Data leak, intrusion, or suspected security incident? Report a security incident immediately.

Report security incident
EBH Security

Cybersecurity for Education · Training & Awareness

Cybersecurity training and awareness for the education sector in Morocco

In schools, universities and training centers, IT budgets are often limited and dedicated security teams rare. The human factor — recognizing a phishing email, adopting good authentication habits — remains the most cost-effective security lever, in a sector where phishing is the leading entry point for ransomware.

+23%

year-over-year rise in ransomware attacks on the education sector (2025)

Comparitech Education Ransomware Roundup 2025

Why training is the priority lever in education

Ransomware attacks against the education sector rose more than 20% in a single year, and phishing remains the main entry vector: a deceptive email clicked by a single administrative staff member can be enough to compromise an entire school or university network.

Unlike other sectors, education rarely has a security budget comparable to a bank or an industrial company. Training and awareness offer a particularly favorable cost-to-impact ratio: they reduce risk at the source without requiring heavy technical investment.

Concrete risks in schools and universities

Administrative staff with access to financial or payroll systems are a prime target for fake-vendor or urgent-wire-transfer fraud, a targeted phishing scenario that's especially effective without trained vigilance. Student accounts, often protected by weak or reused passwords across multiple platforms, are another massive entry point given the sheer volume of users.

Multi-factor authentication is often missing or poorly deployed on student and staff accounts, and the use of personal devices (BYOD) to connect to institutional systems further widens exposure, outside the IT team's direct control.

What an awareness program means in an educational setting

An effective program distinguishes audiences: phishing simulations and targeted messaging for administrative and finance staff (particularly exposed to fraud), tailored workshops for teaching staff, simplified awareness for students on password hygiene and recognizing phishing attempts. Generic content, identical across all profiles, quickly loses effectiveness.

Measuring progress over time — through repeated campaigns and maturity tracking — is essential to adjust the program, and is coordinated with an IT team that's often already stretched thin by daily operations.

Go further

See the full presentation of Training & Awareness or all our solutions for Cybersecurity for Education.

FAQ

Frequently asked questions

Both, but with differentiated content: administrative and finance staff need in-depth awareness of targeted fraud, while students mostly benefit from simple messaging on password hygiene and recognizing phishing.

Next step

Take stock of your security posture

Let's discuss "Training & Awareness" applied to your industry.