Nine IT controls Australian schools should expect

Not a maturity framework. Nine specific things a school should already have, what each one is for, and the single piece of evidence that tells you whether it is genuinely running.

When a school asks us what good looks like, the honest answer is that managed IT services for schools are not exotic. The controls that matter are the same ones that matter everywhere. What differs is how they have to be implemented around a term calendar, a student population that turns over every year, and a data set that belongs to children.

These nine are in rough order of how much risk they remove per dollar. Against each one there is a piece of evidence to ask for, because a description of a control and a working control are not the same thing and only one of them produces an artefact.

How to use this list

Take it to whoever currently provides your managed IT support — internal or external — and ask for the evidence column rather than the description. You are not auditing them. You are finding out which of the nine exist on paper only, which is information you need before you can budget for anything.

Expect two or three gaps. Nearly every school has them, usually in the same places.

Identity and access

1. Phishing-resistant MFA on every staff account

Every account, including the principal, the business manager, the IT coordinator and any service account a human can sign into. The exemptions granted years ago for convenience are the ones that get used.

“Phishing-resistant” matters. SMS codes and push approvals are both bypassable by the phishing kits in general circulation now — we have written about why the second factor you deployed in 2021 may not be holding. Passkeys, or number matching at minimum.

Evidence: a report showing MFA registration state per account, with the exceptions listed and a reason against each.

2. Account lifecycle driven from the student information system

Staff, students, casual relief teachers and contractors created, changed and disabled from one authoritative source. In a school this is not housekeeping — a cohort leaves every December and a new one arrives every January, and manual processes do not survive that volume.

The failure mode is a departed staff member's mailbox still receiving parent correspondence, or a Year 12 account still active in March.

Evidence: a list of enabled accounts with no sign-in for 90 days, reconciled against the current staff and enrolment lists.

3. Administrative access separated and reviewed

Nobody administers a tenant from the account they read email on. Administrative rights are held separately, granted for a period rather than permanently where the platform allows it, and reviewed on a schedule someone owns.

This includes your provider's own access. You should be able to see which of their engineers can reach your environment, and that list should get shorter when their staff change.

Evidence: the current list of privileged accounts, including the provider's, with the date of the last review.

Devices and patching

4. Managed devices, including the ones on the trolley

Enrolled, encrypted, patched, and able to be wiped remotely. The hard part in a school is never the staff laptops — it is the shared trolleys, the specialist labs, the library machines and the BYO programme, where sign-out has to genuinely end the session and a lost device has to be a lost device rather than a lost data set.

Boarding, music, design and sport all tend to have equipment nobody has looked at in three years. It counts.

Evidence: the enrolled device count from your management platform, next to the asset register. If they differ by more than a few per cent, one of them is fiction.

5. Patching with a measured compliance figure

Operating systems, browsers and — the one that gets missed — the third-party applications that are not Microsoft. Adobe, Java, the CAD package in design tech, the plotter driver, the music software, the library system.

Schools patch in the holidays, which is sensible, but a twelve-week gap between windows is a long time. Ask what the exception process is for something critical in week four of term.

Evidence: a patch compliance percentage, by month, for the last six months. A provider who measures it will know it and will usually volunteer that it is imperfect.

Data and recovery

6. Backups that have actually been restored

Covering the student information system, the learning management system, Microsoft 365 or Google Workspace, finance, and the file shares that still hold twenty years of reports. Immutable copies, so that an attacker who reaches your environment cannot delete the recovery path.

The thing to insist on is a measured restore time from a real test, not a target in a document. Backup success reports tell you a job completed. They tell you nothing about whether the data comes back.

Evidence: the most recent restore test report, with the date, the system restored and the elapsed time.

7. A register of every system holding student data

This is the one almost nobody has, and it is the one the last two years of incidents have argued for. Count the platforms with student records at your school — SIS, LMS, wellbeing, library, canteen, sport, music tuition, excursion consent, photography, alumni. The number is larger than the business manager's list.

Each entry needs an owner, a renewal date, and a note on whether the product has been assessed under Safer Technologies 4 Schools, the shared assessment programme run by Education Services Australia across the state, territory, Catholic and independent sectors. ST4S is the nearest thing Australian education technology has to a common privacy and security baseline, and checking it before you sign costs nothing.

Pair the register with a review of what has OAuth access to your tenant. Faculty-approved integrations accumulate quietly and rarely get revoked.

