A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by the Education Technology Insights Advisory Board.

The Kiski School

The Smarter Lock: A Pragmatic Cybersecurity Framework for Schools

Matthew Rosidivito

Technology Risk Advisor

Matthew Rosidivito, CISSP, serves as Director of Technology at The Kiski School, a private, co-educational boarding school in Saltsburg, PA. With extensive expertise in enterprise IT infrastructure and operational strategy, he specializes in building user-focused frameworks that enable intentional and safe innovation across educational institutions.

Pragmatism and compromise aren't words technologists commonly associate with security. But the rapid pace of technological innovation, and the stakeholder expectations that follow, mean these philosophies are essential when balancing technology with cybersecurity in schools. Overly prescriptive and rigid policies introduce friction into everyday operations and inevitably result in low adoption rates and even Shadow IT, where unapproved and unmanaged systems are used by faculty or staff seeking greater convenience. The question isn't whether we should enable innovation; it's how to achieve innovation while maintaining the safety and productivity of our schools.

This tension plays out uniquely in education. Schools must manage a demanding mix of requirements from faculty, students, parents and regulatory compliance. Identity management, networking, endpoint protection, risk assessment and strategic planning all require dedicated accountability from skilled professionals. Technology teams operate in an environment with complexity similar to that of an enterprise business, but with a fraction of the staffing and budget of their corporate counterparts. These realities tempt technologists to avoid new tools in favor of maintaining a predictable operational baseline, but rejecting innovation isn't neutral. Educators expect modern resources to support differentiated instruction. Parents expect seamless communication and payment systems. Administrative workflows depend on efficiency and reliability. Declining innovation carries its own institutional costs, which are measured in teacher satisfaction, enrollment competitiveness and community trust.

"Effective cybersecurity isn't about closing the door; it's about making a smarter lock."

As technologists, we are charged with facilitating change and advancing our industry. To do this safely and efficiently, we follow a risk-based approach starting with asset classification. Because not all systems require equal protection, this classification ensures optimal resource allocation. Student information systems, communication platforms and financial databases require the strongest controls, including encryption, multi-factor authentication and access logging. A breach of these systems leads to compromised privacy, legal ramifications and the erosion of trust. Digital textbooks, library catalogs and classroom projects should indeed be protected, but the reduced risk profile permits fewer controls. Mapping these assets to likely attack vectors reveals the overall attack surface, informing proportional control selection. A measured and proportional deployment of security countermeasures keeps friction low and security high.

Security works best when it doesn't get in the way. A teacher's account routinely accessing a file share from a managed device on the school's network may not require additional verification. An administrator's account logging into accounting software from a personal mobile device deserves additional scrutiny. These conditional access policies can be set up to trigger only where appropriate, preventing unnecessary friction but still protecting sensitive assets. Behind the scenes, modern endpoint protection watches for suspicious behavior and catches threats before they activate, while device management platforms facilitate software updates and device maintenance. These automated systems free technology staff to focus on new initiatives instead of constant firefighting. When an attack does surface, these same tools are force multipliers for tech teams and can turn a stream of unstructured data and confusing logs into a clear sequence of events.

The interpersonal component of information technology management is simultaneously the least technical and the most challenging aspect of the job. Unfortunately, it's also the most important. Technology controls won't solve security challenges if users don't understand why they exist and instead try to work around them. Regular training helps faculty and staff recognize phishing attempts, report suspicious activity and use approved tools confidently. When people feel equipped and supported by their technology tools and staff, adoption of approved tools and policies grows naturally while Shadow IT shrinks. Security is everyone's responsibility, but technology managers need to hold themselves accountable to lead the charge.

Some tools do carry significant risk and may exceed your organization's risk tolerance. Deciding how much risk your school can tolerate is a complex process that demands representatives across functions: from legal and technology to academics and athletics. Transparent communication and collaboration across departments ensure that strategic goals are kept in mind while considering the trade-offs of taking on some risk to achieve those objectives. For example, an AI application that ingests gradebook data presents a large compliance burden, but the benefits to the curriculum could be worth the risk. These discussions build trust between technologists and stakeholders. Sometimes security means saying "no"; other times it means slowing things down just enough to get it right. Both are acts of leadership.

Effective cybersecurity isn't about closing the door; it's about making a smarter lock. The institutions that will thrive during and after the AI age will be those whose security professionals are willing to collaborate across departments, weigh risks and responsibly enable innovation while staying mission-driven. AI tools, cloud services and new learning technologies will continue to accelerate, so building a framework that is user-focused and security-conscious from the ground up will ensure that your school can nimbly navigate these changes. When security and innovation work together, everyone wins: students learn safely, educators teach freely and trust compounds over time.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.

Weekly Brief