News

Audit Blames Funding, IT Priorities for University's Lax Security

Ohio University's Computer Services department was running seven-figure surpluses and spending on generous benefits for employees while it was failing to make adequate investments in firewalls and other computer security measures, according to an outside consultant's report.

The university is in the midst of investigating five cases of data theft since March 2005 in which 367,000 files containing personal information including Social Security numbers, names, medical records and home addresses were exposed.

The audit criticizes the university's Computer and Network Services division for making security a low priority for more than 10 years, though it had an annual budget averaging $11 million and annual surpluses averaging $1.4 million.

The outside consultants, from Moran Technology Consulting of Naperville, Ill., also found the department gave about 65 employees health-club memberships and other additional benefits not enjoyed by other workers at the university.

Not enough skilled computer staff and computer officials who did not "firmly and loudly identify important security problems" contributed to data theft, the audit said.

The audit details a profound problem, said R. Gregory Brown, chairman of the school's board of trustees. Trustees on Friday approved spending up to $4 million to secure university computers.

The university announced April 21 it had discovered a computer breach at its training center for fledgling businesses. Since then, electronic break-ins also were reported at the school's alumni office, health center and the department that handles records for businesses the university hires.

Students, alumni and employees have been told to run credit checks and place fraud watches on their credit card and bank accounts. About two dozen people with ties to the university have told the school they were victimized by identity theft in the last year.

The director of the department, Tom Reid, and the Internet and systems manager, Todd Acheson, have been suspended pending a school investigation.

"It's going to take a long time to develop a cogent response," Reid said. "I'm eager to have the facts come out."

Featured

  • Nebula

    Ahead of AGI, Microsoft and OpenAI Redefine Their Partnership

    In a recapitalization announced Tuesday, OpenAI has launched a new public benefit corporation (PBC) called OpenAI Group, giving Microsoft a 27 percent ownership stake valued at approximately $135 billion.

  • Veeam Acquires Securiti AI To Unify Data Resilience and AI Security

    Veeam Software is making a strategic move into AI and data security by acquiring Securiti AI for $1.7 billion.

  • Microsoft Adds 'Mico' Virtual Assistant to Copilot in Major Fall Update

    In a significant feature update, Microsoft on Thursday said it is reshaping its Copilot AI platform with features that deepen user personalization and enable real-time group collaboration, among other perks.

  • Nutanix Partner Central Rolls Out To Boost Channel Engagement

    Nutanix on Wednesday launched a new platform, Partner Central, to give its channel partners a unified digital workspace for managing sales, tracking incentives and collaborating more effectively.