The Challenge
The client is a private school holding student records, health information, safeguarding material and family financial data. Its network is unusual among organizations of its size: it must serve staff, students and a large population of personal devices simultaneously, while remaining open enough for teaching to happen.
The school had a small IT team responsible for everything from classroom support to infrastructure, and no dedicated security function. Leadership was aware that schools had become a favored ransomware target and wanted an honest assessment before the new academic year rather than a reaction after an incident.
Our Approach
StrikeCyber ran a combined assessment covering the network, the learning platforms and the people, scheduled during a break so that testing could be thorough without disrupting teaching.
- Internal and external network testing, with particular attention to the boundary between student and staff network segments.
- Assessment of the learning management system and the student information system, testing whether a student account could reach staff or administrative functions.
- A phishing simulation against staff, designed to be instructive rather than punitive, followed by a session explaining what the results meant.
The school's IT team worked alongside the operators throughout, which mattered for an organization that would be maintaining these improvements itself with limited resources.
What We Found
- Insufficient network separation. A device on the student network could reach several administrative systems, including a server holding student records.
- Privilege escalation in the student information system. A student account could access reporting functions that exposed data about other students and their families.
- Default and shared credentials. Network equipment, projectors and several classroom systems retained default credentials, and one shared administrative password was known to a significant number of staff.
- Phishing susceptibility concentrated in one workflow. Staff were generally cautious, but a message imitating a routine internal request for a document upload succeeded at a much higher rate.
The Outcome
The school separated its student, staff and administrative networks properly, which closed the most serious finding. The information system vendor was engaged to fix the privilege escalation, and the school verified the fix on a retest. Default credentials were replaced across the estate and the shared administrative password was retired in favor of individual accounts with multi-factor authentication.
The phishing results were used to run targeted training on the specific workflow that had been exploited, rather than generic awareness material. A repeat simulation the following term showed a substantial improvement, and the school now runs the exercise twice yearly as a standing measure.
Why It Matters
Schools hold data about children, families and staff, and they hold it with a fraction of the security resources a comparable business would have. Ransomware crews have targeted the sector deliberately, understanding that an institution facing the loss of an academic year is under acute pressure. Testing before an incident is the difference between fixing a segmentation gap over a break and explaining a breach to a parent community. To assess your school's environment, get in touch.
