Boards do not need to manage technology. They need assurance that school systems, information, images and people are being protected.
Schools hold some of the most sensitive information in their communities: student and whānau records, wellbeing information, staff and payroll details, photographs, and safeguarding restrictions. A cyberattack can interrupt learning or expose this information. A privacy failure can cause harm even when no system has been hacked.
For school boards, cybersecurity and privacy therefore sit alongside health and safety, financial stewardship and student wellbeing. They are governance risks requiring clear oversight, appropriate resourcing and regular assurance.
Cybersecurity and privacy are related but different
Cybersecurity protects systems and information from unauthorised access, loss, attack and disruption. Privacy governs how personal information is collected, accessed, used, shared, retained and removed.
A school can have secure systems and still experience a serious privacy failure.
Examples include publishing the wrong student’s photograph, overlooking a changed image restriction, sending personal information to the wrong person, retaining information longer than necessary, or using an online service without understanding where school data is stored.
What is the board responsible for?
Management operates the controls. The board seeks assurance that risks are understood, adequately resourced and effectively managed.
The board should be confident that:
-
cybersecurity and privacy are recognised in the school’s risk register
-
appropriate protections and processes are operating
-
suppliers handling school information have been assessed
-
the school can respond quickly when an incident occurs
-
gaps are recorded, assigned and followed through
Five things every school board should know
1. Do we know our main risks?
The school has identified its most important cybersecurity and privacy risks and considered the potential impact on students, staff, whānau, learning and school operations.
These risks may include: phishing, account compromise and unauthorised access, ransomware, outages and loss of access to critical systems, loss or inappropriate disclosure of personal information publishing student images or identifying information contrary to restrictions failures involving an external technology supplier
2. Are basic protections in place?
Management can explain the protections that are operating and provide evidence where appropriate.
-
multi-factor authentication for important accounts
-
secure backups that are tested and recoverable
-
access to sensitive information limited to those who need it
-
regular staff cybersecurity and privacy awareness
-
reliable processes for recording and applying student image and information restrictions
3. Do we know where school information is held and shared?
The school knows which systems and suppliers hold personal information, what information they hold, why they need it, and what assurance supports their use.
Where available, schools should prefer independently assessed education technology services, such as products assessed through Safer Technologies 4 Schools (ST4S) that are badged. (ask to see the vendors badge).
4. Can we respond when something goes wrong?
The school has a practical incident response plan that covers both cybersecurity incidents and privacy breaches.
-
who leads the response and who makes key decisions
-
how the incident will be contained and essential services restored
-
when specialist, insurer, legal or government support will be obtained
-
how affected students, staff and whānau will be supported and informed
-
how notification obligations will be assessed
(this is a key part of the ST4S assessment)
5. Does the board receive regular assurance?
Cybersecurity and privacy are included in the board’s risk programme. The board receives clear, non-technical reporting at least annually and after any significant incident or material change.
The board is not looking for a guarantee that nothing will ever go wrong. It is looking for evidence that risks are understood, reasonable protections are operating, and weaknesses are being addressed.
A policy is not enough
Many schools already have cybersecurity and privacy policies, including policies supplied through services such as SchoolDocs. These are an important foundation, but a policy does not by itself demonstrate that protections are operating.
Boards need practical assurance that staff understand the requirements, processes are followed, suppliers are reviewed, incidents are planned for, and identified gaps are being resolved.
Student images are now a privacy and safety issue
Schools publish positive stories across websites, newsletters, apps and social media. That communication matters, but it also creates a growing privacy responsibility.
Image restrictions may arise from parent or student preferences, legal and custody arrangements, wellbeing concerns, or immediate safeguarding risks. Those restrictions can also change over time. Schools therefore need a reliable way to:
-
record who may or may not be published online
-
apply restrictions consistently across communication channels
-
review restrictions when circumstances change
-
locate previously published images when urgent action is required
-
remove, replace or obscure a person’s identity where appropriate
Hail can assist here, backed by accurate school records, clear policy, authorised decision-making and human oversight.
👉️ Our recommendation. Apply Hails Image Privacy feature immediately to record where all images are shared. Only share student images on social media via the Hail service and not directly onto these channels.
What should our board do now?
Risk register. Record cybersecurity, privacy and significant supplier risks.
Ask for assurance, not technical detail. Confirm that basic protections, privacy processes and recovery plans are operating.
Check the school’s suppliers. Know which providers hold sensitive information and what assurance supports their use. ST4S badged products as a default.
Protect student information and images. Ensure restrictions are recorded, applied across channels and updated when circumstances change.
Practise the response. Confirm who will lead, communicate and make notification decisions when an incident occurs.
Review it regularly. Complete the attached assurance check annually and after major incidents, system changes or new safeguarding concerns.
Final thought
Cyber security is no longer optional, and it is no longer “just an IT issue.” For schools, it is a governance responsibility that requires informed oversight, trusted partners, and clear assurance.
Attachments:
-
Cyber Security and Privacy assurance check that a Board can use.
-
Completed example for a school that uses Hail.
Author: Stuart Dillon-Roberts, Founder of Hail and Careerwise. stuart@hail.to
Stuart is a cyber security and privacy specialist with international experience leading security teams and delivering ISO/IEC 27000 aligned services. Across his career, Stuart has worked closely with organisations responding to real-world cyber incidents and data breaches, bringing practical, governance-focused insight into cyber crime, risk management, and resilience in education settings.
At Hail, we see our role as supporting schools — and their boards — to communicate confidently, securely, and responsibly in an increasingly complex digital world. Hail and Careerwise leads the way in security and privacy. Hail information here.
Resources and References.
These resources reflect current best practice in school cyber security governance and are intended to support boards in understanding their oversight role and third-party risk responsibilities.
|
New Zealand governance and education guidance |
International education and cyber risk context |
Supplier assurance and third-party risk |
|---|---|---|
|
Ministry of Education https://www.education.govt.nz/education-professionals/schools-year-0-13/digital-technology |
UK National Cyber Security Centre (NCSC) |
Safer Technologies 4 Schools (ST4S) |
|
Office of the Privacy Commissioner |
UK Department for Science Innovation and Technology https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2025 |
EdTechNZ |
|
Institute of Directors (IoD NZ) |
Center for Internet Security |
References in the article:
-
IOD Cyber Security Guide 2025. Link Here.
-
Ministry of Education: Creating a Cyber Security Policy and Roles and Responsibilities. Link Here



