探花视频

JiscSafeguarding cybersecurity during lockdown

Safeguarding cybersecurity during lockdown

jisc-istock-1132382118
厂辞耻谤肠别:听
iStock

Increasing awareness, training and robust technical controls can protect universities from attacks as staff work remotely

The coronavirus pandemic has changed the ways in which universities work. There has been a mass migration to online platforms and personal devices as academics and administrative staff perform their duties from home. This disruption can expose institutions to a heightened risk from a variety of digital threats, particularly phishing campaigns, and underlines the importance maintaining good cybersecurity practices.

鈥淚 think criminals of any nature have always been opportunistic,鈥 says Gareth Packham, head of information security at Oxford Brookes University. 鈥淚聽don鈥檛 think there are new risks, but I聽think in some cases, yes, the risk level has increased. But if your cybersecurity department has been doing its job well, there shouldn鈥檛 be any nasty surprises.鈥

The ideal scenario is one where phishing campaigns are caught and neutralised by the university鈥檚 IT infrastructure before reaching an individual鈥檚 inbox. Packham says that 鈥渆vent-driven鈥 and seasonal phishing attacks are par for the course. Typically, attacks spike in September and October, when staff and students return to campus, and commonly take the form of emails to students touting bogus hardship schemes. With the Covid-19 outbreak, phishing attacks maintain a similar topical cynicism and are tailored accordingly. Many are unsophisticated but, if not caught by university IT systems, the best line of defence is that individuals are aware, and for universities to offer support to all users of its systems through training and clear communication of best practice.

This is easier said than done, says John Chapman, head of the security operations centre at Jisc, the UK education and research technology solutions not-for-profit. 鈥淓ven seasoned professionals, including those in IT and cybersecurity, can fall victim to a really specific phishing campaign,鈥 he explains. 鈥淲e are all working long hours. We can all be distracted 鈥 maybe you have young children at home who you are trying to home-school. It is very easy to click on something that maybe you shouldn鈥檛 have, or wouldn鈥檛 have if you were more alert, or back in the office. In an office, you also typically have someone you can turn to and ask if they鈥檝e also had a suspicious email, which isn鈥檛 as easy to do in a home environment.鈥

Like all large organisations, universities have many points of entry for cybercriminals. Chapman says tackling this 鈥渆ver-changing threat landscape鈥 should be planned from the ground up, with information security embedded as part of the university鈥檚 broader digital strategy. He cites showing the increasing number of universities passing the UK government鈥檚 Cyber Essentials certification scheme 鈥 up from 14聽per cent in 2018 to 44聽per cent in 2019 鈥 as a positive trend. Passing Cyber Essentials enables organisations to demonstrate a solid grounding in the fundamentals of cybersecurity, and should be accompanied by cybersecurity awareness training for everyone across the organisation. 鈥淕etting the board and the directors to buy into your cybersecurity strategy and getting that embedded throughout the whole organisation is key,鈥 he explains.

Cybersecurity is both a technological and a cultural issue. With more universities adopting cloud-based services to manage their data and systems, there may be a change to the risk environment, as cloud-based systems are managed externally with a third party possibly responsible for updates and security patches. This, allied with IT safeguards such as compartmentalised systems and isolated networks, can help universities mount a sound technological defence against cyberattacks.

During lockdown, enforcing virtual private network (VPN) connectivity from managed devices to university-hosted systems and implementing multifactor authentication can further mitigate risks. Solving the cultural issue requires getting the communication right, and a little more finesse.

Tom Stoddart, assistant director of information security at Manchester Metropolitan University, sees universities鈥 cybersecurity challenges as predominantly cultural, with the huge variation in the type of work undertaken by different departments resulting in the need for bespoke communications and training to raise staff awareness.

鈥淭he idea that there is any one-size-fits-all approach that is going to pique everybody鈥檚 interest is nonsense,鈥 he says. 鈥淪o we have spent quite a lot of time trying to find different senior sponsors for pieces of work and doing our best to adapt our message for different departments.鈥

Packham agrees. 鈥淚聽think it is more about making sure people know what the risks are,鈥 he says. 鈥淎t Brookes, I聽champion a risk-based approach to cybersecurity and working with data. Not all data is of equal value, either to the organisation itself or an attacker. But if you are working with HR or student data, that鈥檚 when you probably do need to seek guidance with people like myself or the team around聽me.鈥

Such measures are now more timely than ever. 鈥淭raining and awareness are particularly important when people are working from home,鈥 he adds. 鈥淚f staff do not understand how to do things safely and securely, then all the policies and procedures in the world won鈥檛 help.鈥

about Jisc and cybersecurity.

This article was commissioned by 探花视频 in partnership with Jisc, the UK body for digital technology and resources in higher education, further education, skills and research.

Brought to you by