In a digitalised educational environment, schools, universities, and other educational institutions use a range of technologies for knowledge delivery, data management, and communication with students and parents. While this brings many benefits, it simultaneously opens the door to numerous threats and risks to users’ digital security and privacy.
Threats and risks for digital security in the educational environment
| Site: | Loomen za stručna usavršavanja |
| Course: | Security and Privacy in the Digital Environment |
| Book: | Threats and risks for digital security in the educational environment |
| Printed by: | Gost (anonimni korisnik) |
| Date: | Tuesday, 28 July 2026, 8:16 AM |
Table of contents
- 1. Introduction
- 2. Overview of the main challenges of digital security in education
- 3. The effects of privacy violations on the educational process
- 4. Strategies for addressing digital security challenges
- 5. The role of technological innovations in privacy protection
- 6. Education and awareness about digital security and privacy
1. Introduction

Figure 9: Main challenges of digital security in education
2. Overview of the main challenges of digital security in education
The digital transformation of education brings many benefits—from improved accessibility of content to personalised learning—but it also entails a range of security challenges that can jeopardise system integrity, student privacy, and the reliability of the educational process. Schools, universities, and other educational institutions often lack sufficient resources or expertise to adequately address the growing threats in the digital environment. Educational institutions typically operate multiple interconnected components of information systems, which further increases the complexity of implementing effective security mechanisms.
The main challenges facing the education sector today include:
1. Technologically outdated equipment
Many educational institutions use certain components of outdated equipment that no longer receive security updates, making them vulnerable to already known attacks. In addition, schools often lack specialised IT teams capable of performing systematic maintenance and security upgrades.
Example:
The Stanford University School of Medicine experienced a data breach as part of a cybersecurity incident related to a third-party file-sharing service known as the File Transfer Appliance (FTA), provided by Accellion Inc.: Statement on the School of Medicine Cybersecurity Incident.
Read more about the incident at link.
2. Weak protection of personal data
In schools and universities, sensitive personal data are collected on a daily basis—such as names, addresses, personal identification numbers, grades, medical information, and even biometric records (e.g., in attendance tracking systems). These data are often stored without encryption, on unsecured servers, or shared with third parties without a clear legal basis. (Common Pitfalls in School Data Protection and How to Avoid Them)
Under GDPR, schools are required to protect the personal data of their students, and violations can result in significant fines.
More information: Croatian Personal Data Protection Agency website offers guides and educational materials on personal data protection
3. Phishing and Social Engineering
Phishing campaigns target teachers, students, and parents via email or messages, attempting to trick them into clicking malicious links or revealing their login credentials. Younger users and employees who are not educated about basic types of fraud can easily become victims of such attacks.
Advice: Introducing mandatory training on recognising fraudulent messages can significantly reduce the number of successful attacks.
Short educational video: What is Phishing?
4. Insufficient Access Control
Student and teacher accounts are often created without appropriate security settings. Weak passwords, the reuse of the same passwords across multiple services, and the absence of multi-factor authentication (MFA) open the door to unauthorised access to school platforms and data.
Solution: Implement a policy requiring strong passwords and MFA for all system users.
5. Reliance on Third-Party Online Tools
Platforms such as Google Workspace for Education, Microsoft Teams, Zoom, and various LMS systems (such as Moodle) process vast amounts of user data. Although most of these tools have strong security mechanisms, their privacy practices and data usage may not always be fully aligned with the national legislation.
It is crucial to carefully review the terms of use and ensure that data are not used for commercial purposes.
Europe PMC Cybersecurity threats to educational institutions: growing concerns for a new era of cybersecurity
Conclusion
The main digital security challenges in education arise from a combination of technical vulnerabilities, insufficient user education, and unclear rules regarding data usage. Addressing these challenges requires a systematic approach that includes technological solutions, legal guidelines, and continuous education of all participants in the educational process.
3. The effects of privacy violations on the educational process
Sources:
4. Strategies for addressing digital security challenges
Given the increasingly frequent digital security threats, from malware to identity theft and privacy breaches, educational institutions need to take systematic and proactive protective measures. Effective strategies include not only technical solutions but also organisational policies and user education.
Outlined below are the key recommended strategies:
Conclusion: A Multi-Layered Approach to Security
Effective protection of an educational institution is based on a multi-layered approach—a combination of technical measures, organisational policies, and the education of staff and students. Although no single strategy is 100 % effective on its own, their synergy significantly reduces the risk of digital threats.
Recommended sources for further reading:
5. The role of technological innovations in privacy protection
Technology has not only transformed the way we learn and teach, but it also provides advanced solutions for protecting the personal data of students, teachers, and other participants in the educational process. Innovations such as encryption, artificial intelligence (AI), automation, and security-by-design play a key role in strengthening digital security in educational environments.
