2026 State of Information Security


I’m pleased to present our FY2026 Information Technology Security Report. This report reflects our ongoing commitment to protecting the University of Missouri System’s information resources while enabling the university’s missions of teaching and learning, research, health care and service.
As technology continues to evolve and cyber threats become increasingly sophisticated, information security remains both a strategic imperative and a shared responsibility. Our mission is to provide policies, processes and tools that protect university data and technology resources while supporting innovation, collaboration and institutional success.
Why Security Matters:
- Protecting Mission-Critical Resources: Secure and reliable technology is essential to supporting education, research, health care and university operations.
- Managing Evolving Risk: Cyber threats continue to grow in complexity, requiring proactive investments in prevention, detection and response capabilities.
- Maintaining Compliance and Trust: Strong security and privacy practices help protect sensitive information, support regulatory compliance and reinforce the confidence of our stakeholders.
- Ensuring Operational Resilience: Effective risk management and business continuity planning help the university remain prepared for disruptions and recover quickly when incidents occur.
Key Accomplishments in FY2026:
- Advanced Research Cybersecurity: UM System became one of the first organizations in the nation to achieve Cybersecurity Maturity Model Certification (CMMC) Level 2, expanding opportunities for federally funded research involving sensitive data.
- Expanded Enterprise Risk Management: We strengthened our Information Security Risk Management Program through enhanced compliance assessments, business continuity planning and standardized risk governance practices.
- Improved Security and Compliance Capabilities: We continued to enhance monitoring, auditing and security operations while supporting accessibility, privacy and regulatory compliance initiatives across the UM System.
Looking Ahead:
As we prepare for FY2027, we will continue focusing on initiatives that strengthen our security posture while supporting the university’s strategic objectives.
Thank you for your continued support and leadership. Together, we are building a secure, resilient and trusted digital environment that enables innovation, protects our community and advances the mission of the system.
Sincerely,
Becky Fowler
Chief Information Security Officer (CISO)
Our Mission: The Information Technology Security Office enables and supports the strategic mission of
the University of Missouri by providing policies, processes, and tools to protect the information resources
of the university.
Our strategic objectives:
- Protect the university’s information technology systems and information assets from unauthorized access, alteration, disclosure or destruction.
- Support the University’s mission of education (teaching and learning), research and engagement (outreach and service).
- Ensure the reliability and availability of the university’s Information Technology systems and information assets.
- Ensure the privacy of faculty, staff and student information and that of other university customers or associates.
- Protect the reputation of the university and ensure compliance with federal and state laws and regulations.
- Establish resources and guidelines that allow all individuals within the university community to practice good data stewardship.
The Information Technology Security Office (ITSO)
This office is comprised of the Chief Information Security Officer (CISO) and an Information Security Officer (ISO) representing each university campus and MU Health Care. Each campus ISO has at least one security analyst in their reporting line. The ISOs and their security analysts collaborate regularly to address operational issues and plan for future improvements.
Security Operations (SecOps)
This team develops policies, processes and practices intended to keep data secure from unauthorized access or alterations. To prevent incidents, the SecOps team proactively monitors the university’s network and IT assets to identify and remediate potential security issues before they are exploited. In addition, SecOps strategically positions security experts and adapts processes to ensure a quick and adequate response to security incidents.
Identity Management (IdM)
The IdM team manages 600,000 accounts of various types. They create and manage policies, standards and processes designed to ensure that authorized people – and only authorized people – have access to the technology resources needed to perform their job functions. This work entails designing and using technically enforced rules regarding who is eligible for an account, for how long and with what level of access.
IT Procurement and Compliance
This team coordinates IT security reviews for purchases that involve information technology. These reviews are essential to maintaining an environment capable of supporting university activities in a secure manner.
Information Security Risk Management (ISRM)
This team focuses on information security risk management to help the university address federal, state and regulatory risk assessment requirements. Working closely with the Office of Ethics, Compliance and Audit Services, UM Privacy, UM Risk Management and UM Office of General Counsel, this team is actively deploying our information security risk management program.
The university’s Security Operations Center (SOC) is in its sixth year of existence. Staffed by security analysts from all four universities and MU Health Care, this system-wide effort provides coverage during business hours and an escalation process after hours to address known or suspected security incidents. SOC analysts identify indicators (alerts) of potential compromise, review and evaluate information about potential cyberattacks, and integrate industry-specific threat intelligence into actionable plans. Security threats are automatically categorized as high, medium, low and informational. The severity of an alert is indicative of the impact it can have on information assets. The higher the severity, the greater the potential impact. A member of the Security Operations Team triages each alert.
The Information Technology Security Office (ITSO) continues to leverage Microsoft Secure Score, a built-in measurement of the security posture of our Microsoft environment that includes email and Microsoft collaboration software such as SharePoint, Teams and OneDrive. Microsoft Secure Score is a continually changing, numerical summary of our security posture based on system configurations, user behavior and other security-related measures. Secure Scores also change when new security threats are identified, resulting in lower scores until institutions mitigate the threat(s). Our Secure Score is not an absolute measurement of the likelihood our systems or data will be breached. Rather, it represents the extent to which we have adopted Microsoft recommended security controls to help manage risk.
Our team’s goal is to remain a minimum of 20 percentage points above Microsoft’s “organizations like yours” score. As of June 29, 2026, our Microsoft Secure Score was 71%, compared to 50% for other similar organizations.
This represents a very dynamic score. It is an evaluation of approximately 280 controls across 40,000 devices and 400,000 accounts. As new vulnerabilities and risks emerge, new mitigations come into play and are reviewed and applied by the Secure Score working group. This data represents the extent to which we have adopted security controls in our Microsoft environment that can help offset the risk of being breached. The total score is always a moving target as Microsoft releases new recommendations, archives old ones and changes the available score often. The total available score at the time of this graph was 1,602 points.
The University of Missouri and the UM System continue to strengthen their leadership in research cybersecurity through the achievement of Cybersecurity Maturity Model Certification (CMMC) Level 2, placing the institution among the first organizations in the nation, and within the top 1%, to meet this rigorous federal standard. This milestone positions researchers across the UM System to pursue a growing number of federal funding opportunities that require the secure handling of Controlled Unclassified Information (CUI), including projects sponsored by the Department of Defense, NASA, the National Institutes of Health and other federal agencies.
Building on the successful certification of the MU Center for Geospatial Intelligence, the university expanded secure research capabilities through the Arculus Research Enclave System, which achieved CMMC Level 2 certification in January 2026. Managed by the MU IT Research Support and Security team and available to researchers throughout the UM System, Arculus provides a secure, compliant environment for storing, managing and analyzing sensitive research data while supporting the university’s long-term research growth and competitiveness.
Leading the way
- Among the first organizations in the nation, and within the top 1%, to achieve CMMC Level 2 certification.
- Enables researchers across the UM System to compete for federally funded research involving Controlled Unclassified Information (CUI).
- Expanded secure research infrastructure through the CMMC-certified Arculus Research Enclave System.
- Strengthens the university’s ability to attract research funding in national security, defense, health sciences and other highly regulated fields.
The Identity and Access Management (IdM) team plays a pivotal role in ensuring the security and efficiency of UM System’s electronic identities and access controls. Their responsibilities encompass the lifecycle management of all centrally managed accounts, including provisioning, deprovisioning and modifications across various platforms such as Active Directory, Azure, Exchange and Google accounts.
The IdM team achieved notable progress in enhancing the system’s electronic identities and access controls over the past year. Currently, the IdM environment manages 1,714,821 identity and username reservations, along with 499,550 active accounts. This impressive scale highlights IdM’s essential role in ensuring secure access and efficient user lifecycle management across the organization.
A key achievement this year was the continued expansion of Grouper, an access management and governance tool. Grouper now supports 674 groups, 2,174,475 memberships and 567,660 unique members.
This growth demonstrates the team’s dedication to integrating more applications and user groups into Grouper.
The Information Security Risk Management Program identifies IT risks and implements safeguards and plans to address and manage those risks.
During FY26, the University of Missouri System continued to mature its Information Security Risk Management Program through a coordinated focus on compliance, institutional resilience and enterprise risk governance. A key accomplishment was the launch of a structured HIPAA compliance assessment program across covered components throughout the UM System, establishing a baseline for identifying compliance risks and strengthening oversight of regulatory requirements.
The program also expanded business continuity and disaster recovery efforts for critical university systems, refining incident response processes, updating recovery plans and incorporating lessons learned from security events to enhance operational preparedness.
To improve enterprise risk visibility and decision-making, the program introduced standardized risk domains and risk reporting frameworks across areas such as identity and access management, third-party and vendor risk management, and enterprise architecture.
