Every day, thousands of students, faculty, and staff rely on digital systems to teach, learn, research, collaborate, and connect at UMass Amherst. As technology becomes more embedded in every aspect of university life, institutions are working to keep pace with increasingly sophisticated online threats.
Recent incidents affecting institutions nationwide, including the widely used Canvas learning management system, have reinforced the importance of cybersecurity not only as a technical priority, but as a shared community responsibility.
For Jeremy Pelegrin, Chief Information Security Officer at UMass Amherst, the conversation around cybersecurity today extends far beyond firewalls and software updates. It’s about protecting teaching and research, strengthening digital trust, and helping the university community develop habits that support a safer digital environment for everyone.
“We have reached a point as a society where cybersecurity must be a responsibility for every person on the UMass campus,” Pelegrin said. “As we navigate through a changing landscape of threats and compliance requirements, it’s really about developing good cyber habits that can be applicable regardless of where the world is going to lead us.”
As technology, artificial intelligence, and online threats continue to evolve, UMass Amherst is approaching digital safety as an ongoing partnership across campus. Here are five things the community should know about how the landscape is changing and how the university is adapting alongside it.
1. Higher education presents a uniquely complex environment.
Universities support large, decentralized communities while also encouraging openness, collaboration, and academic exploration. That balance creates both opportunities and challenges.
Higher education institutions manage research environments, teaching tools, administrative systems, financial data, and personal information across an enormous range of platforms and services. At the same time, universities are designed to foster openness and exploration in ways that differ significantly from many corporate environments.
“Higher ed has so many areas with vastly different needs from a compliance and security perspective to try to protect,” Pelegrin said. “There’s a massive technology footprint for our campus to support.”
Protecting that kind of environment requires a shared approach to digital responsibility across the university community.
2. Cyber threats are evolving faster than ever
Artificial intelligence is accelerating change across the cybersecurity landscape for both defenders and attackers.
Security teams are increasingly using AI to identify patterns, process large amounts of information, and respond to threats more efficiently. But cybercriminals are also leveraging AI to create more convincing phishing attempts, impersonation campaigns, and identity-based attacks at greater speed and scale, says Pelegrin.
“The bad guys are doing the exact same thing,” he said. “They’re using AI to exploit attack vectors that we could have never seen with our legacy processes.”
As the technology evolves, so do the strategies required to defend against emerging threats.
3. Identity has become one of the biggest targets
Cybersecurity today increasingly centers around identity protection.
Compromised usernames, passwords, and email accounts can provide access to multiple systems and services, both within and outside the university environment. Identity-based attacks also tend to rely heavily on social engineering tactics designed to create urgency or exploit trust.
“Attacks appeal to someone’s emotions. They appeal to their sense of, ‘I want to help someone,’” Pelegrin said. “It allows the attacker to exploit human behavior more easily than finding a vulnerability in a technical solution.”
Practices including multi-factor authentication, strong passwords, and thoughtful account management have become increasingly important as identity-based attacks continue to grow.
4. Cybersecurity works best as a partnership.
At UMass Amherst, cybersecurity efforts continue to evolve through collaboration across the university community.
Pelegrin said the university is increasingly approaching cybersecurity as a shared responsibility that includes education, outreach, and ongoing engagement alongside technical protections.
“We have to consider our cybersecurity program holistically,” he said. “We will always need to have technical solutions, but we also must have the mindset of, ‘Let’s get a lot more people involved.’”
Security efforts across campus are increasingly focused on building shared awareness and helping the university community navigate evolving digital risks together, while continuing to support teaching, learning, research, and academic freedom.
“We want to be a partner and not a blocker,” Pelegrin said.
5. Adaptability is essential.
One of the biggest shifts in cybersecurity is the pace of change itself.
As digital tools, communication platforms, and AI capabilities continue to evolve, cybersecurity practices must evolve alongside them. Habits and assumptions that worked even a few years ago may no longer provide the same level of protection today.
“Security right now is not going to be the same as security tomorrow,” Pelegrin said. “The attackers are constantly evolving their threats, and we can’t say, ‘We’ve always done it this way,’ and expect to remain protected.”
For Pelegrin, one of the most important long-term skills institutions and individuals can develop is adaptability.
“Change is inevitable,” he said. “It’s just the reality of the space that we live in.”
UMass Amherst community members with cybersecurity questions or concerns can contact the UMass Amherst Information Security team at @email.