We’re exhibiting at

TribalNet 2026

September 20-24, 2026

Dallas, TX

Booth #320

Education Sector

Three Real-World Purple Team Engagements | Fully Anonymised | ISO 17025 Accredited Methodology

ISO 17025 Accredited · MITRE ATT&CK v15 · All engagements conducted under explicit written authorisation

Sector

Education

Engagement

Purple Team Exercise

ATT&CK Tactics

MITRE ATT&CK v15

Location

United States

About These Case Studies

The following case studies describe real purple team engagements conducted by GLI Secure across education sector organisations. All identifying details — organisation names, locations, system names, and personnel — have been fully anonymised. Statistical outcomes, detection improvements, and regulatory findings are accurate as documented during and after each engagement.

All purple team exercises described in this document were conducted under explicit written authorisation from the client organisation, using GLI Secure’s ISO 17025-accredited testing methodology. MITRE ATT&CK technique IDs are referenced as documented in ATT&CK Enterprise Framework v15.

Confidentiality Notice: These case studies anonymised; any resemblance to specific organisations is coincidental.

focused man working in library

Case Study EDU-CS-01

EdTech Supply Chain Attack — K-12 School District

Testing detection and response against a PowerSchool-style vendor compromise targeting student records

Organisation

A suburban K-12 school district with 28,000 students and 180+ active EdTech applications (anonymised)

Sector

Education — K-12 public school district

Location

Pacific Northwest, United States

Engagement

Purple Team Exercise — EdTech Vendor Access and Student Data Exfiltration

Duration

5 weeks (2-week scoping, 1-day exercise, 2-week remediation)

Frameworks

FERPA 34 CFR Part 99 | COPPA | State student data privacy law | NIST SP 800-171 | MITRE ATT&CK Enterprise v15

The Situation

The PowerSchool breach in 2025 exposed the sensitive data of more than 60 million US students and teachers. The district’s IT Director recognised his own SIS vendor had similar maintenance access configurations. The district used 180+ active EdTech applications. It had never assessed the security of any of them.

The district had no dedicated cybersecurity staff. Security decisions were made by the IT Director and a team of four infrastructure administrators. The concept of a purple team exercise was new to all of them — but after PowerSchool, the IT Director had concluded that understanding vendor access risk was non-negotiable.

The specific scenario to test: if someone compromised the SIS vendor’s support account — exactly as happened with PowerSchool — what could they reach, what could they take, and would anyone notice?

Core Challenge

Determine whether a compromised EdTech vendor support account could access student PII at scale and whether any existing control would detect or prevent the exfiltration — mirroring the PowerSchool attack mechanism.

What GLI Secure Did

We began with an EdTech vendor access audit — the first the district had ever conducted. We mapped all 180+ applications, identified which had access to student PII, reviewed Data Use Agreements in place, and documented access pathways for each vendor.

The exercise simulated a compromised SIS vendor support account with credentials scoped to mirror the real vendor’s maintenance access level. We tested what the account could reach and whether any activity would trigger an alert.

We also tested the district’s FERPA incident response capability — specifically how quickly they could identify the scope of an exposure, activate the FERPA notification process, and revoke vendor access.

The Purple Team Approach

EdTech Vendor Access Audit

Catalogued all 180+ EdTech applications. Found: 67 had access to student PII, only 12 had FERPA-compliant Data Use Agreements, 8 had access broader than their contracted educational purpose, 4 vendors had never responded to the district's security questionnaire.

SIS Vendor Support Access Simulation

Using a test account configured to mirror the SIS vendor's maintenance access, tested what the account could reach. Found: full read access to all student demographic records, emergency contact information, and attendance data for all 28,000 students.

Bulk Data Access Test

Simulated bulk export of student records via the vendor maintenance interface. Found: no access controls on export volume, no alert on bulk exports, and no logging of vendor access sessions at the district level.

Data Staging and Exfiltration

Tested whether data staged during vendor access could be exfiltrated without detection. Found: DLP controls did not apply to the vendor access pathway — exfiltration through the vendor's remote session channel generated no alert.

FERPA Incident Response Activation

Found: no documented FERPA notification workflow, unclear who was responsible for notifying parents, no communication template for a student data breach scenario.

