Colleges & universities
What a campus has to protect
A campus runs a clinic, a financial aid office, student housing, and a research operation, and each one answers to different rules. We take on the parts your security team does not have the hours for, and we report to the people who have to sign.
GLBA Safeguards, owned by someone
Title IV institutions have to designate a Qualified Individual, keep a written risk assessment current, and report to the board every year. Our vCISO serves as the Qualified Individual and owns that calendar, including the report your auditors look for.
Research data and the grant clause
Federal awards increasingly carry NIST SP 800-171 language, and DoD work brings CMMC. We scope the research enclave with the PI and the research office, then write the system security plan before the sponsor asks for it.
Vendors, HECVATs, and the queue
Every department buys software, and every purchase arrives with a HECVAT to review. We take the inbound assessments off your desk, maintain the vendor risk register, and turn the one-off reviews around in days instead of weeks.
The lines between FERPA and HIPAA
Student health and counseling records sit on the boundary between the two laws, and the answer changes by office. We map which records fall under which rule and write policy the registrar, the clinic, and the counseling center can all follow.
Decentralized by design
Academic units run their own systems and hire their own vendors, and central IT finds out later. We build governance that fits that reality: a standard baseline, and a practical way for units to meet it.
Monitoring with analysts behind it
Round-the-clock detection across endpoints, identity, and cloud, with people reviewing what the tooling raises. For a two-person security office, it means someone is reading the overnight alerts and calling you when one matters.