Close

New Research from CDW Explores AI and Cybersecurity

Learn how AI is helping IT teams manage risk and improve resilience.

Sep 15 2026
Security

Risks and Rewards of IoT in Higher Education

Shadow IT is flooding college and university networks as students move back to campus. Here’s how higher ed IT leaders can secure their networks without impacting the student experience.

Connected minifridges, smart speakers and internet-based gaming consoles are among the devices students are bringing to college that IT departments may not have accounted for — or even know are connected to the campus network. These devices may run on default passwords and have little to no security configuration, making them an attractive and vulnerable entry point for a cyberattack.

For higher ed IT, the stakes couldn’t be higher. According to the Zscaler ThreatLabz 2025 Mobile, IoT and OT Threat Report, the education sector saw an 861% rise in malware attacks from Internet of Things devices between 2024 and 2025.

Click the banner below for 2026 CDW Cybersecurity Research Report insights.

 

UCSB Cybersecurity Initiative Relies on a Zero-Trust Security Model

According to the University of California, Santa Barbara, the number of attacks intercepted by the university’s firewall increased by more than 520% between 2020 and 2025, prompting the university to act.

UCSB’s network serves more than 400 connected buildings and about 125,000 connected devices, including IoT technology. That scale made the university’s legacy location-based security system unsustainable. 

“We are fundamentally changing how UCSB has run their network for the last 40 years,” said CTO Shea Lovan said in describing the university’s network overhaul. “But with this approach, our faculty, staff and students will have access to the systems, data, and services that they need to pursue their academic or research objectives — wherever they are on campus or in the world.”

In response to a 2024 mandate from the University of California Office of the President establishing UC systemwide cybersecurity standards — including comprehensive network segmentation and rigorous vulnerability management — Lovan and his team stood up the Secure UCSB initiative, a zero-trust cybersecurity model that grants network access based on user identity (and in some cases, device security posture) over encrypted connections. The approach eliminates access decisions based on physical or network location.

DISCOVER: Zero trust networking is keeping organizations safe.

That effort earned the university the 2026 Zero Trust Champion Award at the Zscaler Public Sector Summit. The award recognizes organizations that are fundamentally redefining cybersecurity in the public and educational spheres.

“By embracing zero trust, we are going beyond just upgrading our infrastructure,” said UCSB CIO Josh Bright in announcing the award. “We are protecting UCSB’s vital research and its thriving campus community. Secure UCSB positions us to operate securely in our rapidly evolving digital future.” 

The initiative’s microsegmentation strategy involves creating separate network segments for IoT devices and operational technology, so if one device is compromised, the threat is contained. 

The Rise of Shadow IoT Devices Among College Students

But what happens when students bring connected devices to campus that escape the IT team’s oversight?

Shadow IT is unauthorized technology, hardware, applications or cloud services used by students, employees or faculty without the knowledge or approval of the university’s IT department. Shadow IoT — a type of shadow IT — occurs when students, faculty or staff bring unauthorized and unmanaged internet-connected devices onto the campus network. To mitigate potential security vulnerabilities and compliance risks that such devices pose, it’s vital that higher ed IT teams identify these unvetted systems.

LEARN MORE: Why visibility is key to data security.

According to a summer 2024 report from Boldyn Networks, students bring an average of three or more internet-ready devices to campus — including laptops, smartphones, gaming consoles, smart plugs and speakers, robot vacuums and more — and expect to be able to use at least two at the same time. 

According to the report, “reliable connectivity is ranked by students as nearly as important as academic rigor and campus safety, with a staggering 84% of students living in residence halls believing that reliable internet access is as essential as campus safety and academic quality.”

This flood of devices leaves higher education IT teams struggling to provide a connected experience for students without unintentionally granting them access to the core network. 

Click the banner below to subscribe to our weekly newsletter.

 

IoT Device Management Is Crucial for Reducing Security Vulnerabilities

But students’ expectations for seamless connectivity often collide with the realities of network security. The 2026 EDUCAUSE Students and Technology Report found that 46% of students encountered a security threat during the past academic year. The SonicWall 2026 Cyber Protect Report showed an 11% year-over-year increase in IoT attacks across sectors. 

Setting device limits — or blocking these devices altogether — might seem like an intuitive next step for IT teams, but students’ expectations have been set, and they are prepared to devise their own work-arounds, such as purchasing travel routers and setting up unmanaged access points, exacerbating the shadow IT issue. 

A single compromised smart plug can be the entry point that an attacker uses to gain a foothold in the network, before moving laterally into valuable systems such as student records or administrative databases.

Part of the challenge is architectural. Captive portals — the web-based logins IT teams have relied on for years — don’t work for IoT devices without a browser to access a login screen. And a single shared Wi-Fi password for an entire residence hall eliminates any isolation between rooms. A student in one room could accidentally cast a video to a TV in another room or pivot across the network to a student laptop across the hall. 

READ MORE: Smart networking solutions power collaboration on campus.

UCSB’s segmented approach is one solution to this challenge. Instead of attempting to secure a flat network carrying 125,000 devices, the university implemented agentless device segmentation alongside zero-trust application connectivity. This allowed it to connect and control traffic between segments so a compromised device in one location is unable to reach systems it shouldn’t connect to. 

Building the Architecture for Secure IoT at Scale

Private preshared key technology is another method of addressing IoT security in higher education, specifically in shared spaces such as residence halls. Rather than a single shared network password for everyone in a building or on a floor, each user receives a unique login credential that grants them access to their own isolated network segment while blocking them from their neighbors. 

From there, automated virtual LAN steering keeps that traffic separated from important systems, such as administrative databases and research servers. IoT devices can still reach their cloud apps to function normally, but they have no path into other parts of the network.

Visibility is key to this operation. Before IT teams can secure or segment anything, they must know what devices are on the network. Artificial intelligence–driven network access control platforms can identify devices the moment they request an IP address, reading DHCP signatures and device identifiers instead of relying on IT teams to manually maintain lists. This identification happens instantly, so the network is aware that it is looking at, say, a smart plug or a gaming console before any issues surface. A system that automatically identifies IoT devices on a network can automatically apply the correct segmentation and security policies without the IT department’s intervention.

Governance and Policy: Managing IoT Across the College Campus

Not all campus technology categories come with built-in governance guardrails, which is an inconsistency that complicates IoT oversight. Some purchasing decisions are shaped by compliance mandates such as the Family Educational Rights and Privacy Act, while others are left largely to individual discretion. 

“Laptops don’t have natural funnels. They have a refresh rate, a chip processor and a price point. Data privacy has a very natural funnel,” says Mark Smith, manager of classroom technologies and esports at CDW. “So, it’s interesting how some of these decisions come with guardrails, while others can be more free will.” 

EXPLORE: Governing shadow data keeps higher ed IT compliant.

That inconsistency is why visibility is so important. When IT teams can see and control every device on the network — whether the device is registered — they no longer have to depend on students or faculty choosing secure devices on their own. Rather, the network itself can enforce the guardrails.

That control expands campuswide to classrooms, libraries and anywhere else the network touches. 

“Card readers for boards, panels in rooms — you can scan in with your college ID, and your profile loads onto the interactive board,” Smith says. “But it also brings in a compliance piece in terms of what type of tech has to be on the access points. Those solutions are now being built into technology planning decisions. It’s not a separate conversation anymore.”

lupengyu/Getty Images