Home / ITRM Insights / Blog / Phishing Attacks
17 Jun 2025
In our newly found technological world, organisations across the globe are more reliant on technology than ever, and educational institutions are no exception. Modern developments are transforming the way that students learn and teachers teach, which has many benefits, but this also comes with a growing risk of cyber security threats.
The education sector has quickly become a favourable target for cyber criminals, with institutions often lacking the resources or technical knowledge to defend against more sophisticated attacks. In our blog, we will explore some of the top threats that are facing the education sector and provide some ways to prevent them.
Phishing has been a top threat for all organisations over the past few years. The UK government reported that 89% of primary and secondary schools that experienced a cyber attack identified phishing as the source. Phishing is a method that utilises impersonation to deceive employees or students into revealing sensitive data, commonly enabling cyber criminals to access a device or the wider IT infrastructure.
There are several ways to safeguard your business against phishing attacks. One of the most powerful tools that we have to defend against cyber attacks is education, due to the fact that phishing relies on human error. By conducting regular cyber security training, you can identify your weak links and fortify your defences using this information. Suppose you do not have the internal resources to provide this training in-house. ITRM offers a service that creates a customisable training program leveraging online learning in various forms, such as courses, videos, and gamification and includes an actionable performance report. In addition to this, we can send simulated phishing emails and 'test' your security.
Another tool that's commonly used is email filtering, which is software that can be installed on your device. This tool automatically analyses incoming emails to detect and block potentially harmful emails such as phishing attempts or malware. This added layer of protection can safeguard your business and prevent countless attacks.
Finally, Multi-Factor Authentication (MFA) is a helpful tool that can be leveraged to improve the security of your school. MFA is a security process that requires you to provide two or more verification methods to access an account or system. By implementing this additional verification step, it becomes more challenging for cyber criminals to gain unauthorised access. One example of utilising MFA is that, before logging into your emails, you will be prompted to verify your authorisation by inputting a code sent to your mobile number. With this additional layer of security, you can deter criminals.
To truly protect your school or college from this threat, we recommend a combination of both methods listed above. This ensures your company is covered from various angles, providing you with multi-layered protection.
You may not be familiar with what a ransomware attack is, but the easiest way to explain it is to liken it to blackmail. Cyber criminals will illegally gain access to your systems, which can be achieved through phishing your employees or students and enabling the cyber criminal to install ransomware software onto these devices unknowingly. Once they have gained access to your systems, the criminals will then encrypt your data and threaten to release it unless you pay a fee.
Now, why would you pay that fee? Cyber criminals can release your data, typically on the dark web, and this can have severe implications for your school. This is because the data you are storing has protected characteristics; the loss of this data will likely lead to significant fines from the ICO. Going beyond the fines, students and families will no longer believe you are a secure organisation, and the reputational damage will be initially devastating and long-lasting. Even if you do give in to the criminals and pay the ransom for your data, there is still a chance that they can leak or sell the data, regardless of whether you pay or not, as they are criminals. In 2025, this threat is prevalent because Artificial Intelligence (AI) has lowered the barrier of entry for committing these crimes.
To prevent a breach like this, it is essential to identify and address your vulnerabilities. Across your IT infrastructure, there are numerous endpoints (laptops, PCs, mobile devices, etc.), with
each device acting as a gateway for a cyber attacker. In recent years, antivirus software has been the primary method for protecting devices; however, in today's digital landscape, that's no longer the case. As big of a threat AI can be to your school/college, it can also help protect it. By enlisting managed detection and response, a tool that combines AI and human experts to scan your device and proactively react to threats in real-time, you can significantly enhance your organisation's protection and reduce the likelihood of a ransomware attack.
One of the most effective ways to protect school systems from cyber threats, such as ransomware, is to ensure that both data and software are consistently maintained. Regularly backing up critical data and storing those backups offline or in a secure cloud environment ensures that institutions can quickly recover in the event of an attack or system failure. Equally important is keeping all software, operating systems, and applications up to date. Cyber criminals often exploit known vulnerabilities in outdated systems, so timely patching is essential to close security gaps. Together, these practices form a strong foundation for resilience, minimising downtime and reducing the risk of data loss.
In 2025, educational technology (EdTech) will be widely used across UK institutions. From virtual classrooms and homework portals to behaviour-tracking apps and communication tools, these platforms have become essential for teaching, learning, and administration. However, with this reliance comes a significant cyber security risk. Many EdTech platforms, especially those adopted quickly or without thorough vetting, may contain vulnerabilities that expose institutions to data breaches or system compromise.
The threat arises when platforms are not built with robust security foundations or fail to comply with data protection regulations, such as the UK GDPR. Some may collect more data than necessary, store it insecurely, or lack proper encryption. Others might integrate poorly with school networks, creating backdoors that cyber criminals can exploit. In some cases, even widely used tools have been found to have flaws that allow unauthorised access to student information or classroom sessions.
To reduce this risk, institutions must be more selective and strategic in their use of EdTech. It's essential to select providers who are transparent about their security practices and demonstrate compliance with relevant data protection laws. Institutions should also be cautious about the permissions they grant to these platforms, ensuring that access is limited to only what is necessary for the tool to function. Keeping all software up to date is equally vital, as updates often include patches for newly discovered vulnerabilities. Finally, conducting regular reviews of all digital tools in use helps ensure that outdated or insecure platforms are identified and removed before they become a liability.
By taking a proactive and informed approach, institutions can continue to reap the benefits of digital learning while safeguarding their systems and the privacy of their students and staff.
Cyber attacks are a threat that no schools, colleges, universities or other educational institutions should overlook. At ITRM, we provide services to secure your business from external threats that are continuously threatening organisations.
Complete the form below to speak with our expert team and start protecting your institution.