Offensive security for education and public sector.
Schools, universities and government bodies concentrate citizen data, constrained budgets and technology accumulated over decades. We test with all three constraints in mind at once.
The combination that makes this sector vulnerable
The problem is rarely a lack of technical competence — it is accumulation. Inherited systems nobody can switch off, integrations built by previous administrations, a user base that grows every term and a perimeter with no single owner. An attacker does not need a sophisticated exploit. They need to find what was forgotten.
- Legacy systems remain in production because they still support an essential process.
- The user base is large, rotating and largely on personal, unmanaged devices.
- Old integrations between departments create implicit trust between systems.
- Student and citizen data includes special categories with statutory protection duties.
What we test in these environments
We start with what is exposed and forgotten, then work through to where personal data actually lives.
Student, staff and citizen portals: login, identity federation, password recovery and object-level authorisation between different roles.
Enrolment, grades, transcripts and finance. We check whether a role can read or alter records outside its remit.
Live subdomains, exposed staging environments, departmental applications and services that survived old migrations.
Data exchange between departments and external systems, including shared credentials and services that trust the caller without validating it.
What access obtained in a lab, library or administrative network reaches — and whether a real barrier exists between those environments.
Open data portals and publishing systems: where disclosure went beyond what the rules require and became exposure.
Evidence for statutory duties
The report is written to inform administrative process and accountability, not only the technical team.
- GDPR in the public sector
- Data protection law applies to public bodies with its own regime. We document data subject exposure and the lawful basis affected in each exploited scenario.
- Children's data
- Educational institutions process children's data, a category with reinforced protection. That changes the severity assigned to each finding.
- Transparency with limits
- There is a duty to publish and a duty to protect. We point out where publication went past what was necessary and became exposure.
- Procurement justification
- The report provides technical diagnosis with evidence, in the format that typically supports procurement justification and budget prioritisation.
How we run under budget constraints
Discovery before testing
In these environments half the value is in discovering what exists. We map the real surface before deciding where exploitation effort is worth spending.
Priority by exposed data
With limited scope we go first for what leads to personal data. Vulnerabilities with no path to sensitive information come later.
Care with legacy systems
Where systems are unsupported, we assess exposure and segmentation without aggressive interaction, so as not to take down a service that cannot be quickly restored.
Phased remediation plan
Remediation is split between what can be done without budget, what requires procurement and what depends on replacing a system.
What you receive
- Executive report for leadership
- Reproducible technical report
- Inventory of exposed surface
- Justified CVSS scoring
- Personal data exposure map
- Phased remediation plan by cost
- Retest of remediated findings
- Attestation letter for the engagement
Sector FAQ
Can you work with reduced scope due to budget limits?
+
Yes, and it is the most common arrangement here. In those cases we invest first in surface discovery, which usually reveals meaningful exposure at low cost, and concentrate exploitation on the paths leading to personal data. The report states explicitly what was left out, so the next engagement can start there.
Are old systems that cannot go down included in testing?
+
They are, with distinct handling. A system without support and without a restoration plan does not receive aggressive active testing. We assess exposure, default credentials and segmentation, measuring what an attacker would reach from it, without causing an outage.
Does the report support procurement or budget requests?
+
It is one of the most frequent uses. The document provides a diagnosis with reproducible evidence and a remediation plan separated by effort and cost, which supports budget prioritisation and administrative process, in language both technical staff and leadership can read.
How do you handle data belonging to minors?
+
As a reinforced protection category. We avoid touching real records whenever a demonstration can be done with test data, mask identifiers in evidence, and raise the severity of any finding exposing that group, even where the technical flaw itself would be rated medium.
Services applied to this sector
Ready to uncover your flaws?
First scoping call is free and covered by NDA. Within 48 hours you receive technical proposal, scope and timeline. No bureaucratic forms.