IT Brief Australia - Technology news for CIOs & IT decision-makers
Australia
Beyond the campus perimeter: Why university cyber defence hinges on identity security

Beyond the campus perimeter: Why university cyber defence hinges on identity security

Wed, 16th Sep 2026 (Today)
Nam Lam
NAM LAM Group Vice President SailPoint

Universities are built to be open, from collaboration between departments, visiting academics moving between institutions, students shifting between courses and casual work, and researchers sharing data with partners overseas. This openness is the whole point of higher education. It is also, increasingly, the reason universities are becoming one of the more exposed sectors in Australian and New Zealand cyber security.

The Australian Higher Education & Research Sector Threat Report 2026, a joint sector threat report from MON-CSIRT, Monash University's cyber security incident response team, and AUSCERT, backed by the Australasian Higher Education Cybersecurity Service, summed up the challenge when it stated, "the traditional network boundary has effectively collapsed, replaced by a new, more volatile identity battleground".

Cyber incidents in higher education can no longer be treated as isolated IT problems. As the report reveals, "With nearly one in three breaches now originating in the supply chain and 98% of compromised credentials stemming from unmanaged 'bring your own devices', cyber security can no longer be relegated to a technical function; it must be elevated to a fundamental pillar of institutional and national resilience." Cyber attacks interrupt teaching, delay critical research, invite regulatory scrutiny, and cause lasting reputational damage. In almost every serious incident, the common thread is identity, with the report noting "as the traditional network boundary fails, the higher education and research sector must accept that identity is the new perimeter".

Open by design, exposed by default

Unlike a bank or a telco, a university cannot simply lock down access without undermining the reason it exists. Thousands of people join and leave every year. Roles overlap constantly: a PhD candidate becomes a research assistant, a professional staff member returns as a student, a visiting lecturer holds an identity at another institution entirely and needs access for a single semester. Administrators grant access to external collaborators, government partners, contractors, and, increasingly, automated systems and AI tools.

The root cause is structural, not technological. Governance is often spread across faculties, schools, and colleges that each run their own systems, frequently for good reason, such as specialist laboratory equipment or work health and safety requirements, but with the effect that no single team has a clear view of who has access to what. Access is granted centrally and then managed locally, and over time that gap becomes what our industry has started calling access by proxy; nobody is quite sure who owns the decision, so nobody revisits it.

Where identity control actually breaks down

Across the sector, the same patterns show up again and again. Shared logins on laboratory and library systems make misuse almost impossible to trace. Visiting and temporary roles quietly outlive the project or the semester they were created for, because offboarding is manual and inconsistent. Access accumulates over years as one person moves between student, casual staff, researcher, and alumnus, with each transition adding entitlements without removing the ones no longer needed. And now, a fast-growing population of machine and AI identities, many of them ungoverned, sits alongside unsanctioned use of AI tools that staff and students adopt faster than institutions can write policy for.

After an incident, the questions that come up aren't really technical ones. Who had access to the compromised system? Should they have had that access? And can we actually prove it was removed when the project, the contract or the enrolment ended? If an institution can't answer those with confidence, it's carrying regulatory, financial and reputational risk it probably hasn't accounted for.

What good looks like

Flinders University in South Australia is a useful local example of what changes when identity becomes a strategic priority. The university retired a legacy identity warehouse that was costly to maintain and out of step with its cloud-first strategy, replacing it with a platform that now manages more than 25,000 identities across students, staff, and its defence-related research programs. The shift was tested early. When the pandemic forced staff and students off campus almost overnight, the platform let Flinders safely extend remote access to around 28,000 people within a month, without losing day-one access to the systems people needed. 

The university's identity journey reflects a broader shift in how identity should get run. Access is now provisioned and removed automatically against systems of record such as student information and HR platforms, rather than left to manual processes and institutional memory.

From back-office task to boardroom priority

For research-intensive universities, the stakes go further. Institutions with defence-related research partnerships carry additional obligations under Australia's Defence Security Principles Framework, and satisfying those obligations is far harder without modern, robust identity security already in place. That's not something IT can own on its own anymore. Audit and risk committees need to know whether it's on the risk register, whether it's actually improving, and whether the institution could show a regulator or a board that access reflects what someone is entitled to right now.

This does not mean that universities should give up the openness that makes them work. Collaboration, mobility, and shared research are still the point. What has to change is the assumption that access, once granted, can be left alone. The institutions getting ahead of this are treating identity security as core infrastructure rather than paperwork, and that shift is what will decide whether openness stays a strength or turns into the next headline.