In the last year, the way education is delivered has changed dramatically. Universities have been operating remotely . The transition from traditional to digital education has been so rapid that it has left many IT networks exposed to errors and other external factors . There have been many cyberattacks on educational institutions, and universities in particular, in recent times . Cybercriminals tend to target large networks (such as those of universities), while at the same time exploiting the fact that teaching staff and students are not trained in the correct and secure use of networks and technologies.
See also: Hacked European Universities by Turkish hacker Jegand

What should universities keep in mind regarding cyberattacks?
University research is valuable to cybercriminals
Universities are involved in a variety of important research projectsthat many would like to gain access to. Cybercriminals may steal research to give to other institutions or sell it. The University of Oxford’s Biology department was targeted by hackers in February. The criminals were likely looking for information about the vaccine, on which the university had collaborated with AstraZeneca. Russian state hackers accused last year by official sources in the US, UK and Canada of attempting to steal research related to vaccines and treatments for COVID-19.
With so much important research lurking on university networks, it is not surprising that last year over half (54%) of universities in the UK (that participated in the survey) said they had reported a breach to the Information Commissioner’s Office.

Furthermore, universities are also a favorite target of ransomware gangs, who try to increase the chances of receiving the ransom by threatening to publish stolen data belonging to the university, students, professors, staff, etc.
See also: Data leaked from Stanford, Maryland and UC Berkeley Universities!
Student and staff personal information can fall into the wrong hands
A study of UK universities found that hackers were able to obtain “high-value” data within an average of two hours. In most cases, universities are not only faced with paying the ransom. There is also the fear of publishing important data that hackers have stolen from the systems.
With a huge number of students, faculty and other staff not trained to recognise phishing emails, universities are hit by millions of such attacks each year. Attackers use phishing techniques to break into university networks and hide, seeking out data they believe to be of higher value. Very often, this information is sold or published on the dark web, which means staff and students can be exposed to other scams as other criminals have access to their data.
Universities can address such attacks with penetration testing, a process in which security professionals act on your behalf to identify and examine vulnerabilities that criminals could exploit. There are also various training tools, such as Sophos Phish Threat, which simulates an attack to practice threat identification.
See also: Blackbaud hack: How much does it affect universities, colleges and K-12 schools?

A cyberattack can take everything offline
Higher education institutions remain a concern for the UK’s cybersecurity agency, with cyberattacks in the sector having increased significantly. In March, the NCSC issued a new warning following a series of ransomware on academic institutions in February. This trend continues with at least one university being targeted every month since the start of 2021.
Since classes are (in many cases) still conducted remotely, a cyberattack could have devastating effects. Students could lose access to course materials, tools, and other resources they need to continue their work. For university students who pay high tuition fees and have important exams ahead of them, the impact of a cyberattack is huge, both financially and personally.
In addition, universities themselves are facing financial problems as restoring systems can be costly, while damage to the institution's reputation can have dire financial consequences for universities that rely on students for income.
Universities must constantly monitor their networks and update them regularly. They must also use reliable antivirus software , while training staff and students in the correct and safe use of technology is also essential
Source: Infosecurity Magazine
