Intelligent CISO Issue 70 | Page 44

industry

UNLOCKED

UNIVERSITY OF SALFORD ENHANCES CYBERSECURITY WITH TANIUM

Mark Wantling , CIO at the University of Salford , tells us how the university has improved its cybersecurity posture by deploying Tanium solutions . He explains how Tanium ’ s real-time visibility , integration with ServiceNow and Microsoft Azure Sentinel , and tools like Tanium Impact have fortified the university ’ s defences against cyberattacks , enhancing endpoint management and fostering a proactive security culture , significantly improving the university ’ s response to cyberthreats and overall IT efficiency .
Mark Wantling , CIO at the University of Salford
Can you elaborate on the specific vulnerabilities in education institutions ’ IT environments that make them attractive targets for cyberattacks ?
Unfortunately , educational institutions are appealing targets for cyberattacks for a number of reasons . To start , universities hold a huge amount of personal data and classified research which criminals would love to get their hands on .
Plus , the optimisation of universities for a hybrid learning environment has led to more distributed networks , with students , staff and visitors using an array of personal devices to connect to networks from different locations . This has increased the attack surface and is making it hard to keep track of the ever-increasing number of endpoints . To add to this , different schools and departments across campuses are often siloed , making visibility even foggier .
For example , our Tanium implementation uncovered shadow IT endpoints and multiple missing patches , revealing the security risk posed by unauthorised devices and outdated software .
Resourcing also plays its part . Universities typically have smaller security and / or IT teams than large corporate organisations , which can hamper the ability to monitor and respond efficiently to cyberthreats . This cements the need for automation to support us in visibility and response .
Key moments in the academic year , like clearing , are an especially attractive time for hackers looking to wreak havoc . If a university were to suffer a cyberattack during that time and be fully offline , it would be nearly impossible to financially recover , as it could mean £ 30 million a year in lost revenue for three years .
How did the shift to remote education in 2020 expose or exacerbate the University of Salford ’ s cybersecurity challenges ?
The shift to remote education in 2020 significantly enlarged and distributed our attack surface . We faced heightened vulnerabilities , with students and staff utilising a mix of personal devices and networks for teaching , learning and research . The increased complexity and diversity of thousands of endpoints led to the discovery of missing critical patches and vulnerabilities , posing a substantial security risk . To address these challenges , we worked to modernise endpoint management , implementing Tanium in 2021 .
Tanium ’ s real-time visibility of endpoints , integration with ServiceNow and Microsoft Azure Sentinel , and capabilities such as Tanium Impact have played a crucial role in enhancing our cybersecurity posture . The integration efforts have facilitated total visibility across platforms , faster response times and improved risk assessment , contributing to a comprehensive security framework and cultural change within the organisation .
What were the key steps and strategies you implemented to strengthen the University of Salford ’ s defences against cybercrime ?
As mentioned , we took a significant step by adopting Tanium to gain real-time visibility across our network and centralise vulnerability
44 WWW . INTELLIGENTCISO . COM