Cybersecurity education: Students work on their own laptops in an open learning environment at a Dutch university of applied sciences.

Cybersecurity in Education: Open Systems, Limited Budget, High Risk.

Cybersecurity education requires making choices that are more critical than in any other sector. By definition, an educational institution must be open: thousands of students log in using their own devices, researchers share data with partners around the world, and instructors switch between systems depending on the course they’re teaching. At the same time, the budget is tied to a funding model that leaves little room for a ten-person security department. This combination of maximum openness and minimal resources makes cybersecurity education a field unto itself. SURF’s “Cyber Threat Landscape for Education and Research 2025” report shows that DDoS attacks, malware, and phishing remain the greatest risks for institutions, with disruption of educational processes, system outages, and reputational damage as recurring consequences.

Why the threat landscape in education is different

A bank can decide who is allowed in. A college cannot. Every academic year, a new cohort arrives with their own laptops, their own phones, and their own habits, and after three to four years, they leave. The student body is constantly changing, which means that every investment in behavioral aspects of cybersecurity education must be made anew. This is a structural characteristic of cybersecurity education, not a temporary problem that you can solve once and for all.

In addition, its attack surface is broader than that of most organizations of comparable size. A university operates student records systems, scheduling systems, digital learning environments, research clusters with computing capacity, library systems, and often also building management and access control systems. Research data, in particular, has its own risk profile: it consists of results that represent years of work and may be of interest to foreign parties. A security team that takes cybersecurity education seriously therefore looks not only at the student environment but also at the research chain. That broader perspective distinguishes cybersecurity education from a standard office environment.

The sector does have something that other industries lack: organized mutual assistance. For more than thirty years, SURFcert has served as the incident response team for Dutch education and research institutions, offering 24/7 support for security incidents, sharing indicators of compromise, and helping institutions set up their own response teams. This sector-wide support lowers the barrier to entry but does not take over the work. Anyone who calls must be able to explain what is going on.

The budget problem is, in reality, a capacity problem

Organizations usually blame their security gaps on a lack of funding. But when you look at the reality on the ground, it’s more often a matter of people. Budget has indeed been allocated for tools, but there’s no one to interpret the alerts. A SIEM that no one reads is just an expensive log server—and that’s just as true in cybersecurity education as it is elsewhere. An EDR solution with alerts set to “accept” by default simply shifts the risk to a dashboard that no one opens.

This dynamic isn’t unique to cybersecurity education, but it’s particularly persistent in this field because procurement processes make it easier to secure funding for a product than for a role. We see the same pattern in organizations struggling to build cybersecurity capabilities on a tight budget: the temptation is strong to buy what’s visible, while the real return on investment lies in the people who operate it. A well-thought-out balance between people and tools almost always yields greater detection capabilities while maintaining the same budget.

There is another reason why cybersecurity education rarely takes precedence over other budget priorities. Security does not yield visible educational results. A new lab can be officially opened with a ribbon-cutting ceremony, but a well-functioning detection process cannot. Anyone seeking support from the board of trustees will therefore need to frame the discussion in terms of the continuity of the core academic process: how many classes would be canceled if the digital learning environment were down for a week, and what would that mean for the academic progress of 15,000 students?

A workable model with a small team

Most organizations do not have a SOC and do not plan to build one. Nor do they need to. What is possible, however, is a layered model in which a small core of in-house staff handles the tasks that only they can perform, while the rest is deliberately outsourced. In cybersecurity education, that core typically consists of two or three people who know their own environment inside and out: which systems are critical, what traffic is normal during exam weeks, and where the research data is stored.

That knowledge can’t be bought. An external party doesn’t know that peak load on the registration system is normal in August but suspicious in March. That’s exactly why the trade-off between outsourcing and building in-house capacity in education often results in a hybrid model: monitoring is handled externally, while interpretation and decision-making take place internally. To provide that interpretation, however, you need someone with analytical skills—and that’s usually not the system administrator who also handles security.

