Artificial intelligence has made it easier for cyberattackers to breach college and university systems and steal valuable student and staff data. Canvas, higher education’s most high-profile victim this year, is remodeling its security to prepare for the inevitable next attempt.
What experts have learned is that colleges may be sorely underprepared for the next evolution in cybersecurity.
“A lot of the conversation around cybersecurity in the next six months is going to be about speed,” says Zach Pendleton, chief architect at Instructure. “Everything that made a good security program a year ago still matters, but the speed at which we’re implementing them doesn’t match the moment.”
Instructure, the edtech company behind learning management system Canvas, suffered one of the largest data breaches in the U.S. this year after cybercriminals gained access through a third-party vendor—an increasingly common occurrence in higher ed.
Your next read: If a three-year degree is controversial, what about a nine-month one?
Higher education’s more meditative, governed approach to technological change is useful for reviewing rigor and long-term quality assurance, Pendleton says. However, a stalled update can leave an institution flat-footed when confronted with a sophisticated technological attack.
Experts at Instructure recognized earlier this year that conventional security practices were being challenged by AI-powered threats, Pendleton says. The company’s renewed defenses remained unfinished when the attack occurred.
“It was a pretty awful situation,” Pendleton adds. “What this means for LMS providers and higher education in general is that we were one of the first education targets, but we’re not going to be the last.”
Retooling cybersecurity
The Canvas breach in May disrupted final exams for classes, and the hackers behind the attack claimed it exposed approximately 3.5TB of user data from more than 8,800 institutions.
The scope of the attack was an important reminder of how consequential learning management systems are to colleges’ daily operations. Nearly every U.S. college and university uses a learning management system, with more than half of all faculty using one daily.
Faculty can best prepare for that level of classroom disruption by backing up gradebooks and course rosters onto a server or storage device not owned by their learning management system.
Instructure plans to prevent further breaches by using AI to harden its defenses and speed up the security review process—a lesson that extends to all software providers working with higher education.
The company is also conducting more frequent penetration tests, which simulate real-world attacks to uncover vulnerabilities before cybercriminals can exploit them.
Instructure has developed tools that actively probe new code for weaknesses before it reaches production environments.
Higher ed should follow Canvas’ lead in strengthening their defenses as AI lowers the cost and complexity of cyberattacks, Pendleton says. Colleges need to test systems more rigorously so they can identify and react to threats more quickly. They should also consider introducing Zero Trust Security practices and consider cybersecurity during every phase of their business and procurement practices.