Connect with us

Telecom

 Education Sector Strengthening against Ransomware, but IT Teams Pay Personal Price – Sophos Report 

Published

on

Kindly share this post

Sophos, a global leader and innovator of advanced security solutions for defeating cyberattacks, has released its fifth annual Sophos State of Ransomware in Education report.
The global study of 441 IT and cybersecurity leaders shows the education sector is making measurable progress in defending against ransomware, with fewer ransom payments, dramatically reduced costs, and faster recovery rates.
Yet, these gains are accompanied by mounting pressures on IT teams, who report widespread stress, burnout, and career disruptions following attacks – nearly 40% of respondents reported dealing with anxiety.
Over the past five years, ransomware has emerged as one of the most pressing threats to education, with attacks becoming a daily occurrence. Primary and secondary institutions are seen by cybercriminals as “soft targets”, often underfunded, understaffed, and holding highly sensitive data.
The consequences are severe: disrupted learning, strained budgets, and growing fears over student and staff privacy. Without stronger defenses, schools risk not only losing vital resources but also the trust of the communities they serve.
Indicators of Success against Ransomware
The new Sophos study demonstrates that the education sector is getting better at reacting and responding to ransomware, forcing cybercriminals to evolve their approach.
Trending data from the Sophos study reveals an increase in attacks where adversaries attempt to extort money without encrypting data.
Unfortunately, paying the ransom remains part of the solution for about half of all victims.
However, the payment values are dropping significantly, and for those who have experienced data encryption in ransomware attacks, 97% were able to recover data in some way. The study found several key indicators of success against ransomware in education:
• Stopping More Attacks: When it comes to blocking attacks before files can be encrypted, both lower and higher education institutions reported their highest success rate in four years (67% and 38% of attacks, respectively)
• Following the Money: In the last year, ransom demands fell 73% (an average drop of $2.83M), while average payments dropped from $6M to $800K in lower education and from $4M to $463K in higher education.
• Plummeting Cost of Recovery: Outside of ransom payments, average recovery costs dropped 77% in higher education and 39% in lower education. Despite this success, lower education reported the highest recovery bill across all industries surveyed.
Gaps Still Need to be Addressed
While the education sector has made progress in limiting the impact of ransomware, serious gaps remain. In the Sophos study, 64% of victims reported missing or ineffective protection solutions; 66% cited a lack of people (either expertise or capacity) to stop attacks; and 67% admitted to having security gaps. These risks highlight the critical need for schools to focus on prevention, as cybercriminals develop new techniques, including AI-powered attacks.
Highlights from the study that shed light on the gaps that still need to be addressed include:
• AI-powered threats: Lower education institutions reported that 22% of ransomware attacks had origins in phishing. With AI enabling more convincing emails, voice scams, and even deepfakes, schools risk becoming test grounds for emerging tactics.
• High-value data: Higher education institutions, custodians of AI research and large language model datasets, remain a prime target, with exploited vulnerabilities (35%) and security gaps the provider was not aware of (45%) as leading weaknesses that were exploited by adversaries.
• Human toll: Every institution with encrypted data reported impacts on IT staff. Over one in four staff members took leave after an attack, nearly 40% reported heightened stress, and more than one-third felt guilt they could not prevent the breach.
“Ransomware attacks on schools are among the most disruptive and brazen crimes,” said Alexandra Rose, Director, CTU Threat Research, Sophos. “It’s encouraging to see schools getting better at responding and recovering, but the real opportunity is to stop attacks before they start. Prevention, backed by strong incident response planning and collaboration with trusted public and private partners, is essential as adversaries adopt new tactics, including AI-driven threats.”
Holding on to the Gains
Based on its work protecting thousands of educational institutions, Sophos experts recommend several steps to maintain momentum and prepare for evolving threats:
• Focus on Prevention: The dramatic success of lower education in stopping ransomware attacks before encryption offers a blueprint for broader public sector organizations. Organizations need to couple their detection and response efforts with preventing attacks before they compromise the organization.
• Secure Funding: Explore new avenues such as the U.S. Federal Communications Commission’s E-Rate subsidies to strengthen networks and firewalls, and the UK’s National Cyber Security Centre initiatives, including its free cyber defence service for schools, to boost overall protection. These resources help schools both prevent and withstand attacks.
• Unify Strategies: Educational institutions should adopt coordinated approaches across sprawling IT estates to close visibility gaps and reduce risks before adversaries can exploit them.
• Relieve Staff Burden: Ransomware takes a heavy toll on IT teams. Schools can reduce pressure and extend their capabilities by partnering with trusted providers for managed detection and response (MDR) and other around-the-clock expertise.
• Strengthen Response: Even with stronger prevention, schools must be prepared to respond when incidents occur. They can recover more quickly by building robust incident response plans, running simulations to prepare for real-world scenarios, and enhancing readiness with 24/7/365 services like MDR.
Data for the State of Ransomware in Education 2025 report comes from a vendor-agnostic survey of 441 IT and cybersecurity leaders – 243 from lower education and 198 from higher education institutions hit by ransomware in the past year.
The organizations surveyed ranged from 100 – 5,000 employees and across 17 countries.
The survey was conducted between January and March 2025, and respondents were asked about their experience of ransomware over the previous 12 months.
Download the State of Ransomware in Education 2025 report on Sophos.com.

