# Florida Higher Ed Seeks Penetration Testing

A regional higher education institution in Florida is actively seeking affordable penetration testing services tailored to the complex and regulated environment of the higher education sector. The institution faces challenges including diverse network segmentation, multiple campuses, compliance with regulations such as FERPA, GLBA, PCI, HIPAA, and the need to address risks from ransomware, credential theft, and insider threats. Budget constraints and the need for pragmatic, risk-prioritized findings are critical factors influencing vendor selection. Public institutions may leverage state CISO programs for support, while private schools must independently source qualified vendors. Community feedback highlights significant price increases from some providers, emphasizing the importance of competitive pricing and appropriate scoping for smaller institutions.

- Procurement professionals should note the specialized requirements of higher education pen testing, including compliance evidence for auditors and grantors.
- Vendors with experience in education sector cybersecurity and flexible pricing models may find opportunities in this market.
- Institutions must consider academic calendar constraints and operational impacts when scheduling testing and remediation.
- Risk prioritization and pragmatic remediation recommendations are essential due to lean IT teams and budget limitations.

**Jurisdictions:** federal
**Industries:** Education
**Topics:** Cybersecurity
**Published:** September 28, 2026

### Vendors
- GuidePoint Security (pen testing provider)
- NetSPI (pen testing provider)
- Kroll (pen testing provider)
- Pondurance (pen testing provider)

### Key Quotes
> We partner with ICUF schools and the vendor we shared drastically raised their prices to where we were quoted $175k to test our network and ERP systems only. We only have 1000 employees with 3200 student users so that price was a bit elevated for us considering students don't connect to our systems. The vendor got a large enterprise contract so we are getting the "we don't want to work with you" rates. The price jumped $140k plus in 1 year when we asked for less to be tested.
> — Community commenter

> Open, decentralized networks with large public IP space and shadow IT; Unmanaged student devices, BYOD, and IoT sharing infrastructure with admin systems; Segmentation between residential, guest, academic, and admin networks as a key test area; Multiple campuses, remote sites, and third-party hosted services; Mixed regulated data: FERPA, GLBA, PCI, HIPAA (clinics), NCAA, export-controlled research; Reports doubling as compliance evidence for insurers, auditors, and grantors; Heavy ransomware, credential theft, and phishing targeting; Technically curious student insiders with legitimate access; Identity sprawl from alumni, applicants, adjuncts, affiliates, and student workers; Academic calendar blackout windows (registration, finals, move-in, financial aid); Academic freedom and departmental autonomy make remediation harder to enforce; Lean teams and budgets, so risk-prioritized findings and pragmatic fixes matter; Legacy and specialized systems (ERP, building controls, lab equipment) that are hard to test or patch; Retesting needed to demonstrate closure to leadership and auditors
> — Original poster

### Sources
- [Higher Ed Pen-Testing Recommendation Please](https://www.reddit.com/r/cybersecurity/comments/1wsk55m/higher_ed_pentesting_recommendation_please) - reddit-cybersecurity