Adam Khan on the Unique Security Challenges in Education IT
Adam Khan, vice president of global security operations for Barracuda Networks, explains what makes securing schools, such as universities, so much more difficult than the average enterprise IT environment.
Transcript
This is Textron tv. Hey guys, thanks for the throw. We're here with Adam Khan, who's vice president of Security Operations for the managed XDR service at Barracuda Networks.
And we're talking about, well, how AI might help all these schools that are the target of these ransomware attacks. Adam, welcome to show. Thank you, Mike.
Thank you for having me. We hear about schools getting hit all the time and they don't really have a whole lot of resources, but then again, they're not AI experts either. So how will all this come together in your mind, to protect these schools and what can be done that we're not doing today?
I think it's first important to understand why this is happening, right? When we talk about ransomware attacks, especially against the educational sector, I think it's clear they're in a very tough spot like universities and colleges. Um, they handle a lot of sensitive information.
So you have student records, you have financial information, and they have research data. And this is the reason why attackers and cyber criminals, um, love kind of going after them. It feels like the attacks themselves are becoming more sophisticated and they're increasing in volume at the same time.
Is it just getting too hard for the average school to kind of manage this process on their own? And what should they be doing versus what should maybe be a service handled by the so-called professionals? Yeah, so I think many of the educational institutions, um, for first and foremost, I think they're working on tighter budgets, right?
Which means that there's a high probability that they have older systems in place and not enough robust security measures, and again, alludes to which leaves them more vulnerable. So I, we could definitely go into what are the best practices as far as, hey, what do they need to adopt when it comes to utilizing the layers AI technologies? Because when we're talking about resource constrained constraints and, um, the fact that, um, there's also budgeting constraints.
It's best for them to kind of partner up with security providers that have the capabilities of AI automation to be able to stop threats like ransomware, uh, in its place. And a lot of this goes back just to the fundamentals of ai. If I'm a university, it seems unlikely I'm ever gonna collect enough data on cybersecurity to train an AI model and then deploy that.
So is the shift to AI gonna push more people that consuming cybersecurity as a service because it's the only way to kind of win the fight? Yeah, I think there's the, the market leaders are very far ahead in this, so absolutely, as you're saying, it's harder for universities to start from, you know, scratch and kind of start adopting and implementing those in-house. The ease of getting into this is the pathway to start utilizing companies that are already far ahead in the journey when it comes to AI and, and cybersecurity when it comes to hardening, um, overall security posture.
So it, it, um, I'm in agreement, like starting from scratch is definitely a uphill battle, uh, for these, uh, educational sector, uh, market. So on the face of it, it would seem that that was intuitively obvious, but what is the hurdle that is there or the challenge, is it a cultural issue that people are just used to doing security the old fashioned way? Or what does it take to kind of get them to shift their mind to thinking it as more of a service?
Yeah, I think first of all, I think one of the biggest things is, is a mind shift, right? Universities first need to recognize that cybersecurity is a major risk, right? To their operations, and it needs the proper funding to be able to handle it in the right manner.
Because what happens is you have significant operational downtime, um, when these attacks happen, and when they happen, they, you know, they have the ability to bring down learning platforms to bring down, um, you know, schools and classes that are being conducted completely online or are utilizing the infrastructure that the school relies on. And, um, you know, that has its own significant downsides where, um, the faculty, the, the students, and even the parents who are on that infrastructure, right, who rely and, and, um, you know, have that trust in that university or that educational institution to be able to service them and when their data gets leaked, right? It's, it's big ramifications, uh, as comes from that.
So, to, to answer your question, yes, they should, uh, recognize and, uh, there's a lot of great players on the market, um, to adopt cybersecurity. It's a easy entryway. Um, and, and, and, you know, adopt those technologies a lot faster and kind of cut the red tape, if that makes sense.
And It also seems like unlike say, a corporation where I can make all the employees take a training class to hopefully make them better at this, if I'm an university setting or a school, I can't really order all the students and the parents and everybody else to take a training class, right? Yeah, no, it's true. I think, but it should be, right?
If we think, look about, think about it, it should be mandatory and, and something that is put into your practice, right? Training the students and, uh, the faculty on how phishing threats work, um, conducting security drills, right? Um, and collaborating with the companies that you're linked up with to first educate the, uh, your audience on why cybersecurity matters and how it affects them in today, day-to-day lives, um, and how it affects the university.
So I think it's a, uh, you're right, right on the track, like there's, there has to be a need to do this kind of, uh, awareness about cybersecurity and, and its risks. Is there something about being a cybersecurity professional in the academic space that's different therefore than every other space where, uh, do I need a lot more courage than the average cybersecurity person? I mean, I think when you're getting into cybersecurity or you're, you are trying to learn in, in university, you obviously are, the, the experience in dealing with real attacks is, is, uh, something that, you know, universities and their, um, uh, students who are learning don't have.
