Higher Education & Research
The most open network in the country, holding some of the most sensitive work in it.
A research university is a genuinely hard security and software environment, and it is hard for reasons that are structural rather than fixable. Openness and collaboration are the mission, not an oversight. Faculty are not employees in the way a corporate security model assumes. Federal sponsors impose obligations that arrive as terms in an award document rather than as a control framework. And the same institution is simultaneously a hospital, a utility, a hotel chain, a payment processor and a defense subcontractor. We have built and run software on this side of the fence, and we design for the institution that exists rather than the one an enterprise architecture diagram would prefer.
What we hear
The problems that actually show up.
Not a market overview. These are the specific failures that bring people to us in this sector.
Research security asked for as a question nobody can answer
NSPM-33 and the sponsor disclosure regime expect an institution to know its researchers’ outside affiliations, subawards and collaborations. That information exists, scattered across conflict-of-interest filings, publication records, award documents and public data, and nobody has ever joined it up.
Controlled data in an uncontrolled environment
One award brings CUI into scope and suddenly a lab that has always worked in the open needs a NIST 800-171 enclave, a system security plan and a POA&M, on the timeline of the award rather than of the IT department.
Program administration eating the program
Cohort tracking, placements, completion evidence and reporting to a sponsor run on spreadsheets maintained by the person who has the least time. Programs are lost to administrative overhead far more often than to bad outcomes.
A workforce pipeline that stops at the diploma
The institution graduates capable people every year and the regional employers who need them have no structured way to meet them before an interview.
Instructional infrastructure that cannot scale
Hands-on technical courses need isolated environments per student, reset between sections and available at 2am the night before it is due. Building that once is a project; running it every semester is a system.
What we build here
Systems we typically build in this sector.
Some of these are whole products; some are one screen that removed a week of manual work. Both count.
- Research-collaboration graphs and affiliation risk review tooling
- Sponsored-program, subaward and disclosure workflow systems
- CUI enclaves and NIST 800-171 system security plan evidence automation
- Cyber ranges, instructional labs and competition platforms
- Cohort, scholarship and program-tracking systems with sponsor reporting
- Research data platforms, catalogs and controlled-access repositories
- Instrument and core-facility scheduling and chargeback
- Student-facing service portals built to Section 508 and WCAG
Integrates with
The estate you already have.
We work through supported interfaces, not screen-scraping that breaks at the next upgrade.
Built to
The standards this sector answers to.
Engineered in from the start. Retrofitting conformance costs several times as much and produces a worse result.
Case studies
Work in this sector.
- 2023–2025Built over two years, still operating
A cyber range that a person can actually run on a Tuesday
Building an isolated hundred-machine training environment is a project. Running one every week, for cohorts and for a multi-institution competition, is a system. We built the second thing.
Read the case study- Concurrent isolated machines per exercise
- 100+
- Competition run across several institutions
- Multi-site
- 2023–202520 months, four phases
One codebase for the public site and the platform behind it
A public-facing site and an internal student-tracking platform, built years apart on stacks nobody still owned. We consolidated them into one application with one design system and one authorization model, and shipped it without a production regression.
Read the case study- Production regressions across the release window
- 0
- Unit and integration tests at handover
- 600+
- 2024–202512 months of research, through peer review
Detecting a controller that changed, without signatures
Control-network traffic is unusually regular, which makes it unusually easy to baseline. We used similarity-preserving hashes to fingerprint the steady state across a multi-vendor PLC bench and public labeled captures, then measured what it actually caught.
Read the case study- Controller vendors validated against
- 4
- Detection from deviation, not from a known-bad list
- No signatures
- 2024About four weeks
The scanner read every barcode except theirs
They had no way to say who was holding what, and a barcode scanner that would not decode their own label format; the capability was licensed separately and they had declined to buy it. Writing the decoder in C cost less than the license and made the rest of the system possible.
Read the case study- Trackable, in and out, by holder
- Every item
- Bought to read their own labels
- No license
- 2024–presentOngoing, still in service
Relative numbers nobody could use, referenced to magnetic north
Autonomous vehicle testing was producing position and rotation relative to wherever the vehicle happened to start, which made every run internally consistent and impossible to compare against any other. Referencing the whole system to magnetic north turned it into data a person could reason about, and it is still collecting.
Read the case study- Position and rotation, comparable across runs
- One frame
- Never decommissioned
- Still running
Further reading
Written up at length.
- Security5 min read
You cannot practice on somebody else's network
A range full of well-built generic scenarios teaches tool proficiency, which is real and which transfers. The decisions that go wrong during an actual incident are specific to one estate, and those are the ones a generic environment cannot rehearse.
- Strategy6 min read
Cited rather than ranked
An answer engine does not hand out positions. It retrieves passages, writes an answer and names the sources it leaned on, which makes the unit of work a section rather than a page and makes most of what is sold as AI SEO unmeasurable.
- Security6 min read
TX-RAMP § 6.2: the exemption a custom build may already have
A Texas university asks for your TX-RAMP certification and the project stops for a quarter. For software the institution commissioned, the program manual says certification does not apply, and then attaches four conditions that decide whether you actually get it.
Sources
- 1.45 CFR Part 164 Subpart C: Security Standards for the Protection of Electronic Protected Health Information (opens in a new tab), Electronic Code of Federal Regulations
- 2.SP 800-171 Rev. 3: Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations (opens in a new tab), NIST
- 3.32 CFR Part 170: Cybersecurity Maturity Model Certification (CMMC) Program (opens in a new tab), Electronic Code of Federal Regulations
- 4.IT Accessibility Laws and Policies (opens in a new tab), Section508.gov
- 5.Web Content Accessibility Guidelines (WCAG) 2.2 (opens in a new tab), W3C,
Next step
Working in higher education & research?
Bring the specific failure, not a requirements document. Forty-five minutes and we’ll tell you what we’d do about it.
- Phone
- (214) 723-2510
- Reply
- A person replies, not a sequence: within one business day, from someone who would be on the engagement.