Google Workspace or Microsoft 365 administration.
  • The academic management platform.
  • Network administration.
  • Backup systems.
  • Remote access.
  • The platforms used to manage devices.

It all comes down to managing joiners and leavers properly

Many of these problems have the same origin: accounts are created when someone needs access to a system, but there is not always an equally clear process for removing them when that person no longer needs it. The solution is to link technology access to the real life cycle of people within the school.

When a new teacher, student or member of staff arrives, the access that matches their profile should be created. When they change role, their permissions should change. And when they leave the school, that access should be deactivated.

The best way to achieve this is to take as the reference the directory the school already has for managing its users. PenwinIn, for example, can be integrated with Google Workspace and Microsoft 365, so that network access follows the same life cycle as the user's account.

This avoids having to maintain separate lists that someone has to remember to update by hand.

Security cannot depend just on nobody making a mistake

Asking users to choose good passwords, not to share them and to be careful with fraudulent emails is necessary. But it cannot be the only security measure. If three people need to use an application and there is just one account that lets them do so, they will probably end up sharing it.

If a classroom computer takes several minutes to log in and the teacher has thirty pupils waiting, it is understandable that there is a temptation to leave the session open. The goal should be to design systems so that working securely is also the easiest way to work.

That means having individual accounts, assigning only the permissions needed, using two-factor authentication on critical accounts and automating joiners and leavers wherever possible. The same Sophos report found that 52% of schools below university level identified human error as a factor that contributed to the incidents.

The answer should not be just to ask people not to make mistakes, but to design an infrastructure that limits the consequences when a mistake inevitably happens.

Where to start

The first review can be done without buying any new equipment.

The first step is to get a list of the active accounts on the school's main systems. From there, you need to check:

  • Which person uses each account.
  • Which accounts are shared by several people.
  • Which users belong to people who are no longer at the school.
  • What access suppliers and former installers still have.
  • Which accounts have administrator permissions.
  • Which of them have two-factor authentication switched on.
  • How access is created when a new person arrives.
  • How it is removed when they leave the school.
  • Whether Wi-Fi access uses a shared password or identifies each user individually.

Experience in schools makes the difference

With this information, a large share of the credential-related risks can be spotted quickly. Identity management in a school cannot be approached in exactly the same way as in an office. Every September, year groups, classes, teachers and pupils change. During the year there are new arrivals, leavers, cover arrangements and device changes.

All of this has to coexist with learning platforms, shared computers, individual devices, administration networks and numerous external services. At PenwinEdu we have spent years working specifically with schools and we know these situations because they are part of how schools run every day. That experience is precisely what we draw on to design systems for our clients that reduce risk without needlessly complicating the work of teachers, administrative staff or IT leads.

It is not just a matter of installing a technology solution. It is about understanding how each school works and making security part of its everyday processes. With PenwinIn we replace the shared Wi-Fi password with the identity each person already uses at the school, integrated with its directory and backed by 24/7 monitoring and technical support with a response within four working hours.

Sources

  1. Sophos, «The State of Ransomware in Education 2026» (agosto de 2026), encuesta a 226 responsables de TI de centros educativos de 17 países (in Spanish)
  2. Reglamento (UE) 2016/679, General de Protección de Datos (RGPD), artículo 33 (in Spanish)
  3. Agencia Española de Protección de Datos, criterios para el tratamiento de datos personales en centros educativos (2023) (in Spanish)

The initial assessment is free and comes with no obligation, and it lets us analyse how access is currently managed at the school and propose a solution suited to its circumstances.