CISOs on a Shoestring Budget : Doing More with Less by Priya Mouli

Reviews

0
No votes yet
Automatic Summary

Building Cyber Resilience in Higher Education: Lessons for Cybersecurity Leaders

In today's world, the integration of **Artificial Intelligence (AI)** in various sectors, particularly in education, is rapidly increasing. However, this rise is often met with the challenge of constrained cybersecurity budgets and overstretched teams. As Chief Information Security Officers (CISOs) and cybersecurity professionals, how can we navigate this landscape and build meaningful cyber resilience under challenging conditions?

Understanding the Current Threat Landscape

Cybersecurity threats in higher education are evolving at an alarming rate. Recent incidents show that institutions are susceptible to breaches that disrupt operations and undermine trust. Just recently, the learning management system, **Canvas**, was targeted, affecting **9,000 institutions globally**. With the demands of a new semester underway, the repercussions can be dire, ranging from delayed classes to financial consequences.

Key statistics highlight the intensity of these threats:

  • Colleges and universities face a cyber attack every **four minutes**.
  • AI-driven impersonation attacks occur roughly every **five minutes**.
  • Users are falling for AI-powered scams **4.5 times** more than traditional phishing attempts.

Shift from Protection to Resilience

In the realm of cybersecurity, merely aiming for protection is no longer sufficient. Organizations must focus on resilience. This involves understanding your organization's **crown jewels**, which could be:

  • Learning Management Systems (LMS)
  • Enterprise Resource Planning (ERP) systems
  • Research environments with sensitive data
  • Identity management platforms

The focus should be on how swiftly an organization can detect, contain, and recover from attacks. For instance, current metrics suggest that hackers can infiltrate systems in as little as **27 seconds**. Therefore, investing in **resilience strategies**, like effective restoration processes and layered security controls, is paramount.

Building a Strong Cybersecurity Culture

A significant factor in successful cybersecurity measures is the culture within an organization. **Culture affects behavior**, and in many cases, security awareness should not feel like a mere check-box exercise. Instead, it should be an integral part of operational enablement. Here are ways to cultivate a stronger cybersecurity culture:

  • Empower staff to report suspicious activities transparently.
  • Reward and incentivize positive security behaviors.
  • Create an environment of psychological safety where reporting is welcomed.

Statistics support this approach: organizations with strong security cultures are **seven times more likely** to detect and report phishing attempts than those relying solely on technical solutions.

The Winning Formula for Cyber Leadership

To thrive under budgetary constraints, it’s crucial to adopt first principles that focus on prioritization and community engagement. Here are some strategic insights:

  1. Identify Your Crown Jewels: Recognize and prioritize your most critical systems.
  2. Understand Dependencies: Assess the contagion risks across interconnected systems.
  3. Conduct Regular Drills: Engage in tabletop exercises that involve technical teams and stakeholders across departments.
  4. Build Trusted Relationships: Foster collaboration over gatekeeping. Speak the language of business leaders to facilitate understanding.
  5. Leverage Community Resources: Utilize collaboration communities and resources tailored for higher education to enhance security measures.

Conclusion: More with Less

As we navigate the era of **continuous disruption** and **technological evolution**, successful cybersecurity leaders will be those who can adapt and pivot operationally, strategically, and culturally. By recognizing cybersecurity as a fundamental pillar of institutional trust and operational continuity, we can not only manage risk but also enable innovation confidently.

In cybersecurity, **doing more with less** is a reality—and it can become our strength. The key to thriving is embracing this landscape and transforming it into an opportunity for growth and resilience.

Thank you for joining this exploration of modern cybersecurity leadership in higher education!


Video Transcription

So here here's what we're dealing with today as, as CSOs or cybersecurity, professionals. So all of our organizations wanna jump on the AI bandwagon. Right?We're actively deploying and experimenting with AI today. And, unfortunately, there's not a proportional increase in the cybersecurity budget to be able to support this adoption. And on top of that, our teams are also stretched very thin given the, given the number of tasks that we need to deal with. So that is exactly why we're here to talk about this. That gap right there is actually the story of today's meaning modern cybersecurity leadership. And despite all of this, budgets remain constrained. Cyber teams remain lean, and expectations on CSOs continue to grow. So the real question becomes, how do we build meaningful cyber resilience, in a world where resources are limited, complexity is exploding, and the attack surface is proliferating?

So that's what I wanna explore with all of you today. This is a bit about me. This is me. Alright? It is not AI generated. So, I will let you go through the slight details. However, I wanna say something else. I lead cybersecurity and risk with a simple belief that trust is the foundation of everything we build in a digital world. And with over twenty years across, of, cyber leadership experience across organizations of varying sizes and risk profiles. I've seen firsthand how quickly risk is evolving and how cybersecurity is no longer peripheral but fundamental to any enterprise's survival today because we're all inherently digital. And today, I serve as, chief information security officer at the University of Alberta in Canada.