In addition, the team coordinated significant internal audit and compliance activities related to IT governance, network controls, security monitoring and vendor risk management. Together, these efforts strengthen the university’s ability to identify, assess and mitigate cybersecurity risks while supporting regulatory compliance, operational resilience and the protection of institutional information assets.
Strengthening institutional resilience
- Expanded HIPAA compliance oversight
- Enhanced business continuity and disaster recovery planning
- Improved incident response and post-incident review processes
- Standardized risk identification and reporting
- Strengthened governance through audit and compliance activities
Building on the Division of IT’s strategic plan, we are prioritizing and working on the following priorities:
Implement Phishing-Resistant Multifactor Authentication
Phishing attacks are becoming more sophisticated and can bypass traditional Multifactor Authentication methods like text codes and push notifications. To further enhance the University of Missouri System’s data security, the Information Security team is transitioning to phish-resistant multifactor authentication. This recommendation adds additional safeguards to protect against sophisticated phishing attempts and will be implemented for access to sensitive systems. Phishing-resistant authentication is designed to stop these attacks by ensuring login credentials can’t be intercepted or reused, even if a user interacts with a malicious message.
Identify and Implement an Identity Proofing Solution
Reduce fraud and impersonation risks by confirming that individuals are legitimate. Identity proofing helps ensure that the right identity is established before the right access is granted. The implementation of an updated solution can help the university reduce fraud, strengthen access controls, improve compliance, and increase trust in the overall identity and access management program.
Azure Information Protection Investigation
Investigate Azure Information Protection, a Microsoft tool to discover, classify and protect sensitive data in the MS environment. Plan and deploy technology to know our data, protect our data and prevent data loss.
MU Health Care Security Partnership
Work with MU Health Care to optimize security and support capabilities in areas where employees hold dual roles (academic/administrative and clinical).
Staffing/Succession Planning
With increased competition for IT Security talent, ensure the university remains competitive and able to attract top talent to deliver results.
IT Risk Management Program
Continue to proactively assess IT risk for enterprise essential systems. Partner with campuses to extend the risk management program.
Identity Management Quality Assurance Efforts
Review existing applications and code to identify opportunities to further stabilize the Identity Management processes that underlie all technology at the university. Increase and enhance the use of Multifactor Authentication in the university environment.
1. Phishing/Social Engineering
- Description: Deceptive tactics (emails, calls, texts) to trick users into disclosing credentials or installing malware
- Impact: Compromised accounts, financial loss, data breaches
- How we’re addressing: Mandatory cybersecurity awareness training for all users. Implement phishing-resistant multifactor authentication (MFA). Conduct quarterly phishing awareness simulations and training. Use AI-driven email filtering and detection tools. Provide a “Report Phishing” function in email clients.
2. Ransomware Attacks
- Description: Malware that encrypts systems/data and demands a ransom for release
- Impact: Loss of access to critical services, reputational damage, financial costs
- How we’re addressing: Perform regular, automated and encrypted backups of all critical systems. Patch and update software routinely. Segment networks to limit lateral-movement of malware. Maintain an incident response plan with ransomware-specific protocols.
3. Unpatched/Legacy Systems
- Description: Outdated or unsupported systems introduce known vulnerabilities
- Impact: Increased susceptibility to exploitation and data compromise
- How we’re addressing: Maintain a centralized inventory of hardware/software. Enforce automatic patching for OS and applications. Decommission unsupported platforms or isolate them from the main network. Establish a technology refresh cycle (e.g. every 3-5 years).
4. Data Privacy & Regulatory Noncompliance
- Description: Improper handling of sensitive data may violate FERPA, HIPAA, GDPR, etc.
- Impact: Legal penalties, loss of funding, reputational harm
- How we’re addressing: Use data classification and tagging tools (e.g. Microsoft Purview). Encrypt sensitive data at rest and in transit. Apply role-based access controls. Conduct annual audits for compliance and data access reviews. Work with General Counsel, Risk Management and Privacy to coordinate efforts.
5. Third-party & Vendor Risks
- Description: Security issues with external software, platforms or services
- Impact: Indirect data breaches, service disruption
- How we’re addressing: Perform vendor risk assessments and require SOC2 or equivalent security attestations. Include security requirements in procurement contracts (e.g. breach notification, data encryption). Use third-party risk management platform for continuous monitoring. Limit third-party data access based on the principle of least privilege.