What if we run a school or university?
Education holds a combination almost nobody outside healthcare matches: records about children, kept for decades, on some of the thinnest technology budgets of any sector.
A student record created today follows a person into adulthood. Disciplinary records, disability and special-education files, counseling notes, immigration status, family circumstances, and health information all attach to somebody who will be in their thirties and forties while that record still exists somewhere. Almost none of it stops being sensitive.
Universities add two further problems on top: research data with no expiry at all, and a hospital in many cases.
The short version:
- Student records are about minors and outlive their childhood, which is a longer horizon than most commercial data carries.
- Special-education, counseling, and health files sit at the top, because they carry lifetime consequence.
- Your estate is mostly vendor products, which makes the work a set of emails rather than a program.
- Universities hold 3 problems at once: student records, research data, and often a health system.
- Procurement is the lever, particularly for the long-lived equipment in buildings.
- A district can do the useful parts without a security team.
Why are student records a long-horizon problem?
Because of who they’re about and how long they persist.
A commercial customer record ages into irrelevance. A record about a 9-year-old does the opposite: it describes somebody at their least able to consent, and it stays attached to them through every stage of life where it could be used against them. A disability diagnosis, a disciplinary incident, a counseling referral, or a record of family circumstances carries consequence into employment, insurance, immigration, and custody decisions decades later.
Institutions also retain far longer than most sectors. Transcripts and enrollment records are frequently permanent by design. Special-education files carry multi-year retention obligations after a student exits. Health and immunization records follow the same clocks as any medical record.
The categories that matter most:
| Category | Why it’s the worst case |
|---|---|
| Special education and disability files | Diagnoses and evaluations that stay true and stay consequential for life |
| Counseling and mental-health notes | The most sensitive material an institution holds about a minor |
| Discipline records | Used against people long after the conduct is irrelevant |
| Immigration and family status | Where exposure can be a safety question. See If you are a high-risk person |
| Health and immunization | Same lifetime clock as any clinical record |
| Transcripts and enrollment | Frequently retained permanently |
What does a university add?
Two more problems, both larger than the student-records one.
Research data has no expiry. Genomic datasets, longitudinal cohort studies, and clinical trial data stay sensitive indefinitely, frequently outliving the study, the grant, the investigator, and sometimes the institution. Human-subjects data carries confidentiality promises made to participants who cannot be re-consented years later. This is the same category the Guide identifies as the worst case for any organization.
An academic medical center is a hospital. If your institution operates one, everything at What if we run a clinic or hospital applies in full, including the connected-device problem.
A third, smaller one: universities hold intellectual property in pre-patent research, which behaves like a trade secret and has the same absence of an expiry date.
What can we actually do on an education budget?
Six things, none of which require a security hire.
- Send the vendor question to your student information system, learning platform, and email provider. Three emails. Those 3 hold most of what matters. The template at What if we are a small business works unchanged.
- Put a post-quantum requirement into technology procurement, including the state or consortium contracts most districts buy through. This is free and it reaches suppliers serving thousands of institutions.
- Identify which record categories carry lifetime sensitivity. Special education, counseling, health, and immigration status sit at the top. This is a records-office exercise rather than a technical one.
- Review retention against what the rules actually require. Education retains heavily by habit, and material kept past obligation is exposure the institution chose to carry.
- Name an owner. In a district this is often the technology director; in a university it needs somebody who can reach both central IT and the research side.
- For universities, ask the research office separately. Research data frequently sits outside central IT entirely, on grant-funded infrastructure nobody else inventories.
Why is buying through a consortium an advantage?
Because it concentrates the leverage that individual institutions lack.
Most districts and many institutions purchase through state contracts, regional consortia, or cooperative purchasing agreements. A post-quantum requirement added at that level reaches every member at once and carries far more weight with a supplier than any single district could.
If your institution buys through such a vehicle, the highest-value action available is raising the requirement with the consortium rather than with the vendor directly. That’s a single conversation that moves an entire purchasing bloc.
What about the buildings?
The category most institutions forget, and the one where the cost is capital rather than software.
Access control, cameras, HVAC and building management, bell and PA systems, and campus card infrastructure all carry cryptography, frequently fixed at manufacture, on equipment nobody plans to replace for 15 years. A card reader installed in 2027 will still be installed in 2042.
That makes procurement the only lever that works. Equipment bought now sets the exposure, and asking the question at purchase costs nothing.
Questions people ask
Does student privacy law require this? No education privacy statute names post-quantum cryptography. The obligations are general standards about protecting records, interpreted against what was publicly known, and the replacement standards have been public since August 2024.
We have 2 people in IT for the whole district. Then the 3 vendor emails and the procurement question are your entire program, and they’re genuinely most of the available value.
Our systems are all cloud-based now. Are we fine? Providers migrate their own infrastructure, and a substantial share of configuration stays on the customer side. It also means the vendor question is the right one to ask, which is the easier position. See What can I not fix myself.
What about the research data nobody knows about? That’s the common finding at universities. Grant-funded infrastructure, departmental servers, and individual investigators’ storage frequently sit outside any central inventory, and surfacing them is worth more than any technical fix.
Should we tell parents or students? Only if asked, and then honestly. The accurate answer for most institutions is that records are encrypted, the encryption is being replaced industry-wide, and you’ve asked your vendors for timelines.
Is anyone in education actually doing this? Few institutions in any sector are finished, and education is not further behind than comparable public bodies. The standards were only finalized in August 2024.
Where to go next
- Where do we actually start is the first 90 days for any organization.
- What if we run a clinic or hospital applies if you operate an academic medical center.
- What can I not fix myself covers the vendor question in depth.
- What of our company data is at risk covers the data-lifetime sort.
- For Business Leaders MOC is the full business route.
Last verified 2026-07-31 · Maintained by Addie LaMarr, LaMarr Labs.