Original document on LinkedIn
Created on 2025-05-20 12:48
Published on 2025-05-20 13:38
I'm always looking for resources that can truly make a difference in our schools and MATs. Cyber security is more critical than ever for protecting our learning environments, and I recently watched a Softcat CyberSecurity YouTube webinar that offers some incredibly valuable insights, particularly for network managers and technicians. While the webinar was prompted by recent retail sector attacks, the experts rightly note that the topics are relevant to customers in all verticals of all sizes, in both public sector and corporate. This absolutely includes education.
I would specifically like to highlight a section of the video by Kieron Newsham, Chief Technologist - Cyber Security, Softcat between 18m 50s and 31m 27s where he highlights a number of actions that ought to be within the gift of all Network Managers, everywhere, to ensure that they are doing all they can to protect their school or MAT systems and data.
Why should network managers and technicians take the time to review this video?
The expert sources acknowledge that while security and protection remain paramount, we now live in a world where we all need to be in a situation where we're planning for being the victim of a breach. This proactive approach, discussed by experts with decades of experience, is essential for maintaining operational resilience in educational settings. The webinar covers critical ground from understanding current threats to practical mitigations and recovery strategies – all framed in a way that helps organisations of any size.
Drawing from my own experience in the education sector, I understand some of the core struggles network managers and technicians face in implementing effective cyber security measures:
Budget Constraints: Education institutions often operate on tight budgets, making it difficult to afford advanced security tools, sufficient staffing, or external expert services.
Staffing and Skills Gaps: Attracting and retaining cyber security talent is challenging due to competitive salaries in the private sector. Existing IT staff are often stretched thin, wearing many hats (as mentioned in the transcript ), leaving limited time for proactive security work.
Complex and Distributed Environments: Schools and universities have multiple buildings, sometimes spread across sites, housing a vast array of devices (personally owned and institution-owned) used by a highly diverse user base (students, staff, visitors).
User Awareness and Behaviour: Managing security risks posed by a large, transient user population with varying levels of technical understanding and different online behaviours (e.g., students clicking on links) is a constant battle. Security measures that impede access or convenience can face significant resistance.
Legacy Systems and Technical Debt: Many institutions rely on older infrastructure and software that may not be easily patchable or compatible with modern security controls, creating vulnerabilities.
Focus on 'Keeping the Lights On': The immediate demands of ensuring network uptime and accessibility for teaching, learning, and administration often overshadow strategic, long-term security projects (a challenge also noted more broadly in the transcript ).
Procurement Challenges: Purchasing processes in the public sector can be slow and complex, delaying the acquisition and deployment of necessary security solutions.
Balancing Security with Accessibility: Implementing stringent security controls must be carefully balanced with the need to provide open access to resources for educational purposes.
These struggles make the insights from the Softcat webinar, particularly around prioritisation , leveraging external partners , improving governance , and focusing on fundamental controls like MFA and patching , even more crucial for the education sector.
Highlights from the webinar include:
Understanding the Current Threat Landscape: Experts discuss the escalation of ransomware attacks and the rise of Ransomware as a Service (RaaS), which lowers the technical barrier for attackers. They also highlight the prevalence of supply chain attacks and the continued exploitation of zero-day vulnerabilities.
Specific Threat Actors: The transcript details groups like Scattered Spider, known for sophisticated advanced social engineering targeting large enterprises, and their tactics, techniques, and procedures (TTPs) . Dragon Force is mentioned as a RaaS service, sometimes used interchangeably with Scattered Spider due to historical linkages .
Scattered Spider TTPs Relevant to Education:
Identifying individuals with escalated admin rights and privileges through open source .
Using fishing and vishing to trick help desks into resetting passwords .
Exploiting multi-factor authentication (MFA) through techniques like SIM swapping .
Excelling at impersonating employees or vendors to trick help desk or IT teams via supply chain relationships .
Using portable executables to establish persistence, move laterally, escalate privileges, and install remote access tools .
Key Mitigation Strategies Discussed:
Enforcement of strong multi-factor authentication (MFA) , prioritising fishing-resistant methods like hardware tokens or passkeys over SMS or push notifications, as Scatter Spider is known for bypassing weak MFA and MFA bombing .
Implementation of strong identity and access management , including the principle of least privilege and regularly reviewing/disabling unused accounts .
Regular patching of systems and software , prioritising vulnerabilities used in previous ransomware attacks .
Hardening remote access (RDP, VPNs) with strong security controls and MFA . RDP should be enforced over secure communications , locked down to host addresses, and limited to specific user profiles . External RDP and SSH ports should generally be blocked .
Education of employees against fishing and impersonation tactics , encouraging a verify before you act culture .
Reducing the use of remote access tools where not needed and ensuring legitimate use is logged and monitored .
Implementing network segmentation (macro or micro) to limit lateral movement and reduce the blast radius of an incident .
Leveraging Endpoint Detection and Response (EDR) and Network Detection Response (NDR) tooling, actioning collected telemetry in a SIEM or XDR tool, as ransomware TTPs can be obvious at later stages (e.g., disabling volume shadow services) .
Ensuring strong governance , including an executive-sponsored mandate or charter for security and informing organisational risk profiles .
Operational Resilience and Recovery:
Emphasising the critical need for stakeholder management, alignment, and collaboration across IT, Security, and the C-suite . Misalignment leads to confusion and delays .
Stressing that everyone in the company owns the ransomware strategy if they touch it .
Advising organisations to start planning from a "we've been breached" standpoint and work backwards .
Integrating Business Continuity (BC), Disaster Recovery (DR), and Cyber Resilience strategies, rather than building them piecemeal .
The last line of defence is your data , specifically your last good data backup .
Highlighting the importance of ransomware-resilient backups , especially immutable backups that cannot be altered or deleted .
Storing the last good data backup in an air-gapped vault to build a clean room for recovery .
Defining and testing Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs) is crucial .
The importance of testing your plans regularly .
Acknowledging that medium-sized organisations are likely to heavily rely on outsourcing for security services and need to assure those suppliers . A virtual CISO service can help build a well-defined strategy .
On-premise and cloud security require a common security policy and expectation , treating them differently in terms of management but aiming for the same security posture . Understanding the responsibility matrix with hyperscalers is key .
Understanding threats like Scattered Spider's social engineering tactics and the importance of robust backup and recovery plans starting from a "breached" mindset are directly applicable to protecting student data and ensuring the continuity of education.
I highly recommend reviewing the video to gain a deeper understanding of these critical topics and how you can apply them within your school or MAT. Being informed and prepared is your best defence.