Managed IT services for Australian schools in 2026

Two of the largest incidents to hit Australian education this year did not start inside a school. They started at a supplier. That changes what you should be buying, and what you should be asking a provider to be accountable for.

Most writing about managed IT services for schools is written for businesses and has the word “school” substituted in. It usually misses the two things that make a school different: you hold detailed records about children, and a large part of your environment is operated by somebody else.

This is a guide to evaluating a provider with those two facts in front of you. It applies to independent and Catholic schools choosing their own provider, and to government schools buying anything that sits outside the departmental build.

What changed this year

Three events from the first half of 2026 are worth having in mind, because they set the questions you should be asking.

In January, the Victorian Department of Education disclosed that an unauthorised party had accessed a database holding student information from all of its government schools — names, school-issued email addresses, year levels, school names and encrypted passwords. The department reset student passwords across the system, and the Office of the Victorian Information Commissioner opened an investigation.

In early May, Instructure disclosed a breach of its cloud environment. Canvas is the learning management system for a great many institutions worldwide, and the Australian impact ran to well over a hundred organisations, including Queensland state schools, TasTAFE and several universities. Names, email addresses, student identifiers and messages exchanged inside the platform were affected.

In June, an Adelaide secondary college notified families of an incident, and a fortnight later the group responsible published hundreds of gigabytes of what it claimed was school data on a leak site.

Read together, they say something specific. One was a departmental system, one was a global vendor, and one was a single school. The single school is the only one where a local IT provider would have had the access to prevent it — and it is the one that ended with data published. The other two are the reality of a modern school environment: you are accountable for information you do not host, on platforms you cannot patch.

Which privacy law applies to you

This is the first thing to establish, because IT security and compliance obligations differ by sector and a provider who cannot tell them apart will design to the wrong one.

  • Non-government schools — independent and Catholic — are generally covered by the Commonwealth Privacy Act and the Australian Privacy Principles. The small business exemption is little help: most schools are over the $3 million turnover threshold, and a school that runs a health or counselling service handles health information, which brings the Act into play regardless of turnover. The Notifiable Data Breaches scheme applies.
  • Government schools sit under their state or territory privacy legislation and information commissioner rather than the Commonwealth Act. Several jurisdictions now have their own mandatory notification regimes — New South Wales public sector agencies have been under one since November 2023 — and the reporting path, the regulator and the record-keeping obligations are all different.

Then there is the Children's Online Privacy Code, which the OAIC is required to register by 10 December 2026. The Code binds online service providers rather than schools directly, but its drafting has been widened to reach services “primarily concerned with children's activities” — which is a description of most of your EdTech stack, including systems that report student progress to parents and share photographs. Schools will feel the Code through supplier contracts, default settings and consent flows over the next couple of years, not through a new obligation of their own.

General information about regulatory obligations, not legal advice. Which regime applies to your school, and what it requires, is a question for your own counsel or your association's legal service.

Why a school is not just a small business with a bell

A 900-student school has the seat count of a mid-sized business and none of the simplifying assumptions. Four differences matter when you are scoping managed IT support.

The population turns over completely
A cohort arrives every January and another leaves every December, and casual relief staff arrive weekly. Identity lifecycle is not an annual tidy-up, it is a term-by-term process that has to be automated from the student information system or it will not happen.
Some of your users are adversaries
Not maliciously, usually. But a school network is the only environment we work in where a meaningful share of users actively try to get around the controls, have time to do it, and share what works. Filtering and device policy have to survive that.
The maintenance window is the holidays
Which are also when the site is least staffed. Anything that requires downtime has to be planned around a calendar that is fixed years in advance, and a provider who cannot resource January and the mid-year break is not much use to you.
Parents are stakeholders, not customers
An outage in the parent portal or a mishandled notification becomes a community conversation within an hour. The communications side of an incident is a real part of the work, and it should be in the plan before you need it.

What the scope should actually cover

A proposal for a school should name these explicitly. If it does not, they are either missing or chargeable.

  • Identity and account lifecycle for staff, students, casual relief and contractors, driven from the SIS, with revocation on the same day someone leaves.
  • Device management across school-owned fleets and BYO programmes, including the shared-device and trolley scenarios that break most standard builds.
  • Backup and tested restore covering the student information system, the LMS, Microsoft 365 or Google Workspace, and finance — with a measured recovery time, not a target.
  • Monitoring and response with a stated authority to act out of hours, and a named path to a human when something is actually happening.
  • Filtering and online safety tooling, including how alerts about student wellbeing reach the right staff member rather than an inbox nobody owns.
  • Vendor and integration management — the SIS, LMS, library, canteen, sports and parent communication systems, and every integration between them.
  • Incident response, including the notification decision, the regulator path for your sector, and who drafts the letter to families.

