Skip to content
MarketScale
‹ Back to IndustriesSoftware & Technology

Cybersecurity Compliance is Only Half the Battle for EdTech

TechCrunch recently reported on accusations levied by the Federal Trade Commission against edtech giant Chegg – the FTC filed a legal complaint earlier this week indicating that Chegg’s lapses in cybersecurity compliance has resulted in numerous separate data breaches in recent years, and that these breaches were avoidable with better cybersecurity practices. Sai Huda, CEO…

This story was produced through MarketScale. See how Software & Technology teams put it to work with Executive Thought Leadership.

By Software And Technology · Cyber Security ComplianceCybersecurityEdtechResponse Plan
Share

Key takeaways

01

TechCrunch recently reported on accusations levied by the Federal Trade Commission against edtech giant Chegg – the FTC filed a legal complaint earlier this week indicating that Chegg’s lapses in cybersecurity compliance has resulted in numerous separate data breaches in recent years, and that these breaches were avoidable with better cybersecurity practices.

Get featured

Want to get featured in MarketScale Software & Technology?

Create a free MarketScale workspace and get your company's expertise featured across our Software & Technology coverage. No credit card, no demo required.

Request an invite

TechCrunch recently reported on accusations levied by the Federal Trade Commission against edtech giant Chegg – the FTC filed a legal complaint earlier this week indicating that Chegg’s lapses in cybersecurity compliance has resulted in numerous separate data breaches in recent years, and that these breaches were avoidable with better cybersecurity practices.

Sai Huda, CEO of CyberCatch, explains that cybersecurity compliance is only the first step in ensuring data security for edtech customers. The knack is ongoing maintenance and management of those security systems to identify and plug holes as needed – with thousands of attacks levied against educational institutions, hackers will always find vulnerabilities and exploit them.

Sai’s Thoughts

“Along with that, there’s gotta be two other things they’ve gotta do. One is they’ve gotta test those controls regularly. So just implementing the hundred eight controls and thinking you’re in compliance, it is just step one, the step 2, 3, 4, 5, 6, 7, 8, 9, 10 are to continuously test those controls because controls will break.

So, the key is to find those control failures, those security holes before the attackers do, and then plug them, and therefore the attackers will not be able to exploit those security holes and will not be able to be successful. The third thing the school sector must do is to have an incident response plan because it’s not a question of if, but when an incident will happen.

So the key is to be able to detect this incident and then to be able to respond so that damage is mitigated so that perhaps ransomware isn’t spread. Perhaps it can be curtailed. Data can be prevented from being stolen. Incident response plan is also key, and it must be implemented. That’s the way to be successful.

K12 schools are definitely in line of sight of attackers. CyberCatch scanned over 11,000 websites, internet facing assets of K-12 schools in the US and we found over 60% having vulnerabilities attackers can easily exploit break in, install ransomware and steal data.

So, this along with the FTCs order, should be a wakeup call for the whole K-12 sector to be proactive.”

Your experts belong here

Every story in MarketScale Software & Technology starts with a company putting its solutions engineers, product teams, and customer engineers on the record. Buyers are already reading this topic. The only question is whose experts they find.

Buyers ask AI engines who to consider, and published expert answers are what those engines cite.

Get your team featuredSee how it works15 minutes, straight to a calendar.

About the author

SA
Software And Technology

Follow Software & Technology Insights

Get new expert content in your inbox.

Software & Technology: are you visible to AI?

Before they reach out, Software & Technology buyers ask AI engines which vendors to trust. See how AI describes your company today, and where competitors show up instead.

Free workspace

You just read one Software & Technology expert. Your company is full of them.

This article was produced through MarketScale. The same platform turns your solutions engineers, product teams, and customer engineers into the articles, video, and social content Software & Technology buyers are searching for. Create a free workspace and see it with your own people. No credit card, no demo required.

NPS +73 · 1,000+ creators · 38+ countries

What you get, free

Your own MarketScale Studio workspace
One video edit a month, on us
AI writing, editing, and publishing tools
In-platform coaching to learn the system

More Software & Technology Insights

OpenAI's GPT-6 Astra pitch is to skip integrations and run the software UI itself

OpenAI's GPT-6 Astra pitch is to skip integrations and run the software UI itself

OpenAI shipped GPT-6 Astra on Sept. 3 with a "computer use" capability that lets the model operate existing software UIs directly instead of requiring custom API integrations. The staged rollout through Daybreak, ChatGPT tiers, and AWS shifts the automation bottleneck from building connectors to governing UI-driven sessions, with speed measured in minutes per task as the cost input.

