The 4 Security Gaps That Appear in Schools and Early Learning Centres
- Shane Webster
- Jul 22
- 4 min read
Updated: Aug 3
Across the schools and early learning centres we support in Melbourne and regional Victoria, one pattern comes up often when we're brought in to review cyber security. The setup was configured well originally, but the environment has kept moving around it.
Over the years, new platforms have gone in, and older systems have quietly stayed on. Accounts and devices have grown alongside the staff turnover of any busy setup, and the environment now looks quite different from the one the original configuration was built for.
This is where cyber security gaps in schools tend to appear. The original configuration was set against a smaller environment than the one it's now working across, and the coverage hasn't quite kept up.
Here are the four gaps we see most often when our team looks over the essentials in a school or early learning centre.
MFA Coverage for Staff and Privileged Accounts
Most schools already have MFA in place for regular staff mailboxes. The gap tends to appear when a staff or privileged account sits outside the policy, particularly administrator accounts that can make changes across the environment.
Student and service accounts are used differently and require security controls matched to their purpose rather than the same MFA approach. The priority is to enforce MFA across all staff and privileged accounts, then restrict, monitor and regularly review any exceptions.
MFA is one of the most effective ways to strengthen security with minimal impact on day-to-day work. Closing the gap starts with checking which staff and privileged accounts sit inside the current policy and bringing any exclusions back into review.
Backup Coverage That Hasn't Kept Pace With New School Systems
Backups in schools are usually scoped against the systems that were in place when the setup was first configured. The original scope often included staff email and the main student administration system.
Since then, new platforms may have come in for things like document storage, wellbeing, HR, finance and compliance. These sit alongside the original coverage rather than being folded into it.
The ACSC's guidance on backups is that they're only useful if the school knows what's covered and has tested that the data can actually be restored. A common assumption we see is that if a system is cloud-based, the provider looks after the backup. In most cases, the provider is responsible for keeping the platform running, not for restoring the school's data if something goes wrong.
Closing the gap starts with a list of every system the school relies on day to day, and a check of which of those sit inside the current backup. From there, it's a question of whether the backup is running often enough, and whether anyone has tested that a restore actually works.
Access That Stays After People Leave, or Spreads Further Than It Should
Access in a school or early learning centre covers a wide mix of people. Alongside permanent staff, there are casuals, contractors, placement students and volunteers who all need a login at some point. Accounts are created quickly to keep things moving, and the closing-down step when someone leaves or changes roles doesn't always follow at the same pace. Permissions carry across from previous roles, and shared logins for older systems keep circulating past the point they were needed.
Under the Australian Privacy Principles, schools are expected to hold personal information securely and limit access to those who need it. Access that no longer matches someone's role sits outside that expectation, even if the person is still on staff.
Closing the gap is a review rather than a rebuild. It looks at who has access to what, whether that still matches the role they're in, and whether there's a clear process for closing accounts down when someone leaves.
Unmanaged Devices and Endpoint Drift Across School Device Fleets
School device fleets are more varied than most other environments. There's a mix of staff laptops, classroom devices used by multiple students, older machines still in active service, and personal devices that staff or students bring in for specific tasks. Not all of these devices sit inside the same management system, and coverage across patching, encryption and endpoint protection can vary widely depending on how the device was brought into the environment.
ACSC guidance on patching treats device-level protection as one of the core mitigations for reducing exposure. In a school, that's harder to hold together across a fleet where each device type has its own path in and out of the environment. Devices that fall outside the management system quietly fall behind on updates and end up without the protections applied to the rest of the fleet.
Closing the gap starts with a clear view of every device connecting to the school's network and data, and which of those sit inside the current management setup. From there, the question is what to do about the devices sitting outside, whether that's bringing them into the management system or restricting what they can reach.
Where a Review of Your School's Cyber Security Starts
None of these four gaps point to a school doing something wrong. They come up because the environment has kept moving, and the original setup was scoped against a smaller version of it. Looking over the essentials is what brings the two back into line.
At plexusIT, we work with schools and early learning centres across Melbourne and regional Victoria as part of our managed IT services. Alongside the day-to-day support, we look at whether MFA covers staff and privileged accounts, what's inside the backup scope, who has access to what, and how your device fleet is being managed.
The result isn't a long report. It's a clear view of where the essentials are covered and where they've slipped, a practical order for closing the gaps that matter most, and a partner who helps keep your environment safe for the future.
Want to know where your security stands? Book a time with our team here.