1. Data Encryption
Data encryption allows information to be converted into an unreadable format for anyone except authorised users with the corresponding key. This ensures that even if data is stolen or leaked, attackers cannot read its content.
Application in educational institutions:
- Educational institutions can use encryption to store students’ personal data (e.g., grades, medical information, etc.) in information systems (ISVU).
- Data transmission between teachers and students via email should be secured using cryptographic protocols or through document classification implementation (Information Security Act), ensuring that all important documents are protected with multiple security elements (confidentiality, non-repudiation, integrity, completeness).
2. Artificial Intelligence Systems for Threat Detection
Advanced AI algorithms can analyse user behavior patterns and detect suspicious activities that indicate a potential security incident—such as unusual logins, attempts to access restricted areas of the system, or malware propagation.
Practical example:
- Blackboard and Microsoft 365 Education integrate AI systems that automatically detect and block unauthorised login attempts in real time.
- Universities in the United States use AI to monitor compromised user accounts and automatically reset passwords.
More information:
IBM – How AI is transforming cybersecurity
3. Secure Learning Platforms with Built-in Privacy Protection (Privacy by Design)
The “Privacy by Design” concept involves integrating personal data protection into the core of technology and processes, rather than adding it later. This means that platforms like LMSs (e.g., Moodle, Google Classroom) must have:
- clear access controls,
- pseudonymisation and anonymisation capabilities,
- mechanisms for user consent management,
- transparent display of who, when, and why data are being used.
Example:
Moodle allows administrators detailed control over user privacy, and the system is designed in accordance with EU GDPR guidelines.
More on the concept: European Data Protection Supervisor (EDPS) – Privacy by Design
4. Automated Tools for Access and Permission Management
Human errors—such as incorrectly assigned access rights or failure to deactivate accounts—are common causes of security incidents. Automated Identity and Access Management (IAM) tools can:
- regularly check who has access to which data,
- automatically revoke access for former employees or students,
- notify administrators of unusual activities.
Example:
The University of Zagreb implements an LDAP system with automated access control via the AAI@EduHr infrastructure.
Conclusion
Technological innovations form the foundation for privacy and security protection in education. However, their effectiveness depends on how institutions implement them and the extent to which organisational changes, policies, education, and oversight accompany them. By investing in advanced technologies and ensuring their proper use, educational institutions can significantly reduce the risk of incidents while simultaneously strengthening the trust of students, parents, and teachers.
6. Education and awareness about digital security and privacy
Although technological measures such as encryption, firewalls, IDS, SIEM, and MFA are crucial for securing digital systems, they are not sufficient on their own. The greatest security risk often comes from the users themselves—their lack of knowledge and failure to follow basic rules, carelessness or inattention, and lack of confidence in their ability to recognise threats.
Therefore, educating all participants in the educational process—students, teachers, administrative staff, and even parents—is a key component of protecting personal data and systems.
1. Regular Education for Teachers, Students, and Parents on Digital Hygiene
Digital hygiene includes a set of basic habits that users should adopt to behave responsibly and safely online:
- using strong and unique passwords,
- regularly updating devices and software,
- recognising phishing messages and social engineering attempts,
- protecting personal information on social media,
- safely using public Wi-Fi networks.
Example:
In Slovenia, the Ministry of Education, in collaboration with SI-CERT and ARNES, organised a national campaign called Varni na internetu (“Safe on the Internet”), which includes educational brochures, videos, and workshops for schools and parents.
The following link is available in Slovenian only. Participants may use free AI-powered translation tools to access the provided materials.
Varni na internetu – Education and Tools
2. Introducing a Curriculum on Digital Literacy and Security from an Early Age
Learning about digital security should start in primary school, with age-appropriate content that introduces students to concepts such as:
- digital identity,
- digital footprint,
- privacy and security,
- cyberbullying, phishing, social engineering,
- fake news and data manipulation.
The goal is to help children develop critical thinking and responsible behaviour toward digital technologies.
3. Workshops and Simulations of Security Incidents
Practical experience helps users be prepared for real threats and have a clear plan for managing cyber incidents. Training should include:
- phishing attack simulations,
- exercises responding to ransomware and other cyber incidents,
- scenarios involving data theft or improper sharing of information.
In such workshops, organisations and participants learn to recognise threats, know whom to contact, and take steps to prevent or mitigate damage.
Example:
In the United Kingdom, schools often collaborate with the National Cyber Security Centre (NCSC), which offers free cyber incident simulation toolkits and organises educational events for children and teachers.
NCSC – CyberFirst Schools Program
Conclusion
Technology can protect systems, but only education can protect users. Investing in continuous education on digital security and privacy is key to creating a cyber-safe educational environment.
Education should not be a one-time activity but a continuous process that evolves and adapts to new threats and technologies.
Background Colour
Font Face
Font Size
1
Text Colour
Font Kerning
Image Visibility
Letter Spacing
0
Line Height
1.2
Link Highlight