Home / Purple Team Services / Education Sector
Education Sector
Three Real-World Purple Team Engagements | Fully Anonymised | ISO 17025 Accredited Methodology
ISO 17025 Accredited · MITRE ATT&CK v15 · All engagements conducted under explicit written authorisation
Sector
Education
Engagement
Purple Team Exercise
ATT&CK Tactics
MITRE ATT&CK v15
Location
United States
About These Case Studies
The following case studies describe real purple team engagements conducted by GLI Secure across education sector organisations. All identifying details — organisation names, locations, system names, and personnel — have been fully anonymised. Statistical outcomes, detection improvements, and regulatory findings are accurate as documented during and after each engagement.
All purple team exercises described in this document were conducted under explicit written authorisation from the client organisation, using GLI Secure’s ISO 17025-accredited testing methodology. MITRE ATT&CK technique IDs are referenced as documented in ATT&CK Enterprise Framework v15.
Confidentiality Notice: These case studies anonymised; any resemblance to specific organisations is coincidental.
Case Study EDU-CS-01
EdTech Supply Chain Attack — K-12 School District
Testing detection and response against a PowerSchool-style vendor compromise targeting student records
Organisation
A suburban K-12 school district with 28,000 students and 180+ active EdTech applications (anonymised)
Sector
Education — K-12 public school district
Location
Pacific Northwest, United States
Engagement
Purple Team Exercise — EdTech Vendor Access and Student Data Exfiltration
Duration
5 weeks (2-week scoping, 1-day exercise, 2-week remediation)
Frameworks
FERPA 34 CFR Part 99 | COPPA | State student data privacy law | NIST SP 800-171 | MITRE ATT&CK Enterprise v15
The Situation
The PowerSchool breach in 2025 exposed the sensitive data of more than 60 million US students and teachers. The district’s IT Director recognised his own SIS vendor had similar maintenance access configurations. The district used 180+ active EdTech applications. It had never assessed the security of any of them.
The district had no dedicated cybersecurity staff. Security decisions were made by the IT Director and a team of four infrastructure administrators. The concept of a purple team exercise was new to all of them — but after PowerSchool, the IT Director had concluded that understanding vendor access risk was non-negotiable.
The specific scenario to test: if someone compromised the SIS vendor’s support account — exactly as happened with PowerSchool — what could they reach, what could they take, and would anyone notice?
Core Challenge
Determine whether a compromised EdTech vendor support account could access student PII at scale and whether any existing control would detect or prevent the exfiltration — mirroring the PowerSchool attack mechanism.
What GLI Secure Did
We began with an EdTech vendor access audit — the first the district had ever conducted. We mapped all 180+ applications, identified which had access to student PII, reviewed Data Use Agreements in place, and documented access pathways for each vendor.
The exercise simulated a compromised SIS vendor support account with credentials scoped to mirror the real vendor’s maintenance access level. We tested what the account could reach and whether any activity would trigger an alert.
We also tested the district’s FERPA incident response capability — specifically how quickly they could identify the scope of an exposure, activate the FERPA notification process, and revoke vendor access.
The Purple Team Approach
EdTech Vendor Access Audit
Catalogued all 180+ EdTech applications. Found: 67 had access to student PII, only 12 had FERPA-compliant Data Use Agreements, 8 had access broader than their contracted educational purpose, 4 vendors had never responded to the district's security questionnaire.
SIS Vendor Support Access Simulation
Using a test account configured to mirror the SIS vendor's maintenance access, tested what the account could reach. Found: full read access to all student demographic records, emergency contact information, and attendance data for all 28,000 students.
Bulk Data Access Test
Simulated bulk export of student records via the vendor maintenance interface. Found: no access controls on export volume, no alert on bulk exports, and no logging of vendor access sessions at the district level.
Data Staging and Exfiltration
Tested whether data staged during vendor access could be exfiltrated without detection. Found: DLP controls did not apply to the vendor access pathway — exfiltration through the vendor's remote session channel generated no alert.
FERPA Incident Response Activation
Found: no documented FERPA notification workflow, unclear who was responsible for notifying parents, no communication template for a student data breach scenario.
Vendor Access Revocation
Found: only one IT staff member knew the vendor access revocation process, and that individual was not available during the exercise day — a single point of failure in breach response.
MITRE ATT&CK Techniques Tested
| ATT&CK ID | Technique | Detection Result |
|---|---|---|
| T1199 | Trusted Relationship (SIS Vendor Access) |
NOT DETECTED
No vendor session monitoring at district level. |
| T1530 | Data from Cloud Storage (SIS Student Records) |
NOT DETECTED
No anomaly detection on data access volume. |
| T1048 | Exfiltration via Vendor Channel |
NOT DETECTED
DLP does not cover vendor remote session traffic. |
| T1213 | Data from Information Repositories |
NOT DETECTED
Logging not enabled on SIS maintenance... |
| T1078 | Valid Accounts (Vendor Credentials) |
NOT DETECTED
No behavioural monitoring on vendor accounts. |
Key Findings
Critical
55 of 67 Apps Without FERPA Data Use Agreements:
55 EdTech applications accessing student PII had no FERPA-compliant DUA. Each represents an active FERPA violation — the district is sharing student records without required contractual protections.
Critical
Zero Vendor Session Monitoring:
No monitoring existed on any vendor remote access session. The PowerSchool attack mechanism was directly replicable in this environment.
Critical
No FERPA Breach Response Capability:
No documented FERPA notification workflow existed. In a real breach, the district would be unable to notify affected families within the legally expected timeframe.
High
Bulk Export Without Restriction:
The SIS maintenance interface allowed unlimited bulk export of all 28,000 student records in a single session.
High
Single-Person Access Revocation Knowledge:
Only one IT staff member knew the vendor access revocation procedure. If unavailable, the compromised access cannot be revoked.
Measurable Outcomes
| DUA Coverage | Increased from 12 to 67 applications within 90 days |
| Apps Without DUA | 8 applications suspended pending DUA completion |
| Vendor Session Monitoring | Monitoring deployed for all 12 highest-risk vendor connections |
| FERPA Response Plan | Documented workflow created with 3 trained staff members |
| Access Revocation | Procedure documented and 3 staff members trained |
| SIS Export Controls | Volume limits and alerting implemented on SIS maintenance exp... |
Regulatory Impact
55 EdTech applications without FERPA-compliant Data Use Agreements represents a systemic FERPA compliance failure. FERPA requires written agreements with any third party that accesses education records, specifying that the third party will not redisclose the records. Every application without a DUA creates independent FERPA exposure.
The PowerSchool breach specifically highlighted the DUA gap — districts with DUAs had contractual leverage that districts without DUAs did not. The PowerSchool litigation involving 100+ school systems was structured in part around the adequacy of DUA protections.
The absence of a documented FERPA breach notification process is itself a compliance gap. State student data privacy laws in over 40 states create notification obligations that the district had no process to satisfy.
“
After PowerSchool, I asked myself: if our SIS vendor was compromised tomorrow, would we know? The purple team exercise answered that question: no. We had 55 EdTech apps accessing student data without any data use agreement. We had no monitoring on vendor sessions. We had no breach response plan. We were exactly as vulnerable as every district affected by PowerSchool.
— IT Director, K-12 School District (anonymised)
Key Takeaways
- The PowerSchool attack mechanism is replicable in nearly every US school district. The distinguishing factor is whether vendor access is monitored and whether DUAs are in place.
- The PowerSchool attack mechanism is replicable in nearly every US school district. The distinguishing factor is whether vendor access is monitored and whether DUAs are in place.
- Single-person knowledge dependencies in security response procedures are a systemic vulnerability in under-resourced school districts. Critical procedures must be documented and cross-trained.
- Purple team methodology is accessible to organisations without dedicated security teams. The exercise was structured around the district’s actual resources and produced findings a four-person IT team could act on.
Case Study EDU-CS-02
Ransomware Simulation, Mid-Sized School District
Testing backup integrity and recovery capability against a Rhysida-style summer break attack
Organisation
A K-12 school district with 41,000 students operating 52 schools (anonymised)
Sector
Education — K-12 public school district
Location
Southwest United States
Engagement
Purple Team Exercise — Ransomware Attack and Business Continuity Validation
Duration
6 weeks (3-week planning, 2-day exercise, 1-week remediation and SLCGP documentation)
Frameworks
FERPA | COPPA | CISA K-12 Cybersecurity Act | NIST SP 800-171 | NIST SP 800-171 | MITRE ATT&CK Enterprise v15
The Situation
In summer 2025, a Rhysida ransomware attack encrypted the entire IT infrastructure of a school district three states away during the July maintenance window — with school scheduled to start in 6 weeks. The district paid the ransom. The superintendent of the district in this case study read every article and recognised his district’s identical profile: similar infrastructure, similar security staffing (two IT staff with no dedicated security expertise), similar budget constraints.
The state education agency had announced SLCGP grant funding was available, but accessing it required documentation of security programme gaps. The district conducted a purple team exercise to determine both whether a Rhysida-style attack would succeed and to produce the gap documentation required for the SLCGP application.
The defining question: how long would the district be down, and would backup systems actually enable recovery within the school start deadline?
Core Challenge
Determine whether the district’s backup systems would enable recovery from a complete ransomware encryption event within the school start deadline, and identify the specific gaps that SLCGP grant funding should address.
What GLI Secure Did
The exercise combined a technical simulation testing ransomware precursor detection and backup integrity, with a business continuity test examining whether the district could maintain essential operations during an extended IT outage.
The scenario used the Rhysida attack profile: initial access via an unpatched internet-facing VPN, lateral movement across the district’s flat network, and simultaneous encryption of administrative and SIS systems.
The backup restoration test was the most consequential element: an actual partial restoration from available backup systems, measuring the real time required against the school start deadline.
The Purple Team Approach
Network Architecture Review
Finding: completely flat network, no VLAN segmentation between administrative systems, SIS, and classroom infrastructure. An attacker who compromised one system had unrestricted access to all systems.
Internet-Facing Vulnerability Scan
Found: VPN appliance running firmware 14 months out of date with a documented critical CVE exploited in the comparable Rhysida district attack.
Backup System Audit
All backups were on network-connected storage accessible from the administrative network. No offline backups existed. SIS backup jobs had been failing silently for 3 months, meaning no usable SIS backup existed.
Ransomware Simulation (Isolated Environment)
Using isolated test systems, simulated ransomware encryption to measure recovery scenarios. With no offline backups, the only recovery pathway for most systems was a full rebuild from scratch.
Recovery Timeline Modelling
Ransom payment: 4-6 days (uncertain outcome). Rebuild from scratch: 4-8 weeks. Partial recovery using available backups: 2-3 weeks for systems with working backups. School start deadline: 6 weeks away.
SLCGP Gap Documentation
Documented all gaps in SLCGP application format: specific control gaps, risk narrative, proposed remediation, and cost estimates for grant-eligible security improvements.
MITRE ATT&CK Techniques Tested
| ATT&CK ID | TECHNIQUE | DETECTION RESULT |
|---|---|---|
| T1190 | Exploit Public-Facing VPN Appliance |
NOT DETECTED
No EDR on network devices. CVE confirmed exploitable. |
| T1021 | Remote Services (Flat Network Lateral Movement) |
NOT DETECTED
No east-west traffic monitoring. |
| T1486 | Data Encrypted for Impact (Test Systems) |
NOT DETECTED
No ransomware behavioural detection on servers. |
| T1490 | Inhibit System Recovery (Backup Access) |
NOT DETECTED
Backups accessible and enumerable with no alert. |
| T1566 | Phishing (Staff Account Compromise Alternative) |
DETECTED
Email security quarantined simulated phishing in under 2 minutes. |
Key Findings
Critical
No Viable Recovery Pathway:
No offline backups existed. All backup storage was network-accessible and would be encrypted simultaneously with production systems. The district had no recovery option meeting the school start deadline without paying ransom.
