DIGITAL LIBRARY
SECURITY THREATS AND NETWORK PROTECTION IN EDUCATION: AN EMPIRICAL ANALYSIS OF CYBERSECURITY IN PRIMARY AND SECONDARY SCHOOLS
Palacky University (CZECH REPUBLIC)
About this paper:
Appears in: EDULEARN26 Proceedings
Publication year: 2026
Article: 2659
ISBN: 978-84-09-88444-5
ISSN: 2340-1117
doi: 10.21125/edulearn.2026.2659
Conference name: 18th International Conference on Education and New Learning Technologies
Dates: 29 June-1 July, 2026
Location: Palma, Spain
Abstract:
This study examines the state of cybersecurity in primary and secondary schools in the Czech Republic against the backdrop of growing digitalisation of the educational environment and an increasing frequency of cyberattacks. The research draws upon a quantitative questionnaire survey conducted in 2024 with a sample of 125 schools from various regions of the Czech Republic (77 primary and 45 secondary), supplemented by physical audits at five selected schools and interviews with headteachers and network administrators.

The theoretical section of the article systematises the typology of cyber threats according to the OSI reference model and describes the key security components, with particular attention devoted to ransomware and phishing as the two most serious threats in the school environment. The paper also addresses the emergence of generative artificial intelligence as a tool for automating spear phishing campaigns and generating malicious code.

The research findings reveal a marked disparity between the adoption rates of basic and advanced security technologies. Whilst 92 per cent of schools operate a firewall and 73 per cent employ antivirus software, EDR/XDR technology is used by a mere 14 per cent of institutions. IDS/IPS technology is declared as active by 52 per cent of schools; however, physical audits demonstrated that in many cases these systems are effectively non-functional, as licences for their advanced features were not renewed upon the expiry of the project funding period. Disk encryption is entirely absent in 63 per cent of schools.

Serious shortcomings were also identified in the management of mobile devices. Centralised management of tablets and Chromebooks—procured primarily under the Czech National Recovery Plan—is absent in 56 per cent of schools, whilst remote device administration is unavailable in 43 per cent. Backup practices likewise exhibit systemic deficiencies: 62 per cent of schools do not test data recovery procedures, and physical audits revealed that NAS devices serving as backup media had been inadvertently switched off in two of the four schools where network management was outsourced to an external provider, rendering them entirely non-functional.

With regard to security incidents, 45 schools in the sample reported experience of a cyberattack. Ransomware successfully compromised 14 schools, of which only 3 were able to restore their data from a backup. Phishing in various forms affected 24 schools. Of particular concern is the discrepancy between schools' subjective perception of their incident readiness—90 per cent of respondents assumed they would be capable of an immediate response—and the objective state of their security infrastructure, which does not support such confidence.

On the basis of these findings, the study formulates four key recommendations:
(1) systemic state-level funding of school cybersecurity, for instance through recurring grant schemes targeted specifically at security technologies;
(2) expansion of the National Pedagogical Institute's IT Guru programme to include penetration testing and phishing simulation exercises;
(3) the introduction of systematic training for network administrators; and
(4) the implementation of formalised security policies and crisis response plans as standard organisational procedures.
Keywords:
Cybersecurity, school, ransomware, phishing.