Higher education, research & K-12

An open campus is a security model, not an excuse

Universities run the hardest network in the world: forty thousand unmanaged devices, a research estate that must stay collaborative to be useful, a residential network that is functionally a consumer ISP, and a security team of six. Guardian Sentinel is built for exactly that shape — high coverage, low operational cost, and an education licence that does not punish you for having a lot of people.

  • FERPA
  • GLBA Safeguards Rule
  • NIST SP 800-171
  • CMMC Level 2
  • GDPR
1:6,400 Median ratio of security staff to identities at a mid-size university Against 1:340 in financial services
64% Of education breaches begin with a compromised student or staff credential Guardian Labs sector data, 2024–2026
$3.7M Average cost of a ransomware incident at a research institution Including lost grant time and re-derived datasets
11× Increase in nation-state interest in university research since 2019 Concentrated in materials, aerospace, biotech and AI

The distributed campus

Six networks wearing one name

“The campus network” is a convenient fiction. In practice a university runs half a dozen environments with incompatible risk profiles, different governance and, historically, different security tools. Guardian covers all of them from one console and lets each keep the policy it actually needs.

Administrative Academic & teaching Research & HPC Student residential Medical centre Satellite campuses SIS, finance, HR, admissions Managed devices, strict policy FERPA + GLBA scope Lecture capture, LMS, labs Shared workstations, BYOD Semester-cycle load spikes Grant-funded clusters, CUI Unmanaged Linux, containers 800-171 / CMMC scope 18,000 personal devices Consoles, TVs, IoT, routers Isolate-and-notify posture EHR, imaging, clinical IoT HIPAA scope, uptime critical Shared identity with academia Field stations, city sites Thin links, no local IT Offline-capable enforcement Guardian Sentinel — one console, six policy profiles Shared detections and threat intelligence · per-zone response rules · per-zone data-handling and retention Identity fabric SSO, Shibboleth and eduroam federation · one person, many roles: student, tutor, researcher, alumnus, clinician
Six environments, one console. Policy differs by zone; detection logic and threat intelligence are shared across all of them.

Research & intellectual property

Your research is a national asset. Adversaries worked that out first.

Pre-publication research is the most valuable data a university holds and the least protected: it lives on lab-managed Linux boxes, moves between institutions by arrangement rather than policy, and is handled by post-docs whose careers depend on sharing it. Guardian protects it without making collaboration impossible.

Know where the sensitive work lives

Guardian classifies research artefacts by content and context — genomic sequence files, CAD and simulation output, unpublished manuscripts, grant documents marked as controlled unclassified information — and maps them to the grant, the principal investigator and the export-control category. Most institutions discover CUI in three places they did not expect within the first month.

Explore data protection

Collaboration you can permit, not just tolerate

Research must cross institutional boundaries. Guardian records the transfers instead of blocking them blindly: who moved which dataset to which partner, under which agreement, at what volume. When an export-control review arrives, the answer is a report rather than a six-week reconstruction from email.

Identity protection

HPC without an agent tax

Compute clusters cannot afford a security agent that steals cycles from a queue that is booked eleven months out. The Guardian Linux sensor runs in eBPF with a measured median overhead of 0.4% CPU, no kernel module to break on the next kernel bump, and a scheduler-aware mode that yields during priority jobs.

Workload protection

Targeted-intrusion detection, not commodity malware

The groups that target research do not deploy ransomware; they establish quiet, long-lived access and exfiltrate slowly. Guardian Labs tracks 41 clusters with a documented academic-sector focus and ships their behavioural signatures — credential harvesting from federated SSO, abuse of legitimate collaboration tools, slow DNS exfiltration — as detections, not just indicators.

Threat intelligence
Federally funded work has a floor Institutions holding Department of Defense contracts inherit NIST SP 800-171 and, on many new awards, CMMC Level 2. Guardian maps its controls to all 110 practices and produces the System Security Plan evidence and POA&M inputs directly from live telemetry. Compliance advisory runs the assessment readiness.

Student data privacy

FERPA, GLBA and the records you are legally responsible for

Education records are protected by FERPA regardless of where they end up, and since 2023 the GLBA Safeguards Rule has applied to financial-aid data at every institution that participates in Title IV programmes. Both require you to know where the data is. Most institutions do not, because the data leaves the SIS the moment somebody exports a spreadsheet.

Common education data categories, the obligation attached to each, where the data typically escapes the system of record, and the Guardian control that keeps it in view.
Data category Obligation Where it escapes Guardian control
Education records & transcripts FERPA — disclosure control, access logging, parental and student rights Advisor spreadsheets, departmental shared drives, personal cloud storage Content classification with lineage from the SIS export onward, plus alerting on personal-cloud destinations
Financial aid & FAFSA data GLBA Safeguards Rule — written programme, MFA, encryption, monitoring Third-party servicers, email attachments, ticketing systems Egress monitoring on the aid office, MFA enforcement checks, and an annual control report for the auditor
Health & counselling records HIPAA where the clinic bills, FERPA where it does not Shared clinical workstations, imaging systems, referral email Segmented clinical zone with its own retention policy and a separate access-audit trail
Research data with human subjects IRB conditions, GDPR where EU subjects are involved Lab NAS devices, unmanaged laptops, collaborator transfers Dataset tagging inherited from the IRB protocol, with transfer logging per partner institution
Admissions & recruitment FERPA on matriculation, state privacy law throughout CRM exports, agency portals, marketing platforms SaaS-to-SaaS flow visibility through the integrations layer, with alerting on new data-bearing connections
Alumni & donor records Contractual and reputational; PCI where gifts are taken by card Advancement databases, event platforms, volunteer laptops Payment-path monitoring and least-privilege review on advancement systems

Scroll the table sideways to see every column.

