You are on page 1of 4

CYBERSECURITY FOR

HIGHER EDUCATION
A Platform Approach
Higher education institutions must balance academic openness with protecting the
­personal information and intellectual property of staff and students. It’s ­another
­balancing act to maintain continuous, high-bandwidth access to resources while
­blocking threats and intrusions that could damage the institution’s reputation.
­ etworks® meets the security needs of higher education institutions by
Palo Alto N
­automatically preventing cyberattacks across cloud, network and endpoint devices
at network speeds as well as keeping sensitive data safe by administering granular
­security policies based on users, applications and content.

Higher Education Security Challenges Agile Security for Modern Higher Education Networks
Keeping pace with new threats in dynamic online environments is an ongoing struggle for
• Maintain student satisfaction with high IT teams. Palo Alto Networks helps higher education face security challenges relating to:
network performance and availability.
• Cloud security: Higher education is investing in modern infrastructure for interconnec-
• Protect against cyberthreats growing in
tivity, flexibility and ease of administration. Whether by employing public cloud infra-
speed, volume and sophistication.
structure, specialized cloud services and/or SaaS applications, education institutions
• Prevent data breaches and the loss need to protect the data in transit while ensuring no threats infiltrate their networks.
of sensitive information, including
financial transactions, personal data • Performance: Many schools are consolidating their data centers while increasing
and intellectual property, resulting from virtualization within them to improve performance and productivity. Security must be
third-party-funded research. flexible enough to meet the demands of swiftly changing virtualized environments and
increasing demands for network bandwidth.
• Support faculty by identifying and
protecting vulnerable departmental • Valuable data: Higher education institutions are prime targets for cybercriminals
servers and devices. seeking monetary gain from the theft of cutting-edge research, intellectual property,
• Manage disjointed, distributed network payment data, and student and faculty information.
and endpoint security.
• Appropriate access for all: With students, visitors, faculty, administration, vendors,
equipment managers and research partners on the network, giving the right people
­access to the right resources – without compromising security – is an ongoing challenge.
• Mobile and “smart” device access: With everything from student smartphones to
campus security cameras connecting to the network, IT teams need visibility into who
is using these devices or what users are doing with them.
• Distributed environments: Different departments maintain servers, desktops and other
network-connected equipment with varying levels of host protection. Faculty often use
tablets or notebooks that need to be protected wherever they travel. IT must protect
faculty and staff devices from clickjacking and other schemes that can take over users’
systems or steal identities and login credentials.

Palo Alto Networks | Cybersecurity for Higher Education | Brief 1


Secure High-Performance Education Networks With a ­Platform • Prevent threats from spreading in the data center using
Approach east-west segmentation in virtualized public or private
The Palo Alto Networks Security Operating Platform helps edu- environments.
cational institutions deploy new technologies, including cloud, IoT, • Give administrators valuable insight through near-real-time,
online course delivery and virtualization, without compromising easily understandable reports to help them prevent security
security or performance. The platform automatically prevents incidents.
cyberattacks and reduces risk through real-time visibility and
consistent security across a school’s cloud, network, endpoint
devices and content. “Palo Alto Networks allows us to significantly increase
Higher education institutions around the world use Palo Alto bandwidth, deliver more services faster and elevate
Networks to: ­security. The visibility, scalability and dynamic threat
prevention of Palo Alto Networks makes us confident that
• Prevent the spread of malware and protect critical information
with network segmentation. we can fully protect and support our academic mission.”

