Cyber security for colleges and universities in BC

Colleges and universities are hard to secure because they are built to be open: tens of thousands of accounts, research groups running their own systems, and IT spread across faculties. What works is strong identity, a hard line between research and administrative systems, FIPPA treated as a design requirement, and incidents rehearsed before they happen.

Why post-secondary is harder to secure than a company

A company can decide who is on its network. A campus cannot. Students bring their own laptops into residence, conference guests need Wi-Fi, and visiting researchers need access to shared systems for a term and then leave.

Identity churns every September. A student becomes a teaching assistant, then a staff member, then an alumnus, sometimes on the same account. Accounts nobody closed are where a phished password goes unnoticed.

IT is devolved. A central team runs email and the student information system, while a single lab runs its own servers on a grant that ends before anyone patches them. Faculty and staff are usually represented by unions or associations, and academic freedom shapes what the institution can restrict. Rules that ignore either get grieved or quietly worked around.

Where a university should start with security

Identity first: multi-factor authentication for staff and faculty, then students. Then keep privileged accounts separate from everyday ones, give guest and visiting accounts an expiry date, and review who holds administrator rights in each faculty at least once a year. The controls are on our identity and workplace security page.

How to separate research from administration

Student records, payroll and finance belong on networks that research systems cannot reach. A compromised lab server should give an intruder that lab, not the registrar. Research data needs its own rules, set per project: who may access it, where it may be stored, and what the funder or data-sharing partner requires. Health data and data about Indigenous communities often carry conditions stricter than the institution’s default. Segmenting by trust level is the idea behind zero trust architecture.

What FIPPA means for a BC college or university

Public colleges and universities in BC are public bodies under FIPPA. Under section 30 the institution must make reasonable security arrangements for personal information in its custody or under its control. Section 36.3 requires notice to affected individuals and the commissioner where a breach could reasonably be expected to cause significant harm.

Private universities and private career colleges are different. They are generally private-sector organizations under BC PIPA, not FIPPA, so the FIPPA duties on this page do not describe them; the Canadian privacy law map sets out which Act applies to which kind of organization.

Section 69 requires the head of the institution to conduct privacy impact assessments in line with the minister’s directions. For a new system, the PIA is the natural place to record security decisions; see FIPPA, PIAs and ISAs. We are not lawyers; we work alongside your privacy office and counsel.

Incident readiness on a campus

The hard decisions in a campus incident are rarely technical: who may take the learning platform offline during final exams, who tells students their records were exposed, who speaks to the faculty association. Settle them in a tabletop exercise with the registrar, communications and the privacy office in the room, then write the answers into the incident response plan.

How to assess edtech vendor risk

Campuses run on third-party software: the learning platform and its plugins, proctoring tools, library systems, and apps an instructor signed up for with a departmental card. Each may hold student personal information, so the review should scale with the access each one has. A vendor risk programme keeps that proportionate, and our note on what BC public bodies ask of vendors shows the same process from the supplier’s side.

Security policy, unions and academic freedom

Monitoring and acceptable-use rules are where campus security most often meets a grievance. Consult early and write each rule around a specific risk; see security policy in a unionised workplace.

Questions we are asked

Are BC colleges and universities covered by FIPPA?

Public ones are. Public colleges and universities in British Columbia are public bodies under FIPPA, so the duties to protect personal information, report serious breaches and assess new systems for privacy apply to them directly. Private universities and private career colleges are generally under BC PIPA instead.

Where should a university start with security?

Start with identity: multi-factor authentication for staff and faculty first, then students, and a reliable process for closing accounts when people leave. A stolen password on a forgotten account is one of the easiest ways into a campus.

Can a university monitor faculty email and devices?

Sometimes. Monitoring holds up when it is tied to a stated purpose, proportionate, and known to the people affected, and on a campus it also has to be squared with collective agreements and academic freedom before it launches. Your counsel decides where the legal line sits.

Do edtech vendors need a security review?

Yes, and the review should scale with access. A plugin that reads course content needs a short check; a vendor with administrator access to your student information system needs a full one before the contract is signed.

Nothing here is legal advice. Your privacy office and counsel decide how FIPPA applies to your institution.

Planning security for a campus

Tell us which systems worry you most. We will reply with where we would start and which specialists the work needs. More articles are on the writing index.

Discuss a scope