Ohio University CIO resigns in wake of data breaches
William Sams says a 'new energy level and skill set' needed
Computerworld - William Sams, the CIO of Ohio University in Athens, Ohio, has submitted his resignation weeks after the university disclosed a series of information security breaches that exposed the personal information of tens of thousands of students and alumni.
Sams will continue in his role until a replacement is found, according to a statement on the university’s Web site.
Two top IT staffers -- the university's director of communication network services and the manager of Internet and systems -- have already been suspended and face possible termination over the incidents.
"The IT organization at Ohio University is positioned for a major transition into a 21st century leadership position," Sams was quoted as saying in the statement. "However, it has become clear to me that a new energy level and skill set is going to be required in order to allow our IT organization to realize its potential," he added.
The development should come as no surprise to anyone, given the scope of the breaches, said Pete Lindstrom, an analyst at Spire Security LLC in Malvern, Pa.
But "whether or not the CIO was really at fault in any of this is anybody’s guess," Lindstrom said. "Only the insiders will know if he could have done more and didn’t or whether there was a more persistent problem to begin with," he said.
Sams’ resignation comes amid an IT reorganization that is being implemented on the recommendation of an external consulting firm brought in to audit the university’s security after several breaches were discovered between late April and early June this year.
The audit report from Naperville, Ill.-based Moran Technology Consulting LLC identified a siloed culture and a quasicombative relationship between the university’s network and computer services groups as reasons for a relative lack of good security practices.
Based on recommendations from the audit, the university began restructuring its central IT group. As part of the effort, the university is assigning formal roles, responsibilities and accountability for those working in its central IT organization. About 90% of the staff working in this group are expected to be affected by the restructuring.
The university also plans to deploy real-time and scheduled measures for protecting its systems against viruses on every Windows-based server.
The changes come after the discovery of five separate security breaches, including one that exposed personal information on 137,000 people. The first one was uncovered on April 21, when the FBI informed the university that it had in its possession disk drives containing patent and intellectual property data from a server at the university's Innovation Center.
Less than a week later, university IT officials disclosed that someone had broken into a server supporting alumni relations and had remained undiscovered for more than a year. In early May, the university said that a system belonging to its Hudson Health Center had been broken into, potentially exposing Social Security numbers, dates of birth, patient IDs and clinical information on nearly 60,000 current and former students and faculty.
It was at this stage that Moran was called in to review systems housed in the university's computer services center. That review resulted in the discovery of two more security holes.
Read more about Security in Computerworld's Security Topic Center.


- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Driving Secure Enterprise File Sharing and Syncing in the Enterprise
- GroupLogic's new activEcho is the industry's only secure Enterprise File Sharing and Synching solution that balances the need for simplicity for the end...
- The Enterprise File Sharing Option
- Enterprises and IT departments need to address several critical security issues when considering file sharing and syncing products. Many of today's solutions do...
- Security Strategies to Virtualizing Internet-Facing Applications
- The IT organization at Intel has set a goal to transition their enterprise to a private cloud for their Office and Enterprise applications....
- Cloud Security Planning Guide
- Cloud security considerations span protecting hardware and platform technologies in the data center to enabling regulatory compliance and defending cloud access through different...
- Cloud Security Vendor Round Table
- This vendor round table guide will help you to evaluate different cloud technology vendors and service providers based on a series of questions... All Security White Papers
- Live Webcast
Data Privacy and Protection in Production Environments: New Research from Ponemon Institute - Date: Wednesday, June 13, 2012, 1:00 PM EDT / 10:00 AM PDT
In a recent study conducted by Ponemon Institute, fifty-five percent of respondents... - Data Privacy and Protection in Production Environments: New Research from Ponemon Institute
- Date: Wednesday, June 13, 2012, 1:00 PM EDT / 10:00 AM PDT
In a recent study conducted by Ponemon Institute, fifty-five percent of respondents... - Security Certifications 101 - BlackBerry and all those acronyms what do they mean and why they matter?
- FIPS, Common Criteria, CAPS, AISEP, NFC, NIST, Fraunhofer SIT, CESG, DSD - these are just some of the government and industry certifications which...
- BlackBerry PlayBook OS 2.0 Security Overview
- The presentation provides an overview of BlackBerry PlayBook OS 2.0 security capabilities and features, including: BlackBerry® Balance™ technology, BlackBerry® Bridge, data-at-rest protection, and...
- BlackBerry NFC Security Overview
- The presentation on NFC security will provide an overview of the security protections built into the BlackBerry platform to protect users, application developers...
- Playing Defense: Staying on Top of Your Disaster Recovery Game
- When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing... All Security Webcasts