Evidence: the register itself, and the current list of third-party apps with tenant access, with an approver named against each.

Detection and response

8. Monitoring with someone authorised to act

Logs from identity, endpoints and email reaching a place where they are correlated, with a human who can isolate a device at two in the morning without waking a committee. This is the difference between monitoring and detection and response — one produces alerts, the other produces containment.

Get the authority written down. In an incident, the delay is almost never technical; it is somebody waiting for permission.

Evidence: the standing authorisation to isolate an endpoint or disable an account out of hours, and the last three months of alert volumes with what was done.

9. An incident response plan that names people

Who declares an incident, who talks to the department or the board, who assesses whether it is notifiable, who drafts the message to families, and who files with the regulator. Names and mobile numbers, not role titles, and printed — because a plan stored only in the system you have lost is not a plan.

The regulator differs by sector: non-government schools generally report eligible breaches to the OAIC under the Notifiable Data Breaches scheme, while government schools report through their state or territory scheme. Both belong in the document. So does the 72-hour ransomware payment reporting obligation if your school is over the turnover threshold — we have covered who that catches separately.

Evidence: the plan, plus the date of the last tabletop exercise and who was in the room. If the leadership team has never rehearsed it, it is a document rather than a capability.

What order to do them in

If all nine are open, this is the sequence we would use. It front-loads the controls that stop the most common incidents and defers the ones that mainly improve evidence quality.

Suggested order of implementation for the nine controls
Order Control Why here
1MFA on staff accountsRemoves the single most common way in, in weeks not terms
2Restore testingTells you whether you can recover before you need to
3Privileged accessLimits how far a single compromised account travels
4Account lifecycleStops the backlog growing while you fix everything else
5Device managementSlower, and best aligned to a refresh or a holiday period
6Patching cadenceNeeds the device work done first to be measurable
7System registerA term of steady work; start it now, finish it later
8MonitoringWorth more once identity and endpoints are in order
9Incident planCheap, fast, and the one most likely to be skipped

Number nine is last only because it costs almost nothing and does not depend on the others. If you do one thing this month, do that one.

Questions

Is the Essential Eight the right framework for a school?

It is a reasonable structure, and several education jurisdictions reference it. Note that ASD announced in June 2026 that the Essential Eight will be replaced by a broader body of guidance called the Essentials. The underlying controls carry over, so uplift work is not wasted — but if your school has committed to a specific maturity level in a policy or a funding submission, that wording is worth revisiting.

We covered the transition in The Essential Eight is becoming the Essentials.

How do these controls apply to a BYO device programme?

Differently, and that is fine. On a family-owned device you are protecting the school's data rather than the device: application-level controls, conditional access that checks device health before granting access to school systems, and the ability to remove school data without touching anything else on the machine.

What you should not do is treat BYO as out of scope. It is where a growing share of school data actually lives.

Our provider says all of this is included. How do we check?

Ask for the evidence listed against each control above, in writing, with dates. Nine artefacts. A provider genuinely doing the work can produce most of them the same week, and will tell you honestly which ones they cannot.

A provider who responds with a description of their methodology rather than the artefacts has answered a different question.

What does this cost to close if we are starting from nothing?

The first four are mostly configuration and process rather than new spend — they cost labour, not licences, and a school can usually get through them in a term. Device management and monitoring carry per-user or per-device licensing, and are the ones worth sequencing against a budget cycle.

Non-profit and education licensing is significant, and many schools are not claiming everything they are entitled to. Worth checking before you approve anything.

Why Next Cyber

We produce the evidence column

Nine controls, nine artefacts, dated and measured. Handing over proof rather than a description of our methodology is the difference you are actually shopping for.

  • MFA and lifecycle. Registration state per account with exceptions reasoned, reconciled against staff and enrolment lists.
  • Privileged access. Reviewed on a schedule — including our own engineers’ access to your environment.
  • Measured restores. Date, system and elapsed time from a real test, not a recovery objective in a document.
  • Patch compliance, by month. Third-party applications included, with an exception path for week four of term.
  • Monitoring that acts. Rostered Australian engineers with standing authority to isolate a device out of hours.
  • A plan with names in it. Rehearsed with your leadership team, covering the regulator path for your sector.

Find out which of the nine you actually have

An assessment produces the evidence column for you — measured, dated, and written so a board or a leadership team can read it without a translator.