Why the start of the new school year is an IT security event
![[Translate to English:] [Translate to English:]](/fileadmin/securepoint/allgemein/news/blog/2026/20260818-blog-schuljahreswechsel-als-it-security-ereignis.jpg)
At the start of the school year, schools face a number of IT risks: outdated accounts and permissions, unpatched devices and new personal devices present challenges for IT managers.
From an IT security perspective, the start of a new school year is a critical event. Every change in personnel, roles, devices and responsibilities alters a school’s digital attack surface. User accounts that are not deactivated, permissions that have accumulated over the years, unpatched end devices or unclear lines of responsibility can put sensitive data at risk.
This situation is particularly sensitive in the education sector. Schools process personal data of minors, contact details of parents or guardians, and internal administrative documents. At the same time, a wide variety of user groups come together there; for example, pupils, teachers, administrative staff, school social workers, external service providers, supply staff and school authorities.
The start of the new school year is therefore also a key date for reviewing the entire user lifecycle!
Why the user lifecycle is so important for security in schools
The user lifecycle describes all the stages of a digital account: creation, role assignment, use, modification, suspension and deletion. In businesses, this process is often referred to as Identity and Access Management. In schools, it is at least as important, but is often less formalised.
An account is usually created when a person joins the school and is granted access to email, Wi-Fi, learning platforms, file storage, digital classrooms or administrative applications. Over time, however, responsibilities and roles may change: pupils move to different classes or courses, teachers take on new subjects, fixed-term contracts come to an end, and external staff join the school.
The problem is that, in many environments, new permissions are granted more quickly than old ones are revoked. This leads to a creeping expansion of permissions. A user account becomes more powerful with every school year, even though the original responsibilities have long since ceased to exist. This is precisely where an invisible security vulnerability lies.
From an IT security perspective, the principle of least privilege therefore applies: each person should only be able to access the systems, data and functions that they actually need for their current task. Whilst this principle is not always convenient in day-to-day school life, it is necessary to limit misuse, unauthorised access and data breaches.
Accounts of former or temporary teaching staff that have not been deactivated
At the start of the new school year, teachers leave the school to take up posts elsewhere, retire or complete a fixed-term contract. New supply teachers are granted access at short notice to timetables, class information, learning platforms, teaching materials and communication channels.
In both cases, security risks arise if user accounts are not consistently linked to the actual duration of employment.
- Former staff members could continue to access emails, pupil data, internal documents or cloud storage. Even if there is no malicious intent, unnecessary access remains a data protection and security risk. This is because any active account can be compromised, misused or targeted by phishing attacks.
- Under time pressure, supply teachers are sometimes granted more extensive permissions than would be necessary for their role. This is particularly critical when standard accounts with broad access rights are copied, or when temporary access accounts do not have an expiry date.
It makes sense to use individual, time-limited accounts whose access rights are tailored to the specific task at hand. Access for supply staff should have a fixed expiry date and be deactivated no later than their final day of work. In the case of teachers leaving the organisation, active sessions should be closed, access permissions removed, shared login details changed, and work-related files organised and handed over.
It is important to have a mandatory process: changes in staffing must automatically trigger a review of all digital access rights. This includes not only central school accounts, but also email, learning platforms, video conferencing systems, cloud storage, apps, Wi-Fi access and administrative services.
Shared passwords and shared functional accounts
Shared accounts are practical in day-to-day school life. An account for the specialist classroom, a password for tablets, access for the school office, an account for digital whiteboards or a shared login for supply teaching teams may seem to save time at first.
From a security perspective, however, such accounts are problematic. If several people use the same password, it is almost impossible to trace later who opened files, changed settings, exported data or passed on information. The traceability of actions is a key component of IT security and data protection.
Furthermore, shared passwords often spread unchecked. They are written on sticky notes, sent via messaging apps, stored in emails or passed on verbally. If a person leaves the school or changes their area of responsibility, every known shared password would need to be changed. In practice, this is precisely what is easily overlooked.
