Skip to content

Cyber Resilience in Education: Lessons from the Jisc Security Conference

Cyber threats are evolving faster than many organisations can adapt. The Jisc Security Conference brought this reality into sharp focus by bringing together security professionals, technical specialists and leaders from across higher and further education, research and the public sector to explore how the sector can respond with confidence rather than fear. 

C3IA had the pleasure of attending the event and took the opportunity to learn from peers, understand how threats are developing and identify the steps that organisations can take today to strengthen resilience. What became clear is that cyber security in education is not simply a technology challenge. It is a cultural, operational and strategic challenge that requires regular attention and practical action.  

Building Resilience Begins with People 

A compelling talk from Major General Jonathan Shaw reminded attendees that technology alone cannot guarantee safety. Systems only perform securely when the people operating them are informed, attentive and empowered. 

This has a direct implication for education providers. Investment in technology will only deliver value if staff understand the risks they face and feel confident identifying and reporting potential threats. Regular awareness training, clear reporting channels and visible leadership are essential parts of an effective defence. An informed workforce can stop incidents before systems or data are compromised.  

Responding to AI-Enabled Threats with Equal Pace 

Phishing, Distributed Denial of Service (DDoS) attacks and AI-driven threats emerged as recurring themes. One striking insight was that AI-generated phishing emails are now significantly more effective, with a reported success rate of 54%. Attackers now use AI to produce messages that are more persuasive, context-aware and linguistically polished. 

Organisations should respond by combining training with technical controls. Encourage staff to pause before acting on unexpected messages and make reporting suspicious content easy and judgement-free. Pair this with automated monitoring, threat detection and rate limiting so that abnormal traffic or large-scale attacks can be managed quickly. While technical controls reduce exposure, it is often everyday awareness that prevents compromise.  

Reducing Risk in Hybrid Environments 

Many institutions operate a mix of on-premises and cloud environments. One speaker warned that systems are often built upon rather than rebuilt, leading to layers of complexity that hide vulnerabilities. Adding new components without reviewing the foundation increases risk and can make incident response far more difficult. 

Regular configuration reviews and validation checks are essential. Cloud environments should reflect least-privilege principles with strong identity management and tight control over who can make changes. Legacy systems should be reviewed, patched or decommissioned where possible rather than left unmanaged simply because they still function. A structured approach prevents ageing infrastructure from becoming a silent liability.  

Managing Secure Use of Generative AI 

Large language models and generative AI are becoming commonplace in education. They are powerful, accessible and often transformative for user experience. They also introduce new risks when sensitive information is entered into external systems. 

Institutions can reduce exposure by setting clear policies on acceptable use, restricting access where needed and treating external AI tools as public environments. Secure alternatives can be provided for internal use, particularly where they involve confidential data or intellectual property. Regular reviews, monitoring and guidance help staff use AI confidently without unintentionally introducing risk.  

Tackling Common Weaknesses Before They Escalate 

Speakers highlighted recurring weaknesses in many organisations, including outdated dependencies, legacy Apache deployments, misconfigured Transport Layer Security (TLS) protocols and forgotten public assets. These issues are rarely complex but often persist because they fall between responsibilities or are overshadowed by new projects. 

A structured approach to routine maintenance helps close gaps before they become problems. Automated patching, formal dependency policies, certificate reviews and scheduled vulnerability assessments make proactive maintenance far more effective than reactive recovery.  

Turning Insight into Action 

The Jisc Security Conference made it clear that cyber security is an ongoing practice, not a single project. Organisations that succeed focus on people, processes and systems together, reviewing risks regularly and adapting as threats evolve.  

As an NCSC-assured consultancy, C3IA can help you turn insight into action. Whether through assessments, gap analysis, penetration testing or Cyber Essentials certification, we help you understand your exposure and take practical steps to strengthen your resilience. 

Ultimately, it is not about complex solutions but about building informed, vigilant teams and maintaining systems that are secure by design. These are the foundations for enduring cyber resilience. 

Back To Top