- Advertisement -

Higher ed’s next crisis won’t start in the classroom. It will start in the cloud

Date:

Share post:

Dr. James L. Norrie
Dr. James L. Norrie
Dr. James L. Norrie is a professor of law and cybersecurity and founding dean of the Graham School of Business at York College of Pennsylvania. He is a frequent media commentator, speaker and consultant to industry and the author of Beyond the Code: AI’s Promise, Peril, and Possibility for Humanity (Kendall Hunt, 2025). Contact: [email protected].

Higher education has spent years worrying about enrollment cliffs, declining public trust, political polarization, and, as we enter the AI era, the commoditization of knowledge and the future value of degrees.

Those concerns are real and deserve attention. But another crisis is quietly forming beneath the surface of nearly every college and university, and unlike many institutional challenges, this one may arrive globally and all at once, in a wave of distrust and disruption.

This month’s breach involving the Canvas learning management platform was a stark warning. The immediate discussion focused on familiar questions: Who was responsible?

Was the institution or the software vendor liable? Could FERPA violations emerge if protected student information had been exposed? Even institutions not directly impacted by the incident should pay attention because the uncomfortable answer to many of those questions is some version of “yes.”

Educational institutions cannot outsource their legal and ethical obligations simply because student data resides inside third-party cloud infrastructure. Under FERPA and related privacy obligations, institutions remain responsible for oversight and governance of educational records, even when those systems are operated by outside vendors.

If sensitive information is compromised, scrutiny extends both to the software provider and to the institution itself, potentially creating shared legal liability.

But the larger significance of compromising Canvas extends beyond one vendor or one incident. It exposed a dangerous assumption that has shaped higher education technology strategy for years: the belief that outsourcing infrastructure somehow outsourced accountability.

It did not. And now the time has come for higher education to confront its digital deferred maintenance.

Campuses in ‘technical debt’

Most trustees intuitively understand the risks of delaying building repairs. Roofs leak, boilers fail, and buildings slowly become unsafe. Deferred maintenance compounds quietly until one day the issue is no longer manageable, but structural and unavoidable.

Eventually, if neglect continues, buildings are condemned and demolished. The same thing happens with digital infrastructure, except the damage usually remains invisible until the moment of complete IT failure. We are now approaching that cusp.

For years, many colleges and universities treated IT largely as an operational necessity rather than a strategic institutional investment. Systems were patched incrementally, new applications layered onto aging architecture, and departments adopted disconnected software tools with little enterprise coordination.

Legacy systems remained in place because replacing them was expensive, disruptive, and difficult to prioritize against other institutional pressures.

Over time, this creates what CIOs call “technical debt.” In practical terms, technical debt accumulates when organizations repeatedly prioritize short-term convenience over long-term sustainability.

Like an aging academic building cosmetically renovated floor by floor without replacing the plumbing, wiring, or foundation beneath it, the structure continues functioning even as fragility quietly accumulates behind newly painted walls. That is where many institutions now find themselves digitally.

As a risk-averse sector, institutions often judged vendors by the extent of their higher education penetration, meaning a few brave institutions selected the “winners” and the rest of us followed.

The result was a vast swath of universal, standardized, and largely outsourced EdTech infrastructure posing as a strategic IT ecosystem.

Beneath the interfaces faculty, staff, and students use every day sits an aging ecosystem of inherited permissions, unsupported dependencies, fragmented systems, undocumented workflows, legacy integrations, and software code evolved across decades of updates and version releases.

Some institutional environments now resemble archaeological layers of technological history, where newer cloud platforms rest atop older assumptions about security, identity, trust, and governance.

Historically, institutions survived this complexity because discovering vulnerabilities required significant human expertise, time, and effort. Defenders at least possessed a window of time to identify and patch weaknesses before attacks scaled beyond manageable levels. It was a constant see-saw cyberbattle between human attackers and defenders.

That assumption is swiftly collapsing. Emerging AI platforms such as Mythos signal a profound shift in the cybersecurity threat landscape.

Reportedly, these advanced systems are capable of identifying software vulnerabilities at a scale and speed that dramatically exceeds traditional human capability. After an initial controlled release only to approved entities, Mythos initially generated more than 10,000 previously unknown vulnerabilities across many common software applications (Patch window is officially dead as AI finds bugs faster than humans can squash them | TechRadar).

Cybersecurity is not a narrow IT issue

In future terms, finding hidden weaknesses buried deep inside aging digital systems will increasingly become routine and weaponized at higher scale and lower cost. Relentless AI-enabled attackers will become more effective and current defensive methods will fail to keep pace.

The new bottleneck will become whether organizations can modernize, govern, patch, and defend systems using new AI-enabled tools and methods fast enough to even matter.

That distinction should deeply concern governing boards and institutional leadership because the next era of cyber risk is no longer fundamentally a technology problem. It is increasingly becoming a governance, fiduciary oversight, and institutional sustainability problem.

This is not a criticism of institutional technology leaders. Many have quietly understood these risks for years while operating within constrained budgets, fragmented governance structures, competing institutional priorities, and growing operational complexity.

The problem is not that higher education ignored cybersecurity entirely. The problem is that the sector, like most others, underestimated how quickly AI would accelerate the threat environment while already lacking the financial capacity to modernize aging digital infrastructure.

Unlike physical deferred maintenance, however, digital fragility can scale globally and simultaneously. Normally, technical debt creates localized institutional weakness where an IT problem remains largely confined to one campus.

But cloud concentration changes the equation entirely. As we have now seen, one compromised provider can simultaneously expose thousands of institutions to operational disruption, reputational harm, and legal scrutiny inside shared infrastructure ecosystems.

That is why boards should stop viewing cybersecurity as a narrow IT issue delegated quietly to the CIO or CISO while leadership returns to its “real business.” The operational disruption, legal exposure, reputational consequences, and governance scrutiny following major breaches extend directly into the president’s office and the boardroom itself, making cybersecurity and AI everyone’s business now.

This raises a much larger question. The issue is no longer simply whether colleges and universities are technologically capable or technically compliant. It is whether they are institutionally prepared across all facets of their operations for what comes next.

Related Articles