I had a few amusing tactics. Even with 'professional best practices' (debatable), the human element was still vulnerable.
One example was that my school refused to give out the Wi-Fi password as a form of security, so they'd demand to manually type it in themselves on your machine. A simple keylogger and now the whole school just ignored that rule for a few months.
Another is that while they tried to block things like SSH, VPNs, etc... to get around the school's internet filtering, turns out you could just run SSH over port 80 and have a tunnel out :)