IT and Cybersecurity Teams

Illustration of a woman sitting at a desk with three computer monitors in an office setting.

Cybercrime continues to grow as a threat to the global research community – one that reaches beyond the security of any single institution or system. 

Higher education is one of the most heavily targeted sectors for cyberattack. This is due to the large amount of personal and research data routinely stored by universities, including library systems. IT and information security teams, including Chief Information Security Officers (CISOs) and Information Security Officers (ISOs), sit at the centre of these growing challenges.  

Higher education cybersecurity risks 

According to a UK Government report, almost every UK university (98%) identified breaches or attacks in 2025. A report from Quorum Cyber states that the number of data breaches in the higher education sector jumped by 73% in 2025. According to our own research, reasons university CISOs and ISOs consider the university sector high risk include: 

  • Intellectual property (IP). Universities and research institutions hold large volumes of IP, which is highly valuable.  

  • The distributed nature of institutions. This can make it difficult to put effective policies and security systems in place. 

  • Under-appreciation of the risk. Historically, the sector did not appreciate that it could be a target, due to its non-profit nature, so did not invest enough in protection. 

  • Early adoption of the internet. Previous practices that once worked well may need to be updated. 

  • Budget constraints. Institutions may hold data on ageing infrastructure and operate within tight budgets. 

Publishers are often the first to detect breaches, through irregular download activity or platform analytics. They can alert institutions before internal systems catch it. This kind of cross-sector visibility is central to what SNSI exists to support.  

What are the cybersecurity threats facing universities? 

As part of our 2025 Cybersecurity and Academic Libraries research we conducted interviews with 20 CISOs. They shared that common breach types included: 

  • Phishing. The most frequently reported breach type, affecting staff and students. 

  • Financial fraud. Including payroll redirect attacks and fraudulent claims on student financial assistance. 

  • Multi-factor authentication (MFA) fatigue. Users approving authentication prompts that they did not initiate, giving bad actors a way in through otherwise strong controls. 

  • Virtual private network (VPN) vulnerabilities. Flawed VPN technology providing a route to unsecured servers. 

  • Nation-state targeting. Individual staff members targeted by state-backed actors. 

  • Mass credential-driven downloads. Compromised login credentials used to download large volumes of journal articles in a short space of time. These are often first flagged by the publisher rather than the institution.  

CISOs also pointed to ransomware and third-party vendor compromise as high-impact risks seen more widely across the sector. A single vendor breach can expose multiple institutions at once. In our 2022 CISOs Research report, CISOs pointed to several specific areas of vulnerability:  

  • Human factors. Phishing remains effective, compounded by a lack of awareness or reluctance around additional security steps such as MFA. 

  • Autonomous third-party products. A growing number of applications and services sit outside direct institutional control. Systems are often highly integrated, so if one is compromised, there is a high chance that all will be exploited. 

  • Research security as a lower priority. Research software and systems are often held to a lower security standard than industry equivalents. 

  • Research, data, and IP exposure. Student data and high-value research IP sit side by side, and collaborative, sponsor-funded research can open up further vulnerabilities. 

How SNSI supports IT and cybersecurity teams 

Our research shows that there is often limited collaboration between central IT security and library IT services – even though closer coordination benefits both. SNSI exists to help close that gap to help build a stronger, more resilient research ecosystem.  

We share intelligence, and connect IT and cybersecurity professionals with publishers, librarians, and institutions working on the same problem. Among the things we do to support your work, we: 

  • Commission research into the priorities and experiences of CISOs and information security teams across the sector. 

  • Share intelligence between publishers and institutions. This helps connect threats seen on one side of the ecosystem with what the other is experiencing. 

  • Host sessions on institutional and network security at our annual SNSI Security Summit.

  • Provide practical guidance and resources developed with input from CISOs and security practitioner 

Cybersecurity tips for IT and cybersecurity teams 

Basic cyber-hygiene tools, such as multi-factor authentication (MFA), are a key line of defence in preventing cybercriminals from accessing your university network. Training is also essential to raise awareness. Even with security systems in place, staff and students often do not understand their importance.

Tips that emerged from our 2022 research include:  

  • Use tools and protocols such as MFA, end-to-end encryption of content, end-point detection and response (EDR), and zero trust architecture (ZTA). 

  • Upgrade network security tools, including patching, firewalls, etc. 

  • Test vulnerability detection procedures. 

  • Use prompts such as pop-ups or external sender header in emails to increase awareness. 

  • Increase vigilance around nation-state activity 

  • Provide regular training. This may include cyber essentials training or certification, educating people on new software to stay up to date, public service announcements, and education around cyber threats and what to do if there is an incident. 

Resources for IT and cybersecurity teams 

Learn more with the following resources: