In June, an unauthorized party infiltrated Columbia University’s network, disrupted campus systems, and stole data. Restoring operations required university technology staff, outside cybersecurity experts, law enforcement, administrators, communications officials, and others. Columbia later began notifying affected individuals and offering identity-monitoring services.
The incident illustrated a larger reality for higher education: Cybersecurity is no longer just the chief information officer’s (CIO) problem. AI-generated phishing, ransomware, vendor breaches, research espionage, and the increasing collection of personal data have turned cybersecurity into an enterprise-level governance issue.
The FBI has warned that criminals are using AI to produce highly targeted phishing campaigns at greater speed and scale, making fraudulent messages increasingly difficult to identify. EDUCAUSE, a nonprofit focused on technology and IT in higher education, named “collaborative cybersecurity” the number one issue on its 2026 Top 10 list. Its central message is that institutions must build cultures of shared responsibility rather than delegating risk entirely to technology departments. In the case of cybersecurity, it takes the entire institution to ensure campus information and systems are protected.
A Distinctively Difficult Environment
Colleges and universities are unusually complicated to secure. They combine open networks, legacy systems, valuable research, personal devices, global partnerships, and decentralized decision-making. Academic departments, laboratories, medical centers, foundations, and athletics programs may purchase and manage technology independently.
That decentralization supports academic freedom and allows units to select tools suited to their work. It also creates blind spots. A department may contract with a software provider or store sensitive data without central IT’s knowledge. Researchers collaborate across institutions and countries. Meanwhile, separate university offices hold student records, health information, financial data, donor histories, employment files, and intellectual property.
The answer cannot be to secure universities as though they were closed corporate systems. Institutional leaders must protect data and research while preserving the openness, collaboration, and intellectual freedom central to the academic mission.
Assigning Ownership
The National Institute of Standards and Technology (NIST) emphasized leadership’s role when it added “Govern” to its Cybersecurity Framework 2.0. The function covers strategy, oversight, supply-chain risk, policy, and authority.
Presidents should establish cybersecurity as an institutional priority and determine who holds decision-making authority during a crisis. Trustees need to oversee risk tolerance, funding, and executive accountability. Dashboards or other systems must track unresolved high-risk findings, multifactor authentication coverage, recovery readiness, vendor exposure, and whether accepted risks exceed institutional policy.
Research protection requires particular balance. Federal agencies have warned that foreign entities target sensitive university research. At the same time, overly broad restrictions can damage legitimate international collaboration. The National Science Foundation’s research-security training addresses cybersecurity, disclosure rules, export controls, foreign travel, and foreign talent recruitment programs, while recognizing the value of global research partnerships.
Making Secure Decisions Easier
Shared responsibility cannot consist of annual training followed by instructions to “be careful.” Institutions must make secure behavior practical.
Arizona State University (ASU) created self-service tools that help faculty, staff, researchers, and student employees classify data and identify approved storage options. Instead of requiring every employee to interpret complex policies, the tools guide users through a series of questions and translate the answers into specific actions. The model moves responsibility closer to the people making daily decisions while providing enough institutional structure to support them.
ASU also conducts vendor risk assessments before sharing university data with third parties. Contracts involving sensitive information establish breach-notification deadlines, audit rights, data-retention limits, subcontractor requirements, and procedures for deleting university data when the relationship ends.
The need became clear in May 2026, when Federal Student Aid issued a security alert concerning a breach of the Canvas Learning Management System. The incident involved unauthorized access to usernames, email addresses, course names, enrollment information, and messages. Colleges were advised to review integrations, eliminate unnecessary access, validate data-sharing agreements, and prepare for questions about possible exposure. In response, ASU temporarily took Canvas offline, reset connections to third-party tools, tested integrations for potential vulnerabilities, and increased network monitoring before restoring service.
Practice Before the Breach
Having a response plan in place and rehearsing roles and responsibilities is critical to successfully thwarting or minimizing the impact of a security breach. Leaders should also practice how they will respond.
The Cybersecurity and Infrastructure Security Agency provides tabletop exercise packages for ransomware attacks, phishing, insider threats, and other incidents. Rehearsals can reveal unclear authority, outdated contact lists, untested recovery plans, weak vendor contracts, and transparency guidelines before a real crisis forces leaders to resolve them under pressure.
A CIO can secure systems and coordinate a technical response. Only institutional leadership can decide what must be protected, prioritize risks that are acceptable, and determine how their institution will preserve trust when its defenses fail.









