Number of cyberattack attempts reported by respondents in the education sector vs. average (% of respondents) Education sector Phishing and fraudulent emails remain the most common vectors for attempted network intrusion and account for nearly two thirds of all reported attempts. Cross-sector average 15 % 0 35 % 26 % 26 % 1-5 12 % 6-10 8% 9% 8% 11-20 6% 21-30 3% 3% 3% 31-50 One method of reducing this risk is to test user resilience through simulated phishing campaigns. Compared to the previous year, more organisations in the sector are starting to conduct these types of campaign (Fig. 24). Surveyed respondents in the education sector reported that more than 67 % of all attack attempts did not trigger an incident. Despite this finding, the sector still trails the average and exhibits vulnerability. 0% 1% 51-70 0% 2% 71-100 29 % 100 and more 15 % 0% 10 % 20 % 30 % 40 % 50 % Figure 23 Comparison of education sector organisations‘ approach to testing employees against cyber threats compared to the cross-sector average (% of respondents) Education sector Cross-sector average 5% Other 2% 9% Technical or non-technical exercises 2% 9% Social engineering techniques 7% 18 % 18 % Penetration tests 28 % No tests 33 % 31 % Simulated phishing campaigns 38 % 0% 10 % 20 % 30 % 40 % 50 % Figure 24 37

Select target paragraph3