Cybersecurity Concerns for Education IT as Students Return: Guidelines from Keeper Security

Cybersecurity Concerns for Education IT Teams



With the onset of a new academic year, educational institutions across the country experience an influx of students, faculty, and staff. As school districts and universities hustle to set up accounts and connect numerous devices to their networks, a concerning trend emerges: cybersecurity threats abound in this chaotic environment. Keeper Security, an authority in identity security and Privileged Access Management (PAM), has released crucial guidance for IT teams in education. Here’s what you need to know about the current challenges and strategies to protect against cybersecurity threats.

Increasing Risks During Back-to-School Season



The education sector finds itself as a prime target for cybercriminals, facing an alarming rise in ransomware attacks, identity theft, and data breaches. Schools are attractive to attackers due to their valuable data, including student records and financial information, alongside typically underfunded IT departments which leads to insufficient security measures. The back-to-school period exacerbates existing vulnerabilities, characterized by simultaneous bulk account creations, device enrollments, and third-party app integrations. Unfortunately, research indicates that only 14% of educational institutions mandate security awareness training, paving the way for risks as nearly 20% of parents and students admit to reusing passwords across multiple accounts.

Keeper’s analysis underscores that the rise of artificial intelligence has made phishing attempts significantly more sophisticated. Cybercriminals now leverage AI to craft emails that closely imitate messages from trusted sources like financial aid offices or university leadership. Additionally, the emergence of deepfake technology complicates authentication, as convincing voice and video impersonations decrease trust in communications.

The Unseen Threat of Non-Human Identities



While the focus in cybersecurity often remains on human accounts, educational institutions must also confront the growing challenge posed by Non-Human Identities (NHIs). These digital entities—like service accounts and application programming interface (API) tokens—make up a significant but often overlooked part of school networks. For example, service accounts synchronize student data among systems, yet their credentials seldom undergo routine updates or audits, leaving a substantial attack surface open to exploitation.

As NHIs outnumber human users in many institutions, each one represents a potential entry point for attackers. Keeper Security highlights that failure to adequately manage these identities can lead to breaches that compromise educational environments.

Proactive Measures for Education IT Teams



In light of these growing complexities, here are some recommended strategies for education IT teams:

1. Implement Multi-Factor Authentication (MFA): Prioritize MFA for all staff and student accounts, which remains the most effective defense against credential-based attacks. This should be initiated before new users are onboarded.
2. Use an Enterprise Password Manager: Roll out an enterprise-level password management system to eliminate weak, shared, or reused passwords, ensuring all privileged accounts are secured.
3. Conduct Audits on Privileged Access: Before the school year starts, review access rights for both human and non-human accounts, revoking access for departed employees and removing inactive service accounts.
4. Create an Inventory of Non-Human Identities: Catalog all service accounts, APIs, machine certificates, and AI agents operating within the institution. Visibility into these identities is critical for security.
5. Establish Credential Rotation Policies: Implement regular credential rotation for NHIs, specifically focusing on new integrations brought on for the upcoming school year, especially AI agents and third-party applications.
6. Enhance Phishing Awareness Training: Update training materials to encompass new threats, particularly AI-generated communications.

Keeper Security's innovative platform assists institutions in managing both human and non-human identities, ensuring that every data point remains secure. With tools designed for effective governance and automated credential management, educational IT teams can better navigate the complexities of cybersecurity.

In conclusion, as another school year begins, the call for heightened security awareness within educational institutions becomes more urgent. Implementing proactive measures can safeguard students and faculty, ensuring that the focus can remain on learning rather than combating cyber threats. For further information on safeguarding educational environments, visit Keeper Security.

Topics Other)

【About Using Articles】

You can freely use the title and article content by linking to the page where the article is posted.
※ Images cannot be used.

【About Links】

Links are free to use.