Why Universities Are the Softest Target in the Threat Landscape
A university is not one network; it is hundreds. Open research computing, thousands of student-owned devices in the residence halls, decades of legacy systems, a culture of academic openness, and a population that turns over a quarter every year. Few environments hold as much sensitive data (student records, financial-aid files, medical records, and export-controlled research) behind as few walls.
FERPA governs student education records, the GLBA Safeguards Rule now applies to the financial-aid data every institution handles, campus health centers fall under HIPAA, and federally funded research carries NIST 800-171 and CMMC obligations. An automated scan lists missing patches; it does not tell you whether a compromised dorm laptop can reach the student information system, or whether a phished adjunct exposes a research grant. Thorium bridges that gap. Our team ran offensive operations at the Department of Defense level, and we bring that adversarial rigor to campus environments where the attack surface never sleeps.
Every engagement produces evidence-backed proof of exposure mapped to the regulations that govern your institution, along with a prioritized remediation roadmap and documentation ready for auditors, grant sponsors, and your board of trustees.
WHY CAMPUS IS DIFFERENT
The Campus Attack Surface
Universities carry risks a corporate network simply doesn’t. These are the conditions that make higher education uniquely exposed, and why a generic assessment misses what matters.
Residence Halls
Thousands of unmanaged, student-owned devices share infrastructure with campus systems: a BYOD network you don’t control but must defend.
Open Research
Collaborative, internet-facing research computing that resists lockdown by design, often holding export-controlled or grant-restricted data.
Constant Turnover
A quarter of your users change every year. Credentials, devices, and access churn constantly, and stale accounts pile up faster than they can be cleaned.
Federated Wi-Fi
eduroam and guest networks let visitors from any institution onto your wireless: a standing invitation that must be tested and contained.
Share of higher-education institutions hit by ransomware in the past year
Of the campus population turns over every year, constantly reshaping the attack surface
The federal law protecting student education records, with federal funding tied to compliance
The NIST standard for protecting controlled unclassified information in federally funded research
MAPPED TO THE REGULATIONS THAT GOVERN CAMPUS
One Campus, Several Overlapping Mandates
Each engagement is scoped to produce evidence that maps directly to the administrative and technical safeguards your organization is required to implement and evaluate.
20 U.S.C. §1232g
FERPA: Student Records
We test whether student information systems, portals, and integrations properly restrict access to education records, the core of FERPA compliance.
16 CFR 314 (GLBA)
Financial-Aid Safeguards
The GLBA Safeguards Rule now applies to every institution handling Title IV financial-aid data, and mandates regular testing of the controls that protect it.
45 CFR 164 (HIPAA)
Campus Health Center
University health and counseling centers hold PHI under HIPAA. We test access controls and encryption on the systems that store and transmit it.
NIST SP 800-171
Controlled Research Data
Federally funded research carries CUI obligations. We validate whether the controls protecting research data meet the 110 requirements of 800-171 in practice.
PCI DSS 4.0
Campus Payments
Bursar, dining, bookstore, athletics, and event payments put you in PCI scope. We test the cardholder data environment for segmentation and exposure.
State Breach Laws
Incident Response
State notification laws set hard deadlines after a breach. We stress-test detection and response so your team sees an intrusion before the data walks out.
ENGAGEMENT METHODOLOGY
A Repeatable, Evidence-Driven Process
01
Scope & RoE
02
Reconnaissance
03
Exploitation
04
Student Data Impact
05
Reporting
06
Re-Test
ASSESSMENT COVERAGE
What We Test Across a Campus
Engagements are scoped to your institution. Below are the domains we most commonly assess for colleges and universities and the communities they serve.
STUDENT DATA / SIS
Student Information Systems
Banner, PeopleSoft, Workday Student, and Colleague are tested for authentication bypass, broken access control, and functions that could expose grades, transcripts, and financial-aid records.
BANNER
PEOPLESOFT
FERPA
GRADE TAMPERING
TEACHING / LMS
Learning Management Systems
Canvas, Blackboard, Moodle, and their third-party LTI integrations are tested for account takeover, insecure direct object references, and exposure of course and student data.
CANVAS
LTI
IDOR
ACCOUNT TAKEOVER
RESIDENTIAL / DORMS
Residence Hall Networks
Dorm networks mix thousands of unmanaged student devices, gaming consoles, and IoT with campus infrastructure. We test segmentation, rogue devices, and lateral movement from resident VLANs.
DORM VLAN
ROGUE DEVICE
IoT
SEGMENTATION
RESEARCH / HPC
Research & HPC Environments
High-performance computing clusters, lab networks, and research data stores are tested for exposure of controlled and export-restricted data, weak access control, and unmanaged instruments.
NIST 800-171
CUI
HPC
EXPORT CONTROL
CONNECTIVITY / WI-FI
Campus Wi-Fi & eduroam
eduroam, guest, and departmental wireless are tested for rogue access points, weak authentication, and whether a guest connection can reach administrative or research networks.
EDUROAM
ROGUE AP
WPA2 / WPA3
GUEST PIVOT
ACCESS / IDENTITY
Web Portals & Single Sign-On
Student and staff portals, Shibboleth and SAML single sign-on, and self-service applications are tested for authentication flaws, privilege escalation, and broken authorization across federated systems.
SAML / SSO
SHIBBOLETH
MFA BYPASS
BROKEN AUTHZ
PAYMENTS / PHYSICAL
Bursar, Campus Cards & Facilities
Tuition and dining payments, campus card systems, door access, and physical entry to labs and data closets are tested, including tailgating into open academic buildings.
PCI DSS
CAMPUS CARD
DOOR ACCESS
TAILGATING
HUMAN / SOCIAL
Social Engineering & Phishing
Targeted phishing, vishing, and pretexting against students, faculty, and administrative staff measure susceptibility to credential theft, the entry point for most campus ransomware.
PHISHING
VISHING
STUDENT ACCTS
MFA FATIGUE
STANDARDS & FRAMEWORKS
Aligned to the Regulations That Govern You
FERPA
Student Records
GLBA
Financial Aid
HIPAA
Health Center
PCI DSS
Payments
NIST
SP 800-171
CMMC
Research
WHAT YOU RECEIVE
Documentation Your Auditors and Sponsors Expect
Compliance-Ready Findings Report
A findings report structured to support your FERPA, GLBA, and NIST 800-171 obligations, with reproducible evidence and severity ratings for every issue.
Executive Attestation Letter
A signed engagement summary suitable for your board of trustees, auditors, grant sponsors, and cyber-insurance carriers.
Prioritized Remediation Roadmap
Every finding mapped to a concrete fix and sequenced by risk to student data and research, so your IT team can close the most dangerous gaps first.
Complimentary Re-Test
After you remediate, we re-test the confirmed findings and update your documentation to verify closure, at no additional cost.
We scope every campus engagement individually. Tell us about your environment (SIS, LMS, research, residence halls) and we’ll respond within one business day.
Request a Scoping Call