• Gain granular visibility into network usage. – Simon Lane,


senior professional specialist,
• Automatically prevent known and unknown threats from Enterprise Systems Development,
impacting students, staff, networks and data. University of Southampton
• Protect school-owned devices.
• Simplify and secure BYOD and mobility. Gain Granular Visibility Into Network Usage
• Safely enable cloud use and SaaS applications. Schools can maintain academic freedom while simultaneously
reducing security risks that would affect campus networks and
users. The Palo Alto Networks platform offers granular visibility
“We need to create an environment that’s open and flexible into users and applications, allowing higher education institu-
but super secure. The reason why we moved off our old tions to monitor usage, reduce risk, and maintain high availability
firewall to the Palo Alto Networks platform is because it’s and performance.
next-generation, it’s scalable, and it reduces complexity. We • Employ User-ID™ technology to create role-based
also needed someone who’s looking down the road to see ­permission policies, ensuring everyone has access to the
not only how to deal with current technology and security network r­ esources they need while denying access to
issues but how to handle a future with things like wearables ­systems they don’t.
and other technologies no one has even thought of yet. • Identify thousands of applications traversing the network,
including applications that may pose a risk to the institution’s
– Larry Brandolph, chief information security officer, network or reputation.
Temple University • Monitor application use by group, time of day or other criteria
to ensure critical applications have the bandwidth they need
and IT has up-to-date information for capacity planning.
Prevent the Spread of Malware and Protect Critical ­Information
With Network Segmentation Automatically Prevent Known and Unknown Threats From
Simple-to-manage yet granular network segmentation is key to ­Impacting Students, Staff, Networks and Data
preventing the spread of cyberthreats while serving the diverse Protecting the network, and thereby users and their devices, from
needs of faculty, staff, students and other valid network users. threats constitutes a competitive advantage for many institutions.
Palo Alto Networks platform appliances, whether stand-alone Faculty and students, whether using school-owned devices or
or virtualized, enable campuses to segment networks to reduce their own laptops and smartphones, may unwittingly or deliber-
the chances of threats moving through the network and provide ately put the network or the institution’s reputation
another level of access control to sensitive data or applications. at risk. With new pieces of malware created every minute,
Using Palo Alto Networks next-generation firewalls, you can: higher education IT teams must constantly update the security
posture to remain effective. Palo Alto Networks automatically
• Make use of user information from a wide range of
protects the network from threats with coordinated anti-malware,
­repositories, enabling IT teams to identify users and
IPS, web content filtering and zero-day attack prevention. Palo
groups, not just IP addresses.
Alto Networks threat analysis service conducts dynamic analysis
• Grant or deny user access to network segments hosting of suspicious content – even if it is encrypted – in a virtual
certain applications or servers, providing another layer of environment to discover brand new threats anywhere in the
security beyond usernames and passwords. world. It then triggers the creation of new protections, which are
delivered to all platform sensors in as few as five minutes. Security
• Protect vulnerable systems – such as faculty computers
Operating Platform deployments are continuously updated with
involved in sensitive research, unpatched servers or facilities
protections against new phishing and malware sites, ransomware,
management systems – in their own network segment while
malicious links in emails, and command-and-control infrastructure,
continuously scanning for data exfiltration.
blocking any part of an attack. This automation vastly reduces the

Palo Alto Networks | Cybersecurity for Higher Education | Brief 2


Figure 1: Palo Alto Networks Security Operating Platform

Security Operating Platform • Cloud-delivered security services employ global intel-


The Security Operating Platform prevents successful cyberat- ligence to filter content as well as detect threats and
tacks through automation. It is easy to operate, with capabilities attackers. These services automatically create protections
that work together so you can make the most of scarce cyber- against new threats and attacks as well as continuously
security resources. Enforcement points and shared intelligence update endpoint, network and cloud sensors.
work together at network speed to automatically prevent Palo Alto Networks has recently opened up the platform,
ever-changing cyberthreats from affecting students, computers, enabling you to swiftly take advantage of security innovations
networks or data. Accurate analytics allow you to streamline that meet the particular needs of higher education.
routine tasks and focus on educational priorities. Tight integra-
tion across the platform and with ecosystem partners delivers • Application Framework enables rapid development of
consistent security across cloud, network and mobile devices. custom and third-party applications that make use of
Among the core elements: data from the Logging Service and other cloud-delivered
security services. 

• Network security employs next-generation firewalls
to protect networked services ranging from schools to • Logging Service provides a secure, cloud-based reposi-
school district perimeters and data centers. Integrated tory
for all application and data logs, collecting data from
network security clients extend security policies and pro- various sources while eliminating the burden of scaling
tections to student and staff laptops and mobile devices and maintaining on-premise compute and storage. 

whether they take them home or to the coffee shop. Palo Alto Networks apps on the Application Framework include:

• Advanced endpoint protection safeguards servers, clients • Magnifier™ Behavioral analytics to help discover anomalous
and mobile devices against the latest vulnerability exploits, and malicious user or application activity inside the network.
­ransomware and other malware delivered via any method,
including email, USB drives or other attached devices, and • AutoFocus™ Contextual threat intelligence service for
other channels. 
 malware analytics and hunting tools for security operations
center teams.
• Cloud security provides the same protections as the net-
work security components for private, public and hybrid For more information on the Palo Alto Networks Security
cloud ­environments as well as SaaS applications. Deep Operating Platform, please visit https://www.paloaltonetworks.
integration with native cloud services and automation com/products/security-operating-platform.
tools speeds up multi-cloud deployments. 


