A higher-ed IT team switches gears when it realizes its legacy backup solutions can’t fight cyberattacks

Navigating cybersecurity and crafting backup plans


A higher-ed IT team switches gears when it realizes its legacy backup solutions can’t fight cyberattacks

eCN: Talk a little bit about the behavior side of data security–that can play as much a factor in data security as the software, right?

MD: Absolutely. We have a security department that sends out test phishing examples, and if a user clicks on it, then they know about it. And then users have to go back and do some training. That number is coming down. The problem becomes when someone gets busy with their day, gets an email and the name is going to be from the president of a company or somebody that they may even know–they’ll scrape email addresses off our websites–and so they’re going to make it look like it’s from Morehouse, even though it’s not. We have things in the email that tell them this is from an external site, but people don’t think and it only takes one time.

You know, they click on it, it opens a PDF, and it says, “Oh, you need to put a password in there,” or something like that. That’s why I don’t have a lot of confidence that this is something that could be solved. Because in this case, it’s the users who were giving them what they want, their replicated password field, making it look like they are logging into something and make it look like our webpage. You really can’t blame them, even though we tell them don’t click on links in email. it’s just too much, I think for users to really get a handle on it. And it’s really hard from a security side to manage that because, when it comes to links, how do you know if they are good or bad?

eCN: Does being a medical school make you an especially rich target?

MD: Yes, only because we have a clinic, so we have healthcare data. So we have actual patients out in the remote clinics. And that kind of data is a prime target because it’s got a lot of information that can be used to steal identities. So my understanding is ransomware people go after that kind of data. And we get not just spam. We get phishing emails every day. So we’re constantly being hit.

eCN: Because of the surge of attacks, are these sorts of technologies something you still have to fight for?

MD: At one time we did, but about maybe three years ago, things happened where we said, “Okay, this is what we need to do is start trying to fight these things.” And we really beefed up the security side. We now have the hardware and software to help mitigate some of this as best we can. Security is something that the budget people really now understand is something we’ve got to do.

Sign up for our newsletter

Newsletter: Innovations in K12 Education
By submitting your information, you agree to our Terms & Conditions and Privacy Policy.

eSchool Media Contributors