Critical
SIS Backup Failure, 3 Months of Data Loss:
The SIS backup job had been failing silently for 3 months. In a ransomware event, the district would lose 3 months of student records including enrollment changes, grade updates, and attendance data.
CRITICAL
Unpatched VPN with Known-Exploited CVE:
No documented FERPA notification workflow existed. In a real breach, the district would be unable to notify affected families within the legally expected timeframe.
High
Flat Network:
All district systems were on a flat network. A single compromised workstation had unrestricted access to the SIS, payroll, financial systems, and all administrative infrastructure.
Measurable Outcomes
| VPN CVE Patched | Within 48 hours of exercise |
| Offline Backup Implementation | Air-gapped backup solution implemented within 45 days |
| SIS Backup Monitoring | Backup job monitoring with failure alerting implemented |
| Server EDR | EDR deployed to all servers within 60 days |
| SLCGP Application | Grant application submitted using exercise documentation |
| SLCGP Grant Awarded | $847,000 for network segmentation and security tooling |
Regulatory Impact
The exercise produced the gap documentation required for the SLCGP application. SLCGP requires applicants to document specific security programme gaps, provide a risk narrative, and propose remediation aligned with the state cybersecurity plan. The exercise findings provided this evidence base.
The SIS backup failure has direct FERPA implications. A three-month data loss scenario following a ransomware event would compromise the district’s ability to certify the accuracy of student records for federal funding purposes.
The CISA K-12 Cybersecurity Act requires the National Cyber Director to provide recommendations to K-12 educational agencies on cybersecurity risks. The VPN CVE and flat network architecture align directly with CISA’s documented top attack vectors for K-12 ransomware incidents.
“
We went into the exercise hoping to learn something useful. We came out learning that if Rhysida had hit us on a Friday in July, we would have paid the ransom or started the school year without functioning systems. Finding that out in a controlled exercise, and then using the findings to secure $847,000 in federal grant funding, that is the best return on an IT security investment we have ever made.
— Superintendent, K-12 School District (anonymised)
Key Takeaways
- SLCGP grant documentation is one of the highest-value outputs of a purple team exercise for under-resourced school districts. The exercise findings provide the evidence base that grant applications require.
- Flat networks are the single most impactful architectural vulnerability in K-12 ransomware defence. A single compromised workstation with unrestricted network access can reach every system in the district.Silent backup failures are one of the most dangerous vulnerabilities in education IT. Backup jobs that fail without alerts leave districts believing they have a recovery capability they do not have.
- Flat networks are the single most impactful architectural vulnerability in K-12 ransomware defence. A single compromised workstation with unrestricted network access can reach every system in the district.Single-person knowledge dependencies in security response procedures are a systemic vulnerability in under-resourced school districts. Critical procedures must be documented and cross-trained.
- Rhysida deliberately times attacks at the start of summer break. Minimum IT staffing, the school start deadline, and absent offline backups maximise the pressure to pay ransom quickly.
Ready to test your Education security defences?
