Intelligent CISO Issue 70 | Page 46

industry

UNLOCKED
Tools like Tanium Impact have proved crucial in identifying areas where we may have been overly permissive .
To effectively counter these threats , a multi-layered security approach is crucial . The University of Salford ’ s implementation of Tanium for real-time visibility , integration with ServiceNow and Microsoft Azure Sentinel for streamlined security operations , and the emphasis on cultural change and move to a Zero Trust framework , give us the comprehensive strategy we need . This includes proactive threat detection , rapid response and a security-conscious culture to mitigate risks in an evolving educational IT landscape .
How do you manage the balance between ensuring robust cybersecurity and maintaining an open and accessible IT environment for students and staff ?
Maintaining an open and accessible environment , while ensuring the university is secure , is a challenging task . By its nature there will always be hundreds of thousands of potentially vulnerable endpoints connected to the network , thousands of potential phishing victims with university credentials and a continued need for 24 / 7 access .
Striking a balance between providing adequate protection and allowing the university to function efficiently starts with understanding the university ’ s risk appetite – each institution will differ and having this understanding will shape the level of controls implemented .
It ’ s also important to consider the impact of overly tight , or lapse restrictions . If controls are overly restrictive it starts to strangle the ability for the business to operate , which could either lead to loss of organisational agility or worse , could drive staff and students to look for ways around the controls .
On the other hand , if controls are overly permissive there is an opportunity for bad actors to move very quickly through the organisation , resulting in increased damage and more time and effort to identify , detect and respond to an attack .
To avoid these outcomes , security teams must establish close relationships with staff and students , creating a feedback loop to quickly assess the impact of controls on teaching , research and learning .
Ensuring we have real time visibility into the entire university network is also crucial . This allows us to be less restrictive , as we can immediately react to any threat and cut it off before any damage is done . With the help of automation , we can also ensure that every device is patched , making our environment as secure as possible .
For example , tools like Tanium Impact have proved crucial in identifying areas where we may have been overly permissive , allowing proactive adjustments before bad actors exploit vulnerabilities .
What advice would you give to other educational institutions looking to enhance their cybersecurity , especially in terms of endpoint protection ?
Educational institutions need a proactive security culture to enhance cybersecurity defences . This means having real-time visibility the entire environment , comprehensive software integration and collaborative workflows . Being able to identify a threat quickly from a central console , and initiate remediation , improves response speeds and mitigates the potential impact of a breach .
Plus , operational and customer experience benefits bring significant return on investment . Since implementing Tanium , we ’ ve used fewer resources and saved money . And with complete visibility of the devices connecting to our network , we ’ ve improved the efficiency of software development that has significantly improved customer experience . Prevention is better – and costs far less – than a cure .
46 WWW . INTELLIGENTCISO . COM