Sensitive children. Sprawling EdTech. A regulator and an insurer who are both paying attention.

Independent cyber security advisory for Australian Independent and Catholic K-12 schools — built to work alongside your MSP, not replace them.

Australian schools sit at the intersection of highly sensitive data — student records, NCCD information, safeguarding files, parent and family details, staff HR and finance — and an IT environment that has typically grown one EdTech vendor at a time, often without a single unified view of where the data lives. Compass, Sentral, Canva for Education, Mathletics, ClickView, parent portals, learning management systems, cloud storage, and now embedded AI features in nearly all of them.

The Australian Privacy Principles govern how schools collect, store and manage personal information. The Notifiable Data Breach scheme requires you to act within strict timeframes when something goes wrong. Cyber insurers now expect Essential Eight Maturity 1 attestation at renewal — and won't write the cover if you can't honestly tick the boxes. The OAIC is actively investigating school sector breaches. And staff have already started using ChatGPT, Copilot and Gemini for lesson plans, reports and admin — with or without a school AI policy in place.

Coastal Cyber works with Independent schools and Catholic schools (across Diocesan oversight, MACS, Sydney Catholic Schools, Brisbane Catholic Education and equivalents) to give you the independent governance assurance your Board, your insurer and your families expect — without competing with your MSP, internal IT team or Diocesan information services function.

Relevant services

  • Cyber Health Check — fixed-fee 10-day diagnostic against the ten non-negotiables
  • Privacy Act / APP compliance review for schools
  • Notifiable Data Breach readiness and tabletop exercises
  • Essential Eight Maturity 1 gap analysis and insurance attestation support
  • EdTech vendor and third-party risk oversight
  • Incident response planning — ransomware, data leak, social engineering
  • AI governance and GenAI use policy for staff and students
  • vCISO retainer — school-sector focus, works alongside your MSP
  • Board and School Council cyber briefings
Talk to us about protecting your school

Cyber risk doesn't take school holidays.

Book a free 20-minute call. We'll talk through your current position and tell you honestly whether the Health Check, the vCISO retainer, or neither is the right next step for your school.

Book a free call