Case Study EDU-CS-03
Research University, CMMC 2.0 Adversarial CUI Assessment
Preparing a research university’s defence-funded computing environment for C3PAO certificationTesting backup integrity and recovery capability against a Rhysida-style summer break attack
Organisation
A research university with $340M in annual federal research funding and 14 active DoD contracts (anonymised)
Sector
Education, Research university, doctoral-granting institution
Location
Mid-Atlantic United States
Engagement
Purple Team Exercise, CUI Environment Adversarial Assessment and CMMC 2.0 Gap Analysis
Duration
10 weeks (4-week scoping, 3-day exercise, 3-week gap report and SSP development)
Frameworks
CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2, 110 practices) | DFARS 252.204-7012 | EAR/ITAR | FERPA MITRE ATT&CK Enterprise v15
The Situation
CMMC 2.0 requirements became active in DoD contracts in November 2025. The university held 14 active DoD contracts requiring Level 2 compliance. The Sponsored Research Office had invested significantly in preparing the research computing environment, but had never had an independent adversarial assessment of whether those preparations were effective.
The FBI had briefed the university’s security team in 2024 on documented APT activity targeting US research universities working on quantum computing and advanced materials, both active research areas at this institution. Chinese state-sponsored actors (APT41 and Volt Typhoon) had been specifically documented targeting academic institutions with DoD-funded research programmes.
The university needed a CMMC 2.0 Level 2 gap assessment before a C3PAO assessment, and an SSP and POA&M they could take to the C3PAO examination. They needed the gap assessment conducted under conditions simulating the actual adversary, not just a checkbox review of documentation.
Core Challenge
Conduct an adversarial assessment that identified real-world exploitable gaps in CMMC Level 2 controls, not just documentation gaps, and produce the SSP and POA&M required for C3PAO certification.
What GLI Secure Did
We began with a four-week CUI data discovery exercise, the first comprehensive mapping of where CUI was stored, processed, and transmitted. This exercise alone revealed 14 CUI data stores not in scope for the university’s documented security programme.
The adversarial assessment simulated an APT41-profile attack: spear-phishing targeting faculty researchers with active DoD contracts, lateral movement to CUI repositories, and simulated exfiltration of CUI data.
We mapped all findings to NIST SP 800-171 requirements and structured the output as a CMMC 2.0-ready SSP and POA&M.
The Purple Team Approach
CUI Data Discovery and Classification
Mapped all CUI across 14 DoD contracts. Found: 14 previously undocumented CUI repositories across 6 research laboratories. CUI stored on personally-owned faculty laptops. CUI shared via personal email by 3 faculty members unaware of DFARS handling requirements.
Spear-Phishing Simulation (APT41 Profile)
Sent targeted spear-phishing to 18 faculty researchers with active DoD contracts using domain-specific lures. 7 of 18 clicked the simulated link (39%). A 39% success rate against researchers with access to ITAR-controlled data.
Research Network Lateral Movement
From a simulated compromised faculty workstation, tested lateral movement to CUI repositories. Found: research network inadequately segmented from the general campus network.
CUI Repository Access Testing
9 of 14 CUI repositories were accessible with faculty-level credentials. 3 were accessible via SharePoint/OneDrive, non-FedRAMP-authorised cloud storage. Direct DFARS 252.204-7012 violation.
CUI Exfiltration Testing
DLP did not cover research network traffic. ITAR/EAR-controlled research data could be emailed externally without triggering any DLP alert.
CMMC Practice Gap Assessment
Identified 34 of 110 practices with gaps requiring remediation before C3PAO assessment. Highest-priority gaps concentrated in Access Control, Audit and Accountability, and Configuration Management families.
MITRE ATT&CK Techniques Tested
| ATT&CK ID | TECHNIQUE | DETECTION RESULT |
|---|---|---|
| T1566.002 | Spear Phishing Link (Faculty Targeting) |
SUCCESS
39% click rate. 7 of 18 targeted faculty clicked. |
| T1078 | Valid Accounts (Faculty Credential) |
NOT DETECTED
No behavioural monitoring on research network. |
| T1039 | Data from Network Shared Drive (CUI Repositories) |
NOT DETECTED
No monitoring on CUI repository access. |
| T1213 | Data from Information Repositories (SharePoint) |
NOT DETECTED
SharePoint access not monitored for CUI. |
| T1048 | Exfiltration over HTTPS (External Email) |
NOT DETECTED
DLP does not cover research network egress. |
Key Findings
Critical
14 Undocumented CUI Repositories:
CUI data existed in 14 repositories not included in the documented security programme scope. CMMC requires all CUI data flows to be documented in the SSP, the undiscovered repositories meant the SSP was materially incomplete.
