Students are returning to classrooms and college campuses, but they are not the only ones preparing for the new academic year.
Cybercriminals are looking for opportunities too.
Today’s educational environment depends on email, cloud applications, learning management systems, laptops, tablets, payment platforms, financial aid systems, student information systems, and third-party technology providers. Each connection provides educational value, but it can also expand an institution’s attack surface.
From K-12 schools to major universities, cybersecurity should be part of the back-to-school checklist.
Why Education Is an Attractive Target
Schools possess much more than student grades.
Educational institutions may maintain student and parent information, employee records, payroll data, financial information, authentication credentials, research, intellectual property, health information, and financial aid records.
They also support large communities of students, faculty, administrators, contractors, parents, vendors, and technology providers. This combination of valuable information and a highly connected user population creates opportunities for phishing, credential theft, ransomware, Business Email Compromise, account takeover, and other attacks.
The challenge is not simply protecting computers. It is protecting the institution’s people, data, money, operations, and reputation.
Business Email Compromise: A Serious Financial Threat
One threat deserves particular attention: Business Email Compromise, or BEC.
The FBI describes BEC as one of the most financially damaging online crimes. Attackers exploit trust in email by impersonating executives, vendors, employees, and other trusted parties. The FBI has documented BEC schemes affecting school systems as well as businesses, nonprofits, and other organizations.
Consider how this could play out in an educational environment.
A finance employee receives an email appearing to come from a vendor requesting updated banking information. Human Resources receives a request to change an employee’s direct deposit account. A school administrator receives an urgent payment request that appears to come from a superintendent. A student receives fraudulent financial aid instructions. A parent receives what appears to be a legitimate tuition or fee request.
The message may look legitimate because the attacker has compromised a real mailbox, spoofed a trusted domain, created a lookalike domain, or studied legitimate communications before striking. The FBI has investigated schemes involving compromised accounts, unauthorized forwarding rules, spoofing, and altered wire instructions, including attacks targeting schools.
What Schools Can Do
Require MFA for email accounts, particularly administrators, finance, HR, and other privileged users.
Require independent verification of changes to banking information, direct deposits, wire transfers, and high-value purchases. Do not approve a sensitive financial change based solely on an email.
Train employees to recognize urgency, unusual payment requests, changed banking instructions, suspicious login pages, and subtle changes in email addresses.
Schools should also monitor suspicious mailbox forwarding rules and strengthen their domains against direct impersonation through SPF, DKIM, and DMARC.
Protect the Institution’s Digital Identity
A school’s email domain carries significant trust.
That makes email authentication an important part of the institution’s cybersecurity strategy.
SPF identifies systems authorized to send email for a domain.
DKIM cryptographically signs messages so receiving systems can verify their authenticity.
DMARC builds upon SPF and DKIM to help domain owners establish policies for messages that fail authentication and alignment.
When properly implemented, these technologies make it more difficult for attackers to directly spoof an institution’s legitimate domain.
DMARC is not a complete BEC solution. It cannot stop every compromised account or lookalike domain. It should be part of a layered strategy that includes MFA, email threat protection, user awareness, identity security, and financial verification procedures.
DMARC Has Changed: Understanding RFC 9989
There is another development educational institutions should have on their radar.
In 2026, RFC 9989 became the new standards-track specification for DMARC, replacing RFC 7489 and incorporating Public Suffix Domain functionality previously addressed by RFC 9091.
Among the changes is the new psd tag and a DNS Tree Walk process for determining Organizational Domains.
Under RFC 9989:
psd=y indicates that the domain publishing the DMARC record is itself a Public Suffix Domain and is intended for use by a Public Suffix Operator.
psd=n indicates that the domain is not a Public Suffix Domain but explicitly establishes that domain as the Organizational Domain for itself and its subdomains.
This can be particularly relevant to complex and decentralized environments such as universities.
Imagine a university operating:
example.edu
with environments such as:
engineering.example.edu
research.example.edu
athletics.example.edu
alumni.example.edu
RFC 9989 provides additional mechanisms for determining where organizational boundaries exist when DMARC policies are discovered.
The takeaway for universities is not to simply add psd=n to DNS.
Instead, institutions should review their domain and subdomain architecture, identify every legitimate email sender, understand which departments control portions of the namespace, validate SPF and DKIM alignment, and determine how RFC 9989 affects their existing DMARC design.
For large .edu environments, email authentication should be treated as an architecture and governance issue, not merely a DNS configuration exercise.
Five Practical Back-to-School Security Actions
Schools do not have to solve every cybersecurity problem at once. Start with controls that reduce real-world risk.
1. Protect identities with MFA. Require MFA for faculty and staff, especially administrators, IT, finance, HR, and privileged users. Where feasible, adopt phishing-resistant MFA. CISA identifies MFA, particularly phishing-resistant approaches, as one of the most effective measures for preventing cyber intrusions in K-12 environments.
2. Defend against BEC. Establish verification procedures for wire transfers, banking changes, payroll modifications, purchases, and other sensitive requests. Employees should verify unusual financial instructions through a trusted communication channel rather than simply replying to the email. This aligns directly with FBI recommendations for combating BEC.
3. Secure email and domains. Review SPF, DKIM, and DMARC configurations. Identify every authorized third-party sender and monitor DMARC reporting for unauthorized use. Organizations with complex domain environments should begin evaluating the changes introduced by RFC 9989.
4. Patch and inventory technology. Know what devices, applications, cloud platforms, and vendors have access to institutional systems and data. Keep operating systems, applications, and network infrastructure updated. CISA specifically recommends automatic security updates as an important consideration for K-12 technology.
5. Prepare people for the attack. Conduct practical security awareness training using scenarios employees actually encounter, including fake password resets, fraudulent invoices, direct deposit changes, executive impersonation, suspicious attachments, and MFA fatigue attacks.
The objective is not simply to make users complete annual cybersecurity training.
It is to prepare them to recognize an attack when it arrives.
Start With Risk, Not Another Product
Schools frequently face limited cybersecurity budgets, competing technology priorities, and small IT teams.
The solution is not necessarily another security product.
Start by understanding the institution’s risk.
What sensitive information do you possess? Where is it stored? Who can access it? Which systems are critical to operations? Which vendors have access to your environment? How well protected are your identities and email domains? What would happen if a critical system became unavailable tomorrow?
Those answers help determine where limited cybersecurity resources should be invested first.
How Poole Technology Solutions Can Help
Poole Technology Solutions helps organizations identify cybersecurity risk and translate those findings into practical security improvements.
For educational institutions, this can include cybersecurity readiness and risk assessments, NIST Cybersecurity Framework 2.0 assessments, FERPA-focused reviews, email security assessments, SPF/DKIM/DMARC architecture reviews, RFC 9989 readiness assessments, asset and vulnerability analysis, identity and endpoint security reviews, third-party risk assessments, and prioritized remediation roadmaps.
Our goal is not simply to identify vulnerabilities. It is to help institutions understand which risks matter most and what practical steps can reduce those risks.
Protect the Mission Behind the Technology
Cybersecurity in education is ultimately about protecting more than computers.
It is about protecting students, educators, personal information, financial resources, research, institutional operations, and trust.
As students return to classrooms and campuses, school leaders should ask one important question:
If someone tested our cybersecurity posture today, how confident are we in what they would find?
A new academic year is an opportunity for a fresh start.
Cybersecurity should be part of it.
Poole Technology Solutions helps schools, universities, and organizations assess cybersecurity risk, strengthen email and identity security, protect their digital presence, and build practical strategies for a stronger cybersecurity posture.