Cyber risks in education include threats such as identity theft, violation of student and teacher privacy, unauthorised access to data, addiction to technology, and exposure to disinformation and electronic violence.
The video lesson will show why it is important to be well prepared in case of cyber incidents. A methodology has been developed, with steps for managing cyber incidents, and recommendations for management.
Cybersecurity breaches, such as ransomware attacks, data theft, and DDoS attacks, often result in significant financial damage, business disruptions, and loss of confidential information. Key strategies for preventing future incidents include implementing multi-factor authentication, regularly updating systems, providing security training for users, and developing incident management and recovery plans. A proactive approach and continuous threat monitoring are essential for effective cyber defence. Preparing for cybersecurity incident management is crucial, as it enables timely identification and effective response to threats. Incidents such as malicious attacks, data breaches, or system outages can have severe consequences – ranging from financial losses to damaged reputations. With clearly defined incident response plans, teams can quickly isolate the threat, minimise damage, notify relevant parties, and initiate the recovery process. Additionally, proper preparation ensures compliance with legal regulations and strengthens the organisation's overall resilience to cyber threats. In managing a security incident, it is crucial to not cause further harm, as reckless or hasty actions can worsen the situation, destroy evidence, spread the attack, or disrupt key systems, thereby increasing the overall damage and complicating recovery. Information and communication systems are exposed to various types of threats from three key sources: devices, natural phenomena, and human behaviour. Each of these categories poses a serious risk to the security and availability of ICT resources, and to business continuity. Devices, as a fundamental segment of infrastructure, are susceptible to failures, malware attacks, and unauthorized access. Prevention includes regular maintenance, software updates, the use of antivirus protection, and securing physical access. Otherwise, the consequences can include data loss, operational disruptions, or system crashes, all of which directly impact business processes. Natural threats such as earthquakes, fires, or floods can cause the destruction of physical infrastructure. To mitigate the risk, it is essential to have remote backups, develop disaster recovery plans, and ensure system resilience. Failing to implement these measures can lead to permanent data loss and significant business disruptions. Both categories of threats – devices and natural events – can be effectively prevented by establishing backup sites that can take over as primary locations when needed. The human factor, often the most unpredictable, includes careless mistakes, a weak security culture, social engineering, and malicious internal and external actors. User education, the implementation of multi-factor authentication, and strict access controls are key to prevention. The impact of human errors or deliberate actions can lead to system compromise, sensitive data leaks, and financial and legal consequences. Therefore, it is essential to develop a comprehensive protection strategy that takes all three categories of threats into account to ensure system resilience and data security. A cybersecurity incident refers to any event or activity that threatens or actually breaches the security policies or standards established to protect computers, networks, data, and systems. This includes situations such as unauthorized access to data, malicious attacks (viruses, ransomware), identity theft, and violations of acceptable use policies, such as using corporate devices for personal purposes or unauthorized access to the network. Such incidents can jeopardise the integrity, confidentiality, and availability of information. The response to a cybersecurity incident can vary significantly between those organisations that are unprepared and those with established procedures. Unprepared organisations are often late in recognising and reporting threats, leading to the spread of attacks and increased damage. Lack of coordination slows the response, and insecure data recovery can cause long-term losses. In contrast, organisations with defined protocols quickly detect threats, coordinate responses, and recover effectively, reducing damage and financial losses. Established recovery plans ensure a quicker return to normal operations. The CIA triad represents the three core objectives of information security: confidentiality ensures that data is only accessible to authorized users and protected from unauthorized access; integrity guarantees that data remains intact and accurate during transmission and storage, free from unauthorized alterations; and availability ensures that data and systems are accessible to users whenever needed, without delays or disruptions. According to the National Institute of Standards and Technology (NIST), the lifecycle of managing a cybersecurity incident consists of four key steps. The first is preparation, which involves developing security policies, training employees, and implementing threat monitoring tools. The second is detection and analysis, where threats are identified and analyzed using tools such as IDS (Intrusion Detection System) and SIEM (Security Information and Event Management). This is followed by the incident response, which involves isolating affected systems and stopping the attack. Finally, the recovery and lessons learned phase allows the organisation to analyse the event and improve security measures for the future. The SANS Institute, the largest global organisation focused on cybersecurity, emphasises the importance of developing security policies, defining responsibilities, and establishing monitoring tools. The first step in the SANS (SysAdmin, Audit, Network, and Security) process is preparation. Preparation also involves employee training to ensure they are ready for potential threats. The second step is identification – during this phase, the organisation uses various tools and techniques to detect security threats. SANS stresses the importance of quickly recognising anomalies and signs of an attack in order to take appropriate actions as soon as possible. Next is incident response, where specific measures are taken to minimise damage, such as isolating affected systems, blocking the attack, and notifying relevant teams. The final step is recovery and lessons learned. Once the incidents are stopped, the organisation must restore affected systems and analyse the root causes of the attack. It is crucial to assess the lessons that can be learned from the attack to improve security strategies and prevent future attacks. The SANS framework implies a continuous improvement cycle, as organisations must apply the lessons learned from each incident to enhance their protection and increase resilience against future threats. An organisation should have clearly defined steps and designated responsible individuals to act quickly and effectively in the event of a security incident. The policy outlines the core guidelines and principles that govern the response to incidents, ensuring consistency in procedures. The plan should describe the specific actions to be taken in response to incidents, based on the guidelines from the policy. The procedure outlines the specific steps to be followed, including diagnosis, response, and notification. The organisation must have rules for securely and promptly sharing incident information both within and outside the organisation. Information about the incident should be communicated to the appropriate authorities or partners, such as legal or regulatory agencies. It is important to select a team based on the type of incident, expertise, and available resources to ensure the response is as effective as possible. In addition to the IT department, other sectors, such as the legal or communications teams, may also be involved in resolving the incident. The incident response team should be ready to provide additional support, including helping to recover systems, notifying users, and cooperating with external partners.
Background Colour
Font Face
Font Size
Text Colour
Font Kerning
Image Visibility
Letter Spacing
Line Height
Link Highlight