ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Academia and the cyber security challenge

As the number of cyber security threats continues to rise, Stuart Jubb at Crossword Cybersecurity explores the role academia has to play in a defence strategy of cross-sector collaboration.

 

There’s a perfect storm facing the world of cyber security. Escalating cyber-attacks and rapid technological innovation leave companies stretched thin, trying to defend themselves against threats using existing technology, while simultaneously having to understand and secure new tools and services.

 

Even with enhanced cyber security tools at their disposal, organisations and indeed nations are more exposed than ever.

 

Threat actors are organised and determined, so cyber security teams must match them to defend against them. Hackers collaborate, so organisations must too. Yet, at present this is happening only to a limited extent.

 

Today, collaboration happens only informally, according to chief information security officers (CISOs) with whom we speak. A strategy of increased and better collaboration – across businesses, governments and the academic world – is vital to a more cyber secure future.

 

So why is collaboration so hard to achieve?

CISOs have endured repeat crises over the past few years, such as the Colonial Pipeline attack, the JBS attack, SolarWinds and more. Even when it isn’t a cyber security incident, there is often a cyber security angle.

 

The rapid shift to remote working during the Covid-19 pandemic was a huge cyber security challenge and the war in Ukraine has put lots of organisations on cyber-attack alert. Current threats are so numerous and so fast-moving that executives just don’t have time to plan.

 

Add to that the rate of business change and the pace of new technology adoption, and it’s no surprise that they’re constantly in reactive mode, unable to look beyond the bounds of their own organisation.

 

Firefighting for a strategy

Stuck in firefighting mode, CISOs are constantly chasing the next technology solution, which is never enough. New tools can help, but they need to be deployed as part of a robust strategy, and reinforced with considered and deeply embedded processes and policies if they are to have a notable effect. Instead, cyber security teams find themselves stuck solving the same problems again and again.

 

While it is true that the speed of change in cyber security can sometimes require a change of approach, that is more of a tactical inward-focused consideration. A new and more strategic approach that focuses on forward planning and a big-picture view is required to tackle these real and concerning problems head-on.

 

Organisations should be looking outward for support, joining forces to share intelligence, and planning at least five years ahead and developing collaborative strategies that are flexible enough to accommodate a degree of uncertainty.

 

Academia’s role in cyber security

Academia has a significant role to play in the pipeline of innovation and science in cyber security. Academics can look at the bigger picture and put research effort into solutions to major problems, such as the explosion of data from the Internet of Things or how to secure critical national infrastructure.

 

Companies and governments are often too busy dealing with day-to-day issues to spend significant time on the big picture. On the other hand, academics must guard against naivety; from a distance it may be easy to think they have solutions to problems, but people who work at the cutting edge can often see issues with suggested approaches that those not in the direct line of fire would miss. That’s why partnerships are so important.

 

Though academics do work with companies and governments, 90 per cent of research is initiated by them and sold on. A lot of work is focused on areas of commercial challenge, such as identity management and threat visualisation. Ransomware remains the biggest issue and often SMEs still aren’t spending enough to defend against such attacks. It’s important to teach CIOs and CTOs about the risks and how they can mitigate them.

 

Some industries face more complex challenges, and the work of academia can be particularly beneficial.  Take critical national infrastructure, for example, where nations are reliant on a constellation of technology, they fundamentally can’t protect from hostile state actors.

 

That doesn’t mean they are doing badly, simply that the situation favours the attacker. Governments have a huge waterfront to protect from a highly motivated adversary. Researching vulnerabilities means that academics can help keep systems as secure as possible against malicious actors.

 

However, much critical national infrastructure is run by private companies that answer to their shareholders. They aren’t incentivised to tackle vulnerabilities that might affect others more – and that is a problem academia can’t solve.

 

Academics are also very aware of their role in tackling the skills shortage. Universities can and are setting up courses. PhD candidates are working in industry on cutting-edge projects that will yield new research and often generate new intellectual property. Some PhD candidates are working on projects so secret that they can’t even tell their supervisors what they are doing.

 

However, one problem that academia has is that it can’t offer salaries that experts in cyber security, artificial intelligence and data science can earn in industry, especially with big tech firms. That makes it difficult to attract people with more than theoretical experience of these threats. Academia must find ways to get expert practitioners involved.

 

And the cyber security sector must attract a more diverse range of people, too. Companies need to lower the bar of entry so university courses aren’t the only way in. They might also look beyond technical people; cyber security needs cognitive psychologists, change managers, business experts and more. Cyber security touches every part of the public and private sector, so greater attention must be focused on it.

 

A critical role, but no silver bullet

There is no doubt that academia has a critical, convening role to play in today’s cyber security landscape.  By developing and sharing new ways to thwart attacks, researching the hacker communities that exist, partnering with organisations on research projects and training the next generation of cyber professionals, it is a multi-faceted role, that industry cannot do without. 

 

But academia’s role is not a silver bullet. Closer collaboration between enterprises, academia, government and the IT industry, is the only way that we can all stay ahead of the cyber security challenge.

 


 

Stuart Jubb is Group Managing Director at Crossword Cybersecurity

 

Main image courtesy of iStockPhoto.com


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543