● SAFER CYBERSPACE
and student files the following day using backups. These cases highlight the critical importance of data backups, which should always be
stored separately from other systems.
Estonian schools also frequently experience
denial-of-service attacks, which can temporarily disrupt internet access and daily operations.
Analysis of attack patterns suggests that many
of these incidents are likely orchestrated by students. Such attacks are relatively simple to execute and can even be purchased as a service
from cybercriminals. However, school information systems should be designed to withstand
these types of large-scale intrusions.
Implementing cybersecurity
requirements may initially
seem daunting for school
leaders, but a step-by-step
approach and a clear plan
can make it manageable.
Although it is impossible to eliminate all
risks, every incident provides an opportunity to
learn. Those responsible for information security in schools should share their experiences
with peers to support collective learning and
help prevent similar incidents elsewhere.
Unfortunately, these stories are often kept qui-
Recommendations
for schools starting
with cybersecurity
1.
Raise cybersecurity awareness. Many cyber
threats can be prevented by raising staff
awareness. We recommend starting with RIA’s
free Cyber Test , which around 100 schools
across Estonia have already adopted.
Discuss with the school’s owner. School
leaders should address information security
with the institution’s owner, considering resource
allocation and organisational structure. For
example, they could explore organising cyber-
2.
46
et. The absence of open discussion within the
community reduces awareness and perpetuates
the mistaken belief that such incidents are
uncommon. As the saying goes, a wise person
learns from others’ mistakes, while a fool learns
only from their own.
SCHOOL LEADERS SHOULD SEEK
GUIDANCE FROM STAKEHOLDERS
Cybersecurity in schools is not always within
their direct control. Last year, for example,
there were recurring issues with the examination information system and the Moodle learning environment, both managed by the Ministry of Education and Research. These incidents
underline the importance of investing in centralised e-services.
Estonian schools also rely on various platforms and services, such as electronic school
management systems, provided by private
companies, which often have little or no competition, leaving schools with no viable alternatives. Legally, however, educational institutions
are responsible for ensuring data protection
when outsourcing such services. This can be
achieved through informed and well-considered procurement processes, with assistance
available through RIA’s online training programme. Schools would benefit from pooling
their resources and collectively discussing their
needs to strengthen their position when negotiating with service providers. The experience of
the Estonian Society of Family Doctors shows
security centrally across all local government
institutions, hiring an external service provider
or similar solutions.
Use RIA’s dedicated tool. RIA has developed
the E-ITS profile, based on the Estonian
Information Security Standard, which focuses
on key security requirements for educational
institutions. However, each school should further
customise the profile to address the institution’s
unique needs and characteristics.
Leadership recommendations. The profile
begins with recommendations for school
leaders, who play a critical role in promoting
information security. Leaders should appoint
3.
4.
CYBER SECURITY IN ESTONIA 2025