Back to school: Your students are back. Is your security?
Learn how to move from summer drift to a security posture built for classroom learning.
Ah, summertime. The time of year where you don’t have to worry about school. The sun is shining, you can enjoy your free time, hang out with your family and friends, not think about the school year ahead…
Well, maybe if you’re a student. And definitely not if you’re an IT admin.
For school IT admins, the halls might be quieter, but there’s no shortage of work. Many teams use the time to recover from the chaotic school year and catch up on tasks that needed to be done, like audits, repairs, upgrades and new device onboarding.
It’s also the time to set yourselves (and your students) up for success for the new year. As the first bell approaches and you’ve hopefully found yourself near the end of your backlog, you’re in the best position to improve your security and learning environment. But first, you need to know where you’re at.
Find your bearings: What happened to your fleet in the summer?
What happened to your devices over the summer? Maybe:
- Students took them home: Devices didn’t check into MDM or accessed unknown/insecure networks, rogue apps were installed or MDM profiles were removed with a wipe.
- Devices sat dormant: Lab, cart or other devices missed updates and configurations shifted.
While perhaps not ideal, falling into either case is certainly not unexpected. This is the natural state as teams transition from one phase to the next.
If you want to improve how devices are used at your school, you have to acknowledge where you currently are. You need information like:
- MDM enrollment status
- OS versions
- Last check-in dates
- Installed apps
- Potential shadow IT
With this data in tow, you can start building on your systems and repairing areas that need a little help.
Close the gaps. Then raise the bar.
New school years mean new students, new curricula and new tools. Last year’s security policies and configurations might not be the best fit for the new year’s requirements. You might have compromised on settings last year, or new threats forced a shift in strategy. Either way, it’s prime time to build a posture that meets your school’s current and growing needs.
So how do you move from recovery to reform?
1. Restore your baseline and look past it
Address OS update backlogs and compliance drift you found in your device audit. Devices running known vulnerabilities are a big risk to your school’s security.
Beyond the basics, consider:
- What features are no longer serving teachers and/or students? Can they be removed or disabled?
- What tools, settings or features need to be scaled to more groups?
- Were last year’s security requirements sufficient?
- Did anything change about school, region or government policies?
- What resources or tools did teachers request the most?
Answering these questions will help you decide what apps, configurations and features can improve the classroom experience.
2. Build filtering and guardrails that empower learners
Device restrictions require a careful balance of safety, privacy and productivity. With new threats, teacher or parent complaints, administrative policies and new resources, striking this balance is difficult. You don’t want to be so restrictive that learners can’t access the creative or educational resources they need. Nor so permissive that students find themselves distracted on inappropriate or dangerous websites.
When determining your content filters and guardrails, consider:
- Were restrictions so tight that students found workarounds? If so, what unapproved apps or extensions showed up because of this?
- Do filtering settings match curriculum requirements and how teachers use devices in class?
- How do your content filters affect how teachers and students use and trust their devices?
- Do you have a content filtering tool in place that meets standards and requirements without surveilling students?
Shadow IT — and therefore more risk — shows up when users need to find ways to work around restrictions. Identifying these unapproved resources helps signal that your restrictions aren’t quite what they need to be.
3. Calibrate your security posture
Inexperienced users make good targets for cyber criminals. And some students seem to try to find ways to get in trouble (or stay entertained). Obviously, security incidents put users and their data at risk. They also interrupt learning by making accounts or devices unavailable. Teachers have to deal with these interruptions, either delaying the entire lesson or putting a student with a compromised device at a disadvantage. This is why security is paramount for purposeful learning.
A device’s security posture shouldn’t negatively impact learning. Consider:
- Do you have alerts or automated actions triggered by risky behavior, or are you finding out after the fact?
- If a device is compromised mid-lesson, how fast can a teacher get a working replacement or fallback in front of that student?
- Are your response steps documented and practiced, or improvised each time, and does staff know who to call first?
Every school year is a chance to reset and find your bearings. If you can take the opportunity to cater a device setup for learning, you’re setting students and teachers up for success — even better than they were the year before.
Where to start
- Run a full fleet audit: Pull enrollment status, OS compliance and last check-in time. This data will guide your next steps.
- Audit filtering and security policies against this year’s curriculum: Don’t assume last year’s settings are the default. Review policies against current needs, adjust focus mode settings and update grade-level controls.
- Close the shadow IT surface and adjust: Block the apps and extensions that shouldn’t be there and determine how these workarounds reveal gaps in your current tools. Close those gaps as well.
- Strengthen and adapt: Find ways to improve your security posture against the latest threats. Upgrade your tech stack or device configurations in ways that suit classroom needs.
- Make back-to-school readiness a repeatable annual milestone: Improvements to enrollment, compliance, OS updates, filtering calibrations, shadow IT audits and policies compound every year. Consider ways to make this repeatable and sustainable.
See how Jamf for K-12 helps you evolve your security.