What You Will Learn
- Why AI is uniquely hard to secure
- Why identity is now a frontline security concern, and why a Zero Trust framework isn't a product you can buy, but rather a way of designing systems
- What to confirm on audit trails, proof, and data return before you hand over your data to a vendor
- How NIST CSF, ISO, GDPR, and CCPA compare
- How to approach AI and your school in the coming year
0:00 / 0:00
This article is adapted from an episode of the ATLIS Talking Technology podcast. Jo Bentley, Veracross’s Global CISO, and Mike Martell, Veracross SVP, Business Operations, joined the show to talk through what governing AI actually requires of independent schools. As the former Veracross CISO, Mike Martell oversaw the creation of Veracross’s security strategy, risk management, and technical security operations, including internal AI deployment. Their answers have been condensed for concision and clarity.
What are the biggest AI security challenges for schools?
Mike Martell: I typically come at this question from a technology perspective, because I’ll always be an engineer at heart. We struggle to draw a boundary around AI. With a lot of other traditional technologies, we were able to differentiate the technologies and put them into a category, into a bucket. But AI just breaks through a lot of those categories, a lot of our security perimeters, because of its ability to access so many different types of data, reason over them, and connect with other systems.
And that’s probably the thing that keeps me up most at night: not necessarily the technology itself, but all the connections that the technology has to various systems; auditing those connections, understanding and providing governance for those connections. Many of our schools are still catching up. They are still working to figure out a way to express their values in a policy that helps to prioritize and protect what matters most to them, while also providing access to a revolutionary technology. It’s a tricky balance, because there’s always going to be tension between security, privacy, compliance, and the ability to innovate and educate.
Beyond AI, what are the top security and privacy concerns for schools?
Jo Bentley: For me, outside of AI, the sheer amount of regulatory requirements that we have to interact with, both from a cyber and a privacy point of view, and the changes those requirements are introducing into the ecosystem, is dizzying. For someone like me, that keeps me up at night. When you’re a global company, there are various permutations of these requirements you have to adhere to, and that in itself is a full-time job: just keeping tabs on what one country requires versus the other; how to appropriately engage both on the privacy side of the house and the cyber side of the house. They are distinct requirements, and they’re coming fast and furiously.
MM: I’d pick up on that and say that from a technology perspective: aside from AI perimeters, it’s identity: that identities can be very easily faked at this point, and that a zero trust framework is table stakes when it comes to identity verification: I’ve found that many believe that a zero trust paradigm is a technology you can buy, but it isn’t. It’s a way of thinking. It’s a way of designing systems.
What safeguards does Veracross practice when it comes to adopting AI technologies within the company?
MM: One safeguard has to do with the way we adopt AI as a corporate entity. We are very careful in our understanding of the data perimeter, that is to say, careful about separating our customers’ data, of which we are a processor, from our corporate data.
The second safeguard echoes back to the complex patchwork of global compliance frameworks we’re all subject to: AI in our product, which is an even slower roll. Not only do we have to be very careful about those security perimeters and understand what the technology will do, we also have to be respectful of the requirements and rights that each one of our customers brings, which is very different for a school in Virginia versus a school in Belgium or a school in New South Wales.
Trying to marry up all those requirements takes time and thought, and has a real impact on the product itself, because there are additional technical requirements that have to be met in order to safely apply an AI reasoning technology to customer data.

JB: I’ll just add that we are being careful about what our use cases are. With everything appended with “AI” at the beginning of every sentence, the assumption is that AI does it all. In reality, it does not. You have to be clear about how you intend to use it, for what purpose, and what value it brings to the overall delivery chain. That in itself is extremely important.
How should independent schools vet a vendor that holds their data?
MM: In the almost 10 years I’ve been working in this space, we’ve seen an explosion of requirements. We have schools that have a lot of expertise and a lot of resources to put towards compliance and privacy, such as having internal counsel. And then we have schools on the other end of the spectrum where it’s one person doing many things. On average, it’s somewhere in between those two.
Generally speaking have a general idea of what the requirements are and then come to your vendor with a simple set of questions about how they will help you meet those requirements. Understand that the onus typically is on the school, which, from a GDPR framework, is a controller; the school’s responsibility is to select vendors that meet the requirements they are subject to. Just understanding that is a really big step towards understanding how to have a really good relationship with a vendor from a security and a privacy perspective.
It truly comes back to one thing. It’s your asset; you need proof it is being treated the way you expected.
JB: It’s important to start with two questions. What problem am I trying to solve? What vendors solve that problem? Once you’ve established that and you move into due diligence, remember that your data is your asset, the most important thing in the room. Whoever engages with it is required to protect it in the way you would yourself.
The other thing to remember is that when you entrust an asset to someone else, you are still accountable for it. Out of sight is not out of mind. Look at audit reports and audit trails and have a way to make the vendor prove they are meeting the requirements of the law, your data requirements, and your recovery requirements if for some reason they are no longer there. And if you’ve given them your data, establish how you get it back if and when you no longer want to do business with them.
In practical terms: we can overlay all the regulations and talk about the complexity, but it comes back to one thing. It’s your asset; you need proof it is being treated the way you expected.
Should schools add custom contract addendums for data protection?
