DrochaidHorizon3.ai
NodeZero/Industries/Education
The state of play — Education & Research, 2026

Education attack volumes plateaued. Records exposed jumped 27%.

Third-party platform compromises — Oracle E-Business, MOVEit, PowerSchool — are driving the jump, cascading across hundreds of institutions at once. The British Library's published incident review remains the clearest public statement of what accredited pentesting missed.

27%
year-on-year jump in records exposed by ransomware attacks on educational institutions — from 3.11 million in 2024 to 3.96 million in 2025 — even as attack counts stayed flat (247 → 251).
Comparitech — Education Ransomware Roundup 2025
69%
surge in ransomware attacks on educational institutions in Q1 2025 versus the same period in 2024. Over 85% of higher education ransomware incidents stem from compromised credentials, phishing, and unpatched systems.
Cloud Security Alliance — Ransomware in the Education Sector
82%
of US K-12 schools experienced a cyber incident between July 2023 and December 2024.
Center for Internet Security, via K-12 Dive
The trend

Why Education is in the crosshairs

Five shifts shaping the education and research threat environment — why attack counts plateaued while blast radius grew.

Attack volumes have plateaued, but blast radius has grown

Comparitech's 2025 data is the headline: attack counts barely moved year-on-year (247 → 251), but records exposed jumped 27%. The reason is that the biggest 2025 breaches were not direct attacks on individual universities — they were cascading third-party platform compromises (Oracle E-Business, MOVEit, PowerSchool) that exposed data across dozens or hundreds of institutions simultaneously.

The third-party platform is the primary attack path now

Student information systems (PowerSchool, Ellucian, Workday Student), learning management systems, file transfer utilities (MOVEit, Cleo, Oracle E-Business), library systems, payment processors, and identity providers all hold concentrated education data. The US National Student Clearinghouse MOVEit incident in 2023 touched records from nearly 900 US colleges and universities; PowerSchool's late-2024 incident touched tens of millions of K-12 student records.

Research data is a nation-state target, not just a criminal one

The ASD 2024–25 report is explicit about state-sponsored espionage targeting Australian networks. Group of Eight universities run defence research, medical research, AI research, and commercial collaborations — all high-value intelligence targets. The British Library's published incident review and the 2023 University of Manchester breach (1.1 million NHS research records) both illustrate the research-custodian exposure.

Budget constraints amplify legacy risk

The Cloud Security Alliance reports cybersecurity spending at 3–12% of a typical university IT budget — far below what most sectors now spend. Combined with legacy academic systems, devolved IT where faculties run their own infrastructure, BYOD-by-default on student networks, and the research-collaboration imperative to keep systems accessible to external partners, universities and schools face an unusually wide attack surface with unusually thin defences.

K-12 consequences extend beyond data loss to child safety

The Minneapolis Public Schools incident in March 2023 saw Medusa publish 200,000 stolen files, including student disciplinary records, contact information, and in some cases information about students with restraining orders against family members. The Kido nurseries attack in the UK in 2025 saw attackers publish photographs of children. These are reputational and safeguarding crises, not just data-loss events.

On the record

What regulators and experts are saying

Although the security measures we had in place on 28 October 2023 were extensive and had been accredited and stress-tested, with the benefit of hindsight, there is much we wish we had understood better or had prioritised differently.
British Library
Learning Lessons from the Cyber-Attack
8 March 2024·British Library
The big distinguishing factor for 2025 is that a lot of the breaches that we saw are from these third-party attacks. It's making it harder for schools, effectively, because they've not only got to worry about their own systems, but they've also got to worry about the third-party systems that they're employing.
Rebecca Moody
Head of Data Research, Comparitech
February 2026
The people responsible for this cyberattack stand against everything that libraries represent: openness, empowerment, and access to knowledge.
Roly Keating
CEO, British Library
2023
What is now required

University research can be SOCI Act critical infrastructure

Universities operating research programs critical to national security or a critical infrastructure sector can be designated under the SOCI Act, bringing registration and cyber incident reporting obligations

Higher education and research entities operating designated critical infrastructure assets are subject to the SOCI Act CIRMP obligations. The CIRMP must address four hazard vectors: cyber and information security, personnel, supply chain, and physical security. For the cyber hazard vector, entities must adopt one of five approved frameworks. Not all education providers are SOCI-designated -- it depends on asset criticality designation by the Minister.

Universities also face obligations under TEQSA. The Higher Education Standards Framework Domain 7 (Representation, Information and Information Management) requires institutions to collect, store, and manage information securely as a condition of registration. TEQSA is a quality regulator rather than a cybersecurity standard -- its requirements don't map to specific technical controls the way the Essential Eight or ISO 27001 do, which is why it doesn't have its own compliance page on this site. That said, TEQSA assessors are increasingly looking for evidence that cybersecurity risks are identified and managed, particularly after the major university breaches of 2024-2025. Demonstrating that your IT systems are tested against real attack conditions directly supports the institution's evidence that it meets Domain 7's secure information management requirements.

Universities also face obligations under the Privacy Act 1988 for student and researcher personal information, the Cyber Security Act 2024 for mandatory ransomware payment reporting, and the Defence Trade Controls Act 2012 for entities involved in controlled research. ARC-funded research now requires strengthened security screening, with dual-use research and international collaborations triggering additional scrutiny.

Legislation
SOCI Act — Critical Infrastructure Risk Management Program

Federal legislation that designates higher education as a critical infrastructure sector. Universities and research institutions operating designated assets must maintain a CIRMP addressing four hazard vectors: cyber, personnel, supply chain, and physical security. NodeZero directly validates controls under the cyber hazard vector across student, research, and administrative networks. For the cyber vector specifically, entities must also adopt one of five approved frameworks which define the detailed technical controls.

Your chosen CIRMP cyber frameworkSelect one
Also in effect

A cascade of new obligations

Multiple new regulatory requirements are hitting simultaneously — each increasing the compliance burden and the consequences of failure.

SOCI Act — higher education and research assets

In force

Universities operating research programs critical to a critical infrastructure sector, the defence of Australia, or national security can be designated critical infrastructure under the SOCI Act — bringing asset registration and mandatory cyber incident reporting. Designation is asset-specific, not sector-wide.

Cyber Security Act 2024

30 May 2025

Universities exceeding $3M turnover must report ransomware payments within 72 hours. All universities exceed this threshold. Security standards for smart devices apply to the connected products universities procure — lab equipment, building management systems, and campus IoT.

ARC security screening strengthened

1 Jul 2024

ARC schemes opened for applications after 1 July 2024 carry strengthened security screening. Dual-use research, defence-adjacent projects, and international collaborations trigger ministerial veto risk. Research data security is now an explicit requirement.

TEQSA cybersecurity expectations tightening

In effect

TEQSA Domain 7 requires institutions to operate secure, well-governed information systems as a condition of registration. Following major university breaches in 2024-2025, TEQSA has signalled that cybersecurity risk identification and management is now explicitly assessed during registration renewals and compliance reviews.

Platform credentials

The only autonomous pentesting platform that is:

Essential Eight
Mapped ML1–3
ASD baseline
Privacy Act
Reachability proof
Student & research data
Gartner Peer Insights
4.7 / 5
Customers' Choice (Oct 2025)
310,332
Pentests run
7,013 orgs
Trusted by 7,013 organisations worldwide
Powers the NSA's CAPT program310,332 pentests4.7 Gartner

Prove your network resilience before the next semester starts

See how NodeZero discovers attack paths across your education environment