Two top IT officials at Ohio University (OU) who were suspended in June in connection with data security breaches at the school in recent months were fired yesterday.
In a statement, the Athens, Ohio-based school announced that Tom Reid, the university’s director of communication network services, and Todd Acheson, the manager of Internet and systems for the school, were dismissed in the wake of the breaches — including one that exposed personal information on 137,000 alumni.
The firings come three weeks after the school’s CIO, William Sams, resigned following the disclosure of the security breaches.
Last week, the university announced a 20-point plan to improve information security at the school, which has about 16,640 undergraduate students and 862 full-time faculty members on its Athens campus.
The initiatives that are scheduled to be completed over the next nine to 12 months include the installation of a perimeter firewall, implementation of a system to classify data by the level of security required and an effort to reduce the use of Social Security numbers at the university. When Social Security numbers are needed, the school plans to encrypt them. Also planned is the reorganization of the school’s central IT organization to establish clear roles and responsibilities for each division.
The initiatives are expected to cost between $5.5 million and $8 million.
The changes at OU follow a review of an independent report commissioned to assess the university’s IT security practices. The first breach involved a server containing patent data and intellectual property files at the university’s Innovation Center. That breach was discovered when the FBI told the university it had been provided with disk drives from the server.
A few days later, IT officials noticed that a server supporting alumni relations and development had been compromised and was being used to launch distributed denial-of-service attacks against an external target. That breach — which had remained undiscovered for more than a year — prompted the university to notify alumni of the potential compromise of their Social Security numbers and other personal data.
Then, on May 4, the university discovered that a system belonging to its Hudson Health Center had been broken into, potentially exposing Social Security numbers, dates of birth, patient IDs and clinical information on nearly 60,000 current and past students and faculty.
The discovery of the three break-ins prompted the school’s IT organization to bring in outside experts to conduct a sweeping review of systems housed in the school’s Computer Services Center. The review led to the discovery of two more breaches: One involved a computer that contained IRS 1099 forms for nearly 2,500 vendors and contractors that had done work for the university in 2004 and 2005; the other involved a computer that hosted a variety of Web-based forms, including some that processed online business transactions.




