Site navigation

Top UK Universities Failing to Implement Strong Email Security

Michael Behr

,

UK university email security
With email presenting a major vector for cyber-attacks, inadequate protections create an opening for hackers to access sensitive data.

Top universities in the UK, the US and Australia are putting their students and staff at risk by failing to implement high standards of email security.

Domain-based message authentication, reporting and conformance (DMARC) is a protocol that verifies whether an email is impersonating its source. Implementing it helps to minimise false positives, reduce successful phishing attacks, and tackle the volume of fraudulent emails.

There are three levels of protection under DMARC – monitor, quarantine and reject, with reject being the most secure for preventing suspicious emails from reaching the inbox.

According to a new report from cybersecurity researchers Proofpoint, all the UK’s top ten universities have not implemented the reject level of standards to protect themselves against email-based cyber-attacks.

A total of 65% of the highest ranking US and UK universities had implemented the base level of DMARC protection (Monitor and Quarantine) for their email security.

Including the US and Australia, the company said that 97% of the countries’ top universities had failed to bring in adequate security controls.

Proofpoint previously warned in September 2021 that 85% of the UK’s highest ranking universities lacked adequate protections against email fraud.

When it released its last report, the company marked a 100% rise in the number of top universities publishing a DMARC report since 2019. However, it also noted that six universities had still not provided a report.

Proofpoint EVP of Cybersecurity Strategy Ryan Kalember said: “Higher education institutions hold masses of sensitive personal and financial data, perhaps more so than any industry outside healthcare.

“This, unfortunately, makes these institutions a highly attractive target for cyber criminals. The pandemic and rapid shift to remote learning has further heightened the cybersecurity challenges for tertiary education institutions and opened them up to significant risks from malicious email-based cyber-attacks, such as phishing.


Recommended


“Notably, Proofpoint’s recent Voice of the CISO report found Chief Information Security Officers (CISOs) in the education sector felt the least backed by their organisation. In line with these findings, the World Economic Forum reports that 95% of cybersecurity issues are traced to human error, highlighting that many CISOs still significantly underestimate the risk posed by users. With this, only 47% of education sector CISOs believe users to be their most significant risk.”

He added: “Email remains the most common vector for security compromises across all industries. In recent years, the frequency, sophistication, and cost of cyber-attacks against universities has increased. It’s the combination of these factors that make it especially concerning that the premier universities in the U.S. are currently the most vulnerable to attack.”


Get the latest news from DIGIT direct to your inbox

Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.

To subscribe, click here.

Michael Behr

Senior Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data