With escalating cyber threats and complex third-party vendor risks, universities face unprecedented security challenges. Chris Polkinghorne, Head of Security and Compliance at TechnologyOne, outlines how adopting collective assurance programs can transform isolated vulnerabilities into shared, sector-wide resilience.

Higher education campuses are fascinating places. I was lucky enough to spend some time at a large campus in Brisbane working inside a security architecture team. It struck me that once you head in through the gates, it’s essentially a small city unto itself.
With tens of thousands of students, faculty, researchers, and support staff, the user groups on these campuses are massive. I see these environments regularly through our work with around 60% of higher education providers in Australia and New Zealand, and over 150 different institutions globally.

These aren’t static environments, as they have a huge user churn rate from students onboarding and graduating, industry and government partnerships, and research collaborations with other institutions. This makes them a tasty target for every type of attacker, from smaller cybercrime syndicates all the way up to nation states. In 2025, there were 81 notifiable data breaches in the education sector, making it the fifth most targeted sector in Australia.

In my view, securing these high value environments demands a shared approach to resiliency. No one institution will develop a perfect security posture on their own. In the same way the higher education sector collaborates on agreed standards for qualifications, I believe the standards for cyber resilience in higher education should be built collectively.

Mapping the hidden risks in every campus

Higher education campuses also carry every level of cyber risk. Sensitive research can fall under the SOCI Act, putting universities under critical infrastructure obligations. At the same time, researchers want to be uninhibited to do their work, which requires a degree of adaptation from security teams. Then you have the massive amounts of sensitive student data that attackers will always be looking to steal.

All of this is federated across faculties, schools, and research facilities, so it’s impossible to pull 100% of security decisions through a central security team. What many institutions end up with is a set of best practices for pragmatically managing complexity and lowering risk, rather than a single enforceable standard.

The management of third-party vendors has become a central pillar of these conversations. We’ve increasingly seen the Australian Government ramping up pressure on all organisations to focus on third party vendors involved in their software stack. This is being driven by the sheer number of notifiable breaches that are being traced to “up-the-river” attackers who’ve found a vulnerability in a third-party vendor’s code.

Your students and staff don't see the chain of vendors that leads to their digital interactions. They only see you. If something goes wrong anywhere in that chain, you own the consequences.

Over the years, every campus has collected a hodgepodge of legacy software systems. Some were built for a project that took place two decades ago, but the people involved have moved on. Now, no one knows what’s actually being stored or even how to log in, yet these could be the exact vector an attacker uses to find their way in.

We’re also seeing frontier AI models bringing down the time and cost required to find these forgotten vulnerabilities and chain together exploits. Because of this, it’s simply no longer possible to have this type of legacy system that’s “out of sight, out of mind”.

Vendor scrutiny requires more than a questionnaire

To truly understand your technology environment, you need insight into how your software partners have engineered their solutions. And this needs to go beyond the standard questionnaires that every vendor is required to complete.

To build a complete picture of your campus’ risk profile, you need to know who your vendors are working with, and then a step below that, which other third-party vendors they may be working with. These types of integrations and relationships won’t be revealed just by asking someone to complete a form.

Start with your own end-to-end processes instead. Understand how they work and identify the point where they hand off to a provider. If your service provider hands you a trust portal link and a SOC 2 report, that's perfectly okay for a lot of relationships. But if the risk is high, or if they're doing a lot of important things for you, I'd go beyond that.

If you can’t have a face-to-face conversation with your major service providers, you can’t ensure they’re invested in securing your environment. Having worked in the Queensland Government’s cyber security agency, it always amazed me that I couldn’t have an in-person conversation with a single person from a global software vendor with whom we spent hundreds of millions of dollars.

Without these conversations about how their solution is built, organisations are also missing a valuable opportunity to help service providers to improve their solutions. And I’m not just talking about helpdesk tickets and feedback forms. I mean collaborating directly with the vendor on vital patches and updates that make your unique environment more secure, in turn making the industry more secure.

The rising tide of resilience

We know many of our clients are running the same penetration testing regime or sending us a similar questionnaire to complete. Every institution is paying separately for almost identical assurance programs. A shared resilience approach means creating a community where everyone benefits from a diverse range of unique testing and assurance programs.

We think of it like a community sport that you've got to play together while being really open and transparent. That’s a core part of our methodology as a SaaS company. Any one of our customers who has a great idea or wants to see us uplift something can get in touch with us directly.

The net result is that an improvement of our solution doesn’t just benefit one organisation. It doesn’t matter if you’re a small regional TAFE or one of the biggest universities in the country, those upgrades contribute to improved resilience for everyone.
For me, that’s what makes TechnologyOne different. Our clients truly have their hands on the wheel because they can always have a meaningful conversation with us.

We want to see that type of collaboration improve, and we’re open to suggestions on how we can help to build this culture of shared resilience across the sector. Groups like CAUDIT and AHECS have already built much of this foundation, and we want to support that work where we can.

As one small example, we currently run a bug bounty program that could be opened to students. Nothing is concrete yet, but considering some of the great minds currently studying, teaching, and researching in the sector, we couldn’t think of a better group of stakeholders to consult with.

Ultimately, every brain and every idea is valuable. What’s only a minor concern for one institution could be a huge risk for another, and the more of these risks that we uncover as a community, the more resilient and secure the entire sector will be.

The secure SaaS platform you can trust

38% of data breaches in Australia are caused by cyber security incidents.

Our global SaaS ERP solution delivers the highest security and privacy measures, to keep your data safe.

Find out more

Chris Polkinghorne
Head of Security & Compliance • R&D Enterprise Architecture & Governance