K–12 IT Pros See Careless Insiders and Foreign Governments as Top Security Threats

A new survey of public sector IT professionals finds that the biggest data security threats come from a wide range of sources, from simple carelessness to intentional hacking from foreign governments.

According to the eighth-annual Public Sector Cybersecurity Survey Report from SolarWinds, which provides IT security and management solutions, among education professionals, the most widely cited source of security problems was "careless/untrained insiders," with 58% of respondents from the education sector saying this is a major source of threats. That was followed closely by foreign governments, at 56%. The "general hacking community" came in third, at 54%.

Despite the relatively high profile of ransomware attacks on schools, colleges, and universities, only 26% or education respondents cited ransomware as a concern. Among education sector respondents, 13% said their organizations had been impacted by ransomware in the last 12 months.

Worms (23%) and mobile trojans (21%) also made the list of security concerns among education organizations.

In K–12 specifically, spam was cited as the biggest IT security threat. And according to the data, 54% of K–12 respondents said they "have been impacted by spam in the past 12 months."

Interestingly, in terms of approaches to data security, 92% of education respondents "find it very or somewhat important to implement a zero-trust approach, ranking the highest among all public sector groups and increasing by 10% from 2021." However, among K–12 respondents specifically, 77% "do not know or are not familiar with a zero-trust approach or are not considering a zero-trust approach."

"Lack of zero-trust implementation on the part of workers will open a wide space for hackers to compromise the data security and use them for malicious purposes," said one survey respondent.

What approaches are K–12 institutions taking to data security. According to the survey, "43% of K–12 respondents shared that their organization is following the OMB federal strategy and roadmap, the leading response for K–12 respondents."

Other findings from the survey include:

  • In terms of approaches to zero trust, "OMB and DoD frameworks are relied on most" (33%), followed by NIST Zero Trust architecture (15%) and CISA’s Zero Trust Maturity Model (10%);

  • Among all public sector respondents (government, education, and healthcare included), 66% of respondents "feel their IT environment is extremely/very complex to manage," and just 5% said they "feel extremely confident in their ability to manage these environments"; In K–12, 48% "are moderately confident in their organization’s ability to manage its IT environment, and 48% are slightly confident or not at all confident";

  • Education respondents were least likely to be confident in their organization's ability to manage IT complexity among all public sector types;

  • 52% of education respondents said they "lack visibility across environments";

  • 53% of education respondents said they "lack visibility across teams"; and

  • Among all public sector organizations, "The top three barriers to managing complex IT environments are an insufficient number of IT staff (41%), followed by time constraints (39%), and budget issues (35%)."

"The threat foreign governments pose to the security of government IT systems has steadily increased throughout the years,'' said Brandon Shopp, group vice president, product strategy at SolarWinds, in a prepared statement. "However, it is reassuring to see this year's data showing public sector organizations continue to recognize top security threats, adopt zero-trust strategies, and seek vendor attestations and SBOMs to better secure the software supply chain — all of which are crucial to maintaining a high standard of security across federal and state government, as well as in the education and defense sectors."

The eighth-annual Public Sector Cybersecurity Survey Report is available on SolarWinds' website.

About the Author

David Nagel is the former editorial director of 1105 Media's Education Group and editor-in-chief of THE Journal, STEAM Universe, and Spaces4Learning. A 30-year publishing veteran, Nagel has led or contributed to dozens of technology, art, marketing, media, and business publications.

He can be reached at [email protected]. You can also connect with him on LinkedIn at https://www.linkedin.com/in/davidrnagel/ .


Featured

  •  classroom scene with students gathered around a laptop showing a virtual tour interface

    Discovery Education Announces Spring Lineup of Free Virtual Field Trips

    This Spring, Discovery Education is collaborating with partners such as Warner Bros., DC Comics, National Science Foundation, NBA, and more to present a series of free virtual field trips for K-12 students.

  • glowing padlock shape integrated into a network of interconnected neon-blue lines and digital nodes, set against a soft, blurred geometric background

    3 in 4 Administrators Expect a Security Incident to Impact Their School This Year

    In an annual survey from education identity platform Clever, 74% of administrators admitted that they believe a security incident is likely to impact their school system in the coming year. That's up from 71% who said the same last year.

  • horizontal stack of U.S. dollar bills breaking in half

    ED Abruptly Cancels ESSER Funding Extensions

    The Department of Education has moved to close the door on COVID relief funding for schools, declaring that "extending deadlines for COVID-related grants, which are in fact taxpayer funds, years after the COVID pandemic ended is not consistent with the Department’s priorities and thus not a worthwhile exercise of its discretion."

  • pattern of icons for math and reading, including a pi symbol, calculator, and open book

    HMH Launches Personalized Path Solution

    Adaptive learning company HMH has introduced HMH Personalized Path, a K-8 ELA and math product that combines intervention curriculum, adaptive practice, and assessment for students of all achievement levels.