Education attack volumes plateaued. Records exposed jumped 27%.
Third-party platform compromises — Oracle E-Business, MOVEit, PowerSchool — are driving the jump, cascading across hundreds of institutions at once. The British Library's published incident review remains the clearest public statement of what accredited pentesting missed.
Why Education is in the crosshairs
Five shifts shaping the education and research threat environment — why attack counts plateaued while blast radius grew.
Attack volumes have plateaued, but blast radius has grown
Comparitech's 2025 data is the headline: attack counts barely moved year-on-year (247 → 251), but records exposed jumped 27%. The reason is that the biggest 2025 breaches were not direct attacks on individual universities — they were cascading third-party platform compromises (Oracle E-Business, MOVEit, PowerSchool) that exposed data across dozens or hundreds of institutions simultaneously.
The third-party platform is the primary attack path now
Student information systems (PowerSchool, Ellucian, Workday Student), learning management systems, file transfer utilities (MOVEit, Cleo, Oracle E-Business), library systems, payment processors, and identity providers all hold concentrated education data. The US National Student Clearinghouse MOVEit incident in 2023 touched records from nearly 900 US colleges and universities; PowerSchool's late-2024 incident touched tens of millions of K-12 student records.
Research data is a nation-state target, not just a criminal one
The ASD 2024–25 report is explicit about state-sponsored espionage targeting Australian networks. Group of Eight universities run defence research, medical research, AI research, and commercial collaborations — all high-value intelligence targets. The British Library's published incident review and the 2023 University of Manchester breach (1.1 million NHS research records) both illustrate the research-custodian exposure.
Budget constraints amplify legacy risk
The Cloud Security Alliance reports cybersecurity spending at 3–12% of a typical university IT budget — far below what most sectors now spend. Combined with legacy academic systems, devolved IT where faculties run their own infrastructure, BYOD-by-default on student networks, and the research-collaboration imperative to keep systems accessible to external partners, universities and schools face an unusually wide attack surface with unusually thin defences.
K-12 consequences extend beyond data loss to child safety
The Minneapolis Public Schools incident in March 2023 saw Medusa publish 200,000 stolen files, including student disciplinary records, contact information, and in some cases information about students with restraining orders against family members. The Kido nurseries attack in the UK in 2025 saw attackers publish photographs of children. These are reputational and safeguarding crises, not just data-loss events.
What regulators and experts are saying
Although the security measures we had in place on 28 October 2023 were extensive and had been accredited and stress-tested, with the benefit of hindsight, there is much we wish we had understood better or had prioritised differently.
The big distinguishing factor for 2025 is that a lot of the breaches that we saw are from these third-party attacks. It's making it harder for schools, effectively, because they've not only got to worry about their own systems, but they've also got to worry about the third-party systems that they're employing.
The people responsible for this cyberattack stand against everything that libraries represent: openness, empowerment, and access to knowledge.
University research can be SOCI Act critical infrastructure
Universities operating research programs critical to national security or a critical infrastructure sector can be designated under the SOCI Act, bringing registration and cyber incident reporting obligations
Higher education and research entities operating designated critical infrastructure assets are subject to the SOCI Act CIRMP obligations. The CIRMP must address four hazard vectors: cyber and information security, personnel, supply chain, and physical security. For the cyber hazard vector, entities must adopt one of five approved frameworks. Not all education providers are SOCI-designated -- it depends on asset criticality designation by the Minister.
Universities also face obligations under TEQSA. The Higher Education Standards Framework Domain 7 (Representation, Information and Information Management) requires institutions to collect, store, and manage information securely as a condition of registration. TEQSA is a quality regulator rather than a cybersecurity standard -- its requirements don't map to specific technical controls the way the Essential Eight or ISO 27001 do, which is why it doesn't have its own compliance page on this site. That said, TEQSA assessors are increasingly looking for evidence that cybersecurity risks are identified and managed, particularly after the major university breaches of 2024-2025. Demonstrating that your IT systems are tested against real attack conditions directly supports the institution's evidence that it meets Domain 7's secure information management requirements.
