With cyberattacks and cyberbreaches being a growing threat for UK universities, Dario Perfettibile shares how institutions can proactively address their vulnerabilities.
UK universities are under siege. The latest Government figures show that 91% of higher education institutions experienced a cyberattack or breach in the past year – more than double the rate for British businesses overall. Universities now face impersonation attacks at twice the rate of commercial organisations, along with substantially higher rates of malware and denial-of-service incidents.
Yet, here’s what is genuinely baffling: while IT departments pour resources into network perimeter defences and sophisticated threat detection, many institutions still collect their most sensitive student data through web forms that haven’t been meaningfully updated in a decade.
Think about what flows through a typical admissions form: academic records, National Insurance numbers, family financial information, mental health disclosures, disability accommodation requests. This is exactly the data that attackers want – and universities are collecting it through platforms designed for general business convenience, rather than regulated educational environments.
4 key challenges universities are facing
1. The compliance gap
A recent analysis of 335 UK universities and higher education colleges found something that should alarm every vice-chancellor: 81% are non-compliant with GDPR standards. Only a third have implemented proper consent management, and even among those with such systems, roughly two-thirds inadequately process visitor data.
The University of Greenwich case from 2018 remains instructive. The Information Commissioner’s Office imposed a £120,000 fine after the university accidentally exposed personal details of 19,500 students (including sensitive information about physical and mental health) through an unsecured microsite. The breach had occurred back in 2004 but went undetected for twelve years. It marked the first time a UK university received a fine under data protection legislation.
That case predated current GDPR enforcement. Today, maximum penalties reach £17.5 million or 4% of annual turnover, whichever is higher. For institutions already facing severe financial pressures – nearly half of UK universities now run deficits – a significant regulatory fine could prove catastrophic.
2. Vulnerabilities from legacy forms
Generic web form platforms weren’t built for the regulatory complexity universities face. They lack the granular access controls needed for what GDPR requires under its accountability principle. When admissions counsellors, financial aid officers, academic advisors and athletics recruiters all access the same intake forms, compliance becomes nearly impossible.
Research shows that 88% of organisations using traditional web forms have suffered security incidents in the past two years, with 44% reporting confirmed data breaches through form submissions. The technical vulnerabilities are well documented. Cross-site scripting affects roughly 39% of organisations, session hijacking incidents occur at 28%, and man-in-the-middle attacks at 21%. Many legacy platforms still rely on outdated encryption standards that no longer meet regulatory requirements.
In my experience, the most dangerous aspect isn’t the external threat. It’s the audit trail problem. Department of Education investigations and ICO inquiries require detailed logs showing who accessed what student information and when. Most form solutions simply don’t capture this data with sufficient granularity. When regulators come asking questions, universities find themselves unable to demonstrate basic compliance.
3. Shadow IT
Departmental autonomy creates its own challenges. The Greenwich breach occurred precisely because a training microsite was developed by one department without the university’s knowledge. As the data controller, the university remained legally responsible for security throughout the institution, yet had no visibility into what individual units were deploying.
This pattern repeats across higher education. While institutions may officially support platforms like JISC Online Surveys or Microsoft Forms, departments routinely opt for whatever seems easiest. Each creates its own compliance exposure. Google Forms, for instance, stores data in Google Drive on US servers by default, raising data sovereignty concerns. The platform provides no built-in mechanism to display privacy policies, meaning every form created without manual intervention represents potential regulatory exposure.
4. Data sovereignty
UK universities enrolled 679,000 international students in 2021/22. Study abroad programmes and research collaborations create additional obligations. Generic form platforms typically cannot guarantee where data resides geographically. For universities competing for international enrolment, this isn’t just a compliance issue, it’s an operational risk that could prevent recruitment and admissions in certain countries altogether.
What actually works
The path forward requires treating form selection as a governance decision. That means involving compliance officers, legal counsel and data protection officers in platform evaluation. Security capabilities, audit trail quality, access control granularity and data residency guarantees should drive decisions – not just ease of use or cost.
Universities handle vast amounts of sensitive data including student educational records, research data and financial information. Infrastructure needs end-to-end encryption using validated cryptography, with field-level protection for individual data elements to ensure data is protected, even if the system is compromised. Role-based access controls must enforce least-privilege principles, limiting each user’s permissions to what their specific responsibilities require. Comprehensive audit trails should capture every data access event automatically. This provides transparency, supports compliance and makes it easier to investigate security incidents.
With universities having thousands of students and faculty accessing systems from various locations and devices, Zero Trust principles matter. Every form submission should require validation regardless of authentication history. System architecture should segment different data types containing potential breaches, rather than allowing them to spread network-wide. Staff should receive minimum necessary access rather than broad permissions that persist indefinitely.
Perhaps most importantly, compliance evidence generation needs automation. Manual documentation creates operational burdens while introducing opportunities for error. The best platforms generate GDPR compliance evidence continuously, maintaining records of consent, documenting legitimate processing purposes and tracking retention and deletion – turning compliance from a periodic audit scramble into an embedded operational process.
These measures work together to create a multi-layered security approach that addresses the specific challenges universities face.
Steps to evaluate and improve security
Assessment and planning
- Conduct a comprehensive data inventory to identify all sensitive information (including student records, research data, financial information).
- Identify security gaps across email, file sharing, collaboration and communication platforms.
- Evaluate third-party vendor relationships and data sharing agreements.
- Review compliance requirements.
Technical implementation
- Implement end-to-end encryption for all sensitive data communications.
- Deploy zero-trust architecture with role-based access controls and least-privilege principles.
- Establish comprehensive audit logging and monitoring across all communication channels.
- Integrate multi-factor authentication (MFA) and single sign-on (SSO) capabilities.
- Implement automated data classification and loss prevention controls.
Governance and training
- Develop and enforce data governance policies aligned with educational compliance requirements.
- Provide regular security awareness training for faculty, staff and students.
- Establish incident response procedures specific to educational environments.
Summary
Universities rightly invest heavily in cybersecurity training, identity management and network protection. But those investments are undermined when the actual point of data collection – the forms where students share their most sensitive information – remains inadequately protected.
Obviously, digital intake security matters, so the question is whether institutions will address this vulnerability proactively or wait until they become the next headline breach, ICO investigation or next group litigation order (GLO).
With 91% of universities already experiencing attacks/breaches and 81% failing on GDPR compliance, the odds aren’t favourable for those who choose to wait.
References
- Department for Science, Innovation & Technology (2025) ‘Cyber security breaches survey 2025: education institutions findings’ Available at: https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2025/cyber-security-breaches-survey-2025-education-institutions-findings (Accessed: 16th January 2026)
- 7DOTS (2025) ‘7DOTS Report: 81% of universities at risk of fines due to failure to safeguard student data’. Available at: https://www.7dots.com/our-insights/81-of-universities-at-risk-of-fines-due-to-failure-to-safeguard-student-data/ (Accessed: 16 January 2026)
- BBC News (2018) ‘Greenwich University fined £120,000 for data breach’. Available at: https://www.bbc.co.uk/news/technology-44197118 (Accessed: 16 January 2026)
- Kiteworks (2025) ‘Data Security and Compliance Risk: 2025 Data Forms Survey Report’. Available at: https://www.kiteworks.com/sites/default/files/resources/data-security-compliance-risk-2025-data-forms-report.pdf (Accessed: 16 January 2026)
- Davies, V. (2023) ‘UK universities at high risk of major cyberattacks’. Available at: https://cybermagazine.com/articles/2-2m-top-100-uk-university-and-research-facility-cre (Accessed: 16 January 2026)


