Industries
Cyber security for higher education.
Student data platforms, research networks and campus infrastructure.
What is actually going on here
Universities are hard to secure for a structural reason: openness is the point. Research collaboration, visiting academics, student devices and a culture that resists central control all work against the controls that would be uncontroversial in a bank. Any programme that ignores that will simply be routed around.
The data is more sensitive than people assume. Minors in schools, financial aid records, health information from campus services, and research that may carry export control or commercial value. Ransomware crews have worked out that a university cannot afford to lose a semester.
We work with universities, school groups and edtech platforms, and we run a training academy ourselves, so we understand the difference between security that reads well in policy and security a faculty will actually accept.
Who regulates you, and what they want
Tick the ones that bind you and we will pull together the evidence each of them actually asks for. Nothing is sent anywhere.
Pick one or more above to see what they expect of you.
What goes wrong in this sector
Student and staff record exposure
Student information systems hold identity, academic and financial records together, and are frequently reachable from the open internet because students need access from anywhere.
Research data theft
Where research has commercial or strategic value it attracts capable, patient adversaries. Research networks are usually the least controlled part of the estate, deliberately, which makes the mismatch acute.
Ransomware against academic operations
Timed to admissions or examinations, when the pressure to pay is highest. Recovery is complicated by decentralised IT where nobody has a full inventory of what needs restoring.
Examination and credential fraud
Manipulation of results, or forged credentials issued against a real record. This is an integrity problem rather than a confidentiality one, and it damages the institution's core product.
How we work in this sector
- 01
Separate what must be protected
Student records, finance and examinations do not need the openness the research network does. We start by establishing which zones can be tightened without a fight.
- 02
Test what faces the internet
Portals, learning platforms and remote access, which is where the entire student and staff body arrives from.
- 03
Assess the edtech supply chain
Third party platforms hold pupil and student data under your obligation, particularly where minors are involved and DPDP duties are stricter.
- 04
Train the people
We deliver awareness and technical training through our academy, tailored for faculty, administrators and IT separately, because they face different things.
What we actually keep finding here
Not a threat list copied from a report. These are the patterns that recur across our own engagements in this sector, with an honest note on how often. Where we do not have a precise number we say so rather than inventing one.
- Most engagements
The student records system is internet facing
Because students need access from anywhere, and it was never separated from the openness the research network requires.
- Most engagements
Decentralised IT with no full inventory
Departments running their own systems, which means nobody can say what would need restoring after ransomware.
- Often
Edtech vendors profiling pupils by default
Under DPDP this is prohibited for children, and it is usually enabled in the vendor's default configuration rather than by anyone's decision.
- Most engagements
No multi-factor authentication on staff accounts
The single cheapest control that would prevent most of what we see happen to institutions, absent because of concerns about faculty resistance.
Questions worth asking any provider in this sector
Including us. If a provider cannot answer these clearly, that tells you more than any capability slide will. We would rather you asked them than took our word for it.
- 1
Can you secure the records systems without demanding we close the research network?
- 2
Will you assess our edtech vendors, particularly where children's data is involved?
- 3
What are the three cheapest things we could do that would prevent the most?
- 4
Can training be delivered as a credit bearing module rather than a compliance exercise?
- 5
How will you test during term time without disrupting teaching or examinations?
What we deliver in this sector
- Student information system testing
- Research network segmentation review
- Campus infrastructure & Wi-Fi security
- Identity federation & SSO assessment
- Data privacy & DPDP readiness
- Security awareness programmes
- Cloud & LMS platform security
- Incident response planning
Work in this sector
Named engagements where the client has agreed to be named, and anonymised ones where they have not, which is most of them. Named references are available under NDA.
- Client withheld
Higher education institution, examination integrity
- Scope
- Examination and results systems assessed ahead of a semester, alongside staff awareness training.
- What we found
- Results could be altered without an audit trail that identified the individual.
- Outcome
- Attributable change logging added on results, with approval required for post-publication changes.
- Client withheld
University group, records and research separation
- Scope
- A network deliberately open for research, carrying a student records system that did not need to be.
- What we found
- The records system reachable from the open research network, and no multi-factor authentication on staff accounts.
- Outcome
- Records segmented away from research, multi-factor rolled out to staff, research openness left intact.
- Client withheld
School group, edtech vendor assessment
- Scope
- Third party learning platforms processing pupil data under the group's obligation.
- What we found
- Two vendors profiling pupils by default, which DPDP prohibits for children.
- Outcome
- Profiling disabled contractually and technically, and parental consent records rebuilt for the affected cohort.
Questions we get asked in this sector
How do we secure a network that has to stay open?
Stop treating it as one network. Research openness does not require the student records system to be open. Segment by what the data needs rather than by department, and accept that the research zone will always carry more risk, monitored accordingly.
What does DPDP mean for schools with children under 18?
It is significantly stricter. You need verifiable parental consent, and tracking or targeted advertising to children is prohibited outright. In practice the hardest part is your edtech vendors, several of which will be profiling pupils by default.
We have almost no security budget. Where do we start?
Multi-factor authentication on staff accounts, offline backups of the student records system, and patching whatever faces the internet. Those three prevent most of what we see happen to institutions, and none of them is expensive.
Do you train our staff as well as testing?
Yes. We run corporate and institutional training through our own academy, and for universities we can run it as a credit bearing module rather than a compliance exercise, which changes how seriously students take it.
Not sure where to start?
Book a 30-minute call with a senior engineer. We will walk through your current posture, the frameworks that bind you, and what a realistic programme looks like.