operational burden on IT teams, which would normally have to other malware, credential theft attempts, other exploits, and
manually update multiple security devices across the network to zero-day threats. Staff can use email, other applications, USB drives
block even one part of such attacks. and the web confidently and safely.
Protect School-Owned Devices Simplify and Secure BYOD and Mobility
IT teams must protect school-owned faculty and staff devices from Schools must balance the need for cybersecurity with giving stu-
the latest cyberthreats. Advanced endpoint protection, part of the dents, faculty and their devices speedy access to network resources
Security Operating Platform, coordinates with threat intelligence wherever they are. Unique User-ID technology enables consistent
and pre-emptively blocks known and unknown ransomware and enforcement of security access policies based on who users are,

Palo Alto Networks | Cybersecurity for Higher Education | Brief 3


regardless of campus location, device ownership or which of their Microsoft Office 365®, G Suite™ and Dropbox®. Granular security
devices they are using. For students who bring their own devices, policies help eliminate data exposure and threat risks. For example,
Zero Trust network segmentation – based on the “never trust, you can deny data uploads to personal Box folders and private
always verify” principle – ensures they can access the resources Gmail® addresses while safely enabling collaboration through your
they need while restricting access to sensitive data and applications institution’s Gmail instance and Box environment.
to valid faculty and staff with trusted devices. For faculty and staff
who bring their own devices, a lightweight network security client Increase ROI With Palo Alto Networks Offerings for Higher
works with Enterprise Mobility Management platforms to separate Education
business apps, data and traffic from personal apps on the devices, The biggest question for many IT teams in higher education is
securing business content while respecting privacy. how to maximize user and data protection with minimal network
and security resources. The Security Operating Platform natively
integrates many capabilities, eliminating point products along
“Visibility and throughput is significantly better. Before, we trawled with the cost and management overhead associated with them.
through logs to get information, but now we can see the biggest Platform elements across clouds, networks and endpoints share
risks, where they’re coming from, which apps are being used and security context and work together to automatically prevent quick-
more. The information and detail is fantastic.” ly changing threats from affecting students, endpoints, networks
or data. This platform approach reduces silos of information and
– James Holland, Network and Security Services Manager, manual intervention from overburdened IT teams. Unified visibility,
University of Portsmouth policies, event logging, reporting and analytics across security func-
tions greatly simplify management, ­operations and compliance in
addition to reducing the potential for misconfigurations, outdated
policies or overlooked threats.
Cyberattackers disproportionately target endpoint devices, and Schools may start with one capability and add new ones to the
those devices are more vulnerable outside the campus network. platform over time, growing protection levels without the cost and
The platform’s network security client extends a VPN and granular complexity of managing new network devices. Each security capa-
security to remote faculty, staff and contractors. The lightweight bility automatically correlates insights on newly emerging threats
network security client protects computers, tablets and smart- across endpoints, data centers and cloud resources, ensuring fast
phones wherever they travel, ensuring they maintain the same responses to any threat with no manual intervention required.
security posture and access capabilities as devices inside the As you add security capabilities, coordination increases, and your
network perimeter. organization enjoys even greater return on investment.

Safely Enable Cloud Use and SaaS Applications Getting Started


Palo Alto Networks virtualized platform deployments bring the Start by gaining visibility into the users, applications and content
security of the on-premise network to public and private clouds. in your network. Sign up for a free Security Lifecycle Review. This
Prevent successful cyberattacks on Amazon® Web Services, non-disruptive process will help define top risks due to usage,
­Microsoft® Azure®, and Google® Cloud Platform environments unknown applications, malware and more.
and cloud initiatives on VMware® NSX®, OpenStack®, Microsoft
Hyper-V®, and many other platforms. A suite of tools enables ap- Customers in more than 150 countries and in every industry rely
plication-level control between workloads, policy consistency from on us to improve their cybersecurity posture. For more information
the network to the cloud, fast deployment and dynamic security on Palo Alto Networks, please visit https://www.paloaltonetworks.
policy updates as workloads change. com/company/about-us.

SaaS applications are traditionally invisible to IT. Palo Alto For more information on how we protect higher education
Networks solves this problem by providing full visibility into the networks worldwide, please visit https://www.paloaltonetworks.
day-to-day activities of employees using SaaS applications, such as com/­solutions/industries/education/education-higher.

3000 Tannery Way © 2018 Palo Alto Networks, Inc. Palo Alto Networks is a registered
Santa Clara, CA 95054 trademark of Palo Alto Networks. A list of our trademarks can be found
Main: +1.408.753.4000 at https://www.­paloaltonetworks.com/company/trademarks.html. All other
Sales: +1.866.320.4788 marks mentioned herein may be trademarks of their respective companies.
Support: +1.866.898.9087 cybersecurity-for-higher-­education-sb-050918

www.paloaltonetworks.com

You might also like