Why cyber resilience starts in the boardroom

Why cyber resilience starts in the boardroom

For Australia’s 9,600 schools, cyber risk now sits squarely within school governance, not just IT, with flow-on effects for teaching continuity, financial management, student safety and community trust.

According to Aon’s 2026 Independent Schools Risk Report, cyber risk is the leading concern among participating independent schools in Australia, with one in four schools surveyed experiencing a cyber incident this year – up from one in five schools in 2024.

Fortunately, independent school leaders have been proactively tackling the issue in recent years, with a new report showing that 76% of schools are reporting documented preventative measures to manage cyber risk, up from 66% in 2024.

At the same time, 81% are outsourcing IT functions to third-party technology providers, highlighting the importance of strong cyber governance across both internal operations and external providers.

The questions boards still aren't asking

Lachlan Bowden, practice group leader of education for Australia at Aon, said good cyber governance is about asking the right questions and setting expectations.

"Principals need to work with their IT teams and suppliers to agree clear cyberroles and accountabilities, and make sure risk, not just IT, owns its part of the discussion, as the knock-on effect of downtime and data loss can have significant impacts on schools," Bowden told The Educator.

"Principals should insist on regular, plain English reporting of key risks,incidents and near misses, along with trends and actions."

Bowden said the real test lies in the questions schools aren't yet asking.

"They should also ask more thorough questions about whether critical assets, suppliers and sensitive data are identified and protected," he said. "This goes both ways for risk and IT, by ensuring cyber risks areembedded in business decisions and change management within schools."

Assurance matters more than cost

As more schools hand over the day-to-day running of their IT systems to outside providers, a harder question is emerging for school leaders: when something goes wrong, who's actually left holding the risk? For Bowden, the answer isn't as simple as boards might like to think.

"Outsourcing IT never outsources accountability," he said. "Even where a third party runs most systems, the Principal and board remain responsible for safeguarding students,staff, and the school’s operations."

Bowden said that while third parties can help manage cyber risk, they cannot absorb the reputational, regulatory or educational impact of an incident.

"Many boards still focus heavily on cost and functionality and not enough on assurance, includinghow risk is shared in contracts, what testing and oversight exist, and how quickly the school can detect, respond and recover," he said.

"Strong governance means regularly challenging providers, validating controls independently, and treating cyber resilience as a corestrategic risk."

The playbook nobody's rehearsed

There's a difference between preventing an cyberattack and surviving one, says Bowden. When he's asked what Principals are least ready for, his answer has less to do with servers and software than most would expect.

"Most Principals would discover they’re not prepared for the human impact of a live incident," he said.

"Technical teams may know how to contain an attack, but leadership isoften under prepared for decisions under pressure, particularly what to shut down, who has authority to act, and how to communicate with parents, staff, regulators and the media in real time."

Ultimately, said Bowden, Principals may find that contact details, offline plansand manual workarounds are incomplete or untested.

"In practice, the biggest gap isn’t the loss of critical systems, it is ensuring they have a rehearsed incident playbook that has been walked through, challenged and clearly owned across the school."