Half of Educational Institutions Experienced a Cyberattack in the Past Year

By Tracey E. Schelmetic

It seems to be steeped into our conventional wisdom that cyber hackers only target high-value institutions, such as banks, insurance companies and large sources of cash and personal customer information. But, increasingly, other types of institutions are becoming targets, perhaps because they don’t have the kind of rigorous security that moneyed organizations have, even though they are heavy users of cloud-based applications. They also have plenty of sensitive personal information that can be leveraged by cyber criminals.

According to new research, nearly half of all educational institutions suffered a cyberattack on their cloud infrastructure within the last 12 months. This is according to cybersecurity company Netwrix, which announced its findings for the education sector from its global 2022 Cloud Data Security Report. The report also found that, for 27 percent of them, incidents in the cloud were associated with unplanned expenses to fix security gaps.

"Educational institutions are keen to broaden their cloud adoption: The sector expects to have 56% of the workload to be in the cloud by the end of 2023, compared to this year's 44 percent," said Dirk Schrader, VP of Security Research at Netwrix. "But, without proper visibility into who has access to sensitive data and when and how that data is being used, IT teams will not be able to proactively mitigate data overexposure and spot suspicious behavior in the cloud."

A large percentage of educational organizations confirmed they store sensitive data in the cloud: the study found that 83 percent of schools do. With educators and students constantly sharing that information, schools tend to be more concerned about insider threats than other industries. Forty-eight percent of respondents in this sector consider cybersecurity risks associated with their own employees to be the biggest ones.

"The educational sector has a good reason to be concerned about insider threats since, 42 percent of them experienced account compromise attacks in 2022 compared to the average of 31 percent from the other industries surveyed,” said Schrader. “Accordingly, their IT teams should pay closer attention to identity and access management by implementing a zero standing privilege approach and enforcing strong password policies.”

While some industries may seem to be more likely targets, the fact is, every business is a target and they all should take extra precautions to safeguard their networks, devices, and data with the latest security strategies and solutions from their technology partners.




Edited by Erik Linask
Get stories like this delivered straight to your inbox. [Free eNews Subscription]

MSPToday Contributor

SHARE THIS ARTICLE
Related Articles

3 Key Differences Between Turnkey and Custom-Build Command Centers

By: Contributing Writer    9/16/2026

Modern command centers serve as highly connected environments where operators work with large displays, multiple data sources, integrated technologies…

Read More

SkySwitch Bets Native AI Can Turn UCaaS Partners into Workflow Specialists

By: Erik Linask    9/1/2026

AI-powered UCaaS is transforming how MSPs and technology providers serve SMB customers by combining voice automation, customer experience, and busines…

Read More

4 Benefits of 24/7 Managed IT Support Services

By: Contributing Writer    8/26/2026

Modern IT environments grow more complex by the quarter, leaving internal teams stretched thin across expanding cloud infrastructures, security protoc…

Read More

We Asked Four AI Assistants to Recommend an MSP. Here Is What Decided the Answer

By: Contributing Writer    8/25/2026

A buyer who used to search "managed IT services near me" now asks ChatGPT which provider suits a 50-person firm. The assistant returns two or three na…

Read More

From Visibility to Action: Pure IP Is Rethinking Enterprise Technology Cost Management

By: Erik Linask    8/20/2026

As distributed enterprises struggle with rising carrier costs, unused services, billing errors and complex infrastructure, continuous technology cost …

Read More