Vendor Access Revocation

Found: only one IT staff member knew the vendor access revocation process, and that individual was not available during the exercise day — a single point of failure in breach response.

MITRE ATT&CK Techniques Tested

ATT&CK ID Technique Detection Result
T1199 Trusted Relationship (SIS Vendor Access) NOT DETECTED

No vendor session monitoring at district level.

T1530 Data from Cloud Storage (SIS Student Records) NOT DETECTED

No anomaly detection on data access volume.

T1048 Exfiltration via Vendor Channel NOT DETECTED

DLP does not cover vendor remote session traffic.

T1213 Data from Information Repositories NOT DETECTED

Logging not enabled on SIS maintenance...

T1078 Valid Accounts (Vendor Credentials) NOT DETECTED

No behavioural monitoring on vendor accounts.

Key Findings

Critical

55 of 67 Apps Without FERPA Data Use Agreements:

55 EdTech applications accessing student PII had no FERPA-compliant DUA. Each represents an active FERPA violation — the district is sharing student records without required contractual protections.

Critical

Zero Vendor Session Monitoring:

No monitoring existed on any vendor remote access session. The PowerSchool attack mechanism was directly replicable in this environment.

Critical

No FERPA Breach Response Capability:

No documented FERPA notification workflow existed. In a real breach, the district would be unable to notify affected families within the legally expected timeframe.

High

Bulk Export Without Restriction:

The SIS maintenance interface allowed unlimited bulk export of all 28,000 student records in a single session.

High

Single-Person Access Revocation Knowledge:

Only one IT staff member knew the vendor access revocation procedure. If unavailable, the compromised access cannot be revoked.

Measurable Outcomes

DUA Coverage Increased from 12 to 67 applications within 90 days
Apps Without DUA 8 applications suspended pending DUA completion
Vendor Session Monitoring Monitoring deployed for all 12 highest-risk vendor connections
FERPA Response Plan Documented workflow created with 3 trained staff members
Access Revocation Procedure documented and 3 staff members trained
SIS Export Controls Volume limits and alerting implemented on SIS maintenance exp...

Regulatory Impact

55 EdTech applications without FERPA-compliant Data Use Agreements represents a systemic FERPA compliance failure. FERPA requires written agreements with any third party that accesses education records, specifying that the third party will not redisclose the records. Every application without a DUA creates independent FERPA exposure.

The PowerSchool breach specifically highlighted the DUA gap — districts with DUAs had contractual leverage that districts without DUAs did not. The PowerSchool litigation involving 100+ school systems was structured in part around the adequacy of DUA protections.

The absence of a documented FERPA breach notification process is itself a compliance gap. State student data privacy laws in over 40 states create notification obligations that the district had no process to satisfy.

After PowerSchool, I asked myself: if our SIS vendor was compromised tomorrow, would we know? The purple team exercise answered that question: no. We had 55 EdTech apps accessing student data without any data use agreement. We had no monitoring on vendor sessions. We had no breach response plan. We were exactly as vulnerable as every district affected by PowerSchool.

— IT Director, K-12 School District (anonymised)

Key Takeaways

Ready to test your Education security defences?

Case Study EDU-CS-02

Ransomware Simulation, Mid-Sized School District

Testing backup integrity and recovery capability against a Rhysida-style summer break attack

cybersecurity shield on computer screen

Organisation

A K-12 school district with 41,000 students operating 52 schools (anonymised)

Sector

Education — K-12 public school district

Location

Southwest United States

Engagement

Purple Team Exercise — Ransomware Attack and Business Continuity Validation

Duration

6 weeks (3-week planning, 2-day exercise, 1-week remediation and SLCGP documentation)

Frameworks

FERPA | COPPA | CISA K-12 Cybersecurity Act | NIST SP 800-171 | NIST SP 800-171 | MITRE ATT&CK Enterprise v15

The Situation

In summer 2025, a Rhysida ransomware attack encrypted the entire IT infrastructure of a school district three states away during the July maintenance window — with school scheduled to start in 6 weeks. The district paid the ransom. The superintendent of the district in this case study read every article and recognised his district’s identical profile: similar infrastructure, similar security staffing (two IT staff with no dedicated security expertise), similar budget constraints.

