Converging Campus Physical-Cyber Security

Higher Education Case Study

Converging Campus Physical-Cyber Security for a State University System

Unifying access control, video surveillance, and network security under one accountable operating model — while protecting student data under FERPA.

State University System25,000 students, 3,500 staff
Illustrative scenario. This is a composite engagement model drawn from patterns across real Armorstack work — not a specific named client. Results illustrate our approach and are representative, not a guarantee.
65%
Improvement in Emergency Response
3
Threats Flagged by Correlated Intelligence
0
Student Data Breaches
47
Buildings on Mobile Credential Access
The Challenge

Physical Security and Cybersecurity Were Running as Two Disconnected Programs

A state university system needed to modernize campus security while protecting student data under FERPA. Physical security systems — badge access, cameras, emergency notification — were outdated and completely disconnected from cybersecurity operations. The IT department lacked the resources to manage both student data protection and campus safety infrastructure as two separate disciplines, and a badge anomaly at a dorm entrance had no way of ever reaching the security team monitoring the network.

FERPA complicated the fix rather than simplifying it. The Family Educational Rights and Privacy Act protects “education records” — records directly related to a student and maintained by the institution — from disclosure outside a narrow set of exceptions, chiefly the “school official” exception for staff with a legitimate educational interest. Badge-swipe logs and dorm camera footage were never written with FERPA in mind, but the moment either one is tied to an identifiable student — a specific badge ID matched to a resident roster, a timestamped clip matched to a room assignment — it starts to look a great deal like an education record. That put the university’s registrar and its security operations center in a standoff neither had resolved: the SOC needed real-time access to physical-access data to do its job, and the registrar’s office had no consistent standard for who on a security team qualified as a “school official” with a legitimate interest in seeing identifiable movement data versus de-identified, aggregate patterns. In the absence of that standard, most physical-security data simply never reached the people trying to correlate it with network activity — not because of a technical gap, but because nobody wanted to be the one who guessed wrong on a FERPA disclosure.

The Armorstack Solution

One Converged Operating Model Across All Four Portfolios

CITADELSENTRYCOREVERITY

Armorstack deployed CITADEL for campus access control, video surveillance, and emergency notification; SENTRY for student data protection and network security; CORE for research computing infrastructure; and VERITY for FERPA compliance and strategic IT planning — then built unified monitoring operations that correlate physical and cyber signals instead of triaging them in separate systems.

The first deliverable wasn’t a dashboard. It was a data-sharing agreement, negotiated with the registrar’s office, that defined exactly which physical-access fields could flow into the SOC’s correlation engine in identifiable form, which had to stay de-identified until a documented legitimate-interest trigger fired, and who on the security team was authorized to make that call at 2 a.m. Without that agreement in writing, no amount of integration between CITADEL’s badge readers and SENTRY’s network sensors would have been usable — the SOC would have had the technical ability to see identifiable student movement data and no defensible basis for doing so.

CITADEL

Campus access control, video surveillance, and emergency notification — badge readers and cameras treated as monitored security infrastructure, not standalone facilities equipment.

SENTRY

Student data protection and network security, plus the correlation engine that cross-references badge events against identity and login activity in a rolling 30-minute window.

CORE

Research computing infrastructure — the grant-funded HPC clusters and lab-managed servers supporting engineering, life-sciences, and physical-sciences research — is its own hard problem on a university network. These systems often process CUI (controlled unclassified information) or export-controlled data under ITAR/EAR for federally sponsored research, sit outside central IT’s normal patch cycle, and are frequently administered by graduate students who rotate out every semester. CORE brought this environment under production-grade lifecycle management: a documented patch cadence, endpoint monitoring on every research node, network segmentation isolating research VLANs from residential and administrative traffic, and a change-management process a principal investigator can actually use during a grant deadline instead of waiting three weeks for a ticket.

VERITY

FERPA compliance and strategic IT planning, advised at the board level — including the school-official access standard the registrar and SOC now both operate under.

Detection In Practice

What a Correlated Physical-Cyber Alert Actually Looks Like

“Correlated monitoring” is easy to promise and hard to build. This is the specific detection logic that replaced two blind spots with one signal:

1CITADEL logs a valid badge credential swiping into a residence hall at 3:14 a.m. On its own, this triggers nothing — students keep odd hours, and a single late entry is not an event.
2SENTRY’s correlation engine checks that badge event against the resident’s own access history: this student has not badged into that entrance after midnight all semester, and their class schedule has nothing that would explain the hour.
3Inside the same rolling 30-minute correlation window, SENTRY sees a login attempt to that same student’s campus SSO account from a device fingerprint and IP geolocation never associated with that account before.
4Two weak signals that would each be noise on their own become a composite risk score once they share an identity and a time window. The engine opens one ticket carrying both the badge event and the login attempt, routed to the on-call security desk — instead of two separate queues nobody was cross-checking.
5The analyst’s next move is procedural, not just technical: verify the student by phone or in person — or, if unreachable, place a temporary hold on the account and require a stepped-up MFA challenge — before pulling up any identifiable badge history, because that lookup is itself the FERPA-governed action the registrar agreement was written to control.

That mechanism is what sits behind the “3 threats flagged by correlated intelligence” figure above — a specific badge-plus-login pattern match running continuously across every residence hall on mobile credential access, not a marketing abstraction.

Outcomes

Comprehensive Security Without Compromising Compliance

I

Comprehensive, FERPA-Compliant Security

The university achieved comprehensive campus security with FERPA compliance, cut emergency response times by 65%, and protected sensitive research data.

II

Mobile Credentials, Correlated Intelligence

Students gained secure mobile-credential access across 47 campus buildings, and unified operations flagged 3 potential threat situations by correlating physical and cyber signals that had previously lived in separate systems.

III

A FERPA-Defensible Access Model

SOC analysts can view de-identified, aggregate badge-access patterns without restriction. Any drill-down that surfaces an identifiable student’s movement history now requires a logged, legitimate-interest justification the registrar’s office can review on demand — replacing an ad hoc judgment call with a standard university counsel signed off on.

Ready for Results Like These?

Armorstack converges campus physical security and cybersecurity operations for higher-education institutions balancing FERPA obligations against the need for real-time threat correlation. If badge data and network data still live in separate systems on your campus, let’s talk about what closing that gap actually requires — starting with the access agreement, not just the dashboard.Talk to Armorstack →