Inside Our School IT Lunch & Learn: From Compliance to Resilience
9X5 Consulting | Education Technology
On 4th August 2026, we welcomed school ICT leaders and technology professionals to the 9X5 Consulting office for a Lunch & Learn, hosted by 9X5 Consulting and ManageEngine, focused on a topic that continues to dominate conversations across the education sector: how schools can strengthen cyber resilience while managing the realities of limited resources, growing compliance expectations, and increasingly complex technology environments.
Over lunch, attendees shared experiences from their own schools, discussed common challenges, and explored practical ways to move beyond simply meeting compliance requirements and towards building sustainable, long term security practices.
One theme emerged very quickly: schools today face many of the same cyber threats as large enterprises, but often without the same resources or dedicated security teams. From supporting BYOD programs and cloud applications to managing legacy systems and multiple campuses, school ICT teams are being asked to do more than ever before.
What We Can't See Can Hurt Us
The discussion wasn't centred on fear or worst-case scenarios. Instead, it focused on a more practical question: what does good cyber resilience actually look like for a school?
For many attendees, the answer began with visibility. Before schools can improve security, they need a clear understanding of their environment. Which devices are connected to the network? Which systems are missing critical updates? Who has administrative access? What software is being used across the organisation? These seemingly simple questions often reveal some of the biggest opportunities for improvement.
Looking Beyond Compliance
As the conversation evolved, we looked at the challenge through the lens of the Essential Eight. While many organisations think of the Essential Eight as a compliance framework, the group agreed that its real value lies in helping schools build stronger operational habits. Frameworks and security controls are important, but they are only effective when supported by consistent processes and clear accountability.
Patching and vulnerability management generated particularly lively discussion. Every school has a backlog of updates, vulnerabilities, and competing priorities. Rather than trying to fix everything at once, attendees explored the importance of identifying which risks matter most and focusing efforts where they will have the greatest impact. The consensus was clear: cyber resilience is not about chasing perfection, but about continuously reducing risk in a practical and manageable way.
Who Has Access to What?
The conversation also touched on one of the most common challenges facing educational organisations: balancing accessibility with security.
Whether it's students bringing their own devices, staff requiring access from multiple locations, or contractors supporting critical systems, schools must constantly navigate the tension between enabling productivity and maintaining control. Discussions around identity management, privileged access, and user governance highlighted just how important it is to ensure the right people have the right access at the right time.
Getting Ahead of the Next Incident
Another recurring topic was the shift from reactive to proactive IT operations.
Many schools still find themselves responding to issues after they occur, whether that's a security incident, a failed system, or an overdue audit. The group explored how better visibility, automation, monitoring, and reporting can help ICT teams spend less time firefighting and more time focusing on strategic initiatives that support both security and educational outcomes.
The Value of Shared Experiences
Perhaps the most valuable part of the session was hearing directly from peers. While every school is different, many participants discovered they were facing remarkably similar challenges. From managing scarce resources and technology debt to meeting board level expectations around cybersecurity, the shared experiences reinforced the value of bringing school IT professionals together to learn from one another.
As the event drew to a close, attendees were encouraged to reflect on a few fundamental questions:
- Do we have complete visibility of our technology environment?
- Are we confident in who has privileged access to critical systems?
- How prepared would we be if a significant cyber incident occurred tomorrow?
- Are we building processes that continuously improve our security posture rather than simply preparing for the next audit?
These questions don't require immediate perfection, but they do provide a starting point for meaningful progress.
Thank you to everyone who joined us for the conversation and generously shared their experiences and insights. The challenges facing school ICT teams will continue to evolve, but one message resonated throughout the event: cyber resilience isn't built through a single project or technology investment. It's built through visibility, operational discipline, and a commitment to continual improvement.
Get in Touch
Ready to Strengthen Your School's Cyber Resilience?
Connect with the 9X5 Consulting team to start a conversation about building a more secure, visible, and resilient IT environment for your staff and students.
Get In Touch →