Authors:
Jackson Barreto
1
;
Paulina Rutecka
2
;
Karina Cicha
3
and
Pedro Pinto
1
;
4
Affiliations:
1
ADiT-LAB, Instituto Politécnico de Viana do Castelo, Viana do Castelo, Portugal
;
2
Department of Informatics, University of Economics in Katowice, Katowice, Poland
;
3
Department of Communication Design and Analysis, University of Economics in Katowice, Katowice, Poland
;
4
INESC TEC, Porto, Portugal
Keyword(s):
Cybersecurity, DNSSEC, Higher Education Institutions (HEIs), HTTPS, SSL/TLS, Security Headers, Website Security.
Abstract:
In an era marked by escalating cyber threats, the need for robust cybersecurity measures is paramount, especially for Higher Education Institutions (HEIs). As custodians of sensitive information, HEIs must ensure secure channels for data transmission to protect their stakeholders. These institutions should increase their cyber resilience, recognizing the heightened risk they face from cybercriminal activities. A breach in an HEI’s cybersecurity can have severe consequences, ranging from data confidentiality breaches to operational disruptions and damage to institutional reputation. This paper conducts a comprehensive evaluation of the cybersecurity mechanisms in HEIs within Poland. The focus is on assessing the adoption of important web security protocols—Hyper Text Transfer Protocol Secure (HTTPS) and Domain Name System Security Extensions (DNSSEC)—and the implementation of security headers on HEI websites. This study aims to provide a snapshot of the current cyber defense maturity
in HEIs and to offer actionable insights for enhancing web security practices. The findings indicate a high adoption rate of HTTPS among HEIs, yet reveal significant gaps in web security practices. Also, there is a low adherence to security headers and an absence regarding DNSSEC implementation across the surveyed institutions. These results highlight crucial areas for improvement and underscore the need for HEIs in Poland to strengthen their web security measures, safeguarding their data and enhancing the overall cybersecurity resilience.
(More)