The mismatch is structural, not a failure
A mid-sized university runs a network that would be considered large for a bank, serves a population that turns over by a quarter every year, supports research that must be shareable by definition, and does it with a security team you could fit in a lift. A multi-academy trust runs twenty schools on the budget of one.
Neither situation is going to change, so the useful question is not how to build an enterprise security function. It is how a team of one or two spends the hour a week they have on the things that actually matter to them, rather than on reading the same ransomware story across fifteen outlets.
Why the sector needs its own view
Openness is the mission, not a misconfiguration
Collaboration across institutions, guest access, federated identity, published research and a deliberately permeable network are what a university is for. Security models built on a hard perimeter do not map onto it.
Ransomware hits the sector disproportionately
Term-time timing, high disruption tolerance in the attacker's favour, and a well-documented pattern of targeting institutions during exam periods and enrolment. Schools and trusts are hit as often as universities and have less capacity to respond.
Research is a collection target
Credential harvesting campaigns against academic staff and library systems have run for years and are openly reported. Where research is dual-use, defence-funded or commercially valuable, the interest is state-aligned and persistent rather than opportunistic.
Your population is the attack surface
Tens of thousands of accounts, annual turnover, personal devices, and a user base that is by definition inexperienced. Phishing and account takeover are constant background noise rather than incidents.
You hold data with long consequences
Safeguarding records, health information, immigration status and financial data on minors and young adults. The reputational and regulatory exposure does not scale with your budget.
Suppliers are shared across the sector
Student information systems, virtual learning environments, admissions platforms and payment providers sit behind hundreds of institutions at once, so one compromise reaches all of them.
What ThreatCluster does for an education team
One record per incident
Every source covering the same event grouped into a single record with a sourced timeline, entities, IOCs and ATT&CK mapping. Around 900 articles a day become roughly 70 clusters. If you have an hour a week, this is what makes the hour enough.
Supplier monitoring
Track your SIS, VLE, admissions and payment providers as watched entities. Sector suppliers are compromised regularly and institutions usually hear late.
Exploitation status, not CVSS theatre
Confirmed in-the-wild exploitation separated from the rest of the queue, which is how a one-person team decides what to do first.
A digest somebody will actually read
Daily or weekly, filtered to your platforms and suppliers, formatted to be read on a phone. For most institutions this is the whole product.
Reporting for governors and auditors
Dated, sourced records exportable as briefings for a board of governors, a trust board or an insurer without rewriting.
Running in an afternoon
- Tell it what you run. Platforms, suppliers, sector.
- Pick how it reaches you. Email digest for most, Slack or Teams if you use them.
- Wire in the outputs if you have somewhere to put them. Plenty of institutions never need to.
Hosted, outbound only, no agents, nothing deployed.
Evidence for what you are assessed against
Education institutions sit inside overlapping regimes, and funding or insurance increasingly depends on showing current awareness of sector threats.
- UK DfE cyber security standards for schools and colleges, which expect awareness of current threats
- Cyber Essentials, frequently a condition of funding or insurance
- NIS2, which brings research organisations in scope in the EU
- UK GDPR and the Data Protection Act, where the sensitivity of the data raises the bar
- ISO 27001 Annex A 5.7 where institutions certify
- Cyber insurance renewals, which now ask directly about threat monitoring
ThreatCluster is the monitoring and evidence layer underneath these. It produces the dated, sourced record an assessor asks for.
Questions we get from education buyers
“We have no budget for this.”
The free tier is free permanently and not a trial. We also do sector pricing and free access for institutions through the partnerships route. This is the sector that argument was written for.
“We already get Jisc advisories.”
Keep them, they are authoritative for the UK sector. They do not cover your specific suppliers, the platforms in your estate, or the CVE in the appliance running your remote access.
“I am one person covering twenty schools.”
Then set one digest scoped to the platforms all twenty share, and stop there. That is a legitimate way to use this and it takes ten minutes.
“Our network is too open for any of this to help.”
The openness is not the thing this changes. Knowing which of this week's reporting touches your suppliers and your platforms is useful regardless of your architecture, and arguably more useful because of it.
What we are tracking in the sector right now
Every incident on the education entity page is drawn from live clustering: active clusters, associated threat groups, and the most recent reporting, updated continuously.
Education threat intelligence FAQ
What is threat intelligence for education?
Monitoring of the threats specific to schools, colleges and universities: ransomware campaigns targeting institutions, credential harvesting against staff and students, state-aligned interest in research, and compromise of the shared suppliers the sector depends on.
Is there free or discounted access for educational institutions?
Yes. The free tier requires no card, and there are sector rates and free access routes for institutions, educators and student cohorts through the partnerships page.
Can lecturers use this in teaching?
Yes, and there is a route for classroom cohort access. See partnerships.
Do you cover research security and academic targeting?
Yes. Campaigns targeting academic credentials and research organisations are tracked alongside the rest of the reporting.
Is there a free version?
Yes, permanently, with no card required.
An hour a week, spent on the right things
Free account, no card, ten minutes to set up. Add your platforms and suppliers and let the digest do the rest.