projects

Global Universities

Client: CSIRT.global

1. Organization & Problem Domain

I. Organization Overview

CSIRT.global is a worldwide, non-profit, volunteer-led organization dedicated to addressing cybersecurity vulnerabilities. Through proactive identification, owner notification, and incident prevention, CSIRT.global contributes to a safer digital environment.

Core Activities:

CSIRT.global is independent, apolitical, inclusive, and open. It values personal growth and supports both individuals and the broader community in their development while ensuring the protection of sensitive data.
As the sister organization of the Dutch Institute for Vulnerability Disclosure (DIVD), CSIRT.global has been coordinating international CSIRT activities since 2022, working towards a global network of cybersecurity professionals.

Key Services:

CSIRT.global partners with various organizations, including universities, governmental bodies, private enterprises, and non-profits. It also plays a crucial role in establishing bug bounty programs and cybersecurity collaboration initiatives.

II. Problem Domain

The research project, led by CSIRT.global’s Research Department, aims to identify and mitigate cybersecurity vulnerabilities within universities worldwide. This initiative addresses both technical and organizational challenges, focusing on proactive measures to prevent cyber incidents.
Research Department Activities:

Goals and Responsibilities:

Relevant Systems & Key Metrics:


2. Project Background & Problem Statement

I. Background

Universities and academic institutions worldwide are increasingly targeted by cyberattacks. A recent incident at Eindhoven University of Technology (TU/e) highlighted the urgency for enhanced cybersecurity. Hackers were detected in real-time, disrupting education and delaying exams.
Such attacks not only cause operational disruptions but also jeopardize sensitive student, faculty, and research data. University-affiliated medical centers face similar risks. A proactive cybersecurity approach is essential to maintain educational and research continuity while minimizing damage.
This research initiative stems from the urgent need to address growing cyber threats. Through ethical hacking, CSIRT.global seeks to map vulnerabilities and support universities in enhancing their digital security.

II. Problem Statement

Many universities lack sufficient insight into their digital vulnerabilities, making them more susceptible to cyberattacks. The key contributing factors include:

Without proper security measures, cyberattacks can lead to data breaches, educational and research disruptions, and reputational damage.
Project Objective: This project aims to improve the current cybersecurity landscape by identifying vulnerabilities, implementing security improvements, and increasing resilience against cyber threats. Without this initiative, the academic sector remains an attractive target for cybercriminals, with potentially severe societal consequences.


3. Project Objectives

During their internship at CSIRT.global, students will conduct research on multiple universities to identify and analyze vulnerabilities in their digital infrastructure.

Prerequisites

Before commencing research, students must complete the DIVD Academy Ethical Hacker Course to gain certification and ensure safe usage of cybersecurity tools, including:

Additionally, students will employ structured risk assessment frameworks:

SMART Objectives

Specific: Conduct a cybersecurity assessment of university digital infrastructures, identifying security risks and delivering structured reports with technical analysis, risk assessments, and actionable recommendations.
Measurable:

Acceptable: The project aligns with CSIRT.global’s mission and will be executed by a team of specialists and interns. Universities will receive clear, applicable cybersecurity reports.
Realistic: The research will be conducted using advanced cybersecurity tools and methodologies to systematically analyze vulnerabilities.
Time-Bound:


4. Project Phases & Timeline

Phase 1: Certification (4 weeks)

Phase 2: Initiation (1 week)

Phase 3: Planning & Preparation (1 week)

Phase 4: Reconnaissance (4 weeks)

Phase 5: Scanning & Enumeration (4 weeks)

Phase 6: Reporting (2 weeks)

Phase 7: Remediation & Follow-Up (4 weeks)


5. Conclusion

This project is a vital step in strengthening the cybersecurity posture of academic institutions worldwide. Through structured research, collaboration, and proactive vulnerability management, CSIRT.global aims to create a safer digital landscape for universities and their stakeholders.