Post

Beyond the Essential Eight: cybersecurity governance for Australian schools

Featured photo by CDC on Unsplash.

A school does not exist to achieve a cybersecurity maturity score. It exists to educate students, support their wellbeing and serve its community.

That sounds obvious, but it changes where a cybersecurity strategy should begin. Before choosing a framework or buying another security product, school leaders need to understand what the organisation is trying to achieve, which information and services it depends on, and what could interrupt or undermine those outcomes.

Australia’s Essential Eight provides an important baseline for strengthening security. A school also needs a way to make decisions about risk, assign responsibility, prioritise investment and establish whether its protections actually work.

The school’s purpose should sit above the cybersecurity framework. That is the connection I would want to see in any school cybersecurity strategy.

Start with what the school needs to deliver

Consider three ordinary school priorities: reliable teaching and learning, student wellbeing, and responsible use of new technology.

Each depends on information and systems. Learning platforms need to remain available. Wellbeing records need to be accurate and accessible to the right people. New tools need to offer educational value while handling information appropriately.

The consequences of a failure reach beyond the technology team. An unavailable attendance system affects daily operations. Unauthorised access to pastoral records can harm students and families. A compromised finance account can interrupt payments and damage trust.

Schools also have a demanding mix of users and services: students joining and leaving, relief staff, contractors, family portals, personally owned devices and cloud platforms. Controls have to work within that environment, with staff who need to get on with teaching.

I would therefore begin with a small set of questions:

  • Which services and information are essential to learning, wellbeing and daily operations?
  • What would happen if they became unavailable, were disclosed or could no longer be trusted?
  • Who can decide how much disruption or exposure is tolerable?
  • What evidence would show that the most significant risks are being managed?

Those answers give security work a purpose and help explain why one investment should take priority over another.

Put cybersecurity inside the school’s risk framework

The diagram below shows the relationship I have in mind. School purpose informs strategic objectives. Those objectives shape the enterprise-risk discussion, which includes cyber and information security risk alongside financial, people, safety and other operational risks.

School cybersecurity strategy hierarchy: school purpose leads to strategic objectives and enterprise risk; cyber and information risk then informs security strategy, NIST CSF 2.0, controls and standards, and projects and operations. An example of connecting school purpose to the cybersecurity program. NIST CSF 2.0 is one possible organising framework; the diagram is a planning model, not a mandatory structure.

Read down the diagram and each layer should explain the one beneath it. A project to strengthen administrator access should trace back to a risk, such as compromise of the systems needed to run the school. The risk should trace back to an organisational objective.

Information also needs to travel back up. Recovery exercises, incidents, control assessments and supplier reviews should change leadership’s understanding of risk. The diagram shows the planning hierarchy; governance needs that continuing feedback loop as well.

A useful test is to take any major security project and ask: which school outcome does this protect, who owns the associated risk, and how will we know the investment has helped?

Where the Essential Eight fits

The Australian Signals Directorate (ASD) recommends the Essential Eight as a baseline of mitigation strategies that makes systems harder to compromise.

Its explanation of the eight strategies covers patching software and operating systems, stronger authentication, limiting administrative access, controlling applications and Office macros, hardening user applications, and maintaining backups. ASD describes their intended setting as internet-connected IT networks.

These are worthwhile foundations. They deserve implementation, maintenance and assessment, with clear scope and evidence behind any maturity claim.

The governance question is what surrounds them. Someone still has to decide which services must recover first, who may accept a supplier’s limitations, who leads an incident, and how staff should handle sensitive information. A maturity result alone cannot settle those decisions.

For example, a school might have a sound backup arrangement but discover during an exercise that nobody has agreed how long it can operate without its student administration platform. The technical control and the operational decision need to meet.

My reading is that the Essential Eight should sit within a broader program covering accountability, information handling, suppliers, people, detection, response and continuity. A successful assessment is useful evidence within that program. Leadership still needs to understand the risks that remain.

Use a framework to organise the work

NIST’s Cybersecurity Framework 2.0 is useful here because it is intended for organisations of different sizes and sectors. Its addition of Govern gives explicit attention to leadership decisions and cybersecurity’s place within enterprise risk.

I would translate its six Functions into school questions like these:

FunctionA question for school leaders
GovernWho is accountable, what risks are acceptable, and who makes decisions?
IdentifyWhich information, services and suppliers do we depend on?
ProtectWhich safeguards do those dependencies need?
DetectHow will we recognise an incident, including outside school hours?
RespondWho can contain it, coordinate decisions and communicate with families?
RecoverHow will we restore priority services and sustain school operations?

This gives the principal, business manager and technology team a shared set of questions for reviewing the program.

NIST also provides Current and Target Profiles to describe existing and desired cybersecurity outcomes and compare the gaps. For a school, that can become a practical improvement roadmap: what is in place, what needs to change, who will do it and when.

