PowerSchool
A support portal without multi-factor authentication gave access to student records at schools across North America. (Source: TechCrunch)
The largest breach of student data in US history took one stolen password and a support portal with no MFA. The incidents below share that shape: a campus is thousands of accounts changing every semester, and the ones that survive are the ones that get used.
A support portal without multi-factor authentication gave access to student records at schools across North America. (Source: TechCrunch)
An intrusion into one department's network that went undetected for more than four months, a dwell-time risk every large institution carries. (Source: Stanford Report)
Accounts nobody retired, and third-party education platforms with access nobody governs.
A university offboards a cohort every May. The accounts that outlive graduation, the departed faculty member still in the directory, the research collaborator whose grant ended — those are the access paths, and decentralized IT means nobody sees all of them.
If any answer is "no" or "I would have to ask", that is the blind spot.
The two-page PDF adds the full account of each incident and the control that would have stopped it. Name and work email, and it comes straight back.
The sector page: identity security for education. The service that closes the gap: IGA implementation. And a free audit is 30 minutes with a certified engineer on your own environment, findings in writing: Get a free audit.
Name and work email. The two-page PDF covers each incident in full and the control that would have stopped it.
Needed for the site to work — page delivery, and the spam protection on our forms. These do not track you and cannot be switched off.
Google Analytics and Microsoft Clarity, so we can see which pages are useful and which are confusing. Clarity hides anything you type into a form. We use this to improve the site, not to identify you.
ZoomInfo WebSights, which tells us which organisation a visit is likely to have come from and which pages were read. With this on, ZoomInfo may also set third-party cookies that help it recognise a visit across other websites, and may share that with its own partners. Turning this off stops all of it.