The state education agency had announced SLCGP grant funding was available, but accessing it required documentation of security programme gaps. The district conducted a purple team exercise to determine both whether a Rhysida-style attack would succeed and to produce the gap documentation required for the SLCGP application.

The defining question: how long would the district be down, and would backup systems actually enable recovery within the school start deadline?

Core Challenge

Determine whether the district’s backup systems would enable recovery from a complete ransomware encryption event within the school start deadline, and identify the specific gaps that SLCGP grant funding should address.

What GLI Secure Did

The exercise combined a technical simulation testing ransomware precursor detection and backup integrity, with a business continuity test examining whether the district could maintain essential operations during an extended IT outage.

The scenario used the Rhysida attack profile: initial access via an unpatched internet-facing VPN, lateral movement across the district’s flat network, and simultaneous encryption of administrative and SIS systems.

The backup restoration test was the most consequential element: an actual partial restoration from available backup systems, measuring the real time required against the school start deadline.

The Purple Team Approach

Network Architecture Review

Finding: completely flat network, no VLAN segmentation between administrative systems, SIS, and classroom infrastructure. An attacker who compromised one system had unrestricted access to all systems.

Internet-Facing Vulnerability Scan

Found: VPN appliance running firmware 14 months out of date with a documented critical CVE exploited in the comparable Rhysida district attack.

Backup System Audit

All backups were on network-connected storage accessible from the administrative network. No offline backups existed. SIS backup jobs had been failing silently for 3 months, meaning no usable SIS backup existed.

Ransomware Simulation (Isolated Environment)

Using isolated test systems, simulated ransomware encryption to measure recovery scenarios. With no offline backups, the only recovery pathway for most systems was a full rebuild from scratch.

Recovery Timeline Modelling

Ransom payment: 4-6 days (uncertain outcome). Rebuild from scratch: 4-8 weeks. Partial recovery using available backups: 2-3 weeks for systems with working backups. School start deadline: 6 weeks away.

SLCGP Gap Documentation

Documented all gaps in SLCGP application format: specific control gaps, risk narrative, proposed remediation, and cost estimates for grant-eligible security improvements.

MITRE ATT&CK Techniques Tested

ATT&CK ID TECHNIQUE DETECTION RESULT
T1190 Exploit Public-Facing VPN Appliance NOT DETECTED

No EDR on network devices. CVE confirmed exploitable.

T1021 Remote Services (Flat Network Lateral Movement) NOT DETECTED

No east-west traffic monitoring.

T1486 Data Encrypted for Impact (Test Systems) NOT DETECTED

No ransomware behavioural detection on servers.

T1490 Inhibit System Recovery (Backup Access) NOT DETECTED

Backups accessible and enumerable with no alert.

T1566 Phishing (Staff Account Compromise Alternative) DETECTED

Email security quarantined simulated phishing in under 2 minutes.

Key Findings

Critical

No Viable Recovery Pathway:

No offline backups existed. All backup storage was network-accessible and would be encrypted simultaneously with production systems. The district had no recovery option meeting the school start deadline without paying ransom.

Critical

SIS Backup Failure, 3 Months of Data Loss:

The SIS backup job had been failing silently for 3 months. In a ransomware event, the district would lose 3 months of student records including enrollment changes, grade updates, and attendance data.

CRITICAL

Unpatched VPN with Known-Exploited CVE:

No documented FERPA notification workflow existed. In a real breach, the district would be unable to notify affected families within the legally expected timeframe.

High

Flat Network:

All district systems were on a flat network. A single compromised workstation had unrestricted access to the SIS, payroll, financial systems, and all administrative infrastructure.

Measurable Outcomes

VPN CVE Patched Within 48 hours of exercise
Offline Backup Implementation Air-gapped backup solution implemented within 45 days
SIS Backup Monitoring Backup job monitoring with failure alerting implemented
Server EDR EDR deployed to all servers within 60 days
SLCGP Application Grant application submitted using exercise documentation
SLCGP Grant Awarded $847,000 for network segmentation and security tooling

Regulatory Impact

The exercise produced the gap documentation required for the SLCGP application. SLCGP requires applicants to document specific security programme gaps, provide a risk narrative, and propose remediation aligned with the state cybersecurity plan. The exercise findings provided this evidence base.

