Cybersecurity Improvement Initiative comes with benefits for university, colleges and units

The Office of the CIO is steering a university wide effort to improve cybersecurity on all university owned devices. With support from the provost and backing of deans and unit leaders, the Cybersecurity Improvement Initiative has rolled out. First on the agenda is using industry-leading software to understand when there is suspicious activity on university networks that might be the marker of impending cyberattacks.

“The staff who work as the first line of defense against cyberattacks have great tools at their disposal so that we can do more prevention rather than reaction,” noted Sandra Thompson, associate director of cybersecurity program administration in Technology Services. Endpoint management and cybersecurity professionals are collaborating to bring these tools online all over campus. With them we have visibility into the state and nature of the systems on our network, better vulnerability management through prompt updates and robust protection against ransomware, malware and other attacks that can lead to costly and time-consuming data loss. We expect that it will also streamline required auditing,” she said.

CII phase one deploys two separate but interconnected things: endpoint management software and CrowdStrike software. Endpoint management allows IT staff to remotely manage some day-to-day operations needed for your computer’s overall health, such as batching patches or updates to university devices, rather than visiting each individual computer. Once a device has endpoint management installed, CrowdStrike offers threat detection and mitigation.

Think of it like the notification on your home security system. You can sign up to get notice if the camera sees something. Then you can turn on the camera remotely and determine whether what you see is a squirrel or someone stealing a package off your porch. It works with that same concept in mind. Frontline staff-such as your unit IT professional and staff in the Cybersecurity Operations Center-get notified if something is out of the ordinary. They can then investigate whether what is happening is a threat.

There are many ways that cyber criminals try to steal credentials and personal and university data. When the university can head those off, we protect time, resources and the university’s reputation.

IT specialist Damian Behymer with Library IT has been working to deploy both on all library devices. “CrowdStrike uses machine learning and expertise from security researchers to detect when there are signs of cyberattack. It goes beyond anti-virus software; CrowdStrike can notice unusual behaviors and processes on the university network that can be signs of compromise,” they said. 

Both the College of Education and University Library have completed the phase one work, meaning they reached a critical mass of devices with endpoint management and CrowdStrike successfully installed.

Increasingly universities need to be able to show that they are protecting interests and wellbeing of stakeholders with modern security measures. What we have to defend ourselves from is so much more complex than even 10 years ago, Behymer explained. “Cyberattacks-financial or seeking research data-are increasingly common and threatening. To get grants, we need to demonstrate due diligence and that we take common sense measures to protect data and systems with detection and response software installed broadly.”

The risk of a breach or ransomware falls on each unit or college. Individual IT groups take responsibility for doing security well, they added.

The Library has had CrowdStrike installed since it was available, according to director of library technology Tracy Tolliver. “Because of a previous well-known incident at a British library with a ransomware attack, we did not have to try hard to relate the importance of this because they had seen in that example what can happen if we do not try and secure our systems, monitor them and react quickly.”

Completing the first phase meant collaborating closely with individuals they support. Behymer discovered a handful of devices that needed maintenance to repair a connection with CrowdStrike or devices with operating systems so old they could not install CrowdStrike. “In many cases those devices were for very specific tasks. This meant strengthening relationships with experts and what people did with those computers, and finding out how IT can upgrade or replace the computer so they can still do what they need to do,” they added.

Sergio Correa, IT solutions architecture associate, has been the lead IT staff member for CII in the College of Education. He pointed out that installing endpoint management and CrowdStrike has led to having accurate lists of devices. This will be beneficial as campus moves to modern management tools.

“We also refined our departmental policy for supporting old devices. We found devices that did not support Windows 11 or latest macOS. It made us discuss the topic and come to a conclusion that we feel good about,” he said.

And while Correa was the main person managing the cleanup and installation during the large undertaking, he said he was able to communicate with coworkers about the steps involved in endpoint management, which creates a beneficial redundancy of knowledge and skills.

The College of Education and Library now are well positioned to continue to update devices with needed protections. A dozen more colleges and units are currently undertaking this same work, and eventually the entire campus will undergo the process.

“I am happy to see that campus is devoting resources to this and we had the support we need to implement these cybersecurity measures. The process has gone as smoothly as possible, being that we are one of the first two units to go,” Tolliver said.

Privacy Everywhere Conference: Pioneering Human Centered Data Practices in Higher Education

The Privacy Everywhere Conference, held at the University of Illinois Urbana-Champaign, brought together experts to discuss the critical issue of data privacy. The conference explored a human-centered approach to privacy, balancing innovation with privacy rights and ethical data use. Attendees gained valuable insights into privacy principles from legal, ethical, and industry perspectives, equipping them to implement human-centered privacy practices in higher education and beyond.

