Blog · Cyber security

Why a school's network needs protecting

A school's network is home to many systems and sensitive data: academic records, special educational needs reports, family information, staff employment data, accounting records and management platforms.

What information and services depend on the network

Before talking about cyber security, we need to be clear about exactly what we are protecting. A school's network also serves computers, tablets, interactive panels and many other devices that connect every day. The problem is that, in many schools, the network has grown over the years as new needs have arisen. Equipment, services and access have been added, but the security of the whole has not always been reviewed.

That is why protecting a school's network is not simply a matter of installing a firewall. You have to protect the data, the devices and, above all, the continuity of the school's operations. A school's systems may hold academic records and grades, educational psychology reports and data relating to special educational needs, contact details for students and families, staff employment records and financial data such as direct debits and invoicing for school meals, transport or activities.

Some of this information is particularly sensitive and can affect children for many years. But data is not all that matters. Many of the services that keep the school running every day also depend on the network: the academic management platform, the administration computers, access control, the dining hall, the classroom panels, communications and backup systems.

So there are two things to protect. One is the confidentiality of information, to prevent anyone from accessing it without authorisation. The other is the availability of systems, so that the school can keep running normally.

Schools receive a large number of attempted attacks

The available data show that the education sector is particularly exposed. According to a Check Point Research report published in August 2026, between January and July that year educational organisations received an average of 4,696 attacks a week, compared with 2,150 across all sectors.

These figures refer to detected attack attempts; they do not mean that all of them succeeded. But they do show that educational organisations receive a volume of malicious activity far above the average. There are several reasons for this.

Many people and devices pass through a school. Every school year new students and teachers join, there are staff changes, suppliers who need temporary access and services that have to be available from outside the school. In universities, business schools or open campuses, the attack surface can be even larger.

At the same time, many schools do not have their own IT department. Technology management often falls to an IT lead who combines that role with other duties, or to an external provider. The Sophos report ‘The State of Ransomware in Education 2026’, based on a survey of 226 education technology leaders in 17 countries, also found that 53% of the higher education institutions affected admitted they lacked the expertise needed to detect and stop the attacks.

What happens when the network stops working

Talking about a cyber attack can seem abstract until you look at what it means for the day-to-day running of a school. If the network becomes unavailable or one of its systems is compromised, services that are used constantly can stop working. Teachers may be unable to access learning platforms. The school office may lose access to records or be unable to issue documents. Problems can appear with printers, the dining hall, access control or communications with families.

Lessons can carry on for a while with workarounds, but much of the school's management now depends on its IT systems. If personal data is also exfiltrated or encrypted, the situation stops being merely a technology issue.

The EU General Data Protection Regulation states that certain security breaches must be notified to the supervisory authority without undue delay and, where feasible, within 72 hours at most. Where there is a high risk to the rights of the people affected, it may also be necessary to inform them.

And there is one point that matters particularly for the school's leadership: the school itself remains the data controller even if its IT infrastructure is managed by an external provider. Recovery is not necessarily quick either. According to the same Sophos study, 31% of schools below university level that suffered data encryption needed a month or more to recover.

A month during the school year can coincide with assessment periods, enrolment, meetings with families and a multitude of processes that depend on the school's systems.

Security is built in layers

No single device or tool can fully protect a school's network. A good security strategy combines different measures that complement each other, and none of them replaces the others. A good firewall will not prevent every problem if any device can reach the whole network. Nor is a properly segmented network enough if there are no reliable backups.

Security works when all these measures are part of the same design.

  • Separating the network by type of user and service, so that a classroom device has no direct access to administration systems.
  • Identifying each person who connects, avoiding shared passwords as far as possible.
  • Having a properly configured firewall, with reviewed rules and only the necessary services reachable from the internet.
  • Filtering content, adapting policies to the different phases of education.
  • Managing devices, to know which devices are connected, who uses them and whether they are up to date.
  • Keeping protected backups and checking regularly that they can actually be restored.
  • Monitoring the infrastructure, outside school hours as well, to detect problems before they affect how the school runs.

