The need for higher education executives to understand and exercise appropriate governance of cyber and artificial intelligence (AI) risks has never been more urgent. Sophisticated attacks on educational institutions are at an all-time high, as violations of cybersecurity compliance requirements have resulted in legal action against universities, and the use of AI in campus operations and by students is creating a panoply of new risks.
This is not an easy task.

Governance of cyber risk is arguably more complex in academia than in other industry sectors due to the:
Operational autonomy demanded by faculty and staff;
Culture of open educational collaboration among students and faculty across institutions and borders;
Prevalence of “shadow IT” created through faculty and student use of cloud storage sites for projects and data storage;
Impact of AI on academic policies, curricula, and operations;
Lack of understanding by students, faculty, and institutional review boards of laws and regulations governing privacy, cybersecurity, and AI; and
Deficiencies in digital asset management, particularly data inventories.
"Sophisticated attacks on educational institutions are at an all-time high, as violations of cybersecurity compliance requirements have resulted in legal action against universities, and the use of AI in campus operations and by students is creating a panoply of new risks.” -Jody Westby, Founder Global Cyber Risk
Throwing money at cybersecurity programs is not a silver bullet. Moody’s 2023 Global Cyber Risk Issues Survey indicated that although cybersecurity budgets increased by more than 70% between 2019 and 2023, cybersecurity spending still only accounts for about 8% of an organization’s total technology budget. Respondents from healthcare, housing, and higher education revealed that their cybersecurity budgets were a full percentage point less—about 7% of technology spending. The survey noted that educational institutions with research or medical centers are at particularly high risk of cyber attacks, but the ransomware attacks in 2023 on colleges and universities highlighted the breadth of cyber vulnerabilities in the education sector.
The National Student Clearinghouse claimed that more than 900 colleges were hit in 2023 by a Russian cybercriminal group when it hacked a file transfer software tool called MOVEit, enabling the group to obtain large amounts of personal data. The full list of impacted educational institutions is shocking. The attacks prompted Malwarebytes, a prominent antivirus software company, to label 2023 “the worst ransomware year on record in education.”
"Managing cyber and AI risks requires more than simply hiring personnel to manage privacy, cybersecurity, and AI... it requires establishing a governance framework that undergirds the organization's AI, privacy, and cybersecurity programs." -Jody Westby

CYBER GOVERNANCE FRAMEWORK
Managing cyber and AI risks requires more than simply hiring personnel to manage privacy, cybersecurity, and AI (and scheduling periodic reports to trustees on these issues); it requires establishing a governance framework that undergirds the organization’s AI, privacy, and cybersecurity programs. At its core, the governance of cyber and AI risks boils down to knowing
what digital assets are used in university operations—the data, software, hardware, and networks;
what critical risks are associated with that usage; and
what controls are necessary to manage and monitor those risks.
A cyber governance framework is a formal, cyclical process established by the trustees, which recognizes the separate yet specific roles and responsibilities for board members and management and establishes a process for addressing 1-3 above. Cyber governance best practices require boards and trustees to exercise oversight of risks by identifying critical risks and monitoring them, determining the institution’s risk appetite, and directing the primary actions to be undertaken to manage the identified risks.
Best Practices and Standards
Governance best practices and standards offer blueprints for establishing a cyber governance framework. The most prominent standards are the ISO/IEC 38500 series on the governance of IT (which includes AI), ISO/IEC 27014 on the governance of information security, and ISO/IEC 24143 on information governance. The U.S. Federal Financial Institutions Examination Council (FFIEC) has also developed excellent best practices1 for the governance of IT cybersecurity that can be emulated by other industry sectors. In 2024, the National Institute of Standards and Technology (NIST) issued a revised Cybersecurity Framework 2.02, which includes a new section on governance.
"Throwing money at cybersecurity programs is not a silver bullet." -Jody Westby
There has never been a greater need for tone from the top on cyber and AI risk management. Higher education executives and trustees need to engage experts to help them establish a governance framework that will align with and build on existing cybersecurity and privacy programs and AI policies, close gaps and deficiencies in asset management, identify critical cyber and AI risks, establish information flows to enable effective risk monitoring, and develop risk-transfer strategies. Doing so would enable them to show leadership and educate other industry sectors on proper cyber and AI governance.
https://ithandbook.ffiec.gov/it-booklets/management/
https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf