The need for higher education executives to understand and exercise appropriate governance of cyber and artificial intelligence (AI) risks has never been more urgent. Sophisticated attacks on educational institutions are at an all-time high, as violations of cybersecurity compliance requirements have resulted in legal action against universities, and the use of AI in campus operations and by students is creating a panoply of new risks.
This is not an easy task.
Governance of cyber risk is arguably more complex in academia than in other industry sectors due to the:
Operational autonomy demanded by faculty and staff;
Culture of open educational collaboration among students and faculty across institutions and borders;
Prevalence of “shadow IT” created through faculty and student use of cloud storage sites for projects and data storage;
Impact of AI on academic policies, curricula, and operations;
Lack of understanding by students, faculty, and institutional review boards of laws and regulations governing privacy, cybersecurity, and AI; and
Deficiencies in digital asset management, particularly data inventories.
Throwing money at cybersecurity programs is not a silver bullet. Moody’s 2023 Global Cyber Risk Issues Survey indicated that although cybersecurity budgets increased by more than 70% between 2019 and 2023, cybersecurity spending still only accounts for about 8% of an organization’s total technology budget. Respondents from healthcare, housing, and higher education revealed that their cybersecurity budgets were a full percentage point less—about 7% of technology spending. The survey noted that educational institutions with research or medical centers are at particularly high risk of cyber attacks, but the ransomware attacks in 2023 on colleges and universities highlighted the breadth of cyber vulnerabilities in the education secto