● SAFER CYBERSPACE and student files the following day using backups. These cases highlight the critical importance of data backups, which should always be stored separately from other systems. Estonian schools also frequently experience denial-of-service attacks, which can temporarily disrupt internet access and daily operations. Analysis of attack patterns suggests that many of these incidents are likely orchestrated by students. Such attacks are relatively simple to execute and can even be purchased as a service from cybercriminals. However, school information systems should be designed to withstand these types of large-scale intrusions. Implementing cybersecurity requirements may initially seem daunting for school leaders, but a step-by-step approach and a clear plan can make it manageable. Although it is impossible to eliminate all risks, every incident provides an opportunity to learn. Those responsible for information security in schools should share their experiences with peers to support collective learning and help prevent similar incidents elsewhere. Unfortunately, these stories are often kept qui- Recommendations for schools starting with cybersecurity 1. Raise cybersecurity awareness. Many cyber threats can be prevented by raising staff awareness. We recommend starting with RIA’s free Cyber Test , which around 100 schools across Estonia have already adopted. Discuss with the school’s owner. School leaders should address information security with the institution’s owner, considering resource allocation and organisational structure. For example, they could explore organising cyber- 2. 46 et. The absence of open discussion within the community reduces awareness and perpetuates the mistaken belief that such incidents are uncommon. As the saying goes, a wise person learns from others’ mistakes, while a fool learns only from their own. SCHOOL LEADERS SHOULD SEEK GUIDANCE FROM STAKEHOLDERS Cybersecurity in schools is not always within their direct control. Last year, for example, there were recurring issues with the examination information system and the Moodle learning environment, both managed by the Ministry of Education and Research. These incidents underline the importance of investing in centralised e-services. Estonian schools also rely on various platforms and services, such as electronic school management systems, provided by private companies, which often have little or no competition, leaving schools with no viable alternatives. Legally, however, educational institutions are responsible for ensuring data protection when outsourcing such services. This can be achieved through informed and well-considered procurement processes, with assistance available through RIA’s online training programme. Schools would benefit from pooling their resources and collectively discussing their needs to strengthen their position when negotiating with service providers. The experience of the Estonian Society of Family Doctors shows security centrally across all local government institutions, hiring an external service provider or similar solutions. Use RIA’s dedicated tool. RIA has developed the E-ITS profile, based on the Estonian Information Security Standard, which focuses on key security requirements for educational institutions. However, each school should further customise the profile to address the institution’s unique needs and characteristics. Leadership recommendations. The profile begins with recommendations for school leaders, who play a critical role in promoting information security. Leaders should appoint 3. 4. CYBER SECURITY IN ESTONIA 2025

Select target paragraph3