How Can Schools Trust the Privacy of Education Technology?
I’m always fascinated by the fact that some of the world’s largest organizations often appear to respond to catastrophic disruptions by effectively using “alternative” cybersecurity practices and hoping for the best.
Picture this: You’ve been hacked not once, not twice, but three times by an established criminal group with a solid track record of stealing billions of sensitive data records and paralyzing global retail giants, multinationals, major IT companies, luxury brands, travel companies and key parts of the world’s supply chains.
At this point, it’s worth asking: what exact cognitive process leads to the decision to antagonize such a nefarious entity by completely ignoring them and placating the public with assurances that everything will be just fine? Was it a dare? Did they mean to poke the bear?
As reports that some of the 9000 schools across 100 countries started reaching out to the ShinyHunters extortion group to strike up some kind of side deal, the Canvas/Quercus platform magically came back online.
Regaining access to a system that has become a central point of failure for so many schools must be a major relief, but what about the data stolen from a quarter of a billion students?
While the current calamity reminds people of the harms of misplaced trust in edtech, others remember that the generational impact of shameful breaches like those of PowerSchool, Edmodo, Illuminate, Blackbaud, UnAcademy and many others was due to little more than hubris.
Too harsh?
Even administrators with a disdain for basic information security hygiene will agree that prevention often takes little more than:
‣ treating API security and cloud platforms as critical infrastructure
‣ isolating, segmenting and siloing user databases so the next breach doesn’t result in the loss of every piece of data you’ve got
‣ banning the practice of sharing cloud admin keys and adopting least privilege access
‣ avoiding the exposure of admin logins to the big bad untrusted medium that we collectively call the Internet
‣ auditing admin credentials and even rotating them from time to time
‣ actually testing your incident response procedures before disaster strikes!
As for those who should be accountable for due diligencing platforms entrusted with the data of other people’s children, consider how brave and competent you will look when you take an uncompromising stand on:
● raising the risk profile of companies that start their pitch with “numerous large organizations depend on us”
● strictly blocking your entire cloud supply chain from using any data, including metadata, statistical usage logs and all academic info without an absolute and precise need-to-know
● enforcing data minimization and showing zero tolerance for preserving most student data from one year to the next.
Crazy talk?
Perhaps, but the disciplined adoption of solid infosec practices might have prevented the loss of some 900 million records over the past decade and eliminated the spectre of future victimization.
