
In the past four months, two major breaches have laid bare the risk that Australia’s schools are taking amid their rush to digitise their classrooms.
On 3 September, a data breach at Australian-founded learning platform Mathspace exposed personal information belonging to more than 1 million students, parents and school staff across Australia and New Zealand, with the company confirming attackers exploited a critical software vulnerability that sat unpatched for more than three weeks.
The incident follows the Canvas breach on 6 May, which exposed more than 275 million student and teacher records across 9,000 institutions in 41 countries – including Australia.
New research from cybersecurity company Arctic Wolf has found that nearly 10% of publicly disclosed software vulnerabilities published so far this year, around 3,000 in total, were still awaiting final formal analysis. Put simply, the people meant to be plugging the holes are being forced to decide what to fix first without the full picture.
Complicating matters, UNSW researchers recently found that hundreds of educational apps recommended by Australian state education departments pose privacy and security risks, including collecting sensitive information and transmitting data to third parties.
In April, a UNSW-led audit of nearly 200 school-endorsed apps found most begin harvesting children’s data within seconds – often contradicting their own privacy policies and exposing gaps in oversight by education systems, app developers and regulators.
So, it begs the question: who exactly vets the apps being used inside Australia’s classrooms?
Rather than a single national regulator, vetting is done through a patchwork of state, sector and voluntary bodies, underpinned by a national assessment framework that most – but not all – of schools plug into.
Trust shouldn't hinge on the provider
Jason Duerden is Area Vice President ANZ at SentinelOne, which works with schools and higher-education institutions across Australia to protect student data, staff and digital learning environments.
He says a child should not receive weaker protection because their data has moved from a school system into a private provider’s database.
“Australia needs one minimum security standard for every classroom platform, regardless of who operates it,” Duerden told The Educator. “It should limit what student information can be collected, require providers to disclose where it is copied, and set enforceable deadlines for critical updates, breach notification and deletion.”
Duerden said schools also need proof that those obligations are being met.
“A contract that cannot be checked until after children’s data is stolen offers very little protection,” he said. “That verification should happen centrally through education departments or independent assessors, rather than expecting every principal to audit technology suppliers.”
Duerden said until a national standard exists, education organisations can use the Essential Eight or SMB1001 as a practical baseline and ask suppliers to demonstrate the same alignment.
“Parents do not care which privacy regime applies, when it is their child’s identity and safety at risk.”
How a risk-based approach can help
Steve Hunter, Director of Engineering (APAC) at Arctic Wolf, said the Mathspace incident highlights how difficult it can be for organisations to keep on top of software vulnerabilities.
“With so many new security issues being identified, the challenge is working out which ones pose the greatest risk and need to be fixed first,” Hunter said, adding that rather than playing ‘Whack-a-Mole’ every time a new vulnerability appears, organisations need to take a more risk-based approach.
“Consider whether a vulnerability is already being exploited by attackers, whether the affected system is exposed to the internet, what information it holds or can access, and the potential impact if it is compromised.”
Hunter said this is particularly important in the education sector, where schools, universities and education technology providers can hold large volumes of information relating to students, parents, teachers and staff across a wide range of systems and third-party platforms.
“The priority should be knowing what systems and software you have, understanding where the biggest risks sit, and having a clear process for acting when a critical security warning comes through,” he said.
“It’s not about trying to patch everything at once but making sure the most serious risks don’t get lost in the noise.”
The Educator has contacted Education Services Australia for comment.