The SIS backup failure has direct FERPA implications. A three-month data loss scenario following a ransomware event would compromise the district’s ability to certify the accuracy of student records for federal funding purposes.

The CISA K-12 Cybersecurity Act requires the National Cyber Director to provide recommendations to K-12 educational agencies on cybersecurity risks. The VPN CVE and flat network architecture align directly with CISA’s documented top attack vectors for K-12 ransomware incidents.

We went into the exercise hoping to learn something useful. We came out learning that if Rhysida had hit us on a Friday in July, we would have paid the ransom or started the school year without functioning systems. Finding that out in a controlled exercise, and then using the findings to secure $847,000 in federal grant funding, that is the best return on an IT security investment we have ever made.

— Superintendent, K-12 School District (anonymised)

Key Takeaways

Ready to test your Education security defences?

Case Study EDU-CS-03

Research University, CMMC 2.0 Adversarial CUI Assessment

Preparing a research university’s defence-funded computing environment for C3PAO certificationTesting backup integrity and recovery capability against a Rhysida-style summer break attack

futuristic data control panel e1784656825968

Organisation

A research university with $340M in annual federal research funding and 14 active DoD contracts (anonymised)

Sector

Education, Research university, doctoral-granting institution

Location

Mid-Atlantic United States

Engagement

Purple Team Exercise, CUI Environment Adversarial Assessment and CMMC 2.0 Gap Analysis

Duration

10 weeks (4-week scoping, 3-day exercise, 3-week gap report and SSP development)

Frameworks

CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2, 110 practices) | DFARS 252.204-7012 | EAR/ITAR | FERPA MITRE ATT&CK Enterprise v15

The Situation

CMMC 2.0 requirements became active in DoD contracts in November 2025. The university held 14 active DoD contracts requiring Level 2 compliance. The Sponsored Research Office had invested significantly in preparing the research computing environment, but had never had an independent adversarial assessment of whether those preparations were effective.

The FBI had briefed the university’s security team in 2024 on documented APT activity targeting US research universities working on quantum computing and advanced materials, both active research areas at this institution. Chinese state-sponsored actors (APT41 and Volt Typhoon) had been specifically documented targeting academic institutions with DoD-funded research programmes.

The university needed a CMMC 2.0 Level 2 gap assessment before a C3PAO assessment, and an SSP and POA&M they could take to the C3PAO examination. They needed the gap assessment conducted under conditions simulating the actual adversary, not just a checkbox review of documentation.

Core Challenge

Conduct an adversarial assessment that identified real-world exploitable gaps in CMMC Level 2 controls, not just documentation gaps, and produce the SSP and POA&M required for C3PAO certification.

What GLI Secure Did

We began with a four-week CUI data discovery exercise, the first comprehensive mapping of where CUI was stored, processed, and transmitted. This exercise alone revealed 14 CUI data stores not in scope for the university’s documented security programme.

The adversarial assessment simulated an APT41-profile attack: spear-phishing targeting faculty researchers with active DoD contracts, lateral movement to CUI repositories, and simulated exfiltration of CUI data.

We mapped all findings to NIST SP 800-171 requirements and structured the output as a CMMC 2.0-ready SSP and POA&M.

The Purple Team Approach

CUI Data Discovery and Classification

Mapped all CUI across 14 DoD contracts. Found: 14 previously undocumented CUI repositories across 6 research laboratories. CUI stored on personally-owned faculty laptops. CUI shared via personal email by 3 faculty members unaware of DFARS handling requirements.

Spear-Phishing Simulation (APT41 Profile)

Sent targeted spear-phishing to 18 faculty researchers with active DoD contracts using domain-specific lures. 7 of 18 clicked the simulated link (39%). A 39% success rate against researchers with access to ITAR-controlled data.

Research Network Lateral Movement

From a simulated compromised faculty workstation, tested lateral movement to CUI repositories. Found: research network inadequately segmented from the general campus network.

CUI Repository Access Testing

9 of 14 CUI repositories were accessible with faculty-level credentials. 3 were accessible via SharePoint/OneDrive, non-FedRAMP-authorised cloud storage. Direct DFARS 252.204-7012 violation.

