Recent Wave Of University Hacks Underscores Continued Security Concerns
| PR Newswire Association LLC |
Just this year, hackers have been successful in gaining access to over 740,000 student and alumni personal information records, including social security numbers, combined. The breaches occurred at
These recent breaches highlight the reason why universities need to take security seriously and extend their safeguards beyond unsecure email. While HALOCK's investigation highlighted a certain type of security lapse, the recent breaches underscore that universities need to consider security comprehensively.
Why aren't schools and universities taking the necessary steps to safeguard sensitive information? "Universities in general have limited budgets for information security, and therefore struggle to comply with the numerous laws and regulations regarding the data in their custody," says
Universities are overwhelmed by a number of issues:
- Typical university cultures promote open access to information: A core requirement for information security is the classification of information and systems. And because colleges and universities are quasi-public places, they must separate their public network zones from their sensitive network zones and ensure that each are secured according to their risk.
- Transient and inexperienced student workers: After colleges and universities have separated their sensitive systems from their public systems, they can assign student employees with jobs that manage the public systems, leaving sensitive information in the control of properly trained and vetted permanent employees.
- Limited security and compliance budgets: While colleges and universities have lower budgets than some organizations, no organization has enough budget to address all of their security needs. All organizations must prioritize their investments using the risk assessments that are required by law.
- Student hackers have ample time to target the university that is teaching them hacking skills: Especially for colleges and universities that provide information security courses, academic networks can become the "lab" for course homework … in other words, when you teach information security, expect your students to hack your network for practice. Ensure that those who teach the courses collaborate with IT personnel to detect and prevent the activities that are being taught in the classroom.
- Information technology changes are often limited to seasonal university breaks: Major security patches, upgrades, and security tool implementations are often held off until inter-semester periods when the risk of unavailable systems is lower. But this also means that the security risk is at its highest when class is in session. Proper change management processes can reduce your availability risks while making timely security upgrades.
- Difficulty in educating the
Board of Trustees or Regents on security risks: A well-constructed risk assessment will define risks, in part, by their impact to the mission of the institution. Impacts to students, faculty, research funding and the school's reputation and finances should all be considered as factors in risk assessments. A risk statement that reads, "A breach of PHI records from the research database, which foreseeably could happen over the next year, would result in major fines and would compromise our ability to get IRB approval for future research, as occurred atXYZ University Hospital last year," is far more compelling argument than, "Please can we buy the two-factor authentication appliance? It could prevent a breach!"
According to Kurzynski, "Universities need to get serious about securing their environment. They need to be sure that they are following security standards, as well as the laws and regulations that require the protection of personal information." Some find this challenging especially when budgets are tight.
Universities that implement a risk management framework often find it easier to reach compliance. "Under this framework, organizations invest in security so that they manage the likelihood and impact of breaches," says Kurzynski. "Securing information according to risk becomes much more manageable than might have previously been imagined."
About HALOCK www.halock.com:
Founded in 1996,
312.391.8007 Email
847.221.0203 Email
Read more news from HALOCK.
SOURCE HALOCK
| Wordcount: | 841 |



Advisor News
- Retirement moves to make before April 15
- Millennials are inheriting billions and they want to know what to do with it
- What Trump Accounts reveal about time and long-term wealth
- Wellmark still worries over lowered projections of Iowa tax hike
- Wellmark still worries over lowered projections of Iowa tax hike
More Advisor NewsAnnuity News
- New Allianz Life Annuity Offers Added Flexibility in Income Benefits
- How to elevate annuity discussions during tax season
- Life Insurance and Annuity Providers Score High Marks from Financial Pros, but Lag on User Friendliness, JD Power Finds
- An Application for the Trademark “TACTICAL WEIGHTING” Has Been Filed by Great-West Life & Annuity Insurance Company: Great-West Life & Annuity Insurance Company
- Annexus and Americo Announce Strategic Partnership with Launch of Americo Benchmark Flex Fixed Indexed Annuity Suite
More Annuity NewsHealth/Employee Benefits News
- Trump's Medicaid work mandate could kick thousands of homeless Californians off coverage
- Confidence is the new workplace currency
- Governor signs education package on reading, math, teacher benefits
- Findings from Belmont University College of Pharmacy Provide New Insights into Managed Care and Specialty Pharmacy (Comparing rates of primary medication nonadherence and turnaround time among patients at a health system specialty pharmacy …): Drugs and Therapies – Managed Care and Specialty Pharmacy
- Study Data from Ohio State University Update Knowledge of Managed Care (Preventive Care Utilization, Employer-sponsored Benefits, and Influences On Utilization By Healthcare Occupational Groups): Managed Care
More Health/Employee Benefits NewsLife Insurance News
- New Allianz Life Annuity Offers Added Flexibility in Income Benefits
- Investors Heritage Promotes Andrew Moore to Executive Vice President; Names Him CEO of Via Management Solutions
- Kansas City Life: Q4 Earnings Snapshot
- Gulf Guaranty Life Insurance Company Trademark Application for “OPTIBEN” Filed: Gulf Guaranty Life Insurance Company
- Marv Feldman, life insurance icon and 2011 JNR Award winner, passes away at 80
More Life Insurance News