Independent higher education providers are becoming more digitally dependent every year. That creates risk, but it also creates an opportunity - to treat digital resilience as a strategic, institution-wide responsibility that protects student experience, strengthens operational confidence, and helps providers make better decisions about the future.
I’ve spent much of my career working inside education organisations, so I recognise the challenge of balancing student experience, operational continuity, risk, cost and limited capacity all at once. Digital dependency is not theoretical. It is part of how providers teach, assess, support students, manage operations and maintain trust.
That is why this cannot sit solely with IT. It is a leadership question about continuity, confidence and affordability. Senior teams set direction and priorities, but resilience depends on people across the organisation understanding which services matter most, what they depend on and how disruption would affect students, staff and day-to-day delivery.
Digital resilience is now a strategic issue
The shift is not just that cyber threats are increasing, although they are. The bigger point is that digital services now sit at the heart of teaching, assessment, student support, finance, admissions, identity, communications and daily operations. When they are disrupted, the impact quickly becomes institutional, not just technical.
For smaller and specialist providers, this can feel particularly acute. Lean teams may be managing complex estates, supplier relationships, cloud platforms, learning systems, data flows and identity services with limited time and capacity. One compromised account, supplier or system can affect teaching, assessment, payroll, reputation and trust.
The real risk often sits in the joins
In my experience, the hardest risks to manage are not always the ones that sit neatly in one system or one team. They often sit in the joins - between cloud services and local systems, between suppliers and internal processes, between identity and access, between the network and the user experience, and between what is documented and what only one or two people happen to know.
That is why visibility matters. Independent higher education providers do not need to be large to have complex digital dependencies. A small provider may still depend on multiple platforms, partners and processes to deliver a smooth experience for students and staff. The key question is whether those dependencies are visible, owned and manageable.
Resilience, security and affordability belong together
I do not think the answer is simply to buy more technology. In fact, that can sometimes create more complexity if it is not connected to a clear view of institutional need. The challenge is to build the right level of resilience and security into the services that matter most, in a way that is affordable and sustainable.
I find it helpful to think about this through three connected lenses: capability, cyber security and cost. Can the digital environment support what the institution needs to do next? Can it protect users, systems and data as threats evolve? And are investments being made in a way that avoids duplication, technical debt and more expensive recovery later?
Shared responsibility makes resilience practical
One of the things that struck me at Jisc’s recent Networkshop conference was the appetite for collaboration across the community. People were open about their challenges, but also clear that many are shared. No provider is facing questions about cyber resilience, cloud, identity, data, cost or user experience entirely on its own.
For many providers, the priority is not to build more complexity, but to make proportionate choices that improve confidence and reduce avoidable risk. That might mean clarifying ownership, strengthening supplier assurance, improving incident response, reviewing identity and access, or drawing on shared guidance and expertise where it helps most.
For many providers, the priority is not to build more complexity, but to make proportionate choices that improve confidence and reduce avoidable risk.
Five practical questions for senior teams
A useful starting point is to bring digital resilience into leadership and governance conversations. These questions can help move the discussion from “resilience is important” to “what should we do next?”
- Do we know which services are truly critical - including teaching, assessment, student support, finance, admissions, identity and connectivity?
- Do we understand our dependency map - including cloud platforms, third-party suppliers, network services, identity systems and key data flows?
- Could we continue operating during disruption - and have we tested incident response, business continuity, communications and recovery priorities?
- Are we investing once, well - or duplicating effort through fragmented tools, suppliers or local workarounds?
- Can we evidence improvement for stakeholders - through availability, incident response, cyber maturity, user experience and service resilience?
What different teams can do next
- Senior leaders can set priorities, agree the services the institution cannot afford to lose and ensure resilience is reflected in risk, finance and governance discussions.
- IT and digital teams can make dependencies visible, test incident response plans, review identity and access controls, and advise on practical, affordable improvements.
- Academic and professional services teams can identify where disruption would affect teaching, assessment, student support or operations, and feed that insight into continuity planning.
- Everyone can help by following cyber security guidance, reporting issues quickly and recognising that small actions can reduce institutional risk.
Start with the services people cannot afford to lose
The practical next step is not to try to solve everything at once. Start with the services students and staff cannot afford to lose. Then test the dependencies that keep them running. What happens if identity is compromised? What happens if a supplier system is unavailable? What happens if a critical service is technically available but the experience at the edge - Wi-Fi, authentication, devices or local systems - is not good enough?
Shared guidance, cyber expertise, supplier insight and community learning can help providers make stronger choices without solving every challenge alone. The value is not technology for its own sake. It is confidence: confidence that the services people rely on are understood, protected and able to keep supporting the institution through change.
Digital resilience is therefore both a leadership opportunity and a shared organisational responsibility. By asking better questions, making proportionate decisions and drawing on sector knowledge where it helps most, independent HE providers can strengthen the foundations that support learners, staff and institutional confidence every day.
If you are unsure where to begin, start by identifying the services your students and staff cannot afford to lose, then test the dependencies that keep them running. Jisc can help independent higher education providers explore practical next steps for digital resilience, cyber maturity and shared sector learning – contact [email protected].
Bella Abrams is Jisc's Group Chief Technology Officer