Conference organizer Sheena Bishop was thrilled with the level of participation and quality of the presentations, which continue to improve year over year.

“Attendance had a bump this year, with more than 580 registered individuals from across the Big Ten and other universities,” Bishop said.

The current landscape of data privacy

Debbie Reynolds, “The Data Diva”, provided an in-depth look at the evolving landscape of data privacy, emphasizing the growing concerns and expectations of individuals regarding their personal data. She highlighted that a significant majority of individuals desire more control over their personal data. According to the World Economic Forum, 74% of people want greater control over their data, while 79% of consumers are concerned about how companies use their information (InfoTrust). Organizations that prioritize privacy see a 20% increase in customer satisfaction, and 75% of students believe they should control how colleges use their data (Cornell University Business).

Reynolds shared real-world examples of successes and failures in data use. Successful initiatives include privacy-preserving data sharing for research, transparent student data use, and robust cloud data cybersecurity practices. On the other hand, failures such as unauthorized data collection, invasive proctoring tools, and insecure data storage highlight the ongoing challenges in maintaining data privacy.

As innovation accelerates, Reynolds stressed the importance of aligning data protection strategies with technological advancements. Key focus areas include clearly defined data purposes, tracking data lineage, managing the data lifecycle, and ensuring accountability in data handling practices. She also discussed the unique privacy challenges faced by universities due to the diverse range of sensitive data they collect, and the multiple stakeholders involved.

Reynolds emphasized that prioritizing privacy builds trust, effective data strategies go beyond compliance, ethics should guide data use, and privacy is integral to human safety.

Avoiding the creepiness factor with human-centered privacy

Rachel Switzky, Director of the Siebel Center for Design, explored the fine line between convenience and creepiness in technology and how human-centered design can foster trust.

Switzky began with a game called “Convenient or Creepy?” She presented scenarios such as a phone knowing your exact coordinates, a voice-activated assistant promoting pizza companies after overhearing a conversation and using your palm to pay for groceries. These examples highlighted the delicate balance between helpfulness and invasiveness in modern technology.

She emphasized that crossing the line into a creepy experience often stems from a lack of transparency and control. Switzky outlined the characteristics of a human-centered experience, which empowers users with control over their data, ensures transparency, collects only necessary data, prioritizes ethical practices and maintains strong security.

She detailed the human-centered design process, which involves understanding, synthesizing, ideating, prototyping, and implementing. A case study on the development of the University of Illinois’ first student app demonstrated the practical application of this approach.

Switzky invited attendees to continue the conversation on designing for trust, underscoring the importance of human-centered design in creating technology that respects privacy and fosters trust.

Educational Technologies and Data Privacy

Easton Kelso, a senior undergraduate researcher at Arizona State University studying Computer Science, shared insights on the intersection of educational technologies and data privacy. Kelso and colleagues’ research revealed that educational technologies, which faculty and staff are often required to use in the classroom, can be at odds with student data privacy.

Their team gathered data from IT professionals, chief information security officers, and university policymakers across the U.S. It became clear that higher education institutions face numerous challenges with data privacy when trying to keep pace with technological advancements. Protecting the data collected by these tools is crucial, as data breaches and misuses can have serious security and privacy consequences, particularly for students, who are often required to use these tools.

Kelso’s team conducted a semi-structured interview study with participants in EdTech leadership roles at seven HEIs. The study uncovered the EdTech acquisition process in the HEI context, the consideration of security and privacy issues throughout that process, the pain points in establishing adequate protections in service contracts, and the struggle to hold vendors accountable due to a lack of visibility into their systems.

In a separate study, the ASU researchers noted gaps in the auditing and approval processes for educational technologies at both the college and K-12 levels. Despite privacy concerns, instructors continued to use unsanctioned technologies due to ease of use, cost, and accessibility.

More research into educational technology use and acquisition will help uncover ways to better align the needs of instructors, students, and institutions when looking at data through a privacy lens.

As privacy concerns continue to grow, the insights shared at this conference will be key to shaping the future of data privacy in higher education and beyond, noted Bishop.

“I look forward to using what I learned at this year’s event and am especially excited that we had such a wide range of individuals who want to make privacy considerations part of their work as well.”

Members of the university community can look forward to the next Privacy Everywhere conference from the Office of the CIO in January 2026.

Privacy & Cybersecurity
Digital Computer Lab
1304 W. Springfield Ave.
Urbana, IL 61801
Email: securitysupport@illinois.edu
Log In