Kindly share this post

Ugo Onwuaso is an ICT enthusiast. He believes technology should be used for general good. He holds a Master of Public Administration (MPA) degree from the Lagos state University. Dear Reader, Your support matters. But we believe that technology makes life more exciting and helps improve the lives of people around Nigeria and indeed the world. That is why, we have devoted our energy to independent reportage of technology and finance and how they affect lives. Our incisive and analytical view of how technology news affects the daily life help individuals and organizations make up their minds. Quality journalism costs money. Today, we're asking that you support us to do more. Kindly support our effort to deliver technology and finance journalism to everyone in the world. Donate as little as N1,000. Bank transfers can be made to: UBA Plc 1017156876 Communication Week Media Ltd

Telecom

GITEX Nigeria to spotlight Africa’s $1trn AI economic potential

Published

on

Kindly share this post

Nigeria is strengthening its position as a leading digital economy in Africa as it prepares to host the second edition of GITEX Nigeria, against projections that the continent’s artificial intelligence (AI) economy could generate up to $1 trillion in economic value by 2035.

GITEX Nigeria to spotlight Africa’s $1trn AI economic potential

GITEX Nigeria

GITEX Nigeria, described as West Africa’s largest technology, AI and startup event, is scheduled to hold in Abuja and Lagos from Aug. 31 to Sept. 3, under the patronage of President Bola Tinubu.

The event is supported by the Federal Ministry of Communications, Innovation and Digital Economy in collaboration with the National Information Technology Development Agency (NITDA), endorsed by the Lagos State Government and organised by KAOUN International.

With the theme, “Beyond Connectivity: The Bridge to Sovereign Innovation,” the 2026 edition is expected to bring together global technology companies, investors, policymakers, regulators, startups and other stakeholders to advance Nigeria’s digital transformation agenda.

According to the organisers, the event will focus on strengthening digital resilience, scaling AI infrastructure, attracting strategic investments and building partnerships to support digital sovereignty across Nigeria and West Africa.

Nigeria’s progress in digital skills development is expected to feature prominently at the event, with the Federal Government’s 3 Million Technical Talent (3MTT) programme highlighted as a major intervention.

Advertisement

The programme has recorded 1.87 million registrations across all 774 local government areas, while more than 135,000 Nigerians have been trained through three cohorts.

The programme has also extended learning opportunities to more than 300,000 people through community resources and created 15,000 job and opportunity pathways, according to figures released by the organisers.

Another key initiative, Project BRIDGE, is aimed at expanding Nigeria’s national ICT backbone and improving connectivity in underserved communities.

The project is expected to create up to 20,000 direct jobs and more than 150,000 indirect jobs, train 5,000 Nigerian youths, raise internet penetration above 70 per cent and extend high-speed connectivity to millions of households, businesses, schools and hospitality establishments.

Dr Bosun Tijani, Minister of Communications, Innovation and Digital Economy, said Nigeria’s objective was to build the foundations for digital sovereignty and a globally competitive AI-powered economy.

Advertisement

“Building on the momentum forged through the implementation of Project BRIDGE, our national blueprint for expanding digital infrastructure and connecting communities across Nigeria, our aspiration ahead of this year’s edition is clear: to solidify the foundations Africa needs for digital sovereignty, technological self-determination, and a globally competitive AI-powered economy,” Tijani said.

He said Nigeria was seeking to promote equitable access, accelerate cross-continental progress and position the country as a producer and exporter of digital technologies and AI solutions.

The GITEX Nigeria Government Leadership and AI Summit will open in Abuja on Aug. 31, bringing together ministers, governors and regulators to discuss digital public infrastructure and other issues shaping West Africa’s digital economy.

The GITEX Nigeria Tech Expo and Future Economy Conference, as well as the Startup Festival, will also return for the second consecutive year.

A new component, FDX Nigeria by GITEX, will focus on finance and digital asset exchange, with the organisers describing it as a platform designed to promote financial inclusion and connect emerging technology with global capital.

Advertisement

Gov. Babajide Sanwo-Olu of Lagos State said the state remained central to Africa’s digital transformation, noting its role in attracting talent, capital and innovation.

He said hosting GITEX Nigeria would further support Lagos’ ambition of becoming a smarter, more connected and globally competitive economy.

Kashifu Inuwa Abdullahi, Director-General of NITDA, said Nigeria’s digital future would depend not only on technology adoption but also on resilience, trust and effective governance frameworks.

“GITEX NIGERIA seamlessly complements this mandate, creating a unique environment for the dialogue needed to accelerate responsible AI adoption, develop a secure digital economy, and unlock new opportunities for innovation and economic growth,” Abdullahi said.