Personal accounts with individually assigned roles should therefore be the standard. Functional accounts should only be used where they are technically or organisationally unavoidable. For such exceptions, there must be clearly defined points of responsibility, secure password management, regular password changes and logging of relevant activities.
Particularly sensitive areas should be given additional protection, for example through multi-factor authentication (MFA), separate authorisations or restricted access areas. This applies in particular to administrative data, marks, pupils’ personal data and systems with administrative rights.
Devices after the holidays: unpatched, offline or incorrectly configured
After the summer holidays, two risks converge in school networks. On the one hand, many school devices have been switched off for several weeks and have missed important security updates. On the other hand, new personal smartphones, tablets or laptops, whose security status is unknown, may enter the school network.
School devices should therefore be updated and checked before the first day of term. This does not just apply to operating systems – browsers, Office applications, PDF programmes, video conferencing software, printer drivers, etc. must also be up to date.
Automatic updates alone are not always sufficient for this. Devices may have been offline during the holidays, updates may have been interrupted due to errors, or storage space issues may have prevented updates from taking place. Mobile devices in particular, which have not been connected to the school network for an extended period, should be checked thoroughly.
Proper technical preparation therefore includes, amongst other things:
- Checking for outstanding operating system and security updates
- Updating browsers, Office programmes and educational software
- Checking antivirus software, firewalls and device settings
- Removing apps or profiles that are no longer needed
- Checking certificates, Wi-Fi profiles and VPN access
- Testing digital whiteboards, printers and presentation equipment
- Documenting faulty or unsupported devices
Devices that no longer receive security updates should no longer be used for sensitive school-related tasks. Whilst it is understandable that devices are kept in use for a long time for budgetary reasons, this must not result in outdated systems being granted permanent access to critical networks.
Managing mobile devices in everyday school life
Tablets used for school lessons can be managed using Mobile Device Management (MDM). The MDM system allows apps to be installed, updates to be triggered and permissions to be assigned from a central location, amongst other things. This ensures that only authorised applications are used and that the devices are always up to date.
New personal devices on the school network
With each new school year, the landscape of personal devices also changes. New smartphones, tablets and laptops are brought into the school, the security status of which is unknown.
As a general rule, personal devices should not be granted the same network access as administrative computers, servers or other sensitive systems. A clear separation between the guest, teaching and administrative networks limits the potential consequences if a personal device is compromised. The UTM firewall is used to set up clearly defined network zones with different access rights; it also allows content filters to be defined, for example to prevent access to content that breaches youth protection regulations via the school Wi-Fi.
Schools should set out the minimum requirements for the use of personal devices. These may include:
- an up-to-date operating system
- a screen lock enabled
- no use of insecure or tampered devices
- encrypted connections
- clear rules on the storage of personal data
- separate Wi-Fi networks for guests, teaching and administration
- Confirmation of the terms of use for pupils and teachers
A particularly important question is whether, and if so, what school data may be processed on personal devices. When teachers use personal devices for work-related tasks, issues such as data protection, access controls and the ability to delete data must be clarified. Without clear rules, an uncontrollable ‘shadow IT’ system can quickly emerge.
External learning platforms and scattered user accounts
Many schools use several digital services in parallel, such as learning platforms, video conferencing systems, file storage solutions or cloud services. As a result, a user account often exists not only on the school’s central network, but also on various external applications.
If a user is deactivated in one system, their access to other services may still remain active. This is precisely where complex risks arise. Former users could continue to access course materials, messages, participant lists, shared folders or personal data.
Platforms that are managed separately and do not have automated synchronisation with central school data are particularly problematic. In such cases, account reconciliation often relies on manual lists, emails or individual staff members. Given the time pressures at the start of the school year, this is prone to errors.
Schools should therefore maintain a complete overview of all platforms and user directories in use. The following should be clearly documented for each service:
- Who creates accounts?
