[1]: https://utcc.utoronto.ca/~cks/space/blog/tech/UniversityMone...
There's a lot of requirements that apply to institutions as a whole to clean up their acts and mature a lot of their security processes to even be eligible for grants. A lot of the wild west days are coming to an end, and I've seen a push in several institutions to wrangle unit-level IT groups into one massive IT organization for their entire campuses. Not only is there a lot of security vulnerability there, but it's also a huge cost center that can be squeezed to flatten the curve of tuition, but not have to reduce the salary of three dozen associate deans
* https://bgp.he.net/AS239#_prefixes6
It's just that particular department may not have bothered.