Sector research identifies the drivers of education risk consistently: student data sensitivity, identity controls, cloud and SaaS permissions, vendor access, district staffing, university decentralisation, backup maturity and incident response readiness.
Read that list against the files this desk has published — PowerSchool in 26-0113, Instructure in 26-0501, Nottingham in 26-0518, McGraw Hill in 26-0414 — and the pattern is not that education is careless. It is that the sector was handed a hard problem without the means to address it.
Sensitivity Is Unusually High
Education holds records on minors, special educational needs assessments, safeguarding notes, family circumstances and financial aid information. Very little of it can be minimised, because the institution needs it to do the job.
It is also permanent in a way commercial data is not. A safeguarding record describes something that happened to a child and cannot be superseded by them changing supplier.
Capacity Is Unusually Low
Districts run small teams focused on keeping devices working. Universities are federated by design, with faculties procuring independently and holding their own copies. Neither structure supports a central security function with authority, and neither is going to be reorganised for security reasons.
The Honest Conclusion
Most of our sector files end with a control an organisation could implement. This one does not, because the gap is structural and larger than any institution in it.
What would actually shift the numbers is funding attached to the obligations already imposed, and pooled capability across institutions that cannot each build their own. Both are policy decisions rather than security decisions, and neither is currently being made.
This is an analysis file built on published sector research, listed below, read against files previously published by this desk. The conclusions are ours and are labelled as such. Corrections: corrections@forensicpost.com.