I would keep that roadmap proportionate. A small school needs something its leadership team can maintain, with responsibilities shared appropriately with its system authority or service providers. A larger organisation may need more formal reporting and assurance. In either case, the chosen structure should make decisions easier to explain and follow through.

The frameworks have different jobs

The choice does not have to become a contest between NIST, the Essential Eight, the ISM, CIS and ISO. They serve different purposes, with some overlap.

ReferenceWhere it can help a school’s program
NIST CSF 2.0Organise cybersecurity outcomes, connect them to governance and communicate improvement priorities.
ASD Essential EightEstablish and assess a focused baseline of mitigation strategies.
ASD Information Security Manual (ISM)Provide more detailed security principles and guidance, applied through the organisation’s risk-management process.
CIS Critical Security ControlsHelp prioritise practical safeguards and implementation work.
ISO/IEC 27001:2022Establish and continually improve an information security management system.

ISO/IEC 27001 has a distinct management-system role, which is why I would discuss it alongside the overall program rather than treat it as another technical checklist. ISO also explains that organisations can implement the standard without choosing certification.

A sensible approach is to use a clear organising model, then draw on the implementation guidance needed to address the school’s risks. Maintaining several overlapping spreadsheets is only useful if they lead to better decisions or evidence.

Make ownership visible

The school needs to know who can make each kind of decision. I would make that explicit in the strategy and incident arrangements, adapted to the school’s actual governance structure.

The governing body or relevant system authority needs oversight of material risks, priorities and assurance. The principal and executive need to allocate resources, set operational priorities and make risk decisions within their authority. IT and security specialists need to advise, implement, monitor and escalate.

Business and information owners matter too. The person responsible for student wellbeing helps determine who should access pastoral information. Finance helps define payment controls. Teaching leaders help assess how a restriction will affect classroom practice.

A service provider can operate controls and supply evidence. The school still needs an identified person who reviews that evidence, follows up gaps and escalates decisions that exceed their authority.

For each significant risk, I would want a named owner, an agreed treatment, a review date and a record of who accepted any remaining exposure. That makes the program easier to sustain when staff change.

Put the approach to work

Take a hypothetical school that wants more reliable access to digital learning and administration.

One risk is that compromise of an administrator account allows an attacker to disrupt several core services. The assessment finds inconsistent separation of administrative accounts and limited evidence that critical services can be restored within the time the school needs.

The response could combine stronger privileged access, better monitoring and a recovery exercise. Those activities belong together because they address the same organisational risk.

Leadership can then ask for evidence that administrator accounts meet the agreed standard, alerts reach someone able to act, and a realistic recovery test meets the agreed recovery time. If the exercise fails, the remaining gap needs an owner and a decision about further work.

That is a stronger basis for investment than a proposal that begins and ends with buying a product.

Responsible AI adoption offers another example. A school might want staff to use AI to reduce administration or prepare learning resources. The Australian Framework for Generative AI in Schools provides national guidance on responsible and ethical use for the school community.

Applying the same governance approach, I would ask what the proposed use achieves, what information it involves, how the supplier handles that information, and who checks the outputs. Approval could then carry clear conditions: suitable tools, information-handling rules, staff guidance, human review and a way to report problems.

Security contributes to making the educational opportunity workable. The decision requires teaching, leadership, privacy and technology perspectives together.

Give leadership evidence it can act on

Operational teams need detailed technical measures. Leadership needs those measures connected to consequences and decisions.

For a regular governance report, I would focus on:

  • Material risks: what has changed, which risks exceed agreed tolerance, and who owns them.
  • Critical services: what recovery testing demonstrated and where continuity gaps remain.
  • Control effectiveness: what assessments found, including the scope and exceptions behind maturity claims.
  • Response readiness: whether the right people could act during an exercise or real incident.
  • Decisions required: overdue treatments, supplier concerns and resources needed to reduce exposure.

A report that says backups completed successfully answers an operational question. A report that explains whether the school restored a critical service within its agreed recovery time gives leadership evidence about continuity.

Both have a place. The connection between them makes assurance useful.

A practical starting point

I would begin with a leadership conversation about the school’s most important services and information, supported by the people who operate and use them. Record the significant risks, agree ownership and decide which outcomes need improvement first.

Then map the current program against a framework, identify the most consequential gaps and build a manageable roadmap. Give each action an owner, a due date and a measure of success. Bring the results of testing and incidents back into the next review.

This can start while technical improvements continue. Urgent patching, stronger authentication and recovery work should proceed as the broader program takes shape.

The Essential Eight remains a valuable foundation. Its value increases when the school can explain what those controls protect, how they fit with its other safeguards and what risks still need attention.

The purpose of school cybersecurity is to help the organisation keep educating students, supporting their wellbeing and earning the community’s trust. A strategy should make that purpose visible all the way down to the work being done.

This post is licensed under CC BY-NC-ND 4.0 by the author.