Um, but definitely there's a difference between somebody who's professionally doing it, uh, as opposed to somebody who's actually coming up and learning. And that though answers your question. And most of these institutions can only afford a limited amount of cybersecurity expertise.
And a lot of the times it seems to me they're trying to double up on it, people that have a million other things to do. And so the math equation here seems a little stretched. Oh, it is way off, right?
Because you have, think about universities, they might have multiple locations and buildings across campus, right? Each one of those campuses might have various infrastructure. You have hundreds of, uh, laptops, um, wifi devices all across these campuses that are connected, not to mention firewall switches, and you could go on and on, and then you have, uh, SaaS applications they might be using.
So the role of the IT administrators, like you said, is actually to manage that infrastructure, right? It is not to handle, you know, or even a lot of them, um, unfortunately don't have even the, the capacity, like you said, to handle security threats, right? They're too busy in the day-to-day administration off accounts, off, uh, patching and things like that, um, of, uh, downtime to be able to address cybersecurity.
On top of that, One of the catch 20 twos of cybersecurity, and it probably applies more in academia than anywhere else, is that, uh, the tolerance for processes that are deemed cumbersome is pretty low. And yet when we put cybersecurity, uh, checks in, people start complaining about that the process got a little too complicated, and then they look for ways to end run that. Is there some middle ground that can be found here?
I think it, my view is as far as, you know, a middle ground, I think if you are a cybersecurity provider, right? It's your prerogative to make things easy without causing additional, you know, cumbersome or something that seems as burden for, to the, to the user. So ease of use is, is key in cybersecurity, um, to make it very seamless as you're seeing, um, from biometrics coming into the picture from like you just opening up your phone, seeing your face and logging in, um, and you know, fingerprint, you name it, those, those kind of things.
Security is moving in that direction to make it easy for the users to still go through the actual proper, uh, procedures, right? But making it seamless if that makes, uh, sense. So it's, it's a prerogative for, uh, security providers to do that.
And I think overall they're doing a great job there as well. So implementation and finding out who the right one is for you, uh, I is, is is the, it's the workload the universities has to take on. Have you seen any of these institutions kind of banding together to better secure their campuses in a more cohesive, maybe collective fashion because there's something to be learned from each other, or are they still kinda operating in isolation from one another?
I haven't actually seen that, uh, or, or, you know, heard about, you know, multiple universities kind of getting together. Uh, but I think that's a fabulous, uh, idea, uh, especially if it can be done on like state level. Um, so that's, that's a great suggestion.
But I haven't personally seen or, or, or heard about various universities kind of collaborating. They kind of operate in their own, uh, model because each one has their own data governance policy, right? They, each one has their own privacy policy and, and security policy.
So I would say that would be something to have a standard across the board at, at the state level for universities to follow. So among the universities and other academic institutions out there that you've engaged with one of the ones who are getting it right, doing that, the others are not, what is that kind of thing that leaps out at you that goes, yeah, I sure wish everybody would learn something from these folks and do what? I think, um, that's a great question.
I think from, from the perspective of which ones are doing it, right? I don't have that particular information, you know, right now on the top of my head, but I would say there's definitely, um, challenges that overall universities are facing, right? There's no silver bullet that anybody can say, okay, I'm a hundred percent doing this in, in the proper manner.
Um, you see that from, I don't know if you've heard about the, uh, university of Oklahoma that recently had a breach. So they actually suffered a ransomware attack, um, and that was one of the best, uh, in the sense they were, they were attacked where by a group called fog, uh, ransomware group. And the group only claimed 91 megabits of data of sensitive data.
You might think it's not that much, right? But if you include this was sensitive data from students to financial records and employee data and this data, the ransomware, uh, group actually said, we will publish this online. Uh, and this is to pressure, uh, the victim to into paying ransomware.
So it's, it's, um, it goes kind of beyond this breach, right? Your universities are susceptible now when these attacks happen to regulatory, um, concerns to privacy concerns and concerns with their faculty and students with identity theft and fraud, uh, issues with fraud, that there as well. So there's, they are now going to do a self-assessment on, Hey, what was my p cybersecurity practices at the time of this, this happened?
What are the incident response plans that we had? So I think overall, I think it's more about learning from the, um, the past and what's happened and then try to keep improving as we go forward. Alright, folks, you're hit in here.
The cybersecurity game is changing, especially in academia. The more you go in alone, the more likely bad things are gonna happen. So in the age of ai, might wanna lean on some more platforms out there.
Hey Adam, thanks for being on the show. Thank you for having me, Mike. Have a good day.
All right. And back to you guys in studio.