- Who changes roles and groups?
- Who checks permissions?
- Who deletes or deactivates accounts?
- How are student departures and changes of class reported?
- What data is retained after deactivation?
- Which sharing links, groups and shared folders need to be checked as well?
When using external providers, schools and school authorities should also ensure that there are clear rules governing the erasure, retention, return and processing of personal data.
Unclear division of responsibilities between schools, school authorities and IT service providers
Many security issues throughout the user lifecycle arise from a lack of clarity regarding responsibilities.
The school is responsible for changes in staff, classes and roles. The school authority often provides systems, infrastructure or end devices. An external IT service provider may manage accounts, networks, security solutions or learning platforms. In addition, subject departments or individual teachers manage certain applications themselves.
If it is not clearly defined who is responsible for reporting, approving and technically implementing changes, accounts remain active, permissions remain unchanged and devices remain unpatched. This problem becomes more acute at the start of the school year, as many changes have to be processed within a short space of time.
A written procedure is required for new hires, departures, changes of class, changes of role and temporary access. Each task should be assigned to a specific post and given a deadline.
A workable process might look like this:
- The school reports changes to staff, classes and roles to a designated point of contact.
- The relevant department checks which systems are affected.
- Accounts, groups, roles and device assignments are updated.
- Temporary access is given an expiry date.
- Critical changes are documented.
- Before the start of the school year, a joint review of outstanding issues is carried out.
In addition, escalation procedures are required for urgent account suspensions, such as in the event of a lost device, suspected account misuse or a person leaving the organisation at short notice.
FAQ: Frequently asked questions about the start of the new school year and IT security
This is because many digital identities, roles, devices and access permissions change within a short space of time. New accounts are created, old accounts need to be deactivated, classes and courses change, devices return from the holiday break and external platforms need to be updated. Any change that is not implemented correctly can lead to unnecessary access rights or security vulnerabilities.
The greatest risk is that former employees or individuals who are no longer authorised may continue to have access to personal data, emails, learning platforms or internal documents. Furthermore, unused accounts may be taken over by attackers without this being noticed straight away.
Shared passwords prevent traceability. When several people use the same login details, it is not possible to reliably determine who carried out a particular action. Furthermore, such passwords often spread unchecked and are not consistently changed following staff turnover.
Personal devices should only be connected via separate network segments, such as a guest or teaching network. In addition, minimum requirements should apply, for example up-to-date software, screen locks and clear rules on the processing of personal data. Access to sensitive administrative areas should, as a general rule, be strictly restricted for personal devices.
Mobile Device Management can help with the centralised management of school tablets, smartphones and other mobile devices. This includes app distribution, security policies, user rights, device locking, update status and configurations. Particularly at the start of the school year, MDM helps to get devices up and running more quickly and to implement security standards consistently. However, it does not replace organisational processes; rather, it complements them from a technical perspective.
Conclusion: IT security starts with a smooth migration process
The start of the new school year is an ideal time to systematically review digital accounts, access rights, devices and responsibilities. From an IT perspective, ensuring a secure start to the school year involves, at a minimum, user accounts, staff changes, changes in roles, learning platforms, mobile devices, personal devices, network isolation and clear lines of responsibility between the school, the school authority and the IT service provider.
Technical measures such as role-based models, multi-factor authentication, network segmentation and mobile device management (MDM) can provide significant support. MDM, in particular, is a useful tool for schools to centrally manage mobile devices such as Android and iOS-based tablets and smartphones, deploy applications in a controlled manner and manage user rights in a transparent way. However, it remains important to note that the technology will only function reliably if the user lifecycle is clearly regulated at an organisational level.

![Kevin Thomas [Translate to English:] Kevin Thomas, Ihr PR-Ansprechpartner bei Securepoint.](/fileadmin/securepoint/allgemein/geteilte_inhalte/bilder/securepoint-mitarbeiter/kevin-thomas.jpg)