Back to all resources
guide

IT and Cybersecurity Checklist for Schools: Accounts, Devices, Wi-Fi and Student Data

October 8, 2026
11 min read
IT Rapid Support Team
IT and Cybersecurity Checklist for Schools: Accounts, Devices, Wi-Fi and Student Data

A school needs IT that keeps classes running and keeps student information private: separate accounts for every student and staff member with multi-factor authentication on staff and admin accounts, a managed fleet of laptops, Chromebooks and tablets that can be wiped or replaced quickly, a network that keeps student, staff, guest and administrative traffic apart, content filtering that matches your policies, tested backups of the student information system and finance files, and a process for verifying any change to tuition, payroll or vendor banking details. The difference from an office business is scale and turnover. Hundreds of users, many of them children, share devices and Wi-Fi, and every September the whole population changes at once.

This guide is a practical checklist for heads of school, bursars, business managers and the staff member who ends up looking after technology at private and independent schools, Montessori schools, tutoring centres and other educational organizations in Ontario. It covers accounts, devices, the network, content filtering, student records, payment fraud, backups and the summer refresh, and what to ask when you choose an IT provider. It is written by IT Rapid Support, a managed IT and cybersecurity provider at 7810 Keele St in Vaughan, so read it with that in mind; the checklist applies whoever runs your IT.

What a School Actually Depends On

Before changing anything, list every system the school needs to teach, communicate with families, take payments and pay staff. For most schools the list looks like this:

  • Student and staff accounts, usually Google Workspace for Education or Microsoft 365, plus the learning management system (Google Classroom, Teams or another platform).
  • The student information system that holds enrolment, attendance, grades, medical notes and family contacts.
  • Tuition billing, accounting, payroll and the online payment or donation portal.
  • Student and staff devices: Chromebooks, laptops, iPads, lab computers, classroom displays and printers.
  • The internet connection, firewall, switches and Wi-Fi access points across every building and portable.
  • Phones and the paging or intercom system, door access control and security cameras.

For each item, write down who supplies it, who administers it, where the admin login is kept and the number to call. In many schools that knowledge sits with one teacher or one long-serving staff member, which is the first risk to fix.

Student and Staff Accounts and MFA

  • Every staff member and every student has their own account. Shared logins for a classroom, a lab or the front office make it impossible to tell who did what and impossible to remove one person's access.
  • Multi-factor authentication is on for every staff account, and always for administrators, the bursar's office, the student information system and anything that can move money. Our multi-factor authentication guide covers which methods to choose.
  • Admin rights are held by a small, named group using separate admin accounts, not everyday teacher logins.
  • Students are placed in groups by grade or division so sharing, email and app permissions can be set appropriately for their age, including whether younger students can email outside the school at all.
  • Joiners and leavers follow a written process: staff who leave lose access the same day, and graduating or departing students' accounts are handled according to your retention policy rather than left open indefinitely.

Devices, Chromebooks and Shared Equipment

  • Every school-owned device is enrolled in a management console (Google Admin for Chromebooks, Intune or similar for Windows, Apple School Manager with a device management tool for iPads) so it can be configured, updated, locked and wiped remotely.
  • An up-to-date inventory records each device, its serial number, who it is assigned to and when it reaches the end of its update support. Chromebooks have a published automatic update expiration date; plan replacements before it arrives.
  • Staff laptops are encrypted, patched and protected by managed endpoint security, because they hold report cards, IEPs and family correspondence.
  • Lab and library computers reset to a clean state or are tightly locked down, so one student's session cannot affect the next.
  • Lost and damaged device handling is written down: who reports it, how it is locked, how a spare is issued.

Network Segmentation: Student, Staff, Guest and Admin

A school network carries very different kinds of traffic, and they should not all share one flat network.

  • Students, staff, guests and visiting parents each get their own Wi-Fi network or segment. Guests get internet only, with no access to anything inside the school.
  • Administrative systems, the bursar's office, door access, cameras and printers sit on their own segments with firewall rules between them.
  • Wi-Fi coverage and capacity are planned for a full classroom of devices connecting at once, not for a handful of office laptops.
  • Network equipment is on supported firmware, admin passwords are changed from the installer's defaults, and the configuration is documented so it does not live in one person's head.
  • The internet connection and core network equipment are monitored so outages are seen before a teacher has to report one.

