Two Campus Shutdowns Later, Pennsylvania's Public Universities Are Finally Buying Collective Cyber Defense
Back-to-back ransomware attacks that physically closed two Pennsylvania community colleges in March 2026 forced the state university system to confront a defense gap it had been deferring for years.
Pennsylvania's public institutions have issued five cybersecurity solicitations in the last 30 days against a 12-month monthly average of one, a fivefold spike, and the first time the state's university system has driven that number rather than school districts or pension funds.
The proximate cause is not a new state mandate or a federal deadline. It is two physical campus closures.
In March 2026, Lehigh Carbon Community College was hit by the Medusa ransomware group, which demanded $100,000 and locked the college out of grades, transcripts, and financial systems. Campuses closed for more than a week, with some satellite sites staying dark even longer. Days later, the Interlock group struck Community College of Beaver County, claiming 780 gigabytes of stolen data, and CCBC's campus did not fully reopen until March 30. Two Pennsylvania colleges, two ransomware gangs, one month. Students lost access to coursework mid-semester. Staff lost access to the systems that run the institution.
In H1 2026, one-third of global ransomware attacks on higher education hit U.S. institutions
Source: NationGraph.
The rest of the state's public higher-education system noticed.
On September 1, 2026, the Pennsylvania State System of Higher Education issued a statewide Cybersecurity and Managed Security Services RFP covering the System Office and all 10 PASSHE universities, which together enroll 82,688 students. It is the most significant enterprise security procurement the system has ever attempted, and it exists because PASSHE's universities have never had one: each campus has historically managed its own defenses, absorbing the full cost and complexity of an attack alone. The March closures were a live demonstration of what that model looks like when it fails.
A second solicitation arrived from a different sector. SEPTA, Philadelphia's regional transit authority, issued a firewall licensing RFP due September 3, the agency's most visible cybersecurity procurement since a 2020 malware attack left it still recovering weeks later. SEPTA's timing has a second explanation beyond the campus attacks: CISA added Cisco firewall vulnerability CVE-2026-20349 to its Known Exploited Vulnerabilities catalog in August 2026, setting a federal upgrade deadline of August 14. Transit operators running unpatched Cisco infrastructure faced a hard compliance clock, independent of anything happening on a college campus.
Those two procurements are the substantive new ones. Three of the five logged RFPs are successive versions of the SEPTA firewall solicitation, the raw count overstates the breadth of the surge, but not its urgency.
Nationally, ransomware attacks on higher education trended upward through the first half of 2026, with the United States accounting for the largest share of confirmed incidents globally. Pennsylvania's March attacks fit a documented escalation pattern, not an isolated run of bad luck. Medusa and Interlock, the groups behind the two Pennsylvania strikes, have both expanded their targeting of institutions with lean IT staffing and high data value, exactly the profile of a regional community college.
Pennsylvania does have substantial federal cybersecurity investment flowing in. The state holds $34.5 million in currently active federal grants: $18.8 million from NSF and $10.8 million from DHS, with recipients including Penn State, Carnegie Mellon, Lehigh University, Drexel, and Temple. But those grants are heavily oriented toward AI-cybersecurity workforce education and research, building the pipeline of future security professionals, not patching the operational gaps that left two colleges unable to open their doors in March. The PASSHE RFP is addressing a different layer of the problem: managed detection, response, and monitoring, the day-to-day infrastructure that determines whether an intrusion becomes a closure.
Pennsylvania's IT governance structure makes the procurement gap easier to understand. Executive Order 2016-06 gives the Office of Administration enterprise security authority over state agencies, but PASSHE is an autonomous entity and cannot simply piggyback on commonwealth contracts. The system must self-procure, which is why 10 universities spent years without a consolidated security services contract and why the PASSHE RFP, now that it exists, represents a structural shift rather than a routine renewal.
For students and staff at PASSHE's 10 universities, the practical question is whether a vendor selected under this RFP can actually deliver unified visibility across campuses with different legacy infrastructure. For Pennsylvania's community colleges, which sit outside PASSHE and have no equivalent centralized solicitation on the horizon, the March attacks remain an unresolved warning.
The SEPTA firewall award and the PASSHE vendor selection will both be visible within the next few months. Whether the community college sector, the institutions that actually absorbed the shutdowns, moves toward any collective procurement is the open question the current RFP surge does not yet answer.