Mike Tyson once said, "Everyone has a plan until they get punched in the mouth."
On a campus, that punch usually comes in the form of a disruption everyone assumed the institution was ready for.
It might be a failed backup, an outage during registration or a security incident that exposes a weakness nobody knew existed.
That's the thing about assumptions. They feel like facts right up until they're tested.
Here are four that regularly catch institutions off guard.
Assumption #1: "We're backed up"
Having an untested backup is like carrying a spare tire in your trunk and finding out it's flat when you're stranded on the side of the road.
Most institutions know backups exist. Someone has seen the reports, the notifications and the green checkmarks. However, only a few can confidently say when they last tested a restore, how long recovery would take, or whether the SIS, LMS, email and every departmental system are actually included.
Departmental servers are where this assumption usually breaks. The systems central IT manages are covered. The research share in one college, the lab machine in another and the database a single staff member set up years ago often aren't.
A backup proves its value only when it helps you recover. The most dangerous backup is the one nobody has ever tested.
Assumption #2: "Someone would tell us if there was a problem"
Institutions invest real money in monitoring tools that catch problems fast and alert immediately. Confusing detection with response is an assumption that gets expensive.
A weather alert can tell you a hurricane is coming. It doesn't board up your windows or move your family to safety. The alert is useful only if someone knows what to do next.
Your monitoring tool works the same way. It tells you something is wrong. What happens after that alert goes off — at 2 a.m., over winter break, when your one security analyst is on vacation — is up to you. The GLBA Safeguards Rule expects a documented answer to that question, not an assumption.
Assumption #3: "Our team knows what to do"
Every team looks prepared until game day.
Late one Friday afternoon, a critical system goes offline and suddenly nobody can agree on who's in charge, what to restore first or how long it will take. On a campus with distributed IT, that confusion multiplies: central IT, the college's own technicians and a vendor are all waiting for someone else to make the call.
When there's no documented plan and no practice run, even a good team is starting from zero.
You don't run a fire drill because you expect the building to burn down tomorrow. You do it so that if there ever is a fire, nobody is standing around asking which way to run.
A recovery plan works the same way. When something goes wrong, you don't want your team figuring things out on the fly. You want them following a plan they already know.
Chaos rarely comes from the disruption itself. More often, it comes from not knowing what to do next.
Assumption #4: "It won't happen to us"
Nobody thinks they'll be the one. Until they are. And higher education is now one of the most heavily targeted sectors there is — attackers know campuses hold rich personal data, run open networks and can't afford downtime during a term.
When you're focused on enrollment, students and keeping the term running, a serious disruption feels like something that happens to other institutions. Not yours.
But most disruptions are ordinary. A staff member clicks a bad link in a phishing email, a power event hits a data closet or aging hardware finally gives out. Increasingly, it's also someone pasting FERPA-protected student data into an AI tool nobody approved.
The question isn't whether something unexpected will happen. It's whether you'll be ready when it does.
The institutions that recover fastest aren't the ones that avoided the disruption. They're the ones that expected it.
You can't block a punch you didn't prepare for
In our experience, it's never the big dramatic event that catches institutions off guard. It's the ordinary one that happens on a Wednesday in the middle of midterms.
The good news is that most of these risks can be addressed before they become institutional problems. And that's exactly what we help campuses do — working alongside your existing IT staff, not around them.
We offer 10-minute discovery calls to help administrators and IT leaders understand where they stand. We'll walk through your backups, recovery process and continuity plans to identify what's been tested, what hasn't and where gaps may exist.
One assumption worth adding to the list: that faculty and staff already know how to use AI safely with student and research data. That's why we created Project NoéMI™, our AI-readiness initiative credentialed with George Mason University, built to help faculty and staff become confident, capable AI users — and the first step is completely free.
Sign up for the free AI Acceleration Platform: https://forms.newpush.com/join-noemi-trainer. Want to check your other assumptions first? Call us at 1-303-423-4500 to schedule your 10-minute discovery call.