Sustainability of higher education institutions: Case study on cyber attacks
DOI:
https://doi.org/10.32890/gbmr2023.15.1.2Keywords:
Cyber attacks, Higher Education Institution, Qualitative, case studyAbstract
Institution (HEI). The study adopted a qualitative methodology, employing a single case study as approach. A single case study is a method established to provide insightful examination of inquiries based on an inductive process of data collection, which is appropriate for this study. The study used purposive sampling as technique in selecting the fourteen interviewees. In addition, relevant documents and observation were also conducted to confirm the validity of the data gathered. Using a thematic analysis of qualitative methodology, the findings revealed sustainability of HEI depends on how HEI counter cyber-attacks. Most important, the finding revealed eight themes of cyber-attacks, they are: Malware, Ransom attack, WannaCry, Defacement, Altered content, Denial of service, Dictionary attack and Users negligence. The findings would be useful for HEI in data protection. The empirical findings of this study reflects that HEI is vulnerable to cyber-attacks thus it is imperative for HEI management to govern and tighten their cybersecurity. The findings of this study suggest novel guidance to design security measures that could balance the open system and control security.
Downloads
References
Beaudin, K. (2015). College And University Data Breaches: Regulating Higher Education Cybersecurity Under State And Federal Law. Journal Of College And University Law 41(3), 657-694.
Bedi, R. (2018, June 10). Education minister confirms exam analysis system suspended. The Star Online. Retrieved from https://www.thestar.com.my/news/nation/2018/06/10/online-school-exam-analysis-system-suspended-says-education-ministry/
Bélanger, F., Collignon, S., Enget, K., & Negangard, E. (2017). Determinants of early conformance with information security policies. Information. & Management Advanced Retrieved from online Publication. doi:10.1016/j.im.2017.01.003.
Creswell, J. W. (2013). Qualitative inquiry and research design: Choosing among five approaches (3rd ed.). Thousand Oaks, CA: Sage Publications.
Carapezza, K. (2015). Cyber Ed: How higher education is re-evaluating a growing Threat. Retrieved from http://www.Pri.Org/Stories/2015-08-06/Cyber-Ed-How-Higher-Education-Re-Evaluating-Growing-Threat.
Coleman, L., & Purcell, B. (2015). Data breaches in higher education. Journal of Business Cases and Application. 15, 1-7.
Forbes Technology Council. (2017). What Cyberthreats Do Higher Education Institutions Face? Retrieved from https://www.forbes.com/sites/forbestechcouncil/2017/08/21/what-cyberthreats-do-higher-education-institutions-face/#3cd88eab640d.
Gamma, J. (2014). Just in time research; Data breaches in higher education. EDUCAUSE. Retrieved from https://net.educause.edu/ir/library/pdf/ECP1402.pdf.
Greenberg, A. (2014). North Dakota University System hacked, roughly 300K impacted. from SCmagazine.com. Retrieved from http://www.scmagazine.com/north-dakota-universitysystem-hacked-roughly-300k-impacted/article/337181/. Global Business Management Review: Vol. 15 Number 1 July 2023:
Ismail, Z., Masroon, M., Mohamad Sidek, Z. & Hamzah, D.S. (2010). Framework to manage Information Security for Malaysian Academics Environment. Journal of Info. Assurance & Cybersecurity. Retrieved from http://www.ibimapublishing.com/journals/JIACS/jiacs.html.
Marks, A. (2007). Exploring universities’ information systems security awareness in a changing higher education environment: a comparative case study research. Unpublished PhD thesis, University of Salford, Cardiff, United Kingdom.
Mezzour, G., Carley, L., & Carley, M.K. (2014). Global Mapping of Cyber Attacks. Retrieved from https://ssrn.com/abstract=2729302 or http://dx.doi.org/10.2139/ssrn.2729302.
Mateski, M., Trevino, M.C., Veitch, K.C., Michalski, J.J., Mark Harris, J., Maruoka, S., … Sandia National Laboratories. (2012). Cyber Threat Metrics. SANDIA REPORT SAND2012-2427. Sandia National Laboratories, USA.
Othman Z, & Hamid, FZA (2018). Dealing with un(expected) ethical dilemma: Experience from the field. The Qualitative Report, 23(4), 733-741.
Patton, M.Q. (2002). Qualitative Research & Evaluation Methods. (3rd ed). Thousand Oak: Sage Publications, Inc.
Rajab, M., & Eydgahi, A. (2019). Evaluating the explanatory power of theoretical frameworks on intention to comply with information security policies in higher education. Computer & Security, 80, 211-223.
Ramim, M., & Levy, Y. (2006). Securing E-Learning Systems: A Case of Insider Cyber Attacks and Novice IT Management in a Small University. Journal of Cases on Information Techology. 8 (4), 24-34.
Rezgui, Y., & Marks, A. (2008). Information security awareness in higher education: An exploratory study. Computer. & Security, 27, 241-253.
Roman, J. (2014). Latest incident highlights breach vulnerabilities in academia. Retrieved from http://www.databreachtoday.com/add-butler-university-to-breach-list-a-7007.
Straumshein, C. (2015). A Playground for Hackers. from Inside Higher Ed. Retrieved from https://www.insidehighered.com/news/2015/07/06/pennsylvania-state-u-cyberattackspossibly-part-larger-trend-experts-say.
Verizon (2017). 2017 Data Breach Investigation Report (10th ed). Retrieved from https://www.ictsecuritymagazine.com/wp-content/uploads/2017-Data-Breach-Investigations-Report.pdf.
Williamson, W. (2015). Higher Education Crams for Cyber Security. Security Week Internet and Enterprise Security News, Insights and Analysis. Retrieved from https://www.securityweek.com/higher-education-crams-cyber-security.
Yin, R. K. (2003). Case Study Research: Design and Methods. Thousand Oaks, California: Sage Publications.
Zalaznick, M. (2013). Cyberattacks on the rise in higher education Foreign governments and organized crime targeting institutions’ most sensitive information. Retrieved from www.universitybusiness.com/article/cyberattacks-rise-higher-education.
Published
Issue
Section
License
Copyright (c) 2023 Global Business Management Review (GBMR)

This work is licensed under a Creative Commons Attribution 4.0 International License.
Disclaimer
Global Business Management Review (GBMR) has taken all reasonable measures to ensure that material contained in this website is the original work of the author(s). However, the Journal gives no warranty and accepts no responsibility for the accuracy or the completeness of the material; no reliance should be made by any user on the material. The user should check with the authors for confirmation.
Articles published in the Global Business Management Review (GBMR) do not represent the views held by the editors and members of the editorial board. Authors are responsible for all aspects of their articles except the editorial screen design.
Submission of an article is done with the understanding that the article has not been published before (except in the form of an abstract or as part of a published lecture, or thesis) that it is not under consideration for publication somewhere else; that if and when the article is accepted for publication, the author's consent to automatic transfer of the copyright to the publisher.
