Universities brace for tougher research security rules

Universities brace for tougher research security rules

On 7 September, the federal body that oversees Australia's higher education sector wrapped up a five-week consultation on whether universities should face tougher rules to protect their research from security threats.

The Higher Education Standards Committee (HESC), which sits under the Australian Tertiary Education Commission (ATEC), asked universities and other stakeholders whether the current rules do enough to protect research, data and systems from cyberattacks and foreign interference – and whether stricter requirements are needed.

Sector warns against more red tape

Universities Australia, representing the country’s vice-chancellors, said the sector's next reform phase should lift quality and accountability instead of pile more red tape onto an already heavily regulated system.

“Any new standards need to be evidence-based, workable and developed with the sector. Universities also need sufficient time and support to implement them properly,” Universities Australia Chief Executive Officer Luke Sheehy said in a statement.

Sheehy went on to say that while universities should be held accountable when they fail to meet clear national standards, the new powers being proposed “must be fair, proportionate and carefully bounded.”

“Parliament should closely examine how these powers will work in practice. That includes the safeguards and review mechanisms that apply, and whether the framework properly distinguishes serious or systemic failures from technical or administrative non-compliance,” he said.

“University autonomy matters too. Strong accountability should not unnecessarily extend government or regulatory control over how universities operate.”

Beyond compliance

Nicole Henry, Head of Government Affairs – Australia and New Zealand at Fortinet, said the implications of the tougher rules for universities extend well beyond compliance.

“The Committee has taken care in framing its consultation to recognise that universities are different, and that expectations need to be proportionate to their scale and risk profile,” Henry told The Educator.

“This is more than a compliance exercise because the real test is whether security controls, remediation processes, and decision pathways work when conditions become difficult.”

Henry said openness and collaboration are fundamental to research, with data, identities, and access moving across institutional systems, cloud platforms, specialist infrastructure, industry partners, and international networks.

“These connections bring risks that need to be understood and managed. Risk may also emerge through collaboration and data sharing before it becomes visible through formal institutional processes,” she said.

“It’s important to remember that universities are already managing these risks in practice and there needs to be clarity on how new requirements could duplicate existing obligations without improving security outcomes.”

Henry said institutions should focus on the fundamentals.

“Responses should focus on what is material, where risk can travel, and whether institutions can detect, contain, and respond to disruption while continuing their core research and teaching mission.”

AI, quantum reshaping the risk landscape

Henry said another big consideration for universities and schools is that AI, quantum computing, third-party dependencies, and increasingly interconnected research environments are increasingly changing the risk landscape for these institutions.

“AI and quantum are moving at different speeds; however, they are landing on the same long-lived technology environments that these institutions are already transforming through cloud, automation, and greater connectivity,” she said.

“AI is increasing the speed at which familiar weaknesses can be identified, connected, and exploited across fragmented technology environments and supplier dependencies.”

Henry said quantum computing creates a different, longer-term challenge because cryptography and digital trust are embedded across internal systems, internet-facing services, cloud connections, and third-party integrations.

“The transition to post-quantum security will therefore extend well beyond replacing individual cryptographic algorithms,” she said.

“Third-party dependencies add another dimension because the institutional boundary is no longer a reliable boundary for risk.”

Henry said universities may have strong controls within their own environment yet still be exposed through systems and services they depend on but do not directly control.

“This makes understanding which dependencies could have material consequences for the institution increasingly important,” she said.

“Despite this, the fundamentals remain critical: understanding where important data and dependencies sit; how risk can travel across those dependencies; and designing architecture that can contain disruption without unnecessarily stopping teaching, research, or campus operations.”

Henry said universities should prioritise adaptability over prediction.

Future readiness is less about predicting exactly what comes next and more about maintaining the flexibility to adapt when a technology, supplier or security assumption changes.

Governance under the microscope

When asked what stronger assurance expectations could mean for university leaders and boards moving forward, Henry pointed to…

“Stronger assurance expectations will put greater emphasis on whether university leaders and boards can demonstrate that cyber risk is being managed effectively in practice, rather than relying on policies and controls that look appropriate on paper,” she said.

“Governance needs to give people the context, authority, and decision pathways to act when information is incomplete or time is short.”

For leaders, Henry said this means understanding what is material to the institution, where critical dependencies sit, and how disruption could affect research, teaching, and operations.

“Regular testing and exercising can help establish whether these controls, decision pathways, and escalation processes actually work under pressure,” she said.

“Ultimately, stronger assurance should leave universities better able to manage risk and demonstrate resilience, rather than simply produce better evidence of compliance.”