He said the expertise, investment and partnerships generated through the event would contribute to building an AI ecosystem that was secure, inclusive and capable of supporting Nigeria and West Africa’s long-term competitiveness.

Advertisement

The organisers said Nigeria’s National AI Strategy, 3MTT programme and Project BRIDGE were among initiatives strengthening the country’s capacity in talent development, digital infrastructure, investment attraction and responsible AI adoption.

They said GITEX Nigeria would provide an avenue for global stakeholders to establish partnerships and develop solutions capable of accelerating the region’s digital transformation.

Trixie LohMirmand, CEO of GITEX, said the event was intended to demonstrate that West Africa was ready to convert technological ambition into economic growth, resilience and global competitiveness.

She said GITEX Nigeria would facilitate strategic conversations and partnerships aimed at strengthening regional competitiveness and unlocking scalable growth across Nigeria and West Africa.

Advertisement

Kindly share this post
Continue Reading

Telecom

NCC, Enugu Sign Deal to Operate Digital Industrial Park, Learning Centre

Published

on

Kindly share this post

Nigerian Communications Commission (NCC) and the Enugu State Government have signed an agreement for the operational lease of the NCC Digital Industrial Park and NCC Learning Centre in Enugu.

NCC, Enugu Sign Deal to Operate Digital Industrial Park, Learning Centre

The agreement was witnessed by Dr Aminu Maida, Executive Vice Chairman and Chief Executive Officer of the NCC, alongside members of the Commission’s Board and Management.

The development is expected to strengthen digital innovation, skills development and technology-driven opportunities in the state.

As part of the engagement, the NCC delegation also visited the Enugu Smart School Initiative, where technology is being integrated into teaching and learning.

The initiative is aimed at equipping young Nigerians with relevant digital skills and preparing them for future opportunities in an increasingly technology-driven economy.

Advertisement

The NCC said it remained committed to supporting initiatives that expand digital inclusion, strengthen innovation and develop the talent required to drive Nigeria’s digital transformation.

The Commission said partnerships with state governments and other stakeholders were critical to creating an enabling environment for digital skills development and technology adoption across the country.

Kindly share this post
Continue Reading

Telecom

NCC Asks Telcos to Make Budgetary Provisions for Cybersecurity

Published

on

Kindly share this post

Nigerian Communications Commission (NCC) has directed telecommunications operators to make dedicated budgetary provisions for cybersecurity as part of efforts to strengthen the resilience of Nigeria’s communications infrastructure against the growing wave of cyber threats.

NCC Asks Telcos to Make Budgetary Provisions for Cybersecurity

 

The directive forms part of the Commission’s Cyber Resilience Framework for the Nigerian Communications Sector (CRF-NCS), which introduces new governance, risk management and operational requirements aimed at safeguarding the country’s critical telecommunications infrastructure from increasingly sophisticated cyberattacks.

Under the framework, all licensed telecom operators are expected to establish formal cybersecurity governance structures, dedicate adequate financial resources to cyber resilience programmes, and integrate cybersecurity into their enterprise-wide risk management processes.

The Commission said operators must ensure cybersecurity investments are no longer treated as optional operational expenses but as strategic business priorities necessary to protect network infrastructure, customer information and the country’s digital economy.

Advertisement

According to the NCC, licensees are expected to allocate sufficient budgets to support cyber risk assessments, security technologies, staff training, incident response capabilities, continuous monitoring and compliance with regulatory requirements.

The framework also requires operators to designate senior executives responsible for cybersecurity oversight.

At the same time, boards of directors are expected to provide strategic direction and ensure adequate funding for cyber resilience initiatives.

Speaking on the need for a stronger cybersecurity regime during the unveiling of the framework, Abraham Oshadami, executive commissioner, Technical Services, NCC,  said, “Given the increasing digitalisation of services, the rapid growth of data exchange, and the sophisticated nature of modern cyber threats, the need for a robust, adaptive and inclusive cybersecurity framework has become more urgent.”

He added, “Both state and non-state actors are targeting essential sectors—including ours—through coordinated cyber and physical attacks. These attacks frequently target control systems and data integrity, underscoring the critical risks posed to operational technology (OT), especially in our sector.”

Advertisement

“As cyber threats evolve, they endanger not only system performance but also human safety, amplifying the severity and consequences of disruptions to vital communications infrastructure. Cybersecurity now encompasses human safety and must address the real risk to people’s lives when a system is attacked or compromised.”

The Commission further stated that operators are required to develop comprehensive cybersecurity implementation plans, conduct periodic risk assessments, establish business continuity and disaster recovery procedures, and regularly test their cyber defence capabilities.

In addition, the framework makes cyber incident reporting compulsory. Licensees must inform the NCC’s CSIRT of any major cybersecurity breach within four hours of discovery, and provide a thorough post-incident analysis after mitigation is complete.

 

Advertisement

Kindly share this post
Continue Reading

Trending