MM: This is something I work with every day. The strategy I would advise schools to take is to find counsel you trust: someone who is going to provide you with easy-to-understand advice and guidance about the environment you operate in. Not necessarily someone who’s going to list off a million bullets of legalese, but someone who understands what your operating conditions are; Virginia, or Germany, or New South Wales, wherever you are; and then provides you with practical guidance about what to look for.
And then to your vendor: we do this every day. Veracross maintains a Data Processing Agreement. We maintain other papers that are privacy and compliance related. When a school comes to us with that succinct, practical guidance, we are always willing to work with them to make updates, changes, or addendums; to make a specific version of a contract or a specific version of a DPA that meets that school’s requirements.
For schools, the most efficient way to do this is to know the environment you operate in; bring someone in who can help bridge the gap between your practical day-to-day experience and the ever-changing regulatory framework, and who knows the right keywords; and then someone who can consume a DPA or a contract or an MSA or a privacy policy and actually do that mapping between the concepts that matter most and how they’re expressed in these privacy papers.
What role should edtech providers play in school security and privacy?
MM: The answer has changed dramatically, even over the past five years. When I started in this space the idea of an ed tech vendor providing security advice or information to one of our customers was pretty far-fetched. These days, there isn’t a contract negotiation that goes by without questions about security and compliance, and it is top of mind for many people.
A principle that we have adopted, that I think other vendors should also adopt, is that a rising tide lifts all ships, especially for our customers who don’t have entire teams of security and compliance professionals available to them. We will have deep conversations with them to help them understand what their own positioning is from a technical and a legal perspective, although we still don’t really provide legal advice to our customers. We also take further steps to provide them with some technical insight to help them assess their own systems. If we can help our schools get a bit of an edge in that space through technical, consultative, and other approaches, we’re absolutely going to do that, because that investment is worth it for everyone.
JB: It’s important to inform and educate; in my mind, that is where the security services need to sit. I can’t roll up my sleeves and walk into a school and interact with their network, but I can inform you and educate you on how best to proceed. I can point you to resources. I can have a webinar with you. But I can’t go in and interact with your underlying structures. I think that’s probably where it needs to be.
At the end of the day, schools are communities and being able to reflect that in Veracross’s technology is something that matters very much to us.
What is next for Veracross on security and AI?
MM: We’re going in a lot of different directions, and we’re very excited about them, but there are two that resonate most with this overlap between security, compliance, and AI.
Let me start with the security and compliance perspective. Helping our customers find comfort in what we can bring to them from a security and compliance perspective is very important to us. I’ll use Australia as an example. Australia has a very interesting perspective on data, privacy, and security that is a little bit different from a GDPR model; it’s a little bit different from the way in which many US states and other jurisdictions adopt it. Having meaningful conversations with our customers so we can bring to them what they need, what their underwriters need, and what their communities need, is a big direction we continue to go in. At the end of the day, there are themes and principles that underlie all these regulations and laws, and being able to connect with people on a human level and help understand what their values are in that space is very important to us.
From the AI perspective, Veracross is working on AI tooling for our customers as well. The idea behind it is that we like to think of ourselves as a community operating system, because, like many other large ed tech spaces, we are just so embedded into our customers’ lives, and their parents’ lives, and their students’ lives. Being able to safely and transparently bring tools to our customers (agents, chat, and so on) that help support their community in a healthy way, is a big part of where we want to go from an AI perspective. And to do so in a transparent, safe, and opt-in way. At the end of the day, schools are communities and being able to reflect that in technology is something that matters very much to us.
Which security framework should schools treat as the gold standard?
JB: Instinctively, the ISO standard pops to mind as the gold standard, especially in cyber security. But this comes into play when you’re talking about portability and expense. ISO is usable internationally, but at a significant expense.
When it comes to standards that are usable in most places, I would go out on a limb and say NIST is becoming the de facto standard, for the simple reason that it is effectively free to adopt; US taxpayers cover the cost of the NIST standards, so a school does not have to spend significantly to baseline against it. NIST does a very good job of defining AI structures, AI governance, and underlying cybersecurity controls, and even privacy in the last couple of years. So NIST CSF, in that scenario, becomes the gold standard.But also be aware: if you’re international, people may ask you for more than that, especially when particular regulators are involved.
MM: I agree NIST is fantastic because of the breadth and depth it provides. I also agree that GDPR feels like home. It was really one of the first frameworks that got us all thinking about this, aside from PCI DSS, which has also been around forever, and of course HIPAA and other specialty frameworks. But aligning on GDPR makes sense to me, because so many of the world’s privacy frameworks are derived from GDPR.
And I have to say, CCPA, from a US-based perspective, because up until recently, they’ve really been the thought leaders in that space, even extending beyond some of the protections GDPR traditionally had.
What should independent schools do about AI in the coming year?
JB: Lean into AI: have a clear policy and have a governance structure. Apart from that, as you continue to engage in AI, it’s really exciting. It’s seamless. It’s easy to engage with. But that simplicity, that ease, equally translates to a loss of data, a compromise of an environment, an ill use of the data. So if anything, be clear about what your intentions are; include it in a policy. Have a structure that allows you to continuously understand how you’re interacting. But I will also add: have fun with it.