Higher Education & Research
The most open network in the country, holding some of the most sensitive work in it.
A research university is a genuinely hard security and software environment, and it is hard for reasons that are structural rather than fixable. Openness and collaboration are the mission, not an oversight. Faculty are not employees in the way a corporate security model assumes. Federal sponsors impose obligations that arrive as terms in an award document rather than as a control framework. And the same institution is simultaneously a hospital, a utility, a hotel chain, a payment processor and a defense subcontractor. We have built and run software on this side of the fence, and we design for the institution that exists rather than the one an enterprise architecture diagram would prefer.
What we hear
The problems that actually show up.
Not a market overview. These are the specific failures that bring people to us in this sector.
Research security asked for as a question nobody can answer
NSPM-33 and the sponsor disclosure regime expect an institution to know its researchers' outside affiliations, subawards and collaborations. That information exists, scattered across conflict-of-interest filings, publication records, award documents and public data, and nobody has ever joined it up.
Controlled data in an uncontrolled environment
One award brings CUI into scope and suddenly a lab that has always worked in the open needs an NIST 800-171 enclave, a system security plan and a POA&M, on the timeline of the award rather than of the IT department.
Program administration eating the program
Cohort tracking, placements, completion evidence and reporting to a sponsor run on spreadsheets maintained by the person who has the least time. Programs are lost to administrative overhead far more often than to bad outcomes.
A workforce pipeline that stops at the diploma
The institution graduates capable people every year and the regional employers who need them have no structured way to meet them before an interview.
Instructional infrastructure that cannot scale
Hands-on technical courses need isolated environments per student, reset between sections and available at 2am the night before it is due. Building that once is a project; running it every semester is a system.
What we build here
Systems we’ve shipped in this sector.
Some of these are whole products; some are one screen that removed a week of manual work. Both count.
- Research-collaboration graphs and affiliation risk review tooling
- Sponsored-program, subaward and disclosure workflow systems
- CUI enclaves and NIST 800-171 system security plan evidence automation
- Cyber ranges, instructional labs and competition platforms
- Cohort, scholarship and program-tracking systems with sponsor reporting
- Research data platforms, catalogs and controlled-access repositories
- Instrument and core-facility scheduling and chargeback
- Student-facing service portals built to Section 508 and WCAG
Integrates with
The estate you already have.
We work through supported interfaces, not screen-scraping that breaks at the next upgrade.
Built to
The standards this sector answers to.
Engineered in from the start. Retrofitting conformance costs several times as much and produces a worse result.
Case studies
Work in this sector.
- 2023–2025Built over two years, still operating
A cyber range that a person can actually run on a Tuesday
Building an isolated hundred-machine training environment is a project. Running one every week, for cohorts and for a multi-institution competition, is a system. We built the second thing.
Read the case study- Concurrent isolated machines per exercise
- 100+
- Competition run across several institutions
- Multi-site
- 2023–202520 months, four phases
One codebase for the public site and the platform behind it
A public-facing site and an internal student-tracking platform, built years apart on stacks nobody still owned. We consolidated them into one application with one design system and one authorization model, and shipped it without a production regression.
Read the case study- Production regressions across the release window
- 0
- Unit and integration tests at handover
- 600+
- 2024–202512 months of research, through peer review
Detecting a controller that changed, without signatures
Control-network traffic is unusually regular, which makes it unusually easy to baseline. We used similarity-preserving hashes to fingerprint the steady state across a multi-vendor PLC bench and public labelled captures, then measured what it actually caught.
Read the case study- Controller vendors validated against
- 4
- Detection from deviation, not from a known-bad list
- No signatures
- 2024About four weeks
The scanner read every barcode except theirs
They had no way to say who was holding what, and a barcode scanner that would not decode their own label format — the capability was licensed separately and they had declined to buy it. Writing the decoder in C cost less than the licence and made the rest of the system possible.
Read the case study- Trackable, in and out, by holder
- Every item
- Bought to read their own labels
- No licence
- 2024–presentOngoing, still in service
Relative numbers nobody could use, referenced to magnetic north
Autonomous vehicle testing was producing position and rotation relative to wherever the vehicle happened to start, which made every run internally consistent and impossible to compare against any other. Referencing the whole system to magnetic north turned it into data a person could reason about — and it is still collecting.
Read the case study- Position and rotation, not relative
- Absolute
- Never decommissioned
- Still running
Further reading
Written up at length.
Sources
- 1.45 CFR Part 164 Subpart C: Security Standards for the Protection of Electronic Protected Health Information, Electronic Code of Federal Regulations
- 2.SP 800-171 Rev. 3: Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, NIST
- 3.32 CFR Part 170: Cybersecurity Maturity Model Certification (CMMC) Program, Electronic Code of Federal Regulations
- 4.IT Accessibility Laws and Policies, Section508.gov
- 5.Web Content Accessibility Guidelines (WCAG) 2.2, W3C,
Next step
Working in higher education & research?
Bring the specific failure, not a requirements document. Forty-five minutes and we’ll tell you what we’d do about it.