The University Is the Target
Research IP from DoD grants. Student PII across entire enrollment histories. Financial aid data including SSNs and tax records. PHI from medical schools. 1,000+ U.S. higher education institutions were hit in 2024. FERPA, GLBA Safeguards Rule, HIPAA, CMMC L2, TX SB 820, PCI DSS, and Texas DIR controls — eight compliance frameworks converge on a single attack surface.
Download the Full Threat Brief
Get the complete 2026 Higher Education Cyber Threat Brief — 35 verified sources, 8-framework compliance crosswalk, 12-item action checklist. Delivered to your inbox.
Executive Summary
The highest-value, lowest-defended data portfolio in Texas
Texas universities and community colleges hold research intellectual property from DoD grants worth millions, student PII across entire enrollment histories, financial aid data including SSNs and tax records, and PHI from medical and nursing schools. They operate this on networks built for open academic collaboration — not security. TTUHSC lost 1.4 million patient records to Interlock ransomware in 2024. Columbia University disclosed 870,000 records compromised in May 2025. The education sector's average breach cost reached $3.80 million in 2025.
Threat Landscape — 2024–2026 Incidents
10 documented incidents and campaigns affecting Texas higher education
BEC attacks on Texas universities: $3.05 billion in total BEC losses (FBI IC3 2025). Universities are high-value targets — tuition refunds, vendor payments, construction invoices, alumni donations. Athletics departments, construction projects, and alumni relations offices are the highest-risk units. Southern Oregon University lost $1.9M to a single BEC attack in 2024.
FAFSA ghost student fraud: Fraud rings using AI-generated synthetic identities to create fake enrollments and collect federal Pell Grants. California community colleges reported 31–34% fraudulent applications in 2025. Federal government has prevented over $1 billion in student aid fraud since January 2025. Community colleges with open enrollment are primary targets.
Regulatory Stack — 8 Compliance Frameworks
FERPA + GLBA Safeguards + HIPAA + CMMC L2 + TX DIR + TX SB 820 + TX HB 300 + PCI DSS
| Framework | Scope | Key Penalty | Status |
|---|---|---|---|
| FERPA | All institutions receiving federal education funding | Loss of all federal funding | Active |
| GLBA Safeguards (2023) | Financial aid offices at any institution in federal student loan programs | $50,120/violation/day | Enforced |
| CMMC Level 2 | Research departments with DoD CUI | Contract termination | Nov 2026 |
| HIPAA Security Rule | Medical/dental/nursing schools, teaching hospitals, student health | $1.5M/category/year | Active |
| TX DIR / TAC 202 | All TX public universities and higher-ed institutions | DIR enforcement | Active |
| TX SB 820 | Any breach of TX resident PII | $100/day/resident + AG action | Active |
| TX HB 300 | Health data — stricter than federal HIPAA | $1.5M/year/category | Active |
| PCI DSS v4.0.1 | Tuition payments, bookstore POS, housing deposits, campus cards | $5K–$100K/month | Mandatory |
Primary Attack Vectors
The 207-Day Problem — Applied to Higher Education
Every day of undetected access compounds the damage exponentially
Research data exfiltration: A nation-state actor entering a university research network in September has access through the entire academic year. VOLT TYPHOON-style actors use slow-burn persistence — by detection, the attacker has exfiltrated years of CUI research data from DoD grants.
FERPA funding loss risk: OCR investigations triggered by FERPA breaches take 12–24 months and can result in loss of all federal funding. For a mid-size Texas university, that is $50M+ in annual Title IV aid exposure.
Compliance Cost Math
What a breach actually costs a Texas university
| Exposure Category | Estimated Impact |
|---|---|
| GLBA Safeguards violations | $500K–$2M in combined penalties, remediation, and funding risk. Title IV funding disabled by DE Cybersecurity Team. |
| FERPA funding loss (20K students) | $50M+ annual Title IV aid at risk. $500K–$2M OCR investigation costs. 3–5 year corrective action plan. |
| CMMC contract loss ($15M DoD awards) | $5M–$20M/year at risk. $50K–$150K C3PAO assessment. $200K–$800K POA&M remediation per department. |
| HIPAA OCR settlement | Average $1.9M university settlement. TX HB 300 adds $1.5M/year/category. Notification costs $390K average. |
| Combined TX university breach | $8M–$15M for FERPA+GLBA+HIPAA. With research loss: $20M+ total impact. |
The CoreRecon Approach
The only security posture designed for the higher education attack surface
Pricing: $89–$129/endpoint/month. No enterprise contracts. No six-figure minimums. No RFP required for initial engagement.
30/60/90 Day Action Checklist
12 items. Start today.
- Days 1–30: Identify every system handling FERPA, GLBA, HIPAA, and CUI data. Document your data inventory — first requirement under GLBA Safeguards Rule.
- Days 1–30: Confirm your SPRS score. If negative with active DoD awards, contact Sponsored Programs immediately — you are already non-compliant with DFARS 7012.
- Days 1–30: Audit MFA on SIS (Banner/Workday/PeopleSoft), financial aid, VPN, and email. Deploy MFA on all before Day 30.
- Days 1–30: Verify 24/7 monitoring on network perimeter and research enclaves. If SOC coverage ends at 5pm — confirmed gap.
- Days 1–30: Review incident response plan for SIS ransomware scenario. When was it last tested? Who is the first call?
- Days 31–60: Conduct annual GLBA Safeguards Rule risk assessment. If none since June 2023, you are already in violation.
- Days 31–60: Designate or confirm GLBA Qualified Individual. If held by IT director with no dedicated security focus — immediate regulatory gap.
- Days 31–60: Tabletop exercise: registrar, financial aid, sponsored programs, legal, communications, president's office. Document the response timeline.
- Days 31–60: Segment research enclaves handling DoD CUI from general university networks. NIST 800-171 Control 3.13.5.
- Days 31–60: Vendor risk assessment on top 5 third-party systems. GLBA §314.4(f)(3) makes you responsible for vendor security.
- Days 61–90: Complete SPRS self-assessment for all research departments handling CUI. Build POA&M for any scoring below 110.
- Days 61–90: Initiate CMMC Level 2 gap analysis. November 2026 C3PAO deadline means formal gap analysis needed by Q3 2026.
Protect Your Institution's Data
30-minute security posture assessment for Texas universities and community colleges. We identify your FERPA, GLBA, HIPAA, and CMMC exposure — the gaps between your current protection and what a breach-ready defense looks like. No obligation.