C1. Control Exposure
Decide what’s public on purpose — for the school, for staff, and for students.
In plain language.
Control Exposure is not “hide.” A school has to be findable. Families need to reach the front office, the enrollment page has to rank, and a teacher needs a public email address. Invisibility isn’t a security goal; it’s an enrollment problem with a security excuse.
The practice is narrower and much more answerable: what is public by accident? Not what could theoretically be removed — what got out there without anyone deciding it should.
Almost everything in this category was published by a well-meaning person in a hurry. A staff directory with cell numbers. A field-trip photo with a student ID badge in frame. A shared calendar set to public three years ago by someone who has since retired.
What’s different in a school.
Exposure is the raw material for everything that comes after it. A social-engineering call is only convincing because the caller knew the principal’s name, the bookkeeper’s name, and that the school was mid-fundraiser. None of that was hacked. It was read.
Schools are unusually exposed by design: public calendars, staff directories, board minutes, sports schedules, newsletters. That transparency is a civic good and mostly worth keeping. The work is separating the transparency you chose from the transparency you inherited.
What this looks like in practice.
The same practice, told three ways — so a champion can pick the version they need this week.
The staff directory
A directory page lists every employee with a title and a direct email in first.last@ format. That’s a complete org chart and a valid address pattern — enough to write a convincing message from “the principal” to the bookkeeper. The fix isn’t deleting the page. It’s deciding which roles need a direct address and which route through a shared inbox.
What a student can find about themselves
Have students search their own name and their school’s name. The exercise lands harder than any lecture, because they find things they genuinely forgot posting. It also introduces a real professional skill — open-source research is an actual job function in this field.
The family calendar problem
Vacation posts, school-pickup routines, and geotagged photos tell a stranger when a house is empty and where a child will be at 3pm. Framed for families, this is the least abstract version of C1 there is.
Search yourself, then the school
Thirty minutes, no tools, no budget.
- Search the school’s name. Read the first two pages honestly, not defensively.
- Search your own name plus the school’s name.
- Write down anything neither you nor a colleague published on purpose.
- Start with whoever carries the most personal risk — usually not the head of school.
- Fix one item. Put the rest on next month’s champion agenda.
Activities by grade band.
Each fits a single class period and needs no lab, no licence, and no prior technical background from the teacher.
The Footprint Walk. Give pairs a fictional student profile — a few public posts, a sports roster, a yearbook page. Ask what they can work out that the profile never states: where this person lives, when they’re alone, who their siblings are. Debrief on how little it took.
Open-source research brief. Students research a consenting volunteer — a teacher who has opted in — using only public sources, and write a one-page brief. Then the class writes the reduction plan. This is a real entry-level task in the field, and it maps directly onto ITF+ and CC coursework.
Exposure precedes the attack
Verizon’s 2025 analysis puts social engineering and human error at the center of 60% of breaches, with phishing the initial access vector in 16%. Those messages work because they are specific, and they get specific from public information.
Source: Verizon, 2025 Data Breach Investigations Report. Full reference list on the 4C overview.