{"id":181328,"date":"2026-01-21T17:04:00","date_gmt":"2026-01-21T22:04:00","guid":{"rendered":"https:\/\/testing.news-you-need.com\/index.php\/2026\/01\/21\/why-higher-ed-cios-must-rethink-cybersecurity\/"},"modified":"2026-01-24T15:55:24","modified_gmt":"2026-01-24T20:55:24","slug":"why-higher-ed-cios-must-rethink-cybersecurity","status":"publish","type":"post","link":"https:\/\/testing.news-you-need.com\/index.php\/2026\/01\/21\/why-higher-ed-cios-must-rethink-cybersecurity\/","title":{"rendered":"Why Higher Ed CIOs Must Rethink Cybersecurity"},"content":{"rendered":"<p><a href=\"https:\/\/www.bankinfosecurity.com\/higher-ed-cios-must-rethink-cybersecurity-a-30579\">Why Higher Ed CIOs Must Rethink Cybersecurity<\/a><\/p>\n<p><a href=\"https:\/\/www.bankinfosecurity.com\/higher-ed-cios-must-rethink-cybersecurity-a-30579\">https:\/\/www.bankinfosecurity.com\/higher-ed-cios-must-rethink-cybersecurity-a-30579<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-01-21 17:04:00<\/a><\/p>\n<p>Source Domain: <a href=\"www.bankinfosecurity.com\">www.bankinfosecurity.com<\/a><\/p>\n<p>Author: <a href=\"\"><\/a><\/p>\n<p> Using an unordered list, summarize the following article with between 4 and 8 key points. <\/p>\n<p>                                            Governance &#038; Risk Management<br \/>\n                                                    ,<br \/>\n                                                            Identity &#038; Access Management<br \/>\n                                                    ,<br \/>\n                                                            Patch Management<\/p>\n<p>                    Decentralization and Sprawl Complicate University IT Programs<\/p>\n<p>                                                Jennifer Lawinski                                                     \u2022<br \/>\n                        January 21, 2026 \u00a0 \u00a0 <\/p>\n<p>                Several Ivy League universities including Harvard and Princeton experienced hacks in 2025, showing that even the nation&#8217;s wealthiest universities are vulnerable. (Image: Shutterstock)            <\/p>\n<p>                    Higher education CIOs are working in unique environments where openness and innovation thrive, but recent high-profile breaches at elite institutions show the challenges they face in keeping systems secure.See Also: Zero Trust Under Strain as Organizations Favor Just-in-Time Access<br \/>\nSeveral Ivy League universities &#8211; including Harvard and Princeton &#8211; experienced hacks in 2025 through unpatched enterprise software and sophisticated social engineering campaigns, showing that even the nation&#8217;s wealthiest universities are vulnerable.<br \/>\nTo combat these rising threats, university CIOs need to rethink their operating models, governance and IT ownership structures, said Rob Belk, a cybersecurity consultant with EY.<br \/>\n&#8220;This is probably the most interesting cyber topic that doesn&#8217;t include the word AI,&#8221; Belk said. &#8220;And it&#8217;s dramatically underreported.&#8221;<br \/>\nThis shift is being propelled by the changing higher education landscape itself. Traditional funding sources are in flux, creating uncertainty in already highly decentralized ecosystems. University infrastructure is more like a city than a traditional enterprise ecosystems. Each university can include various schools and departments, research institutes, hospitals, athletic facilities, housing, bookstores and even hotels. The population is constantly shifting, with students, faculty, staff, researchers and guests coming and going each year.<br \/>\nThe challenge is compounded by the fact that many of these groups may control their own IT environments.<br \/>\n&#8220;In many ways, the CIO doesn&#8217;t control &#8211; sometimes not even most of &#8211; the IT that&#8217;s out there,&#8221; Belk said.<br \/>\nFor university CIOs, cyberattacks across these vast and disparate networks are moving faster. Belk noted that attackers&#8217; &#8220;speed to compromise&#8221; has decreased, shortening the windows to mitigate harm. In 2019, organizations had roughly nine hours to detect and contain an intrusion. Today, that window has compressed to about 48 minutes.<br \/>\n &#8220;That&#8217;s shockingly fast,&#8221; Belk says.<br \/>\nAnother risk area for the university is research computing. Historically, research systems have been purchased, operated and maintained by individual schools or principal investigators using grant funding, and many researchers view these systems as personal assets.<br \/>\nCIOs often face opposition to change: &#8220;That&#8217;s my system. You shouldn\u2019t be having anything to do with it because it&#8217;s my research,&#8221; Belk said.