Subject access, answered in hours

A student asks what you hold on them. Guardian's data map answers across the estate — not only the SIS, but the twelve places a copy landed — with the access history attached.

Breach notification, pre-assembled

State notification laws run on days, not weeks. Guardian produces the affected-record set, the timeline and the control narrative as an export, so counsel starts from evidence rather than interviews.

Vendor and EdTech sprawl

The average institution runs 340 SaaS applications, most bought by a department. Guardian surfaces which ones actually receive student data and which merely claimed they might.

Constrained teams & budgets

Designed for a team of six covering forty thousand people

Education security teams are not junior; they are outnumbered. The binding constraint is analyst hours, so Guardian is measured on how few of them it consumes — not on how many alerts it can generate.

WEEKLY ANALYST HOURS · 28,000-STUDENT UNIVERSITY 60 45 30 15 0 Alert triage 41 6 Investigation 16 7 Reporting 9 2 Proactive work 4 55 Previous stack Guardian with managed detection
Reported by a 28,000-student university six months after cutover. Total hours are unchanged; what those hours are spent on is not.

What removes the hours

  • One agent, one console. Endpoint, identity, cloud, email and network telemetry arrive already correlated. No SIEM content engineering, no maintaining nine parsers, no separate consoles for the residential network.
  • Sentinel AI Analyst triages first. Every alert arrives with a written narrative, a verdict and the evidence that produced it. Your analyst decides; they do not assemble.
  • Managed detection covers the night. Guardian MDR holds the 3 a.m. queue with a 3-minute response SLA, and escalates to your team only with a recommendation attached.
  • Student devices self-resolve. Residential-network detections trigger a notification and network quarantine with a self-service remediation page, so the help desk is not the bottleneck during move-in week.
  • Reporting is generated. Board packs, cyber-insurance questionnaires and the annual GLBA report are produced from live data on a schedule.

What it costs to run

Education licensing

Guardian licenses education by managed endpoint, not by identity. Student personal devices on the residential network are covered by network sensing at no per-device charge — because charging a university per student is how security budgets die. Research clusters are licensed per node with a volume tier that recognises an HPC estate is not an office.

See pricing detail
Consortium and system-wide agreements Guardian holds agreements with fourteen higher-education purchasing consortia and supports system-wide licensing across constituent campuses with delegated administration, so each campus keeps its own console view under one contract.

Sector scenarios

Four situations every institution recognises

Move-in week, eighteen thousand new devices

Over four days the residential network absorbs an entire mid-size ISP's worth of unmanaged hardware, a third of it already carrying something unpleasant. Guardian fingerprints each device from network behaviour, quarantines the ones beaconing to known infrastructure, and hands the student a remediation page instead of handing your help desk a ticket. Typical result: 94% of infections resolved without a human conversation.

A department buys an EdTech platform on a departmental card

Six weeks later it is holding grade data for four hundred students and nobody in IT knows it exists. Guardian's SaaS discovery finds the OAuth grant the day it is issued, classifies the data flowing to it, and raises it for review with the actual usage attached — which is a far better conversation than a policy reminder.

A principal investigator's credentials appear in a paste dump

Guardian correlates the exposed credential against live sessions, finds that it is still valid on a federated service that missed the last password rotation, forces re-authentication, and checks the grant's data stores for access from the addresses associated with the leak — all before the researcher reads the email telling them to change it.

Ransomware lands on a Friday of a reading week

Detection at the first encryption attempt, automatic isolation of the affected hosts, and rollback of the encrypted files from Guardian's local shadow store. The 41 institutions in Guardian's education base have collectively lost zero days of teaching to ransomware since 2023. Incident response is on retainer for the case that is worse than that.

We are six people for forty-one thousand identities, and the honest problem was never detection quality — it was that nobody had time to read what the old tools produced. Guardian gives us alerts that arrive already investigated. The first month we finally closed the backlog. The second month we started doing the proactive work we had been writing into strategy documents for four years.

Dr Adaeze Okafor
Chief Information Security Officer, public research university
41 Higher-education institutions running Guardian Sentinel Across nine countries, 1.2 million identities
0 days Teaching lost to ransomware across that base since 2023 Twenty-two contained incidents in the same period
0.4% Median CPU overhead of the Linux sensor on HPC nodes Measured across 18,000 cluster nodes

Bring a demo to your next security committee

Guardian will run a scoped assessment across one faculty, one administrative system and the residential network, and present the findings in the format your committee already uses. Two weeks, no licence commitment, and the report is yours regardless of what you decide.