Close

New Research from CDW Explores AI and Cybersecurity

Learn how AI is helping IT teams manage risk and improve resilience.

Oct 01 2026
Security

Higher Ed’s Path to Advanced Cybersecurity Maturity

Higher education IT leaders can move beyond basic cybersecurity using zero trust, integrated threat detection and continuous threat exposure management.

Higher education institutions face increasing pressure to strengthen cybersecurity while maintaining agility and cost-efficiency. IT leaders must move beyond reactive defense and toward operationalized maturity — creating systems that are resilient, scalable and audit-ready.

Using guidance from the National Institute of Standards and Technology’s Cybersecurity Framework and FINRA’s cybersecurity practices, enterprise-grade security principles can be adapted for use by security leaders for colleges and universities.

This includes advanced zero-trust implementation and integrating endpoint detection and response (EDR) with security information and event management (SIEM) and security orchestration, automation and response (SOAR) platforms to enable continuous exposure management and Software as a Service (SaaS) security posture management.

Click the banner below to read the latest latest cybersecurity research report from CDW.

 

By adopting these approaches, higher education IT leaders can transform security from a cost center into a growth enabler — achieving high-level protection and compliance without sacrificing innovation or speed.

Advanced Zero-Trust Implementation for Higher Education

Aaron Bugal, field CISO for Sophos, explains that zero trust is a journey, not necessarily a specific technology choice or stack. Rather, it is a blend of process, people and technology.

He says that identity has become the new security perimeter, requiring phishing-resistant, auditable, multifactor authentication to verify users and devices continuously.

Network segmentation limits the blast radius of breaches, while modern firewalls combining software-defined WAN, VPN and zero-trust capabilities simplify secure access. Continuous verification and automation enhance visibility and reduce manual workload, maintaining “transient trust” that adapts in real time.

“Around-the-clock detection and response are essential, making 24/7 monitoring and early alert investigation critical,” Bugal says. He adds that leveraging external expertise and automation can strengthen defenses and free teams to focus on strategic risk reduction.

READ MORE: Higher ed institutions are adopting zero-trust strategies.

WatchGuard field CTO Adam Winston says that when integrating EDR with SIEM and SOAR platforms, the goal should be to measure efficiency in the security operations center.

This can be achieved by setting up metrics such as mean time to respond or contain and running regular simulations to identify areas for improvement — without the pressure of real-world scenarios. “Organizations should start by ensuring that their EDR telemetry feeds directly into the SIEM to provide centralized visibility,” Winston says.

Teams can then use breach and attack simulation tools to routinely test the detection of new threats.

Winston adds that it’s important to tune SOAR playbooks based on test results to improve automated containment and facilitate case enrichment. “That way, teams can validate that the data is normalized and consistent across EDR, SIEM and SOAR for accurate correlation,” he says.

Continuous Exposure Management Strategies

Michelle Abraham, research vice president at IDC, says visibility into all of an organization’s assets is the foundation of exposure management. “The asset data should be aggregated and managed holistically, so all risks can be managed as one instead of in silos,” she explains.

DISCOVER: Continuous threat exposure management helps higher ed prioritize risk.

Once the exposures and their associated assets are prioritized based on their importance to the organization, remediation or mitigation efforts remove or block exposures from being exploited by attackers.

“Since exposures are found faster than ever, organizations need to move more quickly to fix issues as well,” Abraham notes. 

Dana Simberkoff, chief risk, privacy and information security officer at AvePoint, says identity threat detection and response (ITDR) naturally complements zero-trust architectures by ensuring even verified, authenticated users are behaving within expected parameters.

“Your users — humans — are always going to be your weakest link,” Simberkoff says. “By focusing not only on identity but also content and context, you can help to make sure that human error does not lead to catastrophic consequences.”

Winston adds that a mature ITDR solution should respond to account creation and removal and continuously detect and respond to identity misuse across sessions, devices and behaviors.

Click the banner below to subscribe to our weekly newsletter.

 

SaaS Security Posture Management

SaaS environments must remain securely configured, access to them appropriately governed, and risky behavior promptly detected and corrected. Enter SaaS Security Posture Management, which “provides a unified view of security posture across all SaaS applications, exposing misconfigurations, risky settings and excessive permissions,” Winston says.

It also identifies overprivileged users, dormant accounts, unmanaged service accounts and risky OAuth app connections across SaaS environments, offering guided fixes for common misconfigurations to reduce manual workload and response time.

For growing teams striving to implement DevSecOps successfully, it’s vital to build code scanning, dependency checks and Infrastructure as Code scanning early in the pipeline to catch issues before deployment.

From there, teams should automate wherever possible, using continuous integration/continuous deployment or delivery pipelines to automate testing, compliance checks, and remediation guidance to reduce manual effort and human error.

UP NEXT: Observability data can lead to actionable insights.

“It’s also essential to standardize secure coding practice by providing developers with secure coding guidelines, reusable templates and security-approved libraries,” he says.

Building a Case for Advanced Security

Bugal says a compelling business case positions security as a strategic risk management initiative, not just a technical expense.

It begins by identifying critical assets and quantifying potential impacts from breaches or downtime, linking security improvements to tangible outcomes such as revenue protection, customer trust and regulatory compliance.

“Demonstrating efficiency through tuned and optimized people, processes and technology linked to industry context strengthens your case,” he says.

Luis Alvarez/Getty Images