CUI Exfiltration Testing

DLP did not cover research network traffic. ITAR/EAR-controlled research data could be emailed externally without triggering any DLP alert.

CMMC Practice Gap Assessment

Identified 34 of 110 practices with gaps requiring remediation before C3PAO assessment. Highest-priority gaps concentrated in Access Control, Audit and Accountability, and Configuration Management families.

MITRE ATT&CK Techniques Tested

ATT&CK ID TECHNIQUE DETECTION RESULT
T1566.002 Spear Phishing Link (Faculty Targeting) SUCCESS

39% click rate. 7 of 18 targeted faculty clicked.

T1078 Valid Accounts (Faculty Credential) NOT DETECTED

No behavioural monitoring on research network.

T1039 Data from Network Shared Drive (CUI Repositories) NOT DETECTED

No monitoring on CUI repository access.

T1213 Data from Information Repositories (SharePoint) NOT DETECTED

SharePoint access not monitored for CUI.

T1048 Exfiltration over HTTPS (External Email) NOT DETECTED

DLP does not cover research network egress.

Key Findings

Critical

14 Undocumented CUI Repositories:

CUI data existed in 14 repositories not included in the documented security programme scope. CMMC requires all CUI data flows to be documented in the SSP, the undiscovered repositories meant the SSP was materially incomplete.

Critical

Non-FedRAMP Cloud Storage for CUI:

3 CUI repositories existed on standard commercial Microsoft 365, not GCC High, which is the minimum FedRAMP-authorised platform for CUI under DFARS. Active DFARS 252.204-7012 violation.

CRITICAL

CUI on Personal Laptops and Personal Email:

CUI on personally-owned faculty laptops and transmitted via personal email by faculty who did not understand DFARS handling obligations. Assets entirely outside the security programme scope.

High

39% Faculty Spear-Phishing Success Rate:

Nearly 40% of targeted faculty clicked on simulated phishing. Research university faculty are among the most targeted individuals for nation-state spear-phishing.

INFO

34 NIST SP 800-171 Practice Gaps:

Gap assessment identified 34 of 110 practices with deficiencies requiring remediation before C3PAO assessment.

Measurable Outcomes

CUI Repositories Documented All 14 undiscovered repositories added to SSP scope
FedRAMP Cloud Migration CUI migrated to Microsoft 365 GCC High within 60 days
Personal Device CUI Policy enforcement and technical controls preventing CUI on personal devices
Faculty Security Training CUI-specific training completed by all 14 DoD principal investigators
NIST SP 800-171 Gaps 34 gaps reduced to 6 within 90 days, C3PAO readiness achieved
System Security Plan Complete CMMC 2.0 Level 2 SSP delivered, 187-page document

Regulatory Impact

CUI on non-FedRAMP-authorised cloud storage was an active DFARS 252.204-7012 violation. DFARS requires CUI to be processed and stored in cloud services that have received FedRAMP authorisation at the Moderate impact level. Migration to GCC High was the highest-priority remediation item.

The personal email CUI transmissions also triggered EAR/ITAR considerations. If any transmitted data fell within EAR or ITAR scope, personal email transmission to external parties could constitute an unlicensed export, a criminal offence.

The 39% faculty spear-phishing success rate demonstrates the gap between CMMC Level 2’s security awareness training requirement (Practice AT.2.056) and operational effectiveness. Research-specific training addressing APT41-profile techniques is required.

We had done the documentation work for CMMC. We had policies, an SSP skeleton, we had mapped most of the 110 practices. What the adversarial assessment showed us was that documentation and operational reality had diverged significantly. The 14 undocumented CUI repositories, the personal laptops with defence data, the SharePoint that wasn’t FedRAMP-authorised, none of that was visible in the documentation. It was all in the researchers’ daily work habits.

— Chief Information Security Officer, Research University (anonymised)

Key Takeaways

Book a Free Education Purple Team Discovery Call

GLI Secure | ISO 17025 Accredited

All case studies are fully anonymised. ISO 17025-accredited methodology. MITRE ATT&CK is a trademark of The MITRE Corporation.

Strengthen your cybersecurity posture today.

Strengthen your cybersecurity posture and protect your organization from evolving threats. Discover how GLI Secure reduces risk, simplifies compliance, and protects customer trust.

Font Resize