<br \/>\nBut as universities view research as a more explicit revenue stream, CIOs are increasingly responsible for research infrastructure that must be secured like an enterprise system, Belk said.<br \/>\n&#8220;The business of research will change,&#8221; he said. &#8220;And when it does, it will operate more like an enterprise. The security and IT supporting it will have to match that reality.&#8221;<br \/>\nFocusing on the Building Blocks of Security<br \/>\nTo navigate the complex higher education environment, Belk said CIOs need to focus on the fundamentals.<br \/>\n&#8220;Be really great at the basics,&#8221; he said. &#8220;We see a lot of organizations that still struggle with some of the fundamentals of monitoring their environments, controlling access. And that is something that needs to be addressed. Because if you&#8217;re struggling with the basics, you&#8217;re leaving yourself open in the first place.&#8221;<br \/>\nThe cyber basics includes having visibility into your environment, consistent monitoring and patching, and rigorous access control, he said.<br \/>\nAccording to research from Mandiant, 33% of breaches come from exploits of software flaws, and university internet-facing systems are especially vulnerable, Belk said. Ensuring that all systems are patched &#8220;would go a long, long way&#8221; in protecting systems and data, he said.<br \/>\nBut many recent higher-education hackers didn&#8217;t gain access through unpatched systems. They made phone calls and used social engineering to access critical systems, which underscores the importance of identity and access management &#8211; and of moving to passwordless systems, Belk said. This challenge is compounded as many university systems manage multiple Active Directories and fragmented IAM systems.<br \/>\nIdentity Management Challenges<br \/>\nTo simplify and modernize environments, he recommends taking a phased approach, beginning with administrative staff and creating passwordless policies at the enterprise level. The next step is changing the student experience, beginning with the new incoming class, so new identity models become the default over time. Faculty and research staff working with legacy systems would be the last to migrate to passwordless systems.<br \/>\n &#8220;I know, by the way, for both of those,&#8221; Belk said, &#8220;In higher ed that&#8217;s easier said than done.&#8221;<br \/>\nBelk sees artificial intelligence as an area of opportunity for university CIOs, especially when it comes to addressing staffing shortages and cybersecurity.<br \/>\nGenerative and agentic AI technologies can help CIOs address staffing shortages caused by funding constraints in areas like contracting, sourcing, compliance and legal review. &#8220;With fewer people, the work doesn&#8217;t go away,&#8221; he says. &#8220;AI becomes a way to close that gap.&#8221;<br \/>\nHe also advises CIOs to consider partnering with researchers and faculty doing cybersecurity work at their own institutions.<br \/>\n&#8220;They&#8217;re usually more than willing to want to be able to demonstrate what their research can do, and it gives them and their students the opportunity to try what they&#8217;re doing in the real world,&#8221; Belk said. <\/p>\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Why Higher Ed CIOs Must Rethink Cybersecurity https:\/\/www.bankinfosecurity.com\/higher-ed-cios-must-rethink-cybersecurity-a-30579 Publish Date: 2026-01-21 17:04:00 Source Domain: www.bankinfosecurity.com&#8230;<\/p>\n","protected":false},"author":1,"featured_media":181329,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/ismg-cdn.nyc3.cdn.digitaloceanspaces.com\/articles\/higher-ed-cios-must-rethink-cybersecurity-image_large-6-a-30579.jpg","fifu_image_alt":"","footnotes":""},"categories":[15],"tags":[26,20,24],"class_list":["post-181328","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-ai","tag-artificial-intelligence","tag-cybersecurity"],"_links":{"self":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/181328"}],"collection":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=181328"}],"version-history":[{"count":1,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/181328\/revisions"}],"predecessor-version":[{"id":181330,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/181328\/revisions\/181330"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/181329"}],"wp:attachment":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=181328"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=181328"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=181328"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}