Security

Educational institutions frequently overlook or misunderstand the importance of cybersecurity.

In this edition of PWNED, our weekly column on digital security failures, we examine a cautionary tale regarding a school official’s complete lack of security awareness.

The following account is provided by Kevin Walker, an experienced IT professional from the UK. While performing consulting services for a school, Walker discovered a laptop belonging to the headteacher.

A sticker on the bottom of the laptop displayed the user’s credentials. Even if the credentials had been complex, the physical note would have compromised them; however, the combination was remarkably simple:

Username: headteacher
Password: headteacher

With access to this device, a malicious actor could have compromised sensitive student data, internal communications, email accounts, and private institutional files, potentially causing severe consequences for staff and students alike.

“A headteacher’s laptop is more than just a portable computer; it serves as a gateway to the most sensitive data within a school,” Walker explained. A cybercriminal gaining access through this device could effectively infiltrate the institution’s network remotely.

Walker reported that this was not an isolated incident of poor security hygiene. He also discovered an institution that maintained an Excel file named “Passwords.xlsx” on a shared drive accessible to students. As the name implies, the file contained login credentials that any bad actor could have exploited.

Additional vulnerabilities observed by Walker included active accounts for former employees, a server with a backup drive permanently connected—allowing hackers to potentially wipe backups—and a Wi-Fi password written on a whiteboard in the reception area. He also encountered critical systems accessible only via obsolete hardware, a machine labeled “Do Not Turn Off” that staff were afraid to touch, and a CCTV monitor running the long-obsolete Windows XP operating system. Furthermore, a supposedly secure server room was being used as a storage closet for stationery and holiday decorations.

Walker noted that, in his experience, the schools he serviced often prioritized other operational concerns over cybersecurity and failed to grasp its critical importance. One administrator even dismissed the need for data protection entirely.

“We don’t need to worry about cybersecurity. They’re only a primary school,” the manager told Walker when he suggested implementing cloud backups.

Walker suggests that the core issue is that schools often operate with outdated equipment and administrators who are preoccupied with other priorities. His recommended solution is to prioritize simplicity in security protocols.

“Make the secure option the easiest option,” Walker advised. “Provide staff with password managers. Implement multi-factor authentication. Conduct regular account reviews. Test backups. Eliminate shared administrator logins. Keep all systems updated. Enforce strong password policies and block credentials that have appeared in known data breaches. If a password has already been leaked online, it is unfit for protecting a school system. These measures may not be as exciting as distributing new iPads, but they are effective.”

Source link

Exit mobile version