By Tony Campbell, Basecamp Sherpa (Governance) at Rmkble

Abstract

Most organisations rely on periodic assessments to assess compliance with regulatory and legal requirements, especially cybersecurity, data governance, and privacy. Yet, due to the rapid speed of change within modern organisations, exacerbated by cloud migrations, SaaS, and AI programmes, the old faithful “annual audit” is no longer delivering the assurance organisations need to stay on track.

Don’t misunderstand me—annual assessments still have value, especially in attesting to compliance for an external audience, as they form the basis of certification. But internally, periodic assessments are nothing more than snapshots of compliance when the assessment was undertaken and don’t represent all the changes to your position since that date.

Take a university, by way of example—unis continually change and transform their infrastructure and have several thousand students onboarding and offboarding each semester, while cloud SaaS products come and go and new research partners spring up anywhere in the world. With the introduction of AI programmes now moving at pace, an assessment conducted as recently as last month will already be out of date.

Education infrastructure is complex

Education establishments are among the most complicated to protect against cyberattacks. Take identity governance, for example: the tide of students coming in and out, along with sessional staff coming and going is already a burden. Yet beneath the user management layer, they also manage application service accounts and API keys, and with AI agents they have an entirely new identity problem to solve.

The second problem relates to the perimeter—or lack thereof. The Canvas incident earlier this year demonstrated this problem well. An attack on Instructure’s software exposed data relating to as many as 275 million global users, including email addresses, student identifiers and private messages.

And even if the university did an excellent job securing its own environment, it will still inherit an cyber risk from downstream platforms, and for any defensive strategy, it’s always worth remembering that unmanaged risks often sit inside someone else’s infrastructure—while it’s the institution that pays the price and deals with the fallout. Understanding holistic risk exposure and properly implementing controls and mitigations, as well as mature and tested response plans, sits squarely as the responsibility of the university.

The Western Australian Auditor General recently reported the results from nine university and TAFE audits, where information and cyber security represented 82% of the identified weaknesses. 64% of findings were carried over from previous years—none of which were special or exotic issues and could be addressed with well-known controls. A lack of information classification, third-party assurance, patching, account lifecycle management, logging and network security were all included in the findings. So, if none of these findings were new, and many are recurring year on year, it begs the question: what’s going wrong?

Changing infrastructure needs a new operating model

Since universities are leading the charge on AI adoption, the pressure on compliance is only increasing. Education sits squarely on the leading edge of research and new ways of working are being tested all the time. AI agents supporting research, admissions, student services and administration are exactly the sort of innovations these institutions should be exploring.

Yet unmanaged adoption of new technology will introduce compliance drift. If a staff member puts institutional information into a public AI chatbot, that data will leave the perimeter and no longer be controlled. If a research team challenges a frontier LLM to surface insights from data, the research information itself may be processed inside someone else's datacentre and stored on discs accessible by others. If an AI agent is hooked into Microsoft 365 or some other institutional repository without properly controlling permissions, again the likelihood of a breach goes up.

Privacy regulators are now responding to this problem. OVIC has already called on Victorian public-sector organisations adopting generative AI to baseline their security maturity, assess information risks, and implement appropriate controls, including continuous monitoring for threats.

The Australian Cyber Security Centre made similar points regarding agentic AI, emphasising strong identity management, privilege controls, human oversight and continuous monitoring for a secure baseline.

And the solution is…?

Putting controls in to manage the risk is not the end of the problem. Governance itself needs to change, since the annual compliance checks mentioned earlier will not represent the change going on every single day within these organisations. Any one of those changes could lead to compliance drift, and potentially a breach. And any breach will result in compliance questions being asked. If the answer is they were compliant five months ago, then it’s not going to satisfy the regulator when millions of private records are in the hands of criminals.

Three different elements of risk management need to fuse together to provide continuous assurance, so that alerting to drift happens in real time. They are:

1. Control mapping. Every organisation should have a catalogue of their obligations and translate privacy, cyber security, AI governance, information management and third-party risk into a common control model. The approach of managing each set of controls via unrelated spreadsheets and disparate teams just doesn’t work—everything is interconnected.

2. Control deployment. Knowing that a control should exist is not enough—if sensitive student information must never be put into an unapproved AI service, there must be a path to technical enforcement. If privileged identities need phishing-resistant MFA, as per the compliance framework, then it’s expected that it’s deployed everywhere, and throughout all new systems. If the policy doesn’t reach the technology, it becomes nothing more than ignored advice.

3. Control monitoring. This is the part that traditional governance struggles with the most. Is the control still configured? Is it still effective? Has someone introduced a new SaaS application, or has an AI agent appeared that bypasses access permissions?

How these questions are answered is important. What’s required is a solution that keeps up with the speed of change—a governance solution that serves as a common spine across the institution, where every obligation maps to a control, and every control is deployed into the solution where they are enforced. Telemetry is then used to demonstrate efficacy, and any exceptions are immediately sent for remediation.

Good governance makes the safe path the easiest path, so before approving the next AI agent, SaaS platform or research technology, governance demands the answer to three questions:

  • What controls apply?
  • Where are they enforced?
  • And are they working right now?

If the organisation can’t answer those questions, another assessment is not the answer. You need to build the capability that can. Then map the controls, deploy them, test them and monitor them continuously. If this is done well, researchers, academics and technology teams can all inherit the freedom to innovate within managed boundaries.

That is when governance finally stops being an obstacle to innovation and starts enabling it.

If you want to have a discussion about continuous governance and discuss solutions for your own environment, feel free to reach out to me directly on LinkedIn or chat with the Rmkble team.

About the author

Tony is a senior cybersecurity and technology leader with more than 30 years’ experience spanning security strategy, service innovation, governance, risk and enterprise transformation and has worked in leadership roles for two decades. At Rmkble, he leads the development of new cybersecurity, governance and AI assurance solutions, translating complex technology and regulatory challenges into practical services that organisations can adopt, operate and scale.

Author Headshot
Get in touch

Let's create positive change for your organisation

If you’re ready to discuss your goals, reach out to us via the form and one of our team members will be in contact with you. Alternatively, drop us a query or an expression of interest at: operations@rmkble.com.au.

Thanks for getting in touch!
We've got your submission and one of our team members will be in touch soon.
Oops! Something went wrong while submitting the form. Please try again or email to operations@rmkble.com.au.