Five student-data files every campus IT admin should lock down this week
If you run IT at a school or college, you already know the leak is not the firewall. It is the files nobody owns.
These five show up on almost every campus I have seen:
The admissions export. A CSV of applicants sitting in someone's downloads folder from last cycle. Names, phones, marks, caste/category fields. Delete the copies. Keep one access-controlled source.
The WhatsApp class groups. Faculty forwarding student lists to coordinate labs. Treat that as a data store. If it has a spreadsheet attached, it is in scope.
The old LMS. The previous Moodle/Google Classroom that never got decommissioned. Student work and emails still live there.
The exam cell shared drive. Answer sheets, seating charts, roll numbers. Usually "everyone in admin" has editor access.
The vendor login spreadsheet. Hostel, ERP, biometric, library. If that sheet leaks, the student records behind those logins leak with it.
None of this requires a new firewall. It requires an inventory and an owner for each system.
If your campus does not have that list written down, start there. That is the job.
