News

Audit Blames Funding, IT Priorities for University's Lax Security

Ohio University's Computer Services department was running seven-figure surpluses and spending on generous benefits for employees while it was failing to make adequate investments in firewalls and other computer security measures, according to an outside consultant's report.

The university is in the midst of investigating five cases of data theft since March 2005 in which 367,000 files containing personal information including Social Security numbers, names, medical records and home addresses were exposed.

The audit criticizes the university's Computer and Network Services division for making security a low priority for more than 10 years, though it had an annual budget averaging $11 million and annual surpluses averaging $1.4 million.

The outside consultants, from Moran Technology Consulting of Naperville, Ill., also found the department gave about 65 employees health-club memberships and other additional benefits not enjoyed by other workers at the university.

Not enough skilled computer staff and computer officials who did not "firmly and loudly identify important security problems" contributed to data theft, the audit said.

The audit details a profound problem, said R. Gregory Brown, chairman of the school's board of trustees. Trustees on Friday approved spending up to $4 million to secure university computers.

The university announced April 21 it had discovered a computer breach at its training center for fledgling businesses. Since then, electronic break-ins also were reported at the school's alumni office, health center and the department that handles records for businesses the university hires.

Students, alumni and employees have been told to run credit checks and place fraud watches on their credit card and bank accounts. About two dozen people with ties to the university have told the school they were victimized by identity theft in the last year.

The director of the department, Tom Reid, and the Internet and systems manager, Todd Acheson, have been suspended pending a school investigation.

"It's going to take a long time to develop a cogent response," Reid said. "I'm eager to have the facts come out."

Featured

  • IBM Giving Orgs a Governance Lifeline in Agentic AI Era

    Nearly overnight, organizations are facing brand-new challenges caused by self-directed AI systems (a.k.a. agentic AI). Big Blue is extending them some help.

  • Microsoft Launches Integrated E-mail Security Ecosystem for Defender for Office 365

    Microsoft is expanding its e-mail security capabilities with the launch of a new Integrated Cloud Email Security (ICES) ecosystem for Microsoft Defender for Office 365.

  • Microsoft Joins Workday's AI Agent Partner Network

    Microsoft has become a key partner in Workday's newly launched AI Agent Partner Network, aligning with other industry leaders to integrate AI agents into enterprise workforce systems.

  • LinkedIn CEO Ryan Roslansky To Lead Microsoft's Productivity Initiatives

    In a strategic leadership realignment, Microsoft has appointed LinkedIn CEO Ryan Roslansky to oversee its consumer and small business productivity software division, encompassing Microsoft 365, Teams and AI-driven tools like Copilot.