HomeCyber BalkansKeeper Security Provides Cyber Guidance for Education IT Teams

Keeper Security Provides Cyber Guidance for Education IT Teams

Published on

spot_img

Keeper Security Urges Educational Institutions to Strengthen Cyber Defenses Ahead of New Academic Year

As educational institutions prepare for a new academic year, Keeper Security, a leading provider of identity security and privileged access management (PAM), has issued a clarion call for schools, colleges, and universities to fortify their cyber defenses. The company highlights significant threats emerging from AI-powered phishing attacks and the rising complexities arising from unmanaged machine identities, both of which are challenging the security landscape of the education sector.

The annual back-to-school rush often results in IT departments becoming inundated with the need to provision accounts, issue credentials, and connect various new devices. This flurry of activity creates a unique opportunity for cybercriminals, who are starved for targets and eager to exploit the vulnerabilities that arise during this hectic period. As schools, colleges, and universities attempt to onboard thousands of students, faculty, and staff while simultaneously enrolling devices and integrating third-party applications, Keeper Security warns that such a frantic pace can lead to misconfigurations, stale credentials, and excessive access permissions—issues that may remain undetected in the chaos.

Educational institutions have become frequent targets for various forms of cyber attacks, including ransomware, credential theft, and data breaches. This vulnerability is exacerbated by the highly sensitive nature of the information that educational entities manage, which includes student records, financial data, and essential academic research. With this in mind, Keeper Security urges institutions to recognize the necessity for improved security protocols.

Keeper’s research reveals that a distinct lack of security awareness is compounding the threats faced by educational institutions. Alarmingly, only 14% of schools mandate security awareness training for staff and students, while nearly 20% of students and parents admit to reusing passwords across both personal and school accounts. Such practices make institutions more susceptible to attacks.

Moreover, the advent of artificial intelligence presents an additional layer of difficulty in cybersecurity. AI-generated phishing messages have become increasingly sophisticated, accurately mimicking communications from IT helpdesks and other trusted university departments. This evolution diminishes the effectiveness of traditional phishing identification, as the communications often lack the spelling and grammatical errors typically found in earlier campaigns. The rise of deepfake technology also enables cybercriminals to impersonate trusted individuals through convincing voice and video simulations, further complicating the security landscape.

Research conducted by Keeper indicates that 52% of education leaders consider deepfake impersonation to be a significant risk; however, only 26% feel they possess the ability to recognize AI-generated threats. The issue is pressing, as 41% of educational institutions have reported being targeted by AI-generated phishing attempts or misinformation campaigns.

In addition to attacks aimed at students and staff, Keeper highlights a less visible yet crucial threat: non-human identities (NHIs). These include service accounts that synchronize student information with learning management systems, API keys connecting third-party educational technology applications, and machine certificates authenticating devices. As educational environments evolve, they increasingly utilize AI agents and bots for various functions, adding to the complexities of identity management.

Keeper warns that conventional identity management practices often overlook the credentials associated with these non-human identities. For example, service account passwords may go unchanged for extended periods, while API tokens for unused applications can remain active, creating potential vulnerabilities. Cloud workloads may accumulate undesired permissions, and improperly configured or expired certificates can further exacerbate security gaps.

Darren Guccione, the CEO and co-founder of Keeper Security, emphasizes the necessity for educational institutions to reevaluate their approach to identity security. “The conversation about education cybersecurity has historically focused on human accounts, such as students and faculty,” he notes. “However, the real blind spot is the vast ecosystem of machine identities that fuel modern educational technology. The back-to-school period is an opportune moment for IT teams in education to assess all identities in their network, encompassing both human and non-human components.”

To address these concerns effectively, Keeper recommends that educational IT teams utilize the window before students return to campus to scrutinize both human and machine access within their systems. Among the proposed strategies are the enforcement of multi-factor authentication (MFA) across all accounts and the deployment of enterprise password management solutions to mitigate the risks associated with weak, reused, or shared credentials.

Institutions are also advised to conduct thorough audits of privileged access and remove permissions linked to former employees, expired service accounts, and applications that are no longer in use. For non-human identities, Keeper advocates for the creation of a comprehensive inventory that includes service accounts, API keys, machine certificates, cloud identities, and AI agents. Additionally, establishing credential rotation policies, particularly for third-party educational technology integrations and newly implemented AI systems, is vital.

As educational institutions increasingly rely on cloud services, connected devices, third-party tools, and AI technologies, Keeper Security argues that understanding which identities have access—and whether they still require that access—is becoming as critical as safeguarding the traditional user accounts of students and staff. In light of evolving cyber threats, the educational sector must prioritize not only its human resources but also the invisible networks that support their operations.

In conclusion, Keeper Security’s proactive guidance underscores the urgency for education institutions to bolster their cybersecurity frameworks in preparation for the challenges of the upcoming academic year. Failure to do so may leave them vulnerable to increasingly sophisticated threats.

Source link

Latest articles

White House Engages Security Firms to Combat Cybercrime

The White House has recently unveiled an initiative aimed at engaging private security firms...

Cybersecurity Awareness Resides in Grassroots Efforts, Not Solely in Policy Frameworks

Cybercrime Has Entered Into Everyday Life In the current hyper-connected landscape, cybercrime has permeated every...

Microsoft Sets Passkeys as Default in Entra ID, Phases Out SMS and Voice Authentication

Microsoft Announces Transition to Passkeys as Default Authentication in Entra ID In a significant shift...

The First Domino of AI Disruption: How Frontier Models Are Revolutionizing Software Security

AI Disruption: A New Era in Software Security In the rapidly evolving realm of technology,...

More like this

White House Engages Security Firms to Combat Cybercrime

The White House has recently unveiled an initiative aimed at engaging private security firms...

Cybersecurity Awareness Resides in Grassroots Efforts, Not Solely in Policy Frameworks

Cybercrime Has Entered Into Everyday Life In the current hyper-connected landscape, cybercrime has permeated every...

Microsoft Sets Passkeys as Default in Entra ID, Phases Out SMS and Voice Authentication

Microsoft Announces Transition to Passkeys as Default Authentication in Entra ID In a significant shift...