In practice, it works well to train an existing administrator to become an analyst rather than hiring from outside. Someone who already knows the organization has an advantage that no job posting can buy. A program like the SOC T1 + T2 Analyst training takes that person from administrative tasks to structured triage and investigation, while preserving their knowledge of the organization. For organizations looking to make the transition to independent investigation, the SOC T3 Analyst training program is the logical next step. Our article on building your first security team details how to assign the roles involved.

Student Accounts and BYOD: Control Rather Than Manage

The idea of managing students’ devices has been abandoned at virtually every institution. What remains is the question of how to configure the network so that an infected device does not become a springboard for further infection. In cybersecurity education, segmentation plays the biggest role here: student traffic should not be on the same segment as the financial administration or the research environment, and that principle can usually be partially implemented using existing network equipment.

Account management is the second pillar. Educational institutions experience an exceptionally high turnover in accounts, and that is precisely where the gaps arise: graduates who still retain access, guest lecturers with an account from 2019, and research staff who move from project to project. A rigorous process for revoking access rights provides greater security than many products available on the market. This is the least exciting aspect of cybersecurity education and, at the same time, the one that yields the highest return per hour invested.

Phishing remains the most common entry point for attackers, and in the education sector, the likelihood of success is high due to the size and turnover of the target audience. Awareness efforts are only effective if they go beyond an annual mandatory module—something we discussed earlier in our article on why security awareness training often fails. For teachers and support staff, targeted cyber awareness training is more effective than a one-size-fits-all campaign, because the scenarios are tailored to the work people actually do.

Preparing for the Incident That Will Eventually Happen

No organization can avoid a serious incident in the long run, no matter how well its cybersecurity training is organized. The question is whether the team will know what to do when it happens. In its guide to incident response planning, the NCSC outlines six steps: assigning roles, conducting a risk analysis, describing scenarios, setting up a reporting channel, communicating the plans, and then continuing to practice. That last step is the one most often overlooked, and that is precisely where the difference lies between a plan on paper and a team that takes action.

Drills don’t have to cost an external firm. A tabletop exercise involving the relevant administrators, a communications advisor, and a member of the board can reveal within two hours where the decision-making process is stalling. Our playbook for incident response drills provides a framework for this that can be implemented without a budget. Organizations that also want to be able to conduct their own digital forensics investigations—for example, because investigative data is involved—benefit from having in-house forensic expertise; the Cyber Forensics Expert training program focuses on precisely that skill.

The ultimate cost of an incident is rarely calculated in advance. Yet that figure is what changes the conversation with management, because it contrasts the investment in cybersecurity education with an amount that actually appears in the budget.

Our overview of the true cost of a cyber incident details the calculation method you can use for this purpose.

From Isolated Measures to Built-Up Capacity

The institutions that have truly made progress in recent years have one thing in common: they have stopped chasing after isolated measures and have started investing in people. This is the same shift we described for the healthcare sector, where smart training works fundamentally differently due to the continuity requirements of the primary process. Education has a similar dynamic: the schedule continues as usual, even during an incident.

Building capacity starts with asking yourself which roles you want to be able to fill in-house in three years. For most colleges and universities, there are two: someone who handles detection and triage, and someone who adapts security policies to the institution’s specific environment. Both roles can be trained internally using existing IT staff. The page for employers explains how such a training program is structured, ranging from open-enrollment classes to a fully in-house program using the organization’s own tools. If you’d like to see what levels are available first, the page listing all training programs offers the full range from beginner to expert, including the comprehensive Cyber Security Specialist program for employees transitioning from other IT roles.

Cybersecurity education isn’t improved by more products, but by people who understand their own environment and know what they’re seeing. That’s the only investment in cybersecurity education that continues to yield a return even after a procurement cycle ends, because knowledge remains within the team while licenses expire.

Would you like to know which program is best suited to the size and level of maturity of your institution? Check out the upcoming start dates or schedule an introductory meeting to discuss the options.