SAFER CYBERSPACE ● that collaboration can facilitate necessary changes to service contracts. Implementing cybersecurity requirements may initially seem daunting for school leaders, but a step-by-step approach and a clear plan can make it manageable. RIA experts observe that a school’s level of cybersecurity rarely depends on its size but instead on the leadership’s attitude. It largely hinges on how seriously they value protecting their community’s data and ensuring that modern learning and working tools can be used securely, without fear of cyber threats. The majority of Estonia’s educational institutions are owned and budgeted by local governments, so school leaders should consult their municipal or city governments to improve cybersecurity. Since municipalities often manage numerous subordinate institutions that rely on shared information systems, a centralised approach to cybersecurity may be more efficient. This could involve hiring dedicated staff or outsourcing the necessary services to a specialist provider. Examples of municipalities that have adopted such a model include Pärnu City and Saaremaa Municipality. RIA regularly organises information days and training sessions to assist schools in meeting cybersecurity requirements, many of which are specifically designed for educational institutions. RIA experts are readily available to offer direct guidance to schools on cybersecurity requirements, and inquiries can be sent to kikk@ria.ee. ● a responsible person for implementing technical requirements, either from the institution or externally, such as an information security manager, IT specialist or computer science teacher. Inventory and access review. Effective cybersecurity starts with understanding the school’s IT assets. Create an inventory of devices and software, and review system and network access for staff and students. Immediately revoke access for graduates and departing employees. Establish information security procedures. Develop an information security policy outlining how IT devices and systems should be used securely within the school. 5. 6. CYBER SECURITY IN ESTONIA 2025 RIA to increase oversight of schools Recently, RIA’s supervision department has been paying greater attention to educational institutions, as the high number of cyber incidents suggests schools are not adequately addressing information security. In 2025, inspections are planned for state high schools and public universities, with some municipal schools likely to be included as well. The goal of these inspections is not to punish but to prevent significant data breaches and disruptions in critical educational systems. To achieve this, RIA identifies security vulnerabilities and deficiencies in meeting cybersecurity requirements and guides institutions in resolving any identified issues within a reasonable timeframe. Schools can also negotiate deadlines for implementing the necessary fixes. If agreements are not honoured or if an institution refuses to cooperate with oversight efforts, RIA has the authority to impose fines. However, fines have only been issued in rare cases. Beyond addressing specific issues at individual institutions, these oversight activities help RIA gain a clearer understanding of the overall state of cybersecurity in Estonia’s education sector. This enables the agency to highlight common challenges, improve prevention efforts, and, if necessary, propose regulatory changes or advocate for additional funding. 7. Review service contracts critically. When outsourcing IT services, carefully examine contracts to ensure clarity on what the service includes and how security incidents will be handled. Take advantage of RIA’s online training. School information security officers should complete the three RIA-created E-ITS online training modules available on the Digital State Academy website. Each course takes about an hour to complete, provides an overview of the field and offers practical advice: - E-ITSi ABC - E-ITSi rakendamine - Turvaline väljast tellimine 8. 47

Select target paragraph3