In 2015, many college and universities suffered substantial data breaches. In each case outlined below, universities lost personally-identifiable information (PII) on thousands of individuals, from their student bodies to faculty and beyond. In addition to the theft of PII, higher education institutions can be the target of large-scale, sophisticated attacks designed to steal trade secrets and intellectual property. The commercial sector is heavily connected to the leading research in science and technology that stems from colleges and universities. Thus, the security posture of higher education institutions is of great importance on a national level.
Penn State
In May, Penn State announced that a breach compromised servers containing information on roughly 18,000 people. During the investigation that followed, an intrusion on their network was found dating back to 2012. While it is very difficult for universities to fully regulate all of their IP space, the fact that an intrusion may have lasted three years without remediation is troubling. Incident response times are crucial to avoiding significant data loss. Many of the biggest data breaches result from networks being compromised for a significant amount of time. According to the 2015 Verizon DBIR, just half of the organizations observed discovered malware events within 35 days.
UConn
Last July, the University of Connecticut announced that servers for their school of Engineering had been accessed by actors in China. The school said that user credentials for roughly 1,800 may have been compromised. Yet, they did not confirm whether any data (or intellectual property) was stolen directly from their servers. In its announcement, the school said the initial penetration of its servers occurred in September 2013.