I opened my session at InstructureCon 2026 with a number that still stops me. In 2019, the average time for an attacker to exploit a known vulnerability was 63 days. Today it's just seven. Attackers are moving roughly nine times faster than they were a few years ago, and the pace is still climbing.
Since ChatGPT arrived in 2022, most of the conversation in our field has been about how AI changed the math for teaching and learning. While the rest of the world used the new tools to generate dad jokes and cat memes, educators were immediately handed hard questions about assessment, honesty, and what teaching looks like now. Those questions won't ever be fully "answered," because the tools and the learners keep changing. The same disruption is happening in security.
Education is now one of the most attacked sectors online
This isn't an Instructure story or even an LMS story. It's an industry-wide one. Microsoft's Cyber Signals report found that education is among the most targeted industries online, with the average institution facing roughly 2,507 attack attempts every week. Ransomware follows the same curve. Comparitech tracked a 23 percent year-over-year rise in ransomware attacks on education in the first half of 2025, and the sector now ranks fourth for ransomware targeting, behind only business, government, and healthcare.
Schools and universities make appealing targets for reasons that won't change soon. They hold enormous amounts of personal and research data, they run on tight budgets and lean IT teams, and they can't simply take systems offline when a semester is in progress. AI hasn't created these conditions, but it’s made them far cheaper to exploit.
Good security is now measured in speed
I've been at Instructure for almost 15 years, and for most of that time, our security program looked the way you'd expect from an enterprise software company: phish-resistant authentication at the perimeter, annual penetration tests and a researcher-led bug bounty program to surface gaps, and certifications like SOC 2 Type II and ISO 27001 to validate the work.
That model was designed for a world where an attack took real resources and deep knowledge of the platform. Finding and exploiting a vulnerability was slow, skilled work. The cost of that work has dropped by a factor of nine. The perimeter still matters, but a strategy that assumes attackers are slow and few is already out of date.
The question I care about isn't how we recover from any single event. It's how we design for a world where attacks are more frequent, cheaper to launch, and harder to see coming. That reframes what "good security" even means. The advantage goes to whoever can detect, decide, and respond fastest while an attack is still taking shape.
We've built toward that. We consolidated and expanded the protections in Canvas by Instructure against cross-site scripting and similar attacks so gaps are easier to find and fix. We added step-up authentication and a second identity layer that shrinks the blast radius if any one account is compromised. And we sharpened real-time detection with better logging, monitoring, and blocking tools. AI is on our side of this too. We use it to validate changes faster and close the gap between finding a weakness and fixing it. But as we do this, our principle remains clear: AI is a tool, not a pilot. A human developer still reviews, signs off on, and takes ultimate ownership of every single change we push to production.
Resilience is becoming its own discipline
The encouraging part is that the sector is already learning this. Sophos, in its State of Ransomware in Education 2025 report, found that 53 percent of education institutions hit by ransomware recovered within a week, up from 35 percent the year before. Recovery is getting faster because more institutions treat continuity as something to plan for in advance rather than improvise mid-crisis.
Hardening reduces risk, but it never eliminates it. Trees with deep roots still have to sway when the storm comes. No honest vendor can promise a world with zero incidents, so the more useful promise is a different one: if something disrupts teaching and learning, you won't be left in the dark, and you'll have options.
We build what you need, and nothing you don't
The principle I keep coming back to: We could ship a long list of continuity features. Instead we're building what institutions have told us they need first.
Backing up a course shouldn't require a strong engineering team, and it shouldn't be a software project. It should be a setting. So we're making scheduled exports something any admin can turn on, starting with the gradebook data that ranked as most important, available to every Canvas customer without an upgrade. We're also building self-service tools to remove data you don't need us to keep, because good stewardship means holding only what's necessary.
The next questions are the interesting ones
We're thinking further ahead than the next release. We’ve heard requests from customers and started exploring what we can do to increase resilience: read-only access so instructors and learners can reach content during an outage, offline grading in our mobile apps, a partnership with AWS to explore failover to a secondary instance. None of these are committed roadmap items yet, but continuity is a shared responsibility, and I'd rather decide what's worth building with our community than for it.
Securing and strengthening these platforms is never finished, for the same reason the work of teaching never is. The tools change, the challenges change, and staying ahead means treating prevention and resilience as living systems rather than boxes to check. We'll keep building in the open, because the collaboration that made edtech what it is will be what keeps it secure.
Where this goes next
InstructureCon was where we started this conversation, but we’re excited to show off where we’re headed next at our New & Next Showcase in October. You can see what else we launched this summer and announced at InstructureCon 2026 here.