Critical
Non-FedRAMP Cloud Storage for CUI:
3 CUI repositories existed on standard commercial Microsoft 365, not GCC High, which is the minimum FedRAMP-authorised platform for CUI under DFARS. Active DFARS 252.204-7012 violation.
CRITICAL
CUI on Personal Laptops and Personal Email:
CUI on personally-owned faculty laptops and transmitted via personal email by faculty who did not understand DFARS handling obligations. Assets entirely outside the security programme scope.
High
39% Faculty Spear-Phishing Success Rate:
Nearly 40% of targeted faculty clicked on simulated phishing. Research university faculty are among the most targeted individuals for nation-state spear-phishing.
INFO
34 NIST SP 800-171 Practice Gaps:
Gap assessment identified 34 of 110 practices with deficiencies requiring remediation before C3PAO assessment.
Measurable Outcomes
| CUI Repositories Documented | All 14 undiscovered repositories added to SSP scope |
| FedRAMP Cloud Migration | CUI migrated to Microsoft 365 GCC High within 60 days |
| Personal Device CUI | Policy enforcement and technical controls preventing CUI on personal devices |
| Faculty Security Training | CUI-specific training completed by all 14 DoD principal investigators |
| NIST SP 800-171 Gaps | 34 gaps reduced to 6 within 90 days, C3PAO readiness achieved |
| System Security Plan | Complete CMMC 2.0 Level 2 SSP delivered, 187-page document |
Regulatory Impact
CUI on non-FedRAMP-authorised cloud storage was an active DFARS 252.204-7012 violation. DFARS requires CUI to be processed and stored in cloud services that have received FedRAMP authorisation at the Moderate impact level. Migration to GCC High was the highest-priority remediation item.
The personal email CUI transmissions also triggered EAR/ITAR considerations. If any transmitted data fell within EAR or ITAR scope, personal email transmission to external parties could constitute an unlicensed export, a criminal offence.
The 39% faculty spear-phishing success rate demonstrates the gap between CMMC Level 2’s security awareness training requirement (Practice AT.2.056) and operational effectiveness. Research-specific training addressing APT41-profile techniques is required.
“
We had done the documentation work for CMMC. We had policies, an SSP skeleton, we had mapped most of the 110 practices. What the adversarial assessment showed us was that documentation and operational reality had diverged significantly. The 14 undocumented CUI repositories, the personal laptops with defence data, the SharePoint that wasn’t FedRAMP-authorised, none of that was visible in the documentation. It was all in the researchers’ daily work habits.
— Chief Information Security Officer, Research University (anonymised)
Key Takeaways
- CUI data discovery, not policy documentation, is the starting point for a credible CMMC assessment. Most research universities significantly underestimate the distribution of CUI across their computing environments.
- Non-FedRAMP cloud storage for CUI is the most common and most consequential CMMC gap in research university environments. Commercial Microsoft 365 or Google Workspace fail the DFARS cloud storage requirement.
- Faculty spear-phishing susceptibility is structurally high in research university environments. Standard annual training is insufficient for a population that is internationally networked and publicly searchable.
- ISO 17020 accreditation positions GLI Secure to conduct the C3PAO Level 2 assessment itself, enabling organisations to move from gap assessment to certification with a single partner.
Book a Free Education Purple Team Discovery Call
GLI Secure | ISO 17025 Accredited
All case studies are fully anonymised. ISO 17025-accredited methodology. MITRE ATT&CK is a trademark of The MITRE Corporation.
Strengthen your cybersecurity posture and protect your organization from evolving threats. Discover how GLI Secure reduces risk, simplifies compliance, and protects customer trust.