How Colleges and Universities Defend Against Cyber Threats

How Colleges and Universities Defend Against Cyber Threats

Colleges and universities store a variety of information and data that is very pleasing to hackers, making these institutions a main target. This has prompted places of higher learning to devise effective ways to deal with information security threats by taking into consideration the motivation of hackers and then developing action plans and strategies based on each motivation to thwart social engineering scammers. This has produced a number of ways to defend against cyberattacks.

Some of the more intriguing motivations for hacking a college or university are financial gain (credit card information is stored in a variety of places: registrar to pay for tuition, the campus bookstore’s POS, etc.) and access to secure data and research information. Based on these motivations, one strategy is to analyze tactics, techniques and procedures (TTPs) of cybercriminals to better understand:

  • Who is targeting;
  • What the criminals want; and
  • Methods the criminals will likely use to gain unauthorized access.

Based on the answers to the TTPs, an effective plan of action can be developed. Here are some ways in which colleges and universities defend themselves against breaches:

Create a culture of openness: The Higher Education Information Security Council encourages colleges and universities to adopt this principle. It allows for open and honest collaboration with other organizations about what is and is not working.

Two-factor authentication (2FA): By adding an extra step to an account log in, an extra layer of protection is added to campus accounts and services. The first step is typically a username and password combination followed by something the user knows, like a PIN; something the user has, like a card or phone; or something the user is, like a fingerprint.

Knowledge-based authentication (KBA): This authentication scheme asks the user to answer at least one “secret” question that the user has previously added usually during account creation. This is less intrusive and appropriate to secure most types of information.

Incident response plans: As soon as a breach occurs, people want answers. It is in the best interest of educational facilities to have an established plan that handles the situation in a way that limits damage and reduces recovery time and costs. The plan should include a policy that defines what exactly constitutes an incident and a step-by-step process to remedy the situation.

Conferences: These events are great places to share knowledge and best practices among other like-minded professionals. Typically, there are expert speakers who speak about a variety of topics to help foster relationships for colleges and universities to defend themselves against threats.

About the Author

Ginger Hill is Group Social Media Manager.

Featured

  • 66 Percent of Cybersecurity Pros Say Job Stress is Growing

    Sixty-six percent of cybersecurity professionals say their role is more stressful now than it was five years ago, according to the newly released 2024 State of Cybersecurity survey report from ISACA, a global professional association advancing trust in technology. Read Now

  • Live from GSX 2024: Post-Show Recap

    Another great edition of GSX is in the books! We’d like to thank our great partners for this years event, NAPCO, LVT, Eagle Eye Networks and Hirsch, for working with us and allowing us to highlight some of the great solutions the companies were showcasing during the crowded show. Read Now

    • Industry Events
    • GSX
  • Research: Cybersecurity Success Hinges on Full Organizational Support

    Cybersecurity is the top technology priority for the vast majority of organizations, but moving from aspiration to reality requires a top-to-bottom commitment that many companies have yet to make, according to new research released today by CompTIA, the nonprofit association for the technology industry and workforce. Read Now

  • Live from GSX 2024: Day 3 Recap

    And GSX 2024 in Orlando, is officially in the books! I’d like to extend a hearty congratulations and a sincere thank-you to our partners in this year’s Live From program—NAPCO, Eagle Eye Networks, Hirsch, and LVT. Even though the show’s over, keep an eye on our GSX 2024 Live landing page for continued news and developments related to this year’s vast array of exhibitors and products. And if you’d like to learn more about our Live From program, please drop us a line—we’d love to work with you in Las Vegas at ISC West 2025. Read Now

    • Industry Events
    • GSX

Featured Cybersecurity

Webinars

New Products

  • FEP GameChanger

    FEP GameChanger

    Paige Datacom Solutions Introduces Important and Innovative Cabling Products GameChanger Cable, a proven and patented solution that significantly exceeds the reach of traditional category cable will now have a FEP/FEP construction. 3

  • Unified VMS

    AxxonSoft introduces version 2.0 of the Axxon One VMS. The new release features integrations with various physical security systems, making Axxon One a unified VMS. Other enhancements include new AI video analytics and intelligent search functions, hardened cybersecurity, usability and performance improvements, and expanded cloud capabilities 3

  • Luma x20

    Luma x20

    Snap One has announced its popular Luma x20 family of surveillance products now offers even greater security and privacy for home and business owners across the globe by giving them full control over integrators’ system access to view live and recorded video. According to Snap One Product Manager Derek Webb, the new “customer handoff” feature provides enhanced user control after initial installation, allowing the owners to have total privacy while also making it easy to reinstate integrator access when maintenance or assistance is required. This new feature is now available to all Luma x20 users globally. “The Luma x20 family of surveillance solutions provides excellent image and audio capture, and with the new customer handoff feature, it now offers absolute privacy for camera feeds and recordings,” Webb said. “With notifications and integrator access controlled through the powerful OvrC remote system management platform, it’s easy for integrators to give their clients full control of their footage and then to get temporary access from the client for any troubleshooting needs.” 3