Skip to content
All industries
Education

Protect research IP, student records, and a network that is designed to be open.

Universities and schools run the most open networks in the enterprise world, with millions of devices, massive BYOD, and research IP worth more than most corporate secrets. Blacklight monitors behaviour without constraining academic freedom or locking down openness.

Incidents and active campaigns in your sector

The pattern is published.

Notable incidents and active campaigns in your sector. The attacker techniques are documented. The regulator timelines are running. Blacklight contains the same patterns autonomously, before the disclosure window opens.

  • US higher-ed (MOVEit campaign)
    Clop ransomware, MOVEit zero-day, 2023
    800K+ records (Univ. System of Georgia)
  • University of Sydney
    Data breach
    27K individuals
  • Rainbow District School Board
    Ransomware, Feb 2025
    Confirmed
Case in point

US higher-ed, 2023: Clop ransomware via the MOVEit Transfer zero-day

Universities run the most open networks in the enterprise world. Millions of devices, massive BYOD, research IP worth more than most corporate secrets. Clop exploited the MOVEit Transfer zero-day across hundreds of US institutions, including the University System of Georgia with 800,000+ records exposed, and Colorado State University (affected via third-party vendors using MOVEit, not a direct deployment). The breaches were often detected only after Clop named victims on the dark web. FERPA notification deadlines started the clock retroactively. Blacklight detects bulk data exfil patterns across HPC, SIS, and LMS systems in real time, including Oracle EBS and similar high-value databases. Academic-freedom-aware baselines flag true anomalies without constraining legitimate research. Ransomware precursors contained before semester-critical systems encrypt. FERPA and GDPR evidence bundled for breach notification.

The Blacklight difference
  • Correlated against live threat intel in seconds, not hours.
  • Contained autonomously, before the human analyst arrives.
  • Regulator-ready evidence, bundled and pre-drafted.
What Blacklight would do

Four moves,
on autopilot.

Every action is logged, explained, and reversible. The analyst always has the last word, but they get the case ready-made.

  • Detect bulk research data exfil across HPC and grant-funded project systems
  • Monitor SIS and LMS access for credential-stuffing and account-takeover patterns
  • Contain ransomware precursors before semester-critical systems encrypt
  • FERPA and GDPR-ready evidence for breach notification
Get started

See what truly predictive
security looks like.

Sixty minutes, under your control. See the platform run on a pre-loaded, anonymised environment, watch one real incident handled end to end, and map it to your sector, without connecting a single data source.

A typical demo
  • 01 A live tour on a pre-loaded, anonymised environment, running from minute one, not slides.
  • 02 One real incident, detected, investigated and contained, written up as a regulator-ready report.
  • 03 Mapped to your world: your sources, your sector's threats and your regulators.
  • 04 The questions your board will ask: deployment, residency, security, integrations and TCO.

No connectors or data required from you. A proof-of-value on your own telemetry is the next step, never the ask on a first call.