Why Higher Ed Needs Better Protection from Modern Ransomware Attacks

Higher education institutions suffering from ransomware attacks is nothing new. However, as institutions shift to distance learning, the attack surface is much greater, giving malicious actors greater opportunity.

Institutions have a plethora of data – student assignments, academic research, administration and admission files, and alumni relations materials. The amount of data institutions have is incredible and increasing – making them prime targets for ransomware attacks.

Ransomware not only creates an issue for institutions by restricting access to critical systems and data, but it also can expose students’ personal information, such as Social Security numbers, passports, and banking details.

When Michigan State University was hit with an attack, the institution chose not to pay – and hackers began publishing financial documents and financial information shortly thereafter. Once an attack occurs, there is no guarantee that stolen data is safe – even if the institution pays a ransom.

With or without ransom payment, any delay by the institution in protecting and restoring data affects its ability to operate effectively. Malicious actors know that institutions are already under immense pressure with increased costs due to pandemic safety measures and the shift to hybrid learning, combined with reduced revenue. Further, a recent advisory from The Treasury Department’s Office of Foreign Assets Control warns that government agencies may consider the payment of a ransom to be a violation of laws relating to financial sanctions and embargoes.

How can higher education institutions address the threat of cyberattacks – while addressing these other challenges? The threat of ransomware attacks necessitates not only a strong defense, but an equally strong offense. There is no guarantee that IT can secure every entry point. And data backup is useful only if it is accessible when it’s needed the most. Equally important is that institutions can get back on their feet after an attack–and do so quickly. Colleges and universities must consider a platform with security built-in, as well as backup and recovery measures to prepare for ransomware attacks that target the last line of defense, data backups.

Data protection – think smarter, not harder

Hackers are evolving their tactics – and institutions must ask what they can do to fully safeguard their data in a time of heightened demand and vulnerability. In theory, it’s easy. Institutions can prevent ransomware attacks by keeping their operating system and tech stack up to date and investing in InfoSec training, network security audits, and vulnerability testing. They can also control access to data and back up files through frequent snapshots and other data-protection methods.

But protecting against a high impact, low probability event is difficult in practice. Backups may not work as effectively or quickly in the event of a real threat. Many systems are not ready to restore large environments in a short timeframe, and failed backups, corrupted data, and slow restores hurt colleges and universities even more. Their highly complex systems face regular issues every day to keep everything operational. Now add in evolving ransomware attacks that target backup data, backup catalogs, and even storage array snapshots, forcing organizations to go through the reconfiguration of backup solutions before even recovering the data.

Higher education must think smarter–not harder–when it comes to data protection.

Simplicity at the forefront

First, IT leaders should consider a data strategy with security built in. Ransomware attacks place immense strain on existing data-protection infrastructure if it’s built on legacy architectures, such as disk and tape. Conventional security measures can safeguard an institution’s data from natural or human-made disasters, data corruption, or accidental deletions, but provide less protection against ransomware.

A ransomware attack is not a normal recovery event that might involve a few lost files or a corrupted database; potentially all files and databases could be encrypted. The same design that optimizes for data ingestion and space-efficiency creates significant drag on recovery speed because data needs to be reconstructed after being widely dispersed through deduplication. Thus, a modern data platform with protection for backups built-in is essential.

Next, institutions should evaluate their backup and recovery measures to ensure they’re up to snuff. Data backups are the last line of defense against ransomware attacks. Focusing on recovery performance helps avoid system downtime, and ultimately works to prevent the crippling effects of halted campus operations and learning. Two metrics are key here: reliability and speed of backup. Backups should not require constant care and feeding, and they should also be simple and immutable. In this case, immutability ensures backups aren’t compromised by attackers even if admin credentials have been compromised. Advanced protection can also come in the form of automated snapshots that prevent backups from being deleted.

We also must evolve our expectations around backup and restore speeds. Backup storage must recover as fast as possible. It also must be done at scale – a single database might require 10 hours to restore. When you consider that an institution can have dozens or even hundreds of databases, it’s no wonder recovery time is often measured in months. Let that sink in for a moment. A 60-day restore period is more than half a semester long. Students and faculty can’t afford that much downtime in instruction and learning, even if the school’s data is only partially affected. Rapid restore is a critical means for institutions to protect themselves against the effects of ransomware attacks. Recovery point and recovery time objectives ensure that they can avoid major organizational and financial impact, protect students’ data, and stay focused on their important research and teaching initiatives.

Modern data protection for evolving threats

Rapid backup and recovery are essential – with a Modern Data Experience as the foundation. A Modern Data Experience is simple. It should be easy to set up, manage, and expand storage, as well as integrate easily with existing backup software. Of course, it must be fast – restoring data and applications quickly enough to actually matter. It should also be seamless. This experience can span any protocol, any tier of service level, and multiple clouds in a single environment. Lastly, it should sustain performance as data volumes increase.

Having consistent, real-time access to data is critical for colleges and universities today. And as no institution is immune to ransomware, they need to be able to recover data at scale, as quickly as possible, when systems go down. The backups themselves must be both valid and usable. Modern data protection is fast, simple, and cost-effective. This enables institutions to safeguard against more attacks in the future – and ensure that students and staff can access and use data without being beholden to malicious actors.

Twitter – @MarketScale
Facebook – facebook.com/marketscale
LinkedIn – linkedin.com/company/marketscale

Follow us on social media for the latest updates in B2B!

Image

Latest

brand-agency
The Future of Brand-Agency Dynamic in the Age of AI
September 17, 2024

Hosted by Aby Varma, founder of Spark Novus, this episode of The Marketing AI SparkCast features David DeWolf, CEO of Knownwell. They discuss how AI reshapes brand-agency relationships, blending human creativity with AI’s efficiency to manage agency collaborations. In this episode of The Marketing AI SparkCast, Aby Varma, founder of Spark Novus—a company that…

Read More
leadership habits
CARE to Win and The 4 Leadership Habits Needed to Build High-Performing Teams
September 17, 2024

In today’s evolving workplace, the need for emotionally intelligent leadership habits has never been greater. On the Holistic Leadership podcast, leadership expert and author Alex Draper, the CEO of DX Learning, discussed the four critical habits from his book CARE to Win that help leaders eliminate toxicity in the workplace. With workplace mental health…

Read More
leverage blockchain
The Time to Leverage Blockchain is Now: Cosmic Explainers with Cosmic Wire’s Jerad Finck
September 17, 2024

DisruptED’s upcoming new series, “Cosmic Explainers,” sets the stage for a comprehensive introduction to the building blocks of Web3, blockchain, and crypto technologies. As the world embraces 5G, interconnected AI, and the evolving metaverse, Jerad Finck, the CEO at Cosmic Wire, is ready to break down these complex concepts. His extraordinary journey from medical…

Read More
HVAC careers
The Collective Responsibility to Promote Skilled Trades: Why Society Needs to Highlight the Trades as a Respected Career Path
September 17, 2024

Despite the common emphasis on college degrees as the primary route to success, skilled trades offer a crucial and undervalued pathway for career development. As industries report a severe skills shortage, the necessity for a robust workforce of skilled laborers becomes undeniable. The Bureau of Labor Statistics highlights this urgency in its report on…

Read More