
All organisations face challenges establishing and maintaining secure digital identities that permit access for insiders while keeping outsiders at bay. This is especially pertinent for higher education institutions, which are some of the most organisationally complex identity and security environments. They require a large degree of openness to facilitate learning and research, but also a high levels of vault-type protection to safeguard sensitive data. Robust security can therefore only be achieved by implementing a tailored set of solutions that account for the unique attributes of the campus environment.
Tertiary institutions must cater to a constantly evolving cast of stakeholders and participants, from full and part-time students, researchers, contractors, casual and permanent staff members, affiliated research facilities, educators, guest speakers and so on. Churn is a perennial challenge with students enrolling, graduating, deferring, or dropping out on a constant basis. Employees change roles, move between departments, and take sabbaticals throughout the course of their careers.
Adding complication, a student might also work as a teaching assistant marking papers on a part-time basis or be employed at an on-campus retail outlet, requiring access across multiple tiers. This complexity presents unique security threats and universities have experienced a surge in cyber security incidents in recent years. Identity management infrastructure within education institutions has long been a collection of cloud-based, hybrid platforms, and such disjointed systems can provide attractive targets for malicious actors looking to exploit security weaknesses.
The tertiary education sector often struggles with implementing new technology systems. Many institutions accumulate layers of identity infrastructure over time, adding new platforms to older legacy tech. Active Directory (AD) is the way most modern, complex organisations automate identity workflows, but it must be strategically deployed to reduce security risks. Tertiary institutions have historically run various AD systems, often operating in parallel, which can lead to inconsistencies between sub-environments, resulting in governance gaps. This can create instances where a graduated student or former staff member loses basic access to facilities but retains access to sensitive, cloud-stored data such as research material, leading to a serious governance issue.
At the start of each semester a fresh wave of students arrive to fill the place of recent graduates who have collected their qualifications and are moving into the job market. This continuous turnover can push AD systems to breaking point as identities are created, provisioned, and deprovisioned in vast numbers and tied to specific dates. When student identities are progressed through disjointed AD systems, security risks are magnified. Orphaned accounts, partially disabled identities, and outdated access can result. Each scenario presents a potential attack vector, creating a vast security surface that can prove almost impossible to defend.
Adding to their security challenges, universities are inherently decentralised organisations, spread across colleges, campuses, departments, and research labs. Each department will often maintain their own IT staff and infrastructure, in the hope of delivering flexibility and autonomy. With this decentralisation comes significant governance challenges. IT administrators across various departments may employ different naming conventions, assign access based on local factors without centralised visibility, utilise separate AD domains, and/or use manual processes relying on scripts or native tools.
Such decentralisation limits visibility across an institution and thwarts attempts to maintain consistent security controls. Each domain, campus or department might be enforcing different governance policies and identity controls. Without robust central identity control systems in place, risks are escalated and the threat of attack is compounded. Blind spots can emerge, access and privileges are not uniformly granted and denied, and governance becomes unwieldy and difficult to implement. This lack of coherence also delays detection and response to any breach, further increasing organisational risk.
This combination of risk factors means credential compromise is one of the most effective attack methods against tertiary education institutions. Attackers frequently use MFA fatigue style attacks, or phishing methods to illicitly gain access to student or staff accounts. Once inside they can move across the environment, wreaking havoc, exploiting access to sensitive data and IP for nefarious reasons.
The unique structure of tertiary education institutions makes them complex security environments. Effectively establishing identity credentials across a dynamic community of students, staff, contractors, and visitors, all with varying access requirements, and spread across various locations and housed within different facilities is a massive undertaking. Any failing in this regard can potentially expose the affected organisation to a range of devastating consequences.
At Infotrust, we specialise in solving such complex cyber security challenges. Our team of experts is trusted by some of the nation’s most prominent organisations in both private and public sectors to safeguard priceless IP and sensitive private data. We routinely help in the deployment of cutting-edge identity management solutions to institutions in the education sector, delivering world-class results and ensuring security needs and governance demands are met.
For more information, contact Infotrust today.