In today’s digital age, the value of data continues to skyrocket. The collection, analysis, sharing, and storage of data is integral to success in the day-to-day operations of any higher education institution. Yet as the opportunities of data use continue to increase, the risks associated with data continue to grow with greater financial, legal, and operational implications than ever before. In a rapidly evolving risk landscape within higher education, it is critical to prioritize protecting sensitive information through effective data risk management strategies.
Current Trends in Data Privacy Risk
Evolving tactics of cybersecurity threat actors Threat actors frequently target higher education institutions with cyber-attacks due to the vast array of sensitive information that institutions manage, including student information, employee information, research data, and financial records. Since the onset of the COVID-19 pandemic in 2020, ransomware attacks have become a lucrative scheme for threat actors, and they remain a persistent threat facing higher education institutions. In 2024, the two most common attack vectors for threat actors to gain unauthorized entry into a network were phishing and stolen or compromised login credentials21. Threat actors are now exploiting emerging AI technologies to make phishing attempts appear more legitimate and enable malware to mutate in real time to evade detection22. Following unauthorized entry into a network, the sophistication of ransomware attacks has continued to escalate. In the 4th quarter of 2024, 74% of ransomware cases involved lateral movement by a threat actor within a network. Additionally, 87% of ransomware cases involved data exfiltration, which has fueled concerns about privacy liability issues23. While the sophistication level of ransomware groups varies greatly, more sophisticated ransomware threat actors provide ransomware-as-a-service toolkits to less