(This is Part 1 of our Cybersecurity Awareness Month 2026 series. Stay tuned for Part 2.)
Cybersecurity is never a one-and-done process. At all times, malicious cyberattackers are working 24/7 to steal and exploit data from online environments. In the age of Artificial Intelligence (AI) and other advanced technologies, cyberattack tactics such as phishing emails and AI-generated scams are becoming more convincing, making it more challenging for Managed Service Providers to prevent personal information from getting into the wrong hands.
This year, the Canvas incident has given institutions a reasons to take a closer look at security measures when it comes to their LMS. Today, we look through some of the frequently asked questions in the context of Moodle’s security and what you can do to ensure that your learning environments stay available and well-protected from security risks.
How secure is Moodle? Is there more to Moodle security than networks and firewalls?
Moodle LMS is developed through a ‘security-by-design’ approach and supported by the global security community. The software is continuously tested and monitored, and achieves all privacy compliance obligations. Moodle also provides education and ongoing communication flows to their users and partners.
Your web server and firewall setup is a critical component of a secure Moodle. However, It is important to note that the software is just one part of the equation here. There is always more you can do to ensure a secure LMS beyond these components.
Is my Moodle secure if it is patched to the latest version?
Your Moodle platform is secure when patched to the latest version; however, the security of your data, digital assets, and other sensitive information is more than just a patched Moodle instance.
Some of the questions organisations should be considering include:
- Do you have a suitable HTTPS delivery mechanism for your Moodle to defend against basic Denial of Service attacks and other common threats?
- Who has access to my production (prod) data, such as application backups?
- Where are these backups stored? Are they encrypted at rest?
- Are all admin users authenticating with multi-factor authentication? (via IdP or not)
- How often are we reviewing and deploying Moodle updates and upgrades?
- Do our non-Prod environments (UAT/staging/test) have the same data controls as our production environment?
Should we be encrypting data once outside of the production environment?
Yes! Unencrypted data leaves your platform and sensitive information vulnerable to data breaches from malicious cyberattacks. And because cyber attacks not only happen through external factors, it is important to carefully control who has access to data backups and encryption keys.
From a governance point of view, what should we be doing to make sure that our Moodle data is protected?
Regardless of how your Moodle is housed and managed, it is important to review your security policies and procedures on a regular basis.
At the leadership and operational level, organisations and enterprises should be reviewing these questions regarding accountability:
- Who is responsible for the Moodle data remaining in only the approved locations and visible to those who need access?
- Who is responsible for the cadence and up-to-date nature of the Moodle platform itself? This includes any software and security updates and compliance with privacy regulations.
- Is our authentication workflow in line with best practices, and do we regularly review the current users in our Moodle instance to ensure that only required user entities have access?
- Do we have visibility of malicious authentication attempts at a network level?
- Do we have the right process in place to review any third-party plugins installed on our Moodle platform?
- Do we have access to the right audit log for all events that will allow review and analysis of any potential historical event?
- How are we testing our backup and recovery capabilities in the event of catastrophic issues? What is our RPO and RTO, and are we capable of delivering on this?
- What is next in our iterative and strategic improvements?
From a technical point of view, what should we be doing to make sure that our Moodle data is protected?
At a technical level, there are many steps to ensure your Moodle data is protected. Beyond your firewall and security configurations at the platform level, it is also important to:
- Conduct security audits on a regular cadence.
- Invest in ongoing education and training for all users.
- Host your sites in a secure cloud infrastructure where all the necessary updates, patches and backups are automated and orchestrated.
- Use an experienced hosting and IT managed service provider that specialises in complex enterprise-level IT systems; ideally with 24/7 support.
- Have a plan / appropriate support in place for when things do go wrong.
How important is it that our team or our Moodle provider is ISO27001 and SOC 2-certified?
ISO27001 and SOC 2 are two of the most widely-used compliance standards around the world. Based on data security best practices, both frameworks have rigorous requirements in order to receive either attestation. These certifications are not just another metric, but also an assurance that teams who are certified adhere to their obligations around best practices and keeping your data safe and secure.
However, the reality is that not all teams will have the time or resources to acquire certifications, such as ISO27001 and SOC 2.
Working with teams or service providers with ISO27001 or SOC 2 certifications not only helps protect your business, but also gives you peace of mind that they are conducting the best practices for your organisation. In a world where information and data are prized possessions, investing in a team that will conduct their work at the highest level of compliance and safety will contribute to the backbone of your business, operations, and help you maintain customer trustworthiness for years to come.
Security starts with you.
October is Cybersecurity Awareness Month, an internationally recognized campaign held each October to help the public learn more about the importance of cybersecurity. This year’s theme – Your best defence is you – highlights that minimising cybersecurity risks for your organisation starts with us, and the systems we use to prevent cyber threats, like phishing and unauthorised access.
Secure systems pay off: it diminishes risks, ensures organisational continuity and access, and protects your organisation’s reputation. Cybersecurity is always a moving target and should always be a top priority in a time when cyberattacks can be aided by advanced technologies and AI.
ISO27001-certified, our team at Catalyst is highly committed to maintaining security and improving the resilience of our clients’ learning environments in the cloud, from conducting routine preventative IT maintenance to bringing security best practices to your Moodle LMS.
Get started on securing your Moodle LMS data. Get in touch with our team today and let us show how we can help!