Access often starts with a password

An important part of security depends not on equipment but on how accounts and access are managed. According to the 2026 Sophos report, 85% of ransomware attacks on educational institutions used identity-related techniques, such as compromised credentials.

In addition, 52% of schools below university level identified human error as one of the factors that contributed to the incident. This does not mean that people are the problem. It means that the system must be designed so that a mistake, a compromised password or an old account cannot give access to the whole infrastructure.

In a school there are very common situations that can end up creating risks without anyone having intended them. A Wi-Fi password that was shared years ago and is still in use. The account of someone who has left the school, still active because their removal did not reach every system. A school office computer left logged in. Or a folder that was shared temporarily and whose access was never reviewed again.

These are normal situations that arise through everyday use and that, if there is no procedure for reviewing them, can persist for years. That is why some measures are particularly effective: making sure staff departures are also reflected in the IT systems, having everyone use their own credentials, requiring two-factor authentication on accounts with elevated permissions and giving staff regular training to recognise fraudulent emails and logins.

Many of these measures do not require major investment. They mainly require organisation, clear procedures and, above all, knowledge of the education environment. At PenwinEdu we have extensive experience working with schools, and it is precisely that accumulated knowledge that we draw on for our clients, so that we can get ahead of problems, reduce risks and stop seemingly small situations from turning into serious incidents.

After all, protecting a school's technology is not just a matter of installing security tools: it means understanding how a school works, how its teams operate and what it really needs to keep running every day.

Where to start

Before buying new equipment or taking on new tools, the first step should be to understand the current state of the infrastructure. To do that, it helps to have an inventory of the devices and services connected to the network, to know who has access to each system and to check how accounts and permissions are organised.

Backups also need reviewing: what information is backed up, where it is stored and, above all, when a test restore was last carried out. With that information it is much easier to set priorities. The most sensitive data and the services the school cannot do without should be protected first.

After that, measures can be applied to limit the scope of a possible incident, such as network segmentation or individual access management. And from there, progress can be made in phases, fitting the improvements to the school's calendar and budget.

How we approach security at PenwinEdu

At PenwinEdu we start from the actual state of the school's infrastructure to define which measures are needed and in what order it makes sense to apply them.

We look at aspects such as:

  • What types of users and devices there are and what resources each one needs.
  • How the networks for students, teachers, administration, guests and other devices are separated.
  • How the people who access the network are currently identified.
  • What happens to their access when a student, teacher or member of staff leaves the school.
  • Which services are reachable from the internet and whether they really need to be.
  • Which systems are monitored and what alerts are raised when an incident occurs.
  • What data is included in backups, where it is stored and whether recovery has been tested.
  • Which accounts have elevated permissions and which have two-factor authentication.
  • Which systems and documentation should always remain under the school's own control.

A secure network also has to keep working

From that analysis we can draw up an improvement plan and prioritise actions according to the risk, budget and needs of each school. Not every school needs to make the same investments or tackle every change at the same time. What matters is knowing what risks exist, which are the priority and which specific measures can reduce them.

Security in a school is not just about preventing unauthorised access. It is also about making sure that, if a problem arises, it can be detected early, its scope limited and normal operation restored with as little disruption as possible. At PenwinEdu we have spent over a decade designing and managing networks for schools and colleges. That experience gives us an understanding not just of the technology but also of the particularities of a school's day-to-day life and the problems that can arise when the infrastructure is not properly designed, protected or maintained.

We bring that knowledge to our clients through a combination of network design, security, 24/7 monitoring and technical support with a response within four working hours.

Sources

  1. Check Point Research, informe sobre la vuelta a clase (agosto de 2026), con datos de ataques semanales por organización entre enero y julio de 2026 (in Spanish)
  2. Sophos, «The State of Ransomware in Education 2026» (agosto de 2026), encuesta a 226 responsables de TI de centros educativos de 17 países realizada entre enero y marzo de 2026 (in Spanish)
  3. Reglamento (UE) 2016/679, General de Protección de Datos (RGPD), artículos 9, 33 y 34 (in Spanish)

The initial assessment of the state of the network is free and comes with no obligation. From it we can identify the school's main risks and plan the necessary improvements in an orderly way, prioritising whatever can really affect its security and day-to-day running.