Content Filtering and Acceptable Use

  • Content filtering applies to school devices on and off the school network. Chromebooks and managed laptops can carry filtering policies with them when students take them home.
  • Filtering categories differ by age group; what suits a Grade 2 class does not suit a Grade 12 research project.
  • Staff know how to request that a blocked site be reviewed, and someone is responsible for answering.
  • An acceptable use policy that students, families and staff acknowledge sets expectations for devices, accounts and online behaviour.
  • Filtering is a safety tool, not a substitute for supervision and digital citizenship teaching.

Student Records and Privacy

Schools hold some of the most sensitive personal information of any organization: children's names and addresses, grades, medical and allergy notes, learning plans, custody arrangements and family financial details. Which privacy law applies depends on the kind of institution. Public school boards in Ontario fall under provincial legislation, while independent schools, tutoring centres and childcare operators may fall under PIPEDA for some activities, and health information can raise other obligations. Confirm with your counsel which rules apply to your school; the technical safeguards below are expected in any case.

  • Know where student information lives: the student information system, shared drives, email attachments, spreadsheets on staff laptops and paper files scanned into the cloud.
  • Limit access by role, so a homeroom teacher sees their own class and only the office sees billing and custody information.
  • Encrypt laptops and backups, and keep sharing settings in Google Drive or OneDrive restricted to the school by default.
  • Review the privacy terms and data location of every app teachers sign up for before student data goes into it, and keep a list of approved apps.
  • Have a written plan for what to do if student information is exposed, including who decides whether families or a regulator must be notified. Our PIPEDA compliance IT checklist explains the breach record-keeping side.

Phishing and Payment Fraud on Tuition and Vendor Payments

Schools move a lot of money on a predictable calendar: tuition instalments, field trip and activity fees, donations, payroll and payments to bus, food service and construction vendors. That makes them a target for email fraud.

  • Any request to change vendor, payroll or refund banking details is confirmed by phone using a number you already have, never the one in the email.
  • Families are told in writing that the school will never email new banking details for tuition, and how to check if they receive such a message.
  • Requests from the head of school for urgent gift cards or wire transfers are treated as fraud until confirmed in person.
  • The school's domain has SPF, DKIM and DMARC email authentication so others cannot easily send email that appears to come from the school. Our free email spoofing check shows where you stand.
  • Staff, especially in the office and bursar's office, get short, regular phishing awareness training.

Backups and Recovery

  • Back up the student information system, finance and payroll data, shared drives and staff email. Cloud platforms keep your data running, but deleted or encrypted files may not be recoverable without a separate backup.
  • Keep at least one backup copy that ransomware on the school network cannot reach, and test a restore each term.
  • Export the reports you would need if a cloud system were unavailable during report card season or enrolment, such as class lists, emergency contacts and fee balances.
  • Write down who decides, and in what order systems come back, if the network or a key system is down on a school day.

Plan the Summer Refresh

July and August are the only time a school can replace devices, rebuild the network or migrate systems without disrupting classes. Plan the work in the spring so it is done before staff return.

  • Retire devices that have reached the end of their update support and enrol their replacements.
  • Roll accounts forward: archive or remove graduates, create accounts for new students and staff, move classes and groups to the new year.
  • Apply firmware and software updates to network equipment, review firewall rules and Wi-Fi coverage for any rooms that changed use.
  • Review admin access, the approved app list and filtering policies before the first day.
  • Test backups and the incident plan while there is time to fix what fails.

What to Ask an IT Provider for a School

  • Have they managed Google Workspace for Education or Microsoft 365 for Education tenants, and fleets of Chromebooks or iPads?
  • How would they separate student, staff, guest and administrative networks, and how do they handle content filtering for devices that go home?
  • How fast does a person answer during the school day, and can they come on-site when a classroom problem needs hands on it?
  • Who handles joiners, leavers and the start-of-year account rollover, and is it documented?
  • How do they protect and back up the student information system and finance data, and how often do they test a restore?
  • Is the agreement clear about what is included, and is project work such as a summer refresh or Wi-Fi upgrade scoped and quoted in writing before it starts? Our guide on what a managed IT contract should include lists the clauses to check.

