Building a Strong Cybersecurity Culture in Higher Education
CIOREVIEW >> Cyber Security >> NEWS

Arizona State University

Lester Godsey, Chief Information Security Officer

Building a Strong Cybersecurity Culture in Higher Education

Lester Godsey, Chief Information Security Officer
Lester Godsey, Chief Information Security Officer, Arizona State University

Shared Responsibility, Strong Security

Higher education has long been fertile soil for innovation, openness and collaboration. Unfortunately, those same characteristics also make them attractive targets for cyber adversaries. As institutions expand digital learning, cloud adoption, research partnerships and global collaboration, all enhanced and accelerated by using AI, the cyber risk landscape grows more complex and interconnected. Addressing today’s threats requires more than new tools, policies or even AI. It demands a strong cybersecurity culture grounded in shared responsibility and reinforced through the concept of federated cyber risk management.

The Unique Cybersecurity Challenges Facing Higher Education

Unlike many industries, higher education operates in a highly decentralized environment. Universities often consist of semi-autonomous colleges, departments, research labs, hospitals and auxiliary organizations, each with its own IT systems, priorities and funding models. This fragmentation creates inconsistent security controls, uneven risk awareness and gaps in accountability.

At the same time, institutions manage vast amounts of sensitive data: student records, financial information, health data, intellectual property and federally funded research. Ransomware attacks, data exfiltration, business email compromise and nation-state espionage are no longer hypothetical risks, they are persistent realities. Compounding the problem, universities must balance security with academic freedom, open access, all while minimizing friction for students, faculty and staff.

Another significant challenge is human behavior. Phishing remains the most successful attack vector, and the diversity of the campus population makes consistent security awareness difficult. Many users do not see cybersecurity as part of their role, but as an IT problem rather than a shared institutional responsibility.

Why Culture Matters More Than Controls

While technical defenses are essential, they are insufficient on their own. Firewalls, endpoint protection and monitoring tools cannot compensate for a lack of shared understanding or ownership of cyber risk. A strong cybersecurity culture ensures that individuals across the institution recognize their role in protecting digital assets and understand how their actions contribute to overall resilience.

 Addressing today’s threats requires more than new tools, policies or even AI. It demands a strong cybersecurity culture grounded in shared responsibility and reinforced through the concept of federated cyber risk management. 

Culture influences how people respond to suspicious emails, report incidents, adopt secure behaviors and support security initiatives. In higher education, where authority structures are often flat and consensus-driven, culture can be the difference between a security program that is resisted and one that is embraced.

However, building culture at scale in a decentralized environment requires a governance model that respects institutional autonomy while aligning risk management efforts. This is where federated cyber risk management becomes essential.

Federated Cyber Risk Management as a Cultural Enabler

Federated cyber risk management acknowledges the decentralized nature of higher education while creating a unified framework for managing risk. Instead of imposing a single, rigid security model, a federated approach establishes shared standards, risk language and accountability mechanisms that allow individual units to manage their own risks in alignment with institutional goals.

In this model, enterprise security teams provide governance, tools, threat intelligence and expertise, while colleges and departments retain ownership of their local systems and risks. This shared responsibility reinforces culture by making cybersecurity relevant at every level, not just within the CISO’s office.

Federation also improves visibility. When risk is assessed and reported consistently across units, leadership gains a clearer picture of institutional exposure and can prioritize investments based on real data rather than anecdotes. Just as importantly, departments begin to see how their local decisions affect the broader ecosystem, strengthening collective accountability.

From Compliance to Collective Responsibility

Traditional compliance-driven security programs often focus on meeting minimum requirements. While necessary, compliance alone does not foster engagement or resilience. Federated cyber risk management shifts the conversation from “Are we compliant?” to “How do our decisions impact university risk?”

This shift supports cultural change. Faculty and staff are more likely to engage when security is framed as enabling research, protecting students, and sustaining trust rather than enforcing rules. Risk discussions become collaborative instead of punitive, encouraging earlier reporting of issues and more proactive mitigation.

Training and awareness efforts are also more effective when tailored locally within a shared framework. Departments can contextualize security guidance for their specific environments while reinforcing consistent institutional messaging. Over time, cybersecurity becomes embedded in daily decision-making, not treated as an afterthought.

Building the Future Cyber-Resilient Campus

As cyber threats continue to evolve, higher education must move beyond siloed defenses and reactive responses. Building a strong cybersecurity culture requires recognizing that risk is distributed, responsibility is shared, and resilience is collective.

Federated cyber risk management provides a practical path forward. By aligning decentralized environments under a common risk strategy, institutions can respect academic diversity while strengthening security maturity. More importantly, they can cultivate a culture where cybersecurity is understood not as a barrier to innovation, but as a foundational enabler of teaching, research, and public trust.

In the end, the most effective defense for higher education is not just better technology, it is a community that understands, owns, and manages cyber risk together.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.