Cybersecurity and Privacy Are Board Governance Issues.

wordpress post3PGc9O

Boards do not need to manage technology. They need assurance that school systems, information, images and people are being protected.

Schools hold some of the most sensitive information in their communities: student and whānau records, wellbeing information, staff and payroll details, photographs, and safeguarding restrictions. A cyberattack can interrupt learning or expose this information. A privacy failure can cause harm even when no system has been hacked.

For school boards, cybersecurity and privacy therefore sit alongside health and safety, financial stewardship and student wellbeing. They are governance risks requiring clear oversight, appropriate resourcing and regular assurance.

Cybersecurity and privacy are related but different

Cybersecurity protects systems and information from unauthorised access, loss, attack and disruption. Privacy governs how personal information is collected, accessed, used, shared, retained and removed.

A school can have secure systems and still experience a serious privacy failure.

Examples include publishing the wrong student’s photograph, overlooking a changed image restriction, sending personal information to the wrong person, retaining information longer than necessary, or using an online service without understanding where school data is stored.

What is the board responsible for?

Management operates the controls. The board seeks assurance that risks are understood, adequately resourced and effectively managed.

The board should be confident that:

  • cybersecurity and privacy are recognised in the school’s risk register

  • appropriate protections and processes are operating

  • suppliers handling school information have been assessed

  • the school can respond quickly when an incident occurs

  • gaps are recorded, assigned and followed through

Five things every school board should know

1. Do we know our main risks?

The school has identified its most important cybersecurity and privacy risks and considered the potential impact on students, staff, whānau, learning and school operations.

These risks may include: phishing, account compromise and unauthorised access, ransomware, outages and loss of access to critical systems, loss or inappropriate disclosure of personal information publishing student images or identifying information contrary to restrictions failures involving an external technology supplier

2. Are basic protections in place?

Management can explain the protections that are operating and provide evidence where appropriate.

  • multi-factor authentication for important accounts

  • secure backups that are tested and recoverable

  • access to sensitive information limited to those who need it

  • regular staff cybersecurity and privacy awareness

  • reliable processes for recording and applying student image and information restrictions

3. Do we know where school information is held and shared?

The school knows which systems and suppliers hold personal information, what information they hold, why they need it, and what assurance supports their use.

Where available, schools should prefer independently assessed education technology services, such as products assessed through Safer Technologies 4 Schools (ST4S) that are badged. (ask to see the vendors badge).

4. Can we respond when something goes wrong?

The school has a practical incident response plan that covers both cybersecurity incidents and privacy breaches.

  • who leads the response and who makes key decisions

  • how the incident will be contained and essential services restored

  • when specialist, insurer, legal or government support will be obtained

  • how affected students, staff and whānau will be supported and informed

  • how notification obligations will be assessed

(this is a key part of the ST4S assessment)

5. Does the board receive regular assurance?

Cybersecurity and privacy are included in the board’s risk programme. The board receives clear, non-technical reporting at least annually and after any significant incident or material change.

The board is not looking for a guarantee that nothing will ever go wrong. It is looking for evidence that risks are understood, reasonable protections are operating, and weaknesses are being addressed.

A policy is not enough

Many schools already have cybersecurity and privacy policies, including policies supplied through services such as SchoolDocs. These are an important foundation, but a policy does not by itself demonstrate that protections are operating.

Boards need practical assurance that staff understand the requirements, processes are followed, suppliers are reviewed, incidents are planned for, and identified gaps are being resolved.

Student images are now a privacy and safety issue

Schools publish positive stories across websites, newsletters, apps and social media. That communication matters, but it also creates a growing privacy responsibility.

Image restrictions may arise from parent or student preferences, legal and custody arrangements, wellbeing concerns, or immediate safeguarding risks. Those restrictions can also change over time. Schools therefore need a reliable way to:

  • record who may or may not be published online

  • apply restrictions consistently across communication channels

  • review restrictions when circumstances change

  • locate previously published images when urgent action is required

  • remove, replace or obscure a person’s identity where appropriate

Hail can assist here, backed by accurate school records, clear policy, authorised decision-making and human oversight.