How IT Rapid Support Works With Schools

IT Rapid Support provides managed IT, network support and cybersecurity for private and independent schools, tutoring centres and educational organizations across the Greater Toronto Area from our office at 7810 Keele St in Vaughan. Our helpdesk is available 24/7, we work alongside your existing staff and software vendors, and on-site work is dispatched across the GTA. Support is billed by the hour or covered under an agreement scoped to your campus, staff and devices, and projects are scoped and quoted in writing. The service details are on our page for IT support for schools and education. If something is down right now, our IT emergency checklist covers the first hour. To review your school against this checklist, call (289) 582-9930 or contact us.

Frequently Asked Questions

What IT support does a school need?

At minimum: individual accounts for every student and staff member with multi-factor authentication on staff and admin accounts, managed and encrypted devices with a replacement plan, separate networks for students, staff, guests and administration, content filtering that follows devices home, tested backups of the student information system and finance data, a verified process for any banking change, and a helpdesk that answers during the school day.

Should students and staff be on the same Wi-Fi network?

No. Students, staff, guests and administrative systems should each be on their own network or segment, with firewall rules between them. That stops a compromised student device or a visitor's laptop from reaching staff files, the student information system, cameras or the bursar's office.

How should a school manage Chromebooks?

Enrol every Chromebook in the Google Admin console so policies, content filtering, updates and apps are pushed centrally and a lost device can be disabled remotely. Keep an inventory with serial numbers and each model's automatic update expiration date, and replace devices before they stop receiving updates.

Which privacy law applies to student records at a private school in Ontario?

It depends on the kind of institution and the activity. Public school boards fall under Ontario's public-sector privacy legislation, while independent schools and other private educational organizations may be subject to PIPEDA for some activities, and health information can bring in other rules. Confirm with your counsel which laws apply; the technical safeguards in this checklist, such as access control, encryption, MFA and tested backups, are expected either way.

What cybersecurity threats do schools face most?

The common ones are phishing emails that capture staff passwords, fraudulent requests to change vendor, payroll or tuition banking details, gift card scams that impersonate the head of school, ransomware reaching shared drives, over-shared documents containing student information, and accounts of former staff that were never removed. Multi-factor authentication, call-back verification of banking changes and prompt offboarding stop most of them.

When should a school plan its IT refresh?

Plan in the spring and do the work in July and August, when devices can be replaced, accounts rolled forward and network changes made without disrupting classes. Leave time before staff return to test backups, Wi-Fi coverage and filtering on the new setup.

Share this resource

IT Rapid Support Team

IT Rapid Support Team

Managed IT & Cybersecurity, GTA

IT Rapid Support Team is a security expert with extensive experience in creating security guidelines.

More from this author

Related Resources

All Resources
IT and Cybersecurity Checklist for Restaurants: Keeping the POS, Wi-Fi and Card Data Safe
guide
•
October 8, 2026

IT and Cybersecurity Checklist for Restaurants: Keeping the POS, Wi-Fi and Card Data Safe

The IT and security controls a restaurant needs: keeping the POS running during service, internet failover, separating guest Wi-Fi from payment systems, PCI DSS basics, staff turnover and shared logins, delivery platform and payment fraud, multiple locations and what to ask an IT provider.

Read more: IT and Cybersecurity Checklist for Restaurants: Keeping the POS, Wi-Fi and Card Data Safe
IT and Cybersecurity Checklist for Manufacturers: A Practical Guide for Ontario Plants
guide
•
October 8, 2026

IT and Cybersecurity Checklist for Manufacturers: A Practical Guide for Ontario Plants

The IT and security controls a manufacturer needs: separating office IT from the plant floor, containing legacy machine PCs, ERP and EDI uptime, backups of machine programs, vendor remote access, payment fraud, customer security questionnaires, shift coverage and what to ask an IT provider.

Read more: IT and Cybersecurity Checklist for Manufacturers: A Practical Guide for Ontario Plants
What to Do in an IT Emergency: A First-Hour Checklist for GTA Businesses
guide
•
October 8, 2026

What to Do in an IT Emergency: A First-Hour Checklist for GTA Businesses

How to tell an IT emergency from an urgent ticket, first-15-minute checklists for network outages, server failures, email down, ransomware and payment fraud, what to have ready before you call, and a one-page emergency plan.

Read more: What to Do in an IT Emergency: A First-Hour Checklist for GTA Businesses

Need Expert Security Advice?

Our team of cybersecurity experts is ready to help you secure your organization. Schedule a free consultation today.

Get in Touch