SERVICES / HIGHER EDUCATION PENETRATION TESTING

SERVICES / HIGHER EDUCATION PENETRATION TESTING

Securing Campus Systems & Student Data

Securing Campus Systems & Student Data

Why Universities Are the Softest Target in the Threat Landscape

A university is not one network; it is hundreds. Open research computing, thousands of student-owned devices in the residence halls, decades of legacy systems, a culture of academic openness, and a population that turns over a quarter every year. Few environments hold as much sensitive data (student records, financial-aid files, medical records, and export-controlled research) behind as few walls.

FERPA governs student education records, the GLBA Safeguards Rule now applies to the financial-aid data every institution handles, campus health centers fall under HIPAA, and federally funded research carries NIST 800-171 and CMMC obligations. An automated scan lists missing patches; it does not tell you whether a compromised dorm laptop can reach the student information system, or whether a phished adjunct exposes a research grant. Thorium bridges that gap. Our team ran offensive operations at the Department of Defense level, and we bring that adversarial rigor to campus environments where the attack surface never sleeps.

Every engagement produces evidence-backed proof of exposure mapped to the regulations that govern your institution, along with a prioritized remediation roadmap and documentation ready for auditors, grant sponsors, and your board of trustees.

WHY CAMPUS IS DIFFERENT

The Campus Attack Surface

Universities carry risks a corporate network simply doesn’t. These are the conditions that make higher education uniquely exposed, and why a generic assessment misses what matters.

Residence Halls

Thousands of unmanaged, student-owned devices share infrastructure with campus systems: a BYOD network you don’t control but must defend.

Open Research

Collaborative, internet-facing research computing that resists lockdown by design, often holding export-controlled or grant-restricted data.

Constant Turnover

A quarter of your users change every year. Credentials, devices, and access churn constantly, and stale accounts pile up faster than they can be cleaned.

Federated Wi-Fi

eduroam and guest networks let visitors from any institution onto your wireless: a standing invitation that must be tested and contained.

79%

79%

79%

Share of higher-education institutions hit by ransomware in the past year

25%

25%

25%

Of the campus population turns over every year, constantly reshaping the attack surface

FERPA

FERPA

FERPA

The federal law protecting student education records, with federal funding tied to compliance

800-171

800-171

800-171

The NIST standard for protecting controlled unclassified information in federally funded research

MAPPED TO THE REGULATIONS THAT GOVERN CAMPUS

One Campus, Several Overlapping Mandates

Each engagement is scoped to produce evidence that maps directly to the administrative and technical safeguards your organization is required to implement and evaluate.

20 U.S.C. §1232g

FERPA: Student Records

We test whether student information systems, portals, and integrations properly restrict access to education records, the core of FERPA compliance.

16 CFR 314 (GLBA)

Financial-Aid Safeguards

The GLBA Safeguards Rule now applies to every institution handling Title IV financial-aid data, and mandates regular testing of the controls that protect it.

45 CFR 164 (HIPAA)

Campus Health Center

University health and counseling centers hold PHI under HIPAA. We test access controls and encryption on the systems that store and transmit it.

NIST SP 800-171

Controlled Research Data

Federally funded research carries CUI obligations. We validate whether the controls protecting research data meet the 110 requirements of 800-171 in practice.

PCI DSS 4.0

Campus Payments

Bursar, dining, bookstore, athletics, and event payments put you in PCI scope. We test the cardholder data environment for segmentation and exposure.

State Breach Laws

Incident Response

State notification laws set hard deadlines after a breach. We stress-test detection and response so your team sees an intrusion before the data walks out.

ENGAGEMENT METHODOLOGY

A Repeatable, Evidence-Driven Process

01

Scope & RoE

02

Reconnaissance

03

Exploitation

04

Student Data Impact

05

Reporting

06

Re-Test

ASSESSMENT COVERAGE

What We Test Across a Campus

Engagements are scoped to your institution. Below are the domains we most commonly assess for colleges and universities and the communities they serve.