👉️ Our recommendation. Apply Hails Image Privacy feature immediately to record where all images are shared. Only share student images on social media via the Hail service and not directly onto these channels.

What should our board do now?

Risk register. Record cybersecurity, privacy and significant supplier risks.

Ask for assurance, not technical detail. Confirm that basic protections, privacy processes and recovery plans are operating.

Check the school’s suppliers. Know which providers hold sensitive information and what assurance supports their use. ST4S badged products as a default.

Protect student information and images. Ensure restrictions are recorded, applied across channels and updated when circumstances change.

Practise the response. Confirm who will lead, communicate and make notification decisions when an incident occurs.

Review it regularly. Complete the attached assurance check annually and after major incidents, system changes or new safeguarding concerns.

Final thought

Cyber security is no longer optional, and it is no longer “just an IT issue.” For schools, it is a governance responsibility that requires informed oversight, trusted partners, and clear assurance.

Attachments:

  1. Cyber Security and Privacy assurance check that a Board can use.

  2. Completed example for a school that uses Hail.

2000 constrained 9a7f18ca 781e 4c3a 8384 99d6485eabec

Author: Stuart Dillon-Roberts, Founder of Hail and Careerwise. stuart@hail.to

Stuart is a cyber security and privacy specialist with international experience leading security teams and delivering ISO/IEC 27000 aligned services. Across his career, Stuart has worked closely with organisations responding to real-world cyber incidents and data breaches, bringing practical, governance-focused insight into cyber crime, risk management, and resilience in education settings.

At Hail, we see our role as supporting schools — and their boards — to communicate confidently, securely, and responsibly in an increasingly complex digital world. Hail and Careerwise leads the way in security and privacy. Hail information here.

Resources and References.

These resources reflect current best practice in school cyber security governance and are intended to support boards in understanding their oversight role and third-party risk responsibilities.

New Zealand governance and education guidance

International education and cyber risk context

Supplier assurance and third-party risk

Ministry of Education
Cyber security and digital safety guidance for schools

https://www.education.govt.nz/education-professionals/schools-year-0-13/digital-technology

UK National Cyber Security Centre (NCSC)
Cyber security guidance for boards and senior leaders

https://www.ncsc.gov.uk/collection/board-toolkit

Safer Technologies 4 Schools (ST4S)
Independent assessment framework for digital products used in schools

https://st4s.edu.au/

Office of the Privacy Commissioner
Privacy breaches, incident response, and notification obligations

https://www.privacy.org.nz/

UK Department for Science Innovation and Technology
Cyber Security Breaches Survey 2025 – Education sector findings

https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2025

EdTechNZ
Aotearoa EdTech Data Privacy Pledge – a sector commitment demonstrating alignment with strong privacy, data protection, and ST4S principles
https://edtechnz.org.nz/the-aotearoa-edtech-data-privacy-pledge-your-gateway-to-st4s/

Institute of Directors (IoD NZ)
Cyber risk governance and board-level responsibility

https://www.iod.org.nz/#/

Center for Internet Security
K–12 education cyber incident reporting and trends

https://www.cisecurity.org/

References in the article:

  1. IOD Cyber Security Guide 2025. Link Here.

  2. Ministry of Education: Creating a Cyber Security Policy and Roles and Responsibilities. Link Here

Attachments

Completed_School_Cybersecurity_and_Privacy_Board_Assurance_Example   Word, 35.1 KB
School_Cybersecurity_and_Privacy_Board_Assurance_Check   Word, 38.3 KB
Share Article

Unlock all the features of Hail with a free trial.

Ready to Transform Your Publishing?

Experience the power of Hail for yourself with a free trial.
Start creating, saving time, and cutting costs—all with no commitment!

Start Your Free Trial
Related Article