UCSB Cybersecurity Initiative Relies on a Zero-Trust Security Model
According to the University of California, Santa Barbara, the number of attacks intercepted by the university’s firewall increased by more than 520% between 2020 and 2025, prompting the university to act.
UCSB’s network serves more than 400 connected buildings and about 125,000 connected devices, including IoT technology. That scale made the university’s legacy location-based security system unsustainable.
“We are fundamentally changing how UCSB has run their network for the last 40 years,” said CTO Shea Lovan said in describing the university’s network overhaul. “But with this approach, our faculty, staff and students will have access to the systems, data, and services that they need to pursue their academic or research objectives — wherever they are on campus or in the world.”
In response to a 2024 mandate from the University of California Office of the President establishing UC systemwide cybersecurity standards — including comprehensive network segmentation and rigorous vulnerability management — Lovan and his team stood up the Secure UCSB initiative, a zero-trust cybersecurity model that grants network access based on user identity (and in some cases, device security posture) over encrypted connections. The approach eliminates access decisions based on physical or network location.
DISCOVER: Zero trust networking is keeping organizations safe.
That effort earned the university the 2026 Zero Trust Champion Award at the Zscaler Public Sector Summit. The award recognizes organizations that are fundamentally redefining cybersecurity in the public and educational spheres.
“By embracing zero trust, we are going beyond just upgrading our infrastructure,” said UCSB CIO Josh Bright in announcing the award. “We are protecting UCSB’s vital research and its thriving campus community. Secure UCSB positions us to operate securely in our rapidly evolving digital future.”
The initiative’s microsegmentation strategy involves creating separate network segments for IoT devices and operational technology, so if one device is compromised, the threat is contained.
The Rise of Shadow IoT Devices Among College Students
But what happens when students bring connected devices to campus that escape the IT team’s oversight?
Shadow IT is unauthorized technology, hardware, applications or cloud services used by students, employees or faculty without the knowledge or approval of the university’s IT department. Shadow IoT — a type of shadow IT — occurs when students, faculty or staff bring unauthorized and unmanaged internet-connected devices onto the campus network. To mitigate potential security vulnerabilities and compliance risks that such devices pose, it’s vital that higher ed IT teams identify these unvetted systems.
LEARN MORE: Why visibility is key to data security.
According to a summer 2024 report from Boldyn Networks, students bring an average of three or more internet-ready devices to campus — including laptops, smartphones, gaming consoles, smart plugs and speakers, robot vacuums and more — and expect to be able to use at least two at the same time.
According to the report, “reliable connectivity is ranked by students as nearly as important as academic rigor and campus safety, with a staggering 84% of students living in residence halls believing that reliable internet access is as essential as campus safety and academic quality.”
This flood of devices leaves higher education IT teams struggling to provide a connected experience for students without unintentionally granting them access to the core network.
Click the banner below to subscribe to our weekly newsletter.
