Securing student data against cyber attacks

Wednesday, 30 November, 2022

Securing student data against cyber attacks

Increasing cyber attacks on educational institutions have had significant implications for teaching and data protection.

To help combat the impacts of cyber attacks, Catholic Education Western Australia (CEWA) has implemented the Tenable Vulnerability Management and Tenable Active Directory Security across its network of schools and colleges.

CEWA, a not-for-profit organisation with over 100,000 students and employees across 149 schools and colleges, consulted with industry analysts following a consolidation exercise. During consultations, Tenable was highly recommended as the solution to help the organisation step up its vulnerability and exposure management efforts.

“Not only is student data commonly targeted because of its value to cybercriminals for conducting fraud, but students are often less vigilant about monitoring and controlling their online activities, which makes them especially vulnerable to being victims of identity theft and fraud for longer periods of time before taking action to protect themselves,” said Lee Swift, Chief Information Security Officer, CEWA.

“Having the security function of the 149 schools across our system consolidated into a central platform promotes collaboration. However, it also means the impact of a cyber attack can ripple across other parts of the organisation. Ensuring that security was embedded across every function of CEWA and making sure that student and employee data were protected is vital to maintaining the faith and trust of the communities we serve.”

With the high-volume usage of thousands of connected devices such as smartphones, web cameras and Apple TVs, having visibility over such a huge footprint can be challenging. Since deploying Tenable.io, the security team has been able to run automated scans without the need for agents, and has full visibility across 17,000 assets. The entire assessment to remediation process has also been streamlined by leveraging Tenable’s predictive prioritisation capabilities, which yields a Vulnerability Priority Rating (VPR) score that combines vulnerability information, threat intelligence and data science to predict which vulnerabilities will likely be exploited. With more predictability and less guesswork, CEWA is able to focus on the vulnerabilities that need to be remediated first based on actual cyber risk.

“We have a responsibility to ensure that students entrusted into our care are learning in environments which are safe. Ensuring that our cybersecurity policies and platforms are of the highest standard across our 149 schools is critical to protecting student data and ensuring they use technology safely,” said Dr Debra Sayce, Catholic Education WA, Executive Director.

Given that identity is central to authenticating users and providing access to network resources, Tenable Active Directory Security is critical to helping CEWA identify any misconfigurations and prevent any attack paths that attempt to leverage Active Directory.

“Prior to using Tenable Active Directory Security, we were only using Microsoft Security Suite and running point-in-time assessments. The ability for Tenable to enhance what we are working with and make our approach to cybersecurity more proactive has been a real differentiator,” Swift said.

Effective analytics and reporting

CEWA’s cybersecurity program has quickly become the cornerstone for a more holistic and proactive approach to cybersecurity across the organisation. In addition to running weekly vulnerability reports, Swift’s team also presents quarterly to CEWA’s risk committee.

“I’m now able to have open and transparent conversations with our leadership team and board of directors about the good, the bad and the ugly and the resources needed to strengthen our risk posture. Tenable makes these conversations easier and helps us understand risk better as an organisation,” Swift said.

Having an effective vulnerability management program has freed up resources for Swift and his team to also work on enhancing CEWA’s Cyber Culture program, which helps students and employees understand their role in cybersecurity.

Image credit: iStock.com/Peach_iStock

Related Products

  • All content Copyright © 2024 Westwick-Farrow Pty Ltd