Prevention

An educational summary of how published guidance suggests campuses can reduce attack surface, raise the cost of intrusion, and detect intrusions earlier. Most successful response begins with good prevention.

Educational summary of public guidance

The recommendations on this page paraphrase publicly available guidance from sources such as CISA #StopRansomware, NIST SP 800-61r3, and EDUCAUSE. They are not professional advice and not a substitute for your institution’s plan, contracts, insurance terms, or applicable law.

Prepare

Reduce attack surface, raise the cost of a successful intrusion, and rehearse the response.

Detect

Catch ransomware activity early — before encryption, ideally during initial access.

Early-warning signals to watch

Three columns of early-warning indicators — Identity, Endpoint, and People — with the rule: two or more signals at once should be treated as a likely incident and investigated immediately.
Pre-encryption tells. Diagram CC BY 4.0.

Most ransomware intrusions show identity, endpoint, and human-reported signals before encryption begins. Watch for combinations rather than single events.

Top prevention controls for higher ed

  1. Phishing-resistant MFA on privileged accounts; MFA campus-wide. Per CISA, only FIDO/WebAuthn and PKI reliably resist phishing.
  2. Immutable, tested backups for tier-1 systems, restored end-to-end at least quarterly.
  3. Network segmentation separating research, administrative, student, and IoT/lab environments.
  4. Hardened remote access: disable internet-exposed RDP; place VPNs behind MFA and conditional access.
  5. Asset and SaaS inventory with monitored exposure to high-impact CVEs — recent higher-ed breaches have been driven heavily by exploited third-party software.
  6. EDR everywhere with documented response playbooks.
  7. Continuous identity hunting: impossible travel, MFA fatigue, OAuth grants, mailbox rules.
  8. Phishing simulations and short, frequent training; reward reporting.
  9. Annual tabletop exercises across IT, leadership, communications, and legal.

Find your role’s prevention steps