STUDENT DATA / SIS

Student Information Systems

Banner, PeopleSoft, Workday Student, and Colleague are tested for authentication bypass, broken access control, and functions that could expose grades, transcripts, and financial-aid records.

BANNER

PEOPLESOFT

FERPA

GRADE TAMPERING

TEACHING / LMS

Learning Management Systems

Canvas, Blackboard, Moodle, and their third-party LTI integrations are tested for account takeover, insecure direct object references, and exposure of course and student data.

CANVAS

LTI

IDOR

ACCOUNT TAKEOVER

RESIDENTIAL / DORMS

Residence Hall Networks

Dorm networks mix thousands of unmanaged student devices, gaming consoles, and IoT with campus infrastructure. We test segmentation, rogue devices, and lateral movement from resident VLANs.

DORM VLAN

ROGUE DEVICE

IoT

SEGMENTATION

RESEARCH / HPC

Research & HPC Environments

High-performance computing clusters, lab networks, and research data stores are tested for exposure of controlled and export-restricted data, weak access control, and unmanaged instruments.

NIST 800-171

CUI

HPC

EXPORT CONTROL

CONNECTIVITY / WI-FI

Campus Wi-Fi & eduroam

eduroam, guest, and departmental wireless are tested for rogue access points, weak authentication, and whether a guest connection can reach administrative or research networks.

EDUROAM

ROGUE AP

WPA2 / WPA3

GUEST PIVOT

ACCESS / IDENTITY

Web Portals & Single Sign-On

Student and staff portals, Shibboleth and SAML single sign-on, and self-service applications are tested for authentication flaws, privilege escalation, and broken authorization across federated systems.

SAML / SSO

SHIBBOLETH

MFA BYPASS

BROKEN AUTHZ

PAYMENTS / PHYSICAL

Bursar, Campus Cards & Facilities

Tuition and dining payments, campus card systems, door access, and physical entry to labs and data closets are tested, including tailgating into open academic buildings.

PCI DSS

CAMPUS CARD

DOOR ACCESS

TAILGATING

HUMAN / SOCIAL

Social Engineering & Phishing

Targeted phishing, vishing, and pretexting against students, faculty, and administrative staff measure susceptibility to credential theft, the entry point for most campus ransomware.

PHISHING

VISHING

STUDENT ACCTS

MFA FATIGUE

STANDARDS & FRAMEWORKS

Aligned to the Regulations That Govern You

FERPA

Student Records

GLBA

Financial Aid

HIPAA

Health Center

PCI DSS

Payments

NIST

SP 800-171

CMMC

Research

WHAT YOU RECEIVE

Documentation Your Auditors and Sponsors Expect

Compliance-Ready Findings Report

A findings report structured to support your FERPA, GLBA, and NIST 800-171 obligations, with reproducible evidence and severity ratings for every issue.

Executive Attestation Letter

A signed engagement summary suitable for your board of trustees, auditors, grant sponsors, and cyber-insurance carriers.

Prioritized Remediation Roadmap

Every finding mapped to a concrete fix and sequenced by risk to student data and research, so your IT team can close the most dangerous gaps first.

Complimentary Re-Test

After you remediate, we re-test the confirmed findings and update your documentation to verify closure, at no additional cost.

Find out what an attacker could reach before the next semester starts.

Find out what an attacker could reach before the next semester starts.

We scope every campus engagement individually. Tell us about your environment (SIS, LMS, research, residence halls) and we’ll respond within one business day.

Request a Scoping Call

Thorium Information Security, LLC.

Hayden, Idaho, USA

Hayden, Idaho, USA

(208) 352-2877

(208) 352-2877

Sales@ThoriumInfosec.com

Sales@ThoriumInfosec.com

Copyright © 2026 Thorium Information Security LLC. All rights reserved.

Copyright © 2026 Thorium Information Security LLC. All rights reserved.