Cyber Risk in Higher Education

Learn where third-party exposure creates blind spots for higher education and what Resilience’s claims data reveals.

3 Min Read

What claims data reveals about cyber risk in higher education

Third-party risk is emerging as higher education’s biggest cybersecurity blind spot. Colleges and universities see roughly 50% more vendor and third-party claims than the rest of Resilience’s portfolio, the cost of sharing clearinghouses, EdTech platforms, and service providers with hundreds of other institutions.

This spring’s Canvas breach affected roughly half of the higher education institutions in Resilience’s portfolio, and the 2023 MOVEit breach reached nearly 900 colleges through vendors’ vendors. Both are findings from Resilience’s new Higher Education Cyber Risk Report.

Si West of Resilience moderates a panel with Hunter Maskill of INSUREtrust Group at CRC Group and Chuck Norton of Resilience on the report’s findings and where third-party exposure creates blind spots in institutions’ security posture.

About Speakers

Unique in the wholesale space, Hunter has spent much of his days in claims advocacy as well as brokering deals, allowing him to learn from the nuances of a claim and then apply that knowledge to best in class cyber and professional liability placements.

Before INSUREtrust, Hunter spent 13 years at AIG, working as a claims adjuster and underwriter before becoming a Regional Underwriting Manager overseeing the cyber and professional liability team. He holds a Business Management degree, with Honors, from the University of Georgia’s Terry College of Business

Throughout his career, Norton has leveraged extensive experience in systems architecture and policy development to partner with stakeholders and build resilient security programs.

Prior to his current role at Resilience, Norton held security leadership positions at Western Michigan University and across various local government organizations. He holds an MBA from Western Governors University, a B.S. from Western Michigan University, and CISSP certification.

He partners directly with risk-focused CISOs to enable better decision-making while assisting brokers in mitigating client exposure. Si’s track record includes building out international security & risk services teams, advising on global underwriting teams, and developing critical incident response frameworks for large-scale, complex books of business. His credentials include 14 years of service in the Royal Marines, an NCSC Assured Instructor status, and an MSc in Cyber Security and Human Factors.

Any company that sells hardware or software with network connectivity into an EU member state has to report vulnerabilities and incidents affecting that product. The regulation calls these products with digital elements, and it applies to the manufacturer regardless of where the manufacturer is based, so a US firm with no EU presence is covered from the moment its first unit ships into the single market.