Digital tools have become an essential part of public education, with digital workspaces, online academic services, collaborative platforms, and artificial intelligence playing a central role in the daily lives of students, teachers, and administrative staff. However, while the National Education system has developed a national cybersecurity doctrine, its implementation varies significantly across different academies and regions. Jacky Galicher, a former academic CIO and CISO, emphasizes the need for digital security to be a shared foundation that ensures equal protection for all users, rather than a local success.
In 2022, as CIO-CISO of the Versailles academy, Galicher led the response to a distributed denial of service attack that disrupted online services for several hours, affecting thousands of users. This event prompted stronger collaboration with RENATER, a French research and education network, to deploy an intrusion detection system and train teams in best practices for managing such incidents. As a result, downtime during subsequent attacks was reduced by 90%. This experience reinforced Galicher’s belief that early detection and well-prepared teams are essential, as no written doctrine can replace effective, real-time response.
The digital transformation of education has brought numerous opportunities, but it has also introduced new vulnerabilities. Cybersecurity is no longer solely the concern of IT specialists. When digital services fail, accounts are compromised, or sensitive data is stolen, the impact is felt directly in teaching, administration, and user trust. While the National Education system has gradually developed a cybersecurity doctrine, defining responsibilities, strengthening protections, and establishing specialized roles, gaps remain between national strategies and their local implementation.
Cyber incidents can have far-reaching consequences beyond technical systems. A distributed denial of service attack once disrupted academic digital services, requiring enhanced cooperation with network operators and improved crisis response capabilities. Other incidents, such as fraudulent modifications to payroll systems and the unauthorized issuance of administrative certificates, have highlighted the need for stronger internal controls, traceability, and validation procedures. These examples show that cybersecurity is not only about protecting information systems but also about safeguarding administrative processes, personal data, and the overall quality of service provided to users.
Despite a clear national cybersecurity strategy, the execution of this strategy depends heavily on local operational capabilities, which vary widely. Some academies have established experienced teams, robust monitoring systems, and effective crisis management procedures, while others face resource limitations or competing priorities. This creates a paradox: while the doctrine is national, its implementation is often determined by local conditions. Cybersecurity has become a key element of the continuity of public services, and students and staff in different regions should have equal access to secure digital environments.
Making cybersecurity a shared culture is essential. Cyberattacks often exploit human behaviors, such as opening phishing emails or using weak passwords. Awareness among staff is as critical as technical measures. Teachers, administrators, and school leaders all have a role in fostering a collective culture of digital risk management, similar to how physical security and crisis management are approached. The goal is not to make everyone a cybersecurity expert but to ensure that all professionals understand their role in maintaining a secure digital environment.
Building a trusted digital educational environment requires more than just technology. Examples from the field show that when detection systems, account management, traceability mechanisms, and awareness campaigns are properly implemented, they yield tangible results. The real challenge now is not to develop new doctrines but to ensure that human, organizational, and technical resources are sufficient to apply these strategies consistently across the entire territory. In a school system that is increasingly digital, the ultimate question is whether cybersecurity can still depend on where one studies or works. If the answer is no, the challenge for the coming years will be to make cybersecurity a common foundation shared by the entire educational system.
Cybersecurity Gaps in France's Public Education System Highlighted
AI-rewritten from original reportingHow it works
cybersecurityeducationdigital-transformationfrancepublic-service



