As the school year began, cybersecurity vendor Barracuda Networks highlighted an opportunity for managed services providers in education, where security management remains a major challenge for IT teams. Schools, colleges and universities are particularly susceptible to ransomware delivered via email, according to Barracuda research published this month.
Through its research arm, Barracuda detected 58.8 million phishing emails targeting 536 education institutions over three months — equivalent to approximately 1,200 per institution each day. The volume underscores the pressure on defenses, although the detection data did not establish how many attacks succeeded. It also illustrates the difficulties IT teams face supporting large, diverse user populations with limited security resources.
The company surveyed 2,000 IT and security leaders in the U.S., Europe and Asia Pacific region, including 113 in education, as part of the study. Despite reporting high rates of email-driven ransomware and account takeover, only 56% or educational institutions could secure accounts and restore operations within a day of an email security incident, the research found.
More than one-third of respondents reported successfully detecting and blocking phishing attacks. Yet education organizations were four times more likely than the global average to admit they couldn’t confirm every email security incident. The uncertainty indicates some attacks may have gone undetected.
“Effective cybersecurity is about more than threat prevention; it is about being able to identify and neutralize incidents before they have a chance to unfold into something more damaging such as ransomware,” Barracuda said in a release accompanying the report.
Investigation and recovery warrant particular attention for MSPs assessing customers’ response capabilities.
Only 58% of education respondents were able to investigate suspicious email activity within a day, compared with 66% overall. Just 56% had the capabilities to secure accounts and restore operations within that period, versus 64% overall.
Nearly 1 in 5 educational institutions surveyed took up to a week to restore normal operations after an incident. That was the highest proportion across industries, Barracuda said.
The company warned in the report about the potential consequences of delays.
“Skills shortages and operational pressures appear to be extending the time attackers can remain active in compromised environments, increasing the potential impact of an incident,” the company said.
Security lapses are more than just a technology issue.
In education, more than a third of respondents said they lacked sufficient expertise in rapid incident response. One-third acknowledged they were slow to react to live incidents..
An expertise gap is a business opportunity for MSPs and managed security services providers. Partners can provide security audits, process improvements and response protocols.
Educating the educators is also an area that needs attention. More than half of respondents in education cited human error and user behavior as leading contributors to incidents.
Technology upgrades also have a role to play. More than 2 in 5 respondents at educational institutions said they would welcome trustworthy AI-assisted detection and investigation tools — the highest percentage among industries surveyed by Barracuda.
Brenda Wall, major account sales representative at Marco Technologies, a national business technology and IT services provider, said combining industry research with customer assessments helps districts prioritize security spending.
“We've found that pairing outside research like Barracuda's with our own technology assessments gives school districts something they rarely get: a clear, prioritized picture of where their actual risk sits,” Wall told Channel Dive. “Budget-conscious administrators don't push back on data — they push back on guesswork.”