Universities also face obligations under the Privacy Act 1988 for student and researcher personal information, the Cyber Security Act 2024 for mandatory ransomware payment reporting, and the Defence Trade Controls Act 2012 for entities involved in controlled research. ARC-funded research now requires strengthened security screening, with dual-use research and international collaborations triggering additional scrutiny.
Federal legislation that designates higher education as a critical infrastructure sector. Universities and research institutions operating designated assets must maintain a CIRMP addressing four hazard vectors: cyber, personnel, supply chain, and physical security. NodeZero directly validates controls under the cyber hazard vector across student, research, and administrative networks. For the cyber vector specifically, entities must also adopt one of five approved frameworks which define the detailed technical controls.
Prescriptive and technically focused. Eight specific mitigation strategies with clear pass/fail controls. Common for government-adjacent entities, defence industry, and smaller organisations adopting ASD guidance.
Where NodeZero appliesBroad lifecycle coverage from governance through recovery without mandating specific technologies. Suited to entities operating across jurisdictions or mapping existing controls into a flexible structure.
Where NodeZero appliesInternational management system standard with formal certification. Chosen by larger entities with mature security programs, international operations, or existing ISO certification investment.
Where NodeZero appliesMaturity model assessing organisational capability across 10 domains. Originally built for the US electricity sector. Process and governance oriented -- less about specific controls, more about repeatable capability.
Where NodeZero appliesSector-specific to energy. Derived from C2M2 and NIST CSF with Australian privacy additions. Managed by AEMO. The default for electricity and gas market participants with OT/ICS environments.
Where NodeZero appliesUniversities and TAFEs hold extensive student, staff, and research participant personal information subject to the Australian Privacy Principles.
Where NodeZero appliesApplies to institutions processing tuition fees, accommodation payments, and other student transactions via payment cards.
Where NodeZero appliesIncreasingly adopted by research-intensive universities to satisfy international collaboration requirements and research data governance.
Where NodeZero appliesMandatory ransomware payment reporting for education providers over $3M turnover.
Where NodeZero appliesA cascade of new obligations
Multiple new regulatory requirements are hitting simultaneously — each increasing the compliance burden and the consequences of failure.
SOCI Act — higher education and research assets
In forceUniversities operating research programs critical to a critical infrastructure sector, the defence of Australia, or national security can be designated critical infrastructure under the SOCI Act — bringing asset registration and mandatory cyber incident reporting. Designation is asset-specific, not sector-wide.
Cyber Security Act 2024
30 May 2025Universities exceeding $3M turnover must report ransomware payments within 72 hours. All universities exceed this threshold. Security standards for smart devices apply to the connected products universities procure — lab equipment, building management systems, and campus IoT.
ARC security screening strengthened
1 Jul 2024ARC schemes opened for applications after 1 July 2024 carry strengthened security screening. Dual-use research, defence-adjacent projects, and international collaborations trigger ministerial veto risk. Research data security is now an explicit requirement.
TEQSA cybersecurity expectations tightening
In effectTEQSA Domain 7 requires institutions to operate secure, well-governed information systems as a condition of registration. Following major university breaches in 2024-2025, TEQSA has signalled that cybersecurity risk identification and management is now explicitly assessed during registration renewals and compliance reviews.
Find your organisation
See how the changes affect you specifically
Universities
43 Australian universities and 8 NZ universities. TEQSA governance requirements, active research programmes requiring security screening, and SOCI obligations for designated research assets.
View details →TAFE & vocational providers
State TAFEs and thousands of private RTOs. Highly distributed campuses with limited dedicated cybersecurity staffing and high student turnover.
View details →K-12 education departments
State education departments and Catholic/independent school networks operating 9,600+ schools serving more than 4 million students with centralised IT governance.
View details →The only autonomous pentesting platform that is:
Prove your network resilience before the next semester starts
See how NodeZero discovers attack paths across your education environment