The last one is the one most often left out, and it is the one that hurts. We have written separately about the nine controls a school should expect to see, with what evidence to ask for against each.

The EdTech supply chain is your real attack surface

Count the third-party systems holding student data at your school. In our experience the honest number is somewhere between twenty and sixty, and roughly a third of them were signed up by a faculty rather than by the business manager.

Every one of those is a place your students' data can leak from, and almost none of them are in your provider's monitoring. This is precisely how the Canvas incident reached Australian schools: nothing was wrong inside the school.

The mechanism that exists to help here is Safer Technologies 4 Schools (ST4S), administered by Education Services Australia for the state and territory departments, the Catholic and independent sectors and the New Zealand Ministry of Education. It assesses digital products against a consistent privacy and security control set and publishes reports through a catalogue available to education jurisdictions. It is the closest thing Australian education technology has to a common baseline, and it costs you nothing to make an ST4S assessment the first question you ask about any new product.

A provider working with schools should know what ST4S is without being told, should maintain the register of what you have connected to your tenant, and should be reviewing OAuth consents and app permissions as a standing item rather than when something goes wrong.

A quick test of your current position: ask for a list of every third-party application with access to your Microsoft 365 or Google tenant, and who approved each one. The length of the pause is the finding.

Reading a proposal without a technical background

Most people making this decision are a business manager, a principal or a board finance committee. You do not need to assess the technology. You need to assess whether the commitments are real, and there are four tells.

  1. Numbers with units. “Rapid response” is not a commitment. “P1 acknowledged within 15 minutes, 24/7” is one, and it can be measured against later.
  2. Named exclusions. Every managed service has boundaries. A proposal that does not list them has not removed them, it has deferred the conversation to an invoice.
  3. Evidence, not description. Where a proposal says it will do something regularly, ask what artefact proves it happened — a restore test report, a patch compliance figure, an access review sign-off.
  4. An exit clause you understood on first reading. Notice period, exit assistance rate, and exactly what is handed over. Tenants and licences should be in the school's name, not the provider's.

Our longer buyer's guide to choosing managed IT services in Australia works through the comparison in more depth, and applies to schools as much as to any other buyer.

Questions

Is a general MSP good enough, or do we need an education specialist?

A general provider with genuine school experience is usually the better outcome. The technical work — identity, endpoints, backup, monitoring — is not education-specific. What is education-specific is the SIS and LMS integration knowledge, the term calendar, the child-safety dimension of filtering, and the notification path for your sector.

Ask how many schools they currently support and speak to one of them. A provider with two school clients and a strong security practice is generally safer than one with twenty schools and no security practice.

We are a government school. Does any of this apply to us?

Partly. Your core build, network and identity are usually departmental and outside your control. What is inside your control is everything the school procures itself: faculty software, parent communication tools, the school website, event and payment systems, and any device fleet bought from school funds. That is a real environment with real student data in it, and it is frequently unmanaged.

How much should a school expect to pay?

Managed services are usually priced per user or per device, so the honest answer is that it depends on how you count students. What we would suggest is asking every provider to quote on the same basis — staff FTE, student headcount, or total devices — and to state which. Proposals quoted on different units cannot be compared, and that is occasionally the point.

Who tells families if there is a breach?

The school. A provider can assess the incident, establish what was accessed, and draft the material — but the notification decision and the relationship with your community belong to you, and a provider offering to own either is offering something they cannot deliver.

What you should insist on is that the decision process exists in writing before you need it, and that it names people rather than roles.

Our website is separate from our IT. Does that matter?

It matters more than most schools expect. The website is where enrolment enquiries, payments and family contact details arrive, it is usually the oldest system you own, and it is often the only one with no patching owner. We have written about website security for schools separately.

Why Next Cyber

The provider we would want running a school

Student data, a term calendar, and an EdTech supply chain you do not control. Schools are where one genuinely accountable provider is worth the most, and where we have built for it deliberately.

  • Identity built on the SIS. Staff, students, casual relief and contractors provisioned and revoked from one authoritative source.
  • Devices, including the trolleys. Shared-device mode, BYO programmes and specialist labs, not just the staff laptop fleet.
  • Tested restores. SIS, LMS, Microsoft 365 or Google Workspace and finance, with a measured recovery time.
  • The supply chain on a register. Every third-party system holding student data, with its ST4S status and an approver against each.
  • Rostered overnight, onshore. Australian owned and staffed, with security cleared personnel available.
  • Notification support, not ownership. We produce the timeline and draft the material. The decision and the community stay yours.

Start with what you actually have

An assessment gives you the list of systems holding student data, who can reach them, and which of them nobody is patching. It is a better first conversation than a proposal.