In today’s digital age, the value of data continues to skyrocket. The collection, analysis, sharing, and storage of data is integral to success in the day-to-day operations of any higher education institution. Yet as the opportunities of data use continue to increase, the risks associated with data continue to grow with greater financial, legal, and operational implications than ever before. In a rapidly evolving risk landscape within higher education, it is critical to prioritize protecting sensitive information through effective data risk management strategies.
Current Trends in Data Privacy Risk
Evolving tactics of cybersecurity threat actors
Threat actors frequently target higher education institutions with cyber-attacks due to the vast array of sensitive information that institutions manage, including student information, employee information, research data, and financial records. Since the onset of the COVID-19 pandemic in 2020, ransomware attacks have become a lucrative scheme for threat actors, and they remain a persistent threat facing higher education institutions. In 2024, the two most common attack vectors for threat actors to gain unauthorized entry into a network were phishing and stolen or compromised login credentials21. Threat actors are now exploiting emerging AI technologies to make phishing attempts appear more legitimate and enable malware to mutate in real time to evade detection22. Following unauthorized entry into a network, the sophistication of ransomware attacks has continued to escalate. In the 4th quarter of 2024, 74% of ransomware cases involved lateral movement by a threat actor within a network. Additionally, 87% of ransomware cases involved data exfiltration, which has fueled concerns about privacy liability issues23. While the sophistication level of ransomware groups varies greatly, more sophisticated ransomware threat actors provide ransomware-as-a-service toolkits to less sophisticated threat actors to lower the barrier to entry to launch an attack and increase the overall volume of ransomware activity24.

Dynamic privacy regulatory framework
From a regulatory perspective, a patchwork of data privacy laws now apply across many states. Beginning with the passage of the California Consumer Privacy Act (CCPA) in 2018, 19 states have enacted comprehensive privacy laws as of the end of 202425. State comprehensive privacy laws, which are separate from breach notification laws, govern a host of issues such as geolocation, data collection, and biometric information. An additional 16 states have privacy legislative bills in process as of the beginning of 2025. As the privacy regulatory landscape rapidly evolves, understanding how and where your institution uses data is crucial for compliance with applicable comprehensive privacy laws. The absence of a unified federal standard exposes higher education to further risk, making it challenging for institutions to comply with a wide range of state privacy laws across various governing jurisdictions. Collaboration with legal counsel is essential to maintain compliance in today’s dynamic privacy regulatory environment.
Third-party vendor risks
Higher education institutions frequently engage with third-party vendors for various services, including IT management, data storage, and educational technologies. These relationships introduce additional layers of risk, as vendors may have access to sensitive institutional and student data. The MOVEit file transfer tool cyber incident in 2023, which exposed the sensitive data of many institutions, exemplified significant threats posed by third-party vendor vulnerabilities. Effective third-party risk management is therefore essential, involving thorough vetting of vendors, continuous security monitoring, and the implementation of stringent data sharing agreements to ensure that third-party partners adhere to the same rigorous data privacy standards as the institutions themselves.
“As the opportunities of data use continue to increase, the risks associated with data continue to grow with greater financial, legal, and operational implications than ever before.” - Tom Infurna
How Cyber Insurance Is Responding to Data Privacy Risk
Coverage for privacy liability and regulatory proceedings is commonly included as a core component of a cyber insurance policy. While this coverage contemplates defense and liability for the unintentional violation of a privacy or cyber law, several insurers are beginning to adjust their coverage approach. In light of steady increases in the frequency and severity of privacy-related events, some cyber insurers may now seek to add policy exclusions for wrongful collection of data, particularly for higher education institutions that are connected to a healthcare system. As complex data privacy risk continues to evolve, discussing privacy liability and regulatory proceedings coverage with your insurance broker is essential. If a wrongful collection exclusion is present on your current cyber insurance policy, ask your broker about risk transfer solutions to address this exposure before your next cyber insurance renewal cycle.
Actionable Insights for Boards to Mitigate Data Privacy Risk
Promote a culture of data privacy and security awareness across your institution.
Establish data governance committees for clear leadership and accountability.
Engage key stakeholders in data privacy initiatives.
Provide annual cybersecurity training for faculty and staff.
Maintain regular cadence of phishing tests for faculty and staff.
Develop and maintain comprehensive data governance frameworks.26
Allocate financial resources for data governance leadership at the enterprise level, including designation of a Chief Data Privacy Officer.
Adopt institutional policies and procedures for the collection, storage, access, and disposal of data.
Conduct regular Privacy Impact Assessments to identify and mitigate potential privacy risks.
Collaborate with legal counsel to ensure compliance with evolving data privacy regulations.
Implement data privacy management tools.27
Maintain comprehensive inventory of the types of data your institution handles, including but not limited to: student data, employee data, research data, financial records, and intellectual property.
Classify data under appropriate categories of sensitivity, such as: public, internal, confidential, and restricted.
Enforce multi-factor authentication (MFA) to protect access to any systems, networks, or applications that contain sensitive information.

BOTTOM LINE
Effective data privacy risk management requires consistent support across an institution, from executive board leadership to faculty and staff. Establishing data governance leadership, investing in strong cybersecurity posture, and promoting privacy and security awareness can help your institution to manage the rapidly evolving and growing risks associated with data privacy.
21 IBM Cost of a Data Breach Report 2024
22 Sentinel One 10 Cyber Security Trends For 2025
23 Coveware Quarterly Report Blog https://www.coveware.com/blog/2025/1/31/q4-report
24 Sentinel One: 10 Cyber Security Trends For 2025
25 IAPP US State Comprehensive Privacy Laws Report, 2024 Legislative Session us_state_privacy_laws_report_2024_session_overview.pdf
26 EisnerAmper Data Privacy in Higher Education
27 RiskDataControl.com The Ultimate Guide to Data Privacy Risk Management