SAFER CYBERSPACE ●
that collaboration can facilitate necessary
changes to service contracts.
Implementing cybersecurity requirements
may initially seem daunting for school leaders,
but a step-by-step approach and a clear plan can
make it manageable. RIA experts observe that a
school’s level of cybersecurity rarely depends on
its size but instead on the leadership’s attitude. It
largely hinges on how seriously they value protecting their community’s data and ensuring that
modern learning and working tools can be used
securely, without fear of cyber threats.
The majority of Estonia’s educational institutions are owned and budgeted by local governments, so school leaders should consult their
municipal or city governments to improve
cybersecurity. Since municipalities often manage numerous subordinate institutions that rely
on shared information systems, a centralised
approach to cybersecurity may be more efficient. This could involve hiring dedicated staff
or outsourcing the necessary services to a specialist provider. Examples of municipalities
that have adopted such a model include Pärnu
City and Saaremaa Municipality.
RIA regularly organises information days
and training sessions to assist schools in meeting cybersecurity requirements, many of which
are specifically designed for educational institutions. RIA experts are readily available to
offer direct guidance to schools on cybersecurity requirements, and inquiries can be sent to
kikk@ria.ee. ●
a responsible person for implementing technical
requirements, either from the institution or externally, such as an information security manager,
IT specialist or computer science teacher.
Inventory and access review. Effective
cybersecurity starts with understanding the
school’s IT assets. Create an inventory of devices
and software, and review system and network
access for staff and students. Immediately revoke
access for graduates and departing employees.
Establish information security procedures.
Develop an information security policy
outlining how IT devices and systems should
be used securely within the school.
5.
6.
CYBER SECURITY IN ESTONIA 2025
RIA to increase
oversight of schools
Recently, RIA’s supervision department has
been paying greater attention to educational
institutions, as the high number of cyber
incidents suggests schools are not adequately
addressing information security. In 2025,
inspections are planned for state high schools
and public universities, with some municipal
schools likely to be included as well.
The goal of these inspections is not to
punish but to prevent significant data
breaches and disruptions in critical educational systems. To achieve this, RIA identifies
security vulnerabilities and deficiencies in
meeting cybersecurity requirements and
guides institutions in resolving any identified
issues within a reasonable timeframe.
Schools can also negotiate deadlines
for implementing the necessary fixes.
If agreements are not honoured or if an
institution refuses to cooperate with oversight
efforts, RIA has the authority to impose fines.
However, fines have only been issued in rare
cases. Beyond addressing specific issues
at individual institutions, these oversight
activities help RIA gain a clearer understanding of the overall state of cybersecurity in
Estonia’s education sector. This enables the
agency to highlight common challenges,
improve prevention efforts, and, if necessary,
propose regulatory changes or advocate
for additional funding.
7.
Review service contracts critically. When
outsourcing IT services, carefully examine
contracts to ensure clarity on what the service
includes and how security incidents will be handled.
Take advantage of RIA’s online training.
School information security officers should
complete the three RIA-created E-ITS online
training modules available on the Digital State
Academy website. Each course takes about
an hour to complete, provides an overview of
the field and offers practical advice:
- E-ITSi ABC
- E-ITSi rakendamine
- Turvaline väljast tellimine
8.
47