UNIVERSITIES ARE ABOUT TO FACE A HARDER CYBER SECURITY ERA
UNIVERSITIES ARE ABOUT TO FACE A HARDER CYBER SECURITY ERA
You’ll have seen the Mythos coverage. Anthropic has teased a tool that can find software vulnerabilities at a scale and speed that wasn’t possible before. Some of the initial panic was called overblown, and reasonably so. AI didn’t invent vulnerability hunting. But the direction of travel is clear. More “vibe coded” tools with questionable governance. More black hats with more powerful tools at their disposal.
This matters for higher education more than most sectors. It matters for everyone in a university’s supplier chain, us included.
WHY HIGHER EDUCATION SITS IN A HARDER POSITION
Universities have a tougher cyber security job than almost any organisation of equivalent size. That isn’t a criticism, it’s structural.
The estate is huge and old: decades of systems across research, student services, finance, HR, CRM and alumni. Some modern, some legacy. The user base turns over constantly, tens of thousands of students arriving and leaving every year, plus staff, contractors, and visiting academics. IT is federated. Schools and departments often run their own tools and supplier relationships, which is appropriate to how universities work, but the perimeter has a lot of doors.
Openness is part of the mission. Universities are built to share and collaborate. That creates a larger attack surface than a bank or a private business would ever accept.
And then there are the suppliers. Agencies, SaaS platforms, contractors. Each one is a potential route in. I know this because we’re one of them.
The sector has been managing well given the constraints but “Managing well” is a different bar from “ready for a step-change in attacker capability”. That’s the bit needing attention now.
CHANGE IS COMING
A few things are converging at once.
AI-accelerated vulnerability discovery. Mythos is the headline, but it’s part of a wider trend. The skill ceiling for attackers is dropping, and the methods are being turbo charged by new AI tools.
Ransomware groups are organised and patient, and higher education has been a target for years.
Supplier chains are the soft route. Attackers go where controls are weakest, which increasingly means smaller suppliers with lower guardrails but access into bigger institutions.
Insurers are tightening up too. Requirements are becoming more demanding – full MFA coverage, ransomware readiness, third-party control – and premiums are rising.
WHAT YOUR PRIORITIES SHOULD BE
The things that matter most over the next eighteen months are not exotic. The hard part is consistency across thousands of people, hundreds of systems, and dozens of suppliers.

WHAT WE’VE DONE AT EDUCATION CUBED
We are a supplier in the higher education chain, so this isn’t abstract for us. We’ve done the same work we’re describing here, at our scale.
Cyber Essentials Plus is our current baseline, the version with independent technical verification, not self-attestation. Getting there meant working through the unglamorous detail: Microsoft 365 tenant hygiene, legacy accounts and unused licences removed, admin roles tightened, MFA across the board, conditional access, mobile device management, and patch cadences defined and followed. We sunset Windows 10 ahead of end-of-support rather than waiting for the deadline.
We put formal policy behind the behaviours, an Employee Lifecycle IT and Access Policy covering onboarding, in-life reviews and offboarding, and an AI Usage Policy setting out where our team can use AI tools, on what data, and under what governance. When our controls flagged suspicious activity associated with external access, we acted on it and tightened our requirements for anyone touching our systems.
This is maintained through a structured programme with our IT partner Trident. Not an annual scramble.
Cyber Essentials Plus is the floor, not the ceiling. The next layer is governance of the data itself. We are working towards ISO-aligned ways of working, the management system that would sit behind a future ISO 27001 framework. We are not certified today and won’t claim it until we are. The work in front of us is less about tools and more about consistent behaviour from people. That’s always the hard part, and AI can’t help you.
WHY THIS MATTERS TO UNIVERSITY MARKETING TEAMS
Marketing data is some of the most attractive data you hold. Prospective student records, applicant journeys, CRM segments, audience lists. It is regulated, commercially sensitive, and useful to attackers in ways that aren’t always obvious.
Phishing campaigns built on real applicant data are far more convincing than generic ones. Ad account compromises cost real money quickly. Email platform breaches damage trust exactly where trust matters most.
The agencies you work with handle a lot of this. The standard you set for them is part of your security posture, whether IT has formalised it that way or not.
FIVE QUESTIONS TO ASK ANY SUPPLIER, INCLUDING US

Good suppliers will answer these without flinching. The answers don’t all need to be perfect today, it’s much better to acknowledge a gap you’re working to plug than papering over it.
A FINAL NOTE
The Mythos coverage will keep evolving. The underlying point will not. AI is making attackers faster, and defenders need to keep up.
For universities, that means getting honest about where the weak points are: in systems, in suppliers, and in the behaviours connecting them. For suppliers like us, it means doing the unglamorous work and being transparent about where we are.
If you are a marketing, IT or IG lead at a university and want to compare notes, get in touch.

Henry
Senior Operations Manager