The one-size-fits-all approach to cybersecurity isn’t fitting all  

The one-size-fits-all approach to cybersecurity isn’t fitting all  

Ram Vaidyanathan, Chief IT Security Evangelist at ManageEngine, discusses how as our learning environments become more sophisticated, so do the threats. Cybersecurity is no longer just about protecting a few databases behind a firewall. It’s about securing the vast and growing ecosystem of tools, devices and AI applications used by schools and universities on a daily basis.  With every new layer of technology, the attack surface expands. And yet, many educational institutions still rely on a one-size-fits-all approach to cybersecurity. And that one-size-fits-all approach, isn’t fitting all.

Just a few years ago, many of us were struggling to manage the dreaded, mundane tasks that form a large portion of our professional lives. This included tasks like manually collecting data for writing reports, sifting through endless online articles for research or spending hours trying to troubleshoot IT systems. Today, ChatGPT and other AI tools are able to do most of the heavy lifting. It is making our lives considerably easier.   

Tasks that used to take hours now take minutes. We are less inclined to procrastinate writing an email when we have ChatGPT at our fingertips to do the jobs we don’t want to do. Professionals can summarise long reports in seconds, students can more easily research and reference work and IT teams can automate repetitive processes with a few clicks. This has happened over the space of a couple of years, and the possibilities are endless (and unknown).  

Our digital capabilities are constantly evolving, and the education sector is no exception. Schools and universities are already starting to embrace cutting-edge tools like Virtual Reality (VR) and intelligent learning platforms. The recent Digital Landscapes in Australian Schools 2025 report found that ‘78.2% of survey respondents report active use of AI education tools, a striking leap given that AI was rarely mentioned in the 2023 study’.  

But as our learning environments become more sophisticated, so do the threats. Cybersecurity is no longer just about protecting a few databases behind a firewall. It’s about securing the vast and growing ecosystem of tools, devices and AI applications.  With every new layer of technology, the attack surface expands. And yet, many institutions still rely on a one-size-fits-all approach to cybersecurity. 

This mindset is outdated and dangerous. 

The false comfort of ‘good enough’ 

Assuming your current cybersecurity systems will ‘do the trick’ is a complacent one-dimensional view. Much of the infrastructure cybersecurity defences are built around relies on technologies that are now five or more years old. And yet, many organisations assume they will suffice. However, with AI advancing at warp speed, we can no longer assume that yesterday’s cybersecurity protocols can keep pace with today’s modern technology.  

The lack of appropriate security measures in place is reflected in the data. In the 2022 to 2023 financial year alone, the Australian Signals Directorate, a key member of Australia’s national security community, received nearly 94,000 cybercrime reports, with the education sector being one of the top targets.   

Cybersecurity isn’t as simple as installing the latest antivirus software or rolling out firewalls and hoping for the best. This type of strategy leaves critical vulnerabilities exposed, particularly in an era of AI, VR and cloud-based learning.  

Just because you haven’t yet fallen victim to an attack doesn’t mean your defences are sound. 

The real question: Is your security working for the environment we are in today and the environment of tomorrow?  

Tailoring security  

With more data being generated and stored in the cloud, often across multiple platforms, educational institutes need cybersecurity solutions tailored to their specific requirements and environments. For instance, the needs of a major university with thousands of remote students are vastly different from those of a small high school with an on-premises system.  

This is where an adaptive and layered approach to security becomes a crucial asset for organisations of all types. Adopting integrated solutions is key for monitoring threats in real-time, detecting anomalies and automatically responding to breaches. By focusing on endpoint protection, like implementing role-based access control and multi-factor authentication, organisations position themselves for long-term safety.   

More importantly, visibility is key to protection – you can’t protect what you can’t see.   

With more work from home arrangements and off-site learning in the education sector, IT teams need to be able to monitor the safety of these applications. This means employing security systems that have visibility of devices, user behaviour and system access. This enables faster response times and smarter decision-making while reducing the risk of threats.   

Balancing innovation with responsibility 

Technology has opened new possibilities in education, from interactive digital classrooms to personalised learning paths that provide additional teaching support. However, with innovation comes a greater level of responsibility. Institutions have a duty to protect their communities and themselves – not just from cyberthreats, but also from data misuse, algorithmic biases and breaches of trust.  

For instance, a student might be using an AI tool to spell-check an essay. Without the appropriate safeguards, this data may be repurposed or shared across networks without consent. Privacy and security concerns like these highlight the need for strong digital governance and security.   

The good news? Awareness around the importance of cybersecurity is growing alongside investments. A 2023 study found that 74% of Australian business leaders were planning to expand the budget for cybersecurity in 2024, while in 2023, only 60% planned to expand this budget. Likewise, the education sector is strengthening its defences across universities through initiatives such as the Australasian Higher Education Cybersecurity Service.  

While the news of cybersecurity budget increases is promising, the investments should be backed by a clear strategy from organisations. As the saying goes, ‘money can’t buy you happiness’, and in this instance, money cannot buy you ultimate safety. It requires many moving parts to come together –education, investment and up-to-date security systems.  

The path forward is a culture of cyber awareness 

Ultimately, the best positioned organisations and institutions won’t be those with the latest software – it will be those with an agile mindset. AI is here to stay – and if the past few years are any indicator, the next game-changing technology is just around the corner. Everyone needs to be more vigilant and aware of potential dangers and their role in stopping them. This means better education, clear boundaries, open dialogue and a robust defence system to back it up.   

There’s no doubt that technology is a powerful enabler, but it must be adopted responsibly and safely.  

Browse our latest issue

Intelligent Edu.tech

View Magazine Archive