
NBOA President and CEO
When I joined NBOA as its president and CEO 16 years ago, school leaders were grappling with the transition from computer labs to one-to-one devices for students. Today, needless to say, we are in a completely different place in terms of school technology. Network connections are embedded not just in the classroom, but in every area of school operations: learning platforms, financial systems, payroll, donor records, HR information, facilities management and communications with families. I could go on.
That means that cyber risk is most certainly not contained to the server room. It’s in every room and department of the school. A disruption in any one of a school’s operational systems can ripple across the entire school community.
That is why I invited Bob Olsen, managing director at Hilco Global and a nationally recognized cybersecurity expert, to be a guest on the Net Assets Podcast. In this latest episode, we discuss the current cyber threat environment for independent schools, lessons from the recent Canvas breach and how AI is impacting cyber risk, prevention and resilience.
Below is an excerpt from the conversation, lightly edited for length and clarity.
Jeff Shields: Cybersecurity is certainly something I hear from almost every business officer I talk to. I want to ask about a real incident that caught the attention of a lot of educators earlier this year: the cyberattack involving Canvas, the learning management platform used by many schools and colleges. When you looked at that incident, did it strike you as unusual, or was it the kind of attack security professionals have been expecting?
Bob Olsen: I wouldn’t say that I was surprised that it happened. Threat actors only have to get it right one time, and companies and organizations have to get it right 100% of the time. I think what surprised me was the number of institutions and overall end users impacted [roughly 275 million]. As schools become more reliant on enterprise-wide solutions — covering everything from development to student information systems to learning management systems — it was not surprising that the impact was so significant. These systems are integrated and ubiquitous across schools.
Jeff Shields: What lessons should school leaders draw from that incident?
Do they understand the criticality of those platforms? Do they have the right steps in place from a resiliency standpoint so that if something bad does happen, they can continue to operate?
Bob Olsen: One lesson is to ask whether schools truly understand how dependent they are on systems and platforms like Canvas, Blackbaud or Finalsite. Do they understand the criticality of those platforms? Do they have the right steps in place from a resiliency standpoint so that if something bad does happen, they can continue to operate?
Step number one is inventorying. That might sound overly simplistic, but schools need to understand which software-as-a-service and cloud-based applications are in use, how they are being used, how critical they are and what data sits within them. It is very hard to protect data correctly or meet privacy and compliance expectations if you do not know what you have and where it sits.
Jeff Shields: Schools use so many different systems: financial systems, payroll data, donor records, HR information, facility systems. How should leaders think about the relative risks among these different types of systems?
Bob Olsen: They all present similar risks. It comes down to how schools use those platforms. Some systems may be more tightly integrated or may contain more sensitive data than similar systems at peer schools. A lot of these systems are integrated, if not technically, then from a process standpoint. If one system that is important to operations is broken or compromised, what is the ripple effect? What is the domino effect?
Jeff Shields: So when a school begins developing a plan, who should be involved?
Boards of trustees, heads of school and business officers are not intended to be technical subject matter experts. They are coming to the table from a business risk perspective, which is appropriate and important.
Bob Olsen: The plan needs to look at this through the lens of risk management. Boards of trustees, heads of school and business officers are not intended to be technical subject matter experts. They are coming to the table from a business risk perspective, which is appropriate and important. Top questions include:
- What do we need to operate as a school?
- What risks are we comfortable with?
- What are the top three to five risks?
- Do we understand our critical systems and the types of data we have?
- Do we have a strong security program and security culture around the use of those tools?
- If something bad does happen, are we comfortable that our cyber insurance actually covers us?
Jeff Shields: You also mentioned artificial intelligence. How is AI changing the cybersecurity landscape?
Bob Olsen: Like any new technology, AI brings positives and negatives. There are many positives in the security space, especially for smaller organizations. Some tools now have AI agents built in that can help resource-constrained schools be more responsive and more sophisticated in their response. Schools are often lean when it comes to IT and technology staffing, so anything that helps automate work and support more intelligent decision-making can be positive.
AI can also help with triage. A security person may face a constant barrage of alerts. AI can help identify the top two or three issues that deserve attention, allowing people to focus their time and expertise on the real threats rather than getting lost in the noise.
Listen to this full episode of the Net Assets podcast.

Jeffrey Shields, FASAE, CAE
NBOA President and CEO
Follow NBOA President and CEO Jeff Shields on LinkedIn.