  • 01Astra operates software via pixels, keyboard, and mouse interactions to bypass API integration work on the long tail of internal tools without clean API access
  • 02OpenAI reported Astra at 40 minutes per task (47% faster than GPT-5.6 Sol at 75 minutes), making task time the practical proxy for compute cost modeling and throughput evaluation
  • 03Enterprises must define governance before broad rollout: eligible workflows for UI automation, audit logging systems, identity and secrets handling, and fallback procedures when UIs change or sessions break

Sep 3, 2026

Cloud is set to take 26% of IT budgets, and hiring is shifting toward platforms

Cloud is set to take 26% of IT budgets, and hiring is shifting toward platforms

Foundry’s 2026 Cloud Computing Study, cited by CIO, reports IT leaders expect 26% of IT budgets to go to cloud computing in the next year and that 74% accelerated cloud migrations in the last 12 months. At the same time, CIO’s coverage of Robert Half Technology’s 2026 IT salary report shows AI/ML engineers at a $170,750 median salary and a striking capability gap, with only 7% of leaders saying they have the capabilities to complete prioritized projects and 65% expecting to upskill existing staff. Separate reporting from Nextgov on senior appointments in the Pentagon CIO office, and Government Technology’s account of Illinois’ multi-agency data-sharing MOU, indicate large organizations are staffing for organizational change, governance, and cross-domain data sharing, not just for lift-and-shift migrations. For enterprise operators, the signal is that cloud programs increasingly depend on internal platform engineering, adoption enablement, and finance-aligned governance, because those functions connect migration speed to day-two operations and business results.

  • 01A useful benchmark for 2026 planning: Foundry’s survey puts cloud at 26% of IT budget next year, so showback/FinOps and workload-level chargeback governance can’t stay a side project (per CIO citing Foundry).
  • 02Talent pricing has become an input to architecture decisions. A CIO, citing Robert Half, compared the median pay for AI/ML engineers ($170,750) with systems administrators ($98,000), arguing that platform standardization and self-service guardrails are as much about labor strategy as technology.
  • 03If 65% of leaders expect to upskill to close gaps, the differentiator becomes your internal adoption system, in-app guidance, runbooks, and training telemetry, not the third new tool in the stack (per CIO citing Robert Half; illustrated by Ferring’s Whatfix rollout reported by BankInfoSecurity).

Sep 2, 2026

AI agents are pushing access controls and testing into the data layer

AI agents are pushing access controls and testing into the data layer

Snowflake is warning that dashboard-era access controls do not hold up once AI agents can query and act across datasets, pushing governance closer to the data layer, according to TechTarget’s Computer Weekly. In parallel, TechTarget reported that enterprise AI-agent testing needs to expand beyond pre-deployment checks into continuous monitoring so agents don’t drift beyond prescribed instructions. InformationWeek’s reporting on CISOs at Intuit, Smartsheet and ETS adds the operational risk: unmanaged “AI orphans” and identity sprawl as agent count grows, which shifts near-term workload onto IAM, data governance and platform engineering teams building the guardrails.

  • 01If an AI agent can reach multiple tools, the real control plane becomes the data layer and identity, not the BI dashboard permissions model.
  • 02Agent rollouts that stop at pre-production testing are likely to miss the failure mode operators actually see, post-deploy tool changes that alter what the agent can do.
  • 03“AI orphans” is a practical inventory problem: if teams can’t enumerate agents, they can’t set ownership, secrets rotation, or access reviews on a schedule.

Sep 2, 2026

Explore More Software & Technology Insights

Read more expert perspectives from across Software & Technology.

Browse Software & Technology Hub

About the Expert

SA
Software And Technology

For B2B teams

Your experts could be publishing here

Stories like this one run on content MarketScale captures from real practitioners. See how your team's expertise becomes coverage in Software & Technology and beyond.

Book a 15-minute demo

Or call us. No forms required. We pick up. 214-945-2512