Target Profile Model to Improve Cybersecurity Capabilities of Educational Institutions Against Cyber-Attacks
摘要
This research addresses the limitations of educational institutions in defining the cybersecurity capabilities needed to protect, respond, and recover from the main cybercrime scenarios in the sector. To date, there is evidence of an increase in cyberattacks targeting educational institutions, and there are no models to define the capabilities to reduce risk, so we focused on creating a cybersecurity target profile model based on NIST based on the reality of the education sector. This model will allow the institution to implement a cybersecurity program autonomously, reduce costs, and prioritize critical capabilities for the institution. In this sense, the model has been confirmed through a case study in which the current cybersecurity posture of the institution was calculated and, based on the gaps identified with the proposed target profile, initiatives to improve it were set up. The results show that the implementation of the model improved critical cybersecurity capabilities in educational institutions by 30%, moving capabilities from a low maturity level (Initial) to a defined level. In addition, a 60% reduction in the cost of implementing the cybersecurity program was shown. Thus, the proposed model allows institutions to find gaps and opportunities for improvement, strengthening their cybersecurity management and maturity in this area. It also helps the implementation of a cybersecurity program by reducing costs and providing autonomy to educational institutions.