{"id":536,"date":"2019-01-15T16:46:42","date_gmt":"2019-01-15T15:46:42","guid":{"rendered":"http:\/\/www.intelligentcio.com\/apac\/2019\/01\/15\/quest-software-expert-on-the-insider-threat-to-the-education-sector\/"},"modified":"2023-05-25T11:51:16","modified_gmt":"2023-05-25T10:51:16","slug":"quest-software-expert-on-the-insider-threat-to-the-education-sector","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/apac\/2019\/01\/15\/quest-software-expert-on-the-insider-threat-to-the-education-sector\/","title":{"rendered":"Quest Software expert on the insider threat to the education sector"},"content":{"rendered":"<p><em>Cybercrime is a growing problem globally and the higher education sector is not immune to this threat, argues Colin Truran, Principal Technology Strategist, Quest Software.<\/em><\/p>\n<p>As today\u2019s modern campus relies on online services to power its learning and teaching environment, a greater number of devices belonging to students or staff connected to the network are exposing universities to cyberthreats.<\/p>\n<p>In turn, valuable data such as breaking research, students\u2019 personal information and employee information, which is collected and kept on file by universities is in danger of being used for nefarious means by hackers. In addition to data being misused, universities are at risk of suffering reputational damage if they are unable to keep their network safe.<\/p>\n<p><strong>The biggest cybersecurity threat<\/strong><\/p>\n<p>As universities own a wide pool of valuable data, their networks are being targeted by a range of different tactics&nbsp; such as phishing attacks or ransomware, as well as a range of hackers&nbsp; \u2013 from nation states, to traditional, independent hacking groups. However, recent findings by Jisc, UK\u2019s not-for-profit organisation offering digital services and solutions to UK higher, further education and skills sectors, found that the biggest threat to universities cybersecurity are the students and staff.<\/p>\n<p>Based on data which Jisc has been collecting for years, the organisation concluded that it is highly likely staff and students are to blame for attacks for one reason \u2013 timing. According to Jisc, attacks on universities dramatically decrease during holidays such as Christmas; Easter, half-terms or summer holidays.<\/p>\n<p>This pattern could signal that attackers are in fact students or staff, or someone <em>very<\/em> familiar with the academic cycle. Additionally, Jisc found that attacks usually start between 8am and 9am, quieten around lunchtime but ramp up around 1pm and 2pm.<\/p>\n<p><strong>Look within the network<\/strong><\/p>\n<p>Students and staff are the core of each educational establishment and as such it is difficult to imagine the biggest cybersecurity threat coming from within. However, often times, the university\u2019s large and inadequately&nbsp;secured network enables malicious activity by being an easy target.<\/p>\n<p>Whilst universities are expected to offer all students the ability to connect their devices to the network and access the university\u2019s digital services, this presents a challenge when it comes to preventing malicious activity and uncontrolled sensitive data sprawl due to poorly designed networks. These complex and large networks not only open universities to cyberthreats but also prevent the educational establishment from offering a stable, secure connection to its digital services for the many devices of students and staff.<\/p>\n<p>An additional issue here is that creativity is not limited to just the students. For example, the university\u2019s technology management teams, with their wide remit and increasingly low funds, often search and find ways to solve network problems with creative scripting and workarounds. This creativity leads to network environments which are highly complex, creating a much larger attack surface area as a result.<\/p>\n<p><strong>How can universities protect their networks and data?<\/strong><\/p>\n<p>In today\u2019s world of rapid growth in personal devices, it is vital that universities implement radical changes to the design of networks. Universities must invest in their digital environment and ensure that they modernise data management practices, remove complexity and isolate sensitive services from student activity.<\/p>\n<p>They also must enable the online environment to understand threats quickly and react accordingly. For example, AI threat detection and automated threat response can detect malicious activity and restructuring the environment can isolate sensitive services from student activity.<\/p>\n<p>By restructuring and investing in their digital environment, universities will be able to offer internal and external nefarious attackers fewer opportunities to attack, as well as less time to do so.<\/p>\n<p><strong>Cybersecurity as a priority <\/strong><\/p>\n<p>The internal and external threat to universities\u2019 cybersecurity is real and it is crucial that universities understand it as such. When it comes to data and network security, complacency is the real danger.<\/p>\n<p>Universities should invest in their own cyberspace security and reduce the need for in-house security teams to become creative when it comes to network problem solving.<\/p>\n<p>By investing in cybersecurity and redesigning their networks, universities can be safer from internal and external threats, keeping valuable data out of hands of hackers and networks up and running.<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cybercrime is a growing problem globally and the higher education sector is not immune to this threat, argues Colin Truran, Principal Technology Strategist, Quest Software. As today\u2019s modern campus relies on online services to power its learning and teaching environment, a greater number of devices belonging to students or staff connected to the network are [&hellip;]<\/p>\n","protected":false},"author":28,"featured_media":539,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[16,18,1576,44],"tags":[334,174,335,336,337,338,233,339,340,341,342,343,344,345],"class_list":["post-536","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-industry-verticals-education","category-enterprise-security","category-analysis-insights","category-top-stories","tag-colin-truran","tag-cybersecurity","tag-cyberthreats","tag-further-education","tag-higher-education","tag-jisc","tag-network","tag-network-security","tag-phishing","tag-principal-technology-strategist","tag-quest-software","tag-ransomware","tag-universities","tag-university"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/posts\/536","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/users\/28"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/comments?post=536"}],"version-history":[{"count":1,"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/posts\/536\/revisions"}],"predecessor-version":[{"id":538,"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/posts\/536\/revisions\/538"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/media\/539"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/media?parent=536"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/categories?post=536"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/tags?post=536"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}