It's, this is a top five Canadian institution that is, a world leader in AI research. And my focus is really on building secure security strategies that don't just defend organizations, but enable them to move faster, innovate safely, and, actually, I will say scale with confidence. And I'm passionate about that, about bringing that discussion alive globally through speaking in forums such as these, writing and contributing to, contributing to, insights and thought leadership articles. Now outside of work, I enjoy writing poetry, traveling, and I'm a bit of a movie buff. My most recent watch being, hail Mary, which I do recommend. I also like noting out on wildlife, especially predators because I will say that their behavior, especially stealth patients and adaptation, often mirrors how cyber threats operate and persist in an environment. So moving on to our agenda, I will begin with the current threat landscape impacting post secondary education or higher education, and then we will discuss how CSOs and cybersecurity professionals in general can operate effectively amid budgetary and operational constraints.

And what I actually wanna share today is not just theory. These are practical lessons and insights from operating in higher education or really any organization because resources are constrained all across. And I would like to say that, regardless of an organization's size, prioritize prioritization, and influence matter more than simply buying the shiny new tools out there. And we will move into practical resilience strategies, and we'll talk about how culture can really scale security outcomes. And I'll conclude with, what I believe can be the winning formula for modern cyber leadership. Now the objective of the session is is not it it's not going to be fear based.

It's not gonna be a fear based storytelling exercise, not a doom and gloom story, but it's about helping, leaders and cyber professionals rethink how cyber programs are built and measured. And cybersecurity is increasingly becoming a business resilience function like I alluded to earlier and one that intersects operations, trust, governance, research continuity, and institutional reputation. So I know this session is about, twenty minutes. That said, please raise your hands. I do wanna keep it interactive. Please raise your hands or post your questions in the audience chat, and I will try to address them as we move along. And I'll also finish the session a few minutes in advance so so there is dedicated time for q and a. Now, this is the state of the cybersecurity landscape in, academia, predominantly in North America.

The most recent one being and this is a live incident as of today, is, there's a learning management system by the name Canvas that has been hacked by Shiny Hunters. It's been it's been in play for the past, couple of weeks. They've impacted 9,000 institutions, globally and impacted a number of users. As of date, there's a number of organizations that have moved to other LMS platforms or, you know, reverted, functionality in very limited, functionality mode. But I just wanted to say that this is cybersecurity is, something that's we we we can't assume if we are hit. Now the story is changing to when we are hit and how often we are hit. So higher education institutions, particularly, I would say, continue to be attractive targets because, disruption creates immediate operational pressure. We're in the start of, spring semester here.

In fact, we started spring semester just last week here, in Canada. And when classes are canceled and when exams are delayed or research systems are unavailable, institutions face not only technical recovery costs, but also reputational and financial consequences. And, just sharing some stats here. Higher education institutions now face roughly one cyber attack every four minutes with AI driven deep fake and imports and executive impersonation attacks roughly occurring at a rate of, one, about five minutes, and, with AI powered deep fake related audio and video related scams being dramatically more effective.

In fact, recent, metrics, state that users are falling for them 4.5 times more than traditional phishing attempts because they're convincing. There's no typos or grammatical errors in there anymore. So moving on, this is a snapshot of what we see in Canadian colleges. I will talk about, because I work at a Canadian university, but I will also talk about some stats as it relates to the, to The US and globally as well. Threat actors today operate like mature businesses, ransomware as a service. There is also CAAS, which is cybercrime as a service, credential marketplaces, and access brokers. They have industrialized cybercrime and made it a very lucrative career model, kind of like a heist. Right? However, I will say that the particular aspects about higher education environments are they combine valuable intellectual property in terms of research data, and other business propriety information.

There is, an ethos of open collaboration and sharing models. There is decentralized IT ownership. So so, typically, you have centralized IT, and then you have a lot of decentralized IT, meaning, techs within each faculty department. And we have a highly diverse user population from you know, if you think about it, from students, which is gen's, which generation, z, and then all the way to baby boomers and even beyond because we do we do have a number of alumni and donors and patients as well. So in many ways, I will say that academia represents one of the most complex identity and access environments in any sector. So moving on to the stats here. Now this has the average base bridge cost in Canadian dollars. It's $6,540,000. If you equate that to US, it's, 4.88, million US dollars. And I will say that, I will say that, you know, over time, the breach cost had significantly increased, especially from 2023 and onward.

Now, one of the defining realities in higher education is, as I alluded to the open collaboration model earlier, it's the tension between openness and control. We support academic freedom, collaboration, visiting researchers. We support international partnerships, including including with government and private and the commercial sectors and highly distributed technology ecosystems. And at the same time, many institutions are also facing enrollment pressures, constrained operating budgets, talent shortages, and growing regulatory expectations. Now this means that cybersecurity professionals and leaders must become highly disciplined in how they prioritize the use of resources and assets. You cannot secure everything equally. You must understand what matters most and protect it accordingly. Now, the industry conversation is shifting from protection to resilience. I would say that protection is, table stakes in today's world.

Resilience defines the present and the future going forward because to my earlier point, no individual or entity is immune from a cyber attack. So that said, one thing I've consistently observed is this. Right? Organizations that succeed in cybersecurity are not necessarily the ones spending the most money. They are the ones that align cyber strategy to business outcomes, to operational realities and to organizational culture. And the question today is how quickly can you detect, contain, recover, and resume operations at the earliest? In fact, the the, the blower on the right that you see here is CrowdStrike's reporting around detections and breakout times. So breakout time is essentially the time for a hacker to get a foothold into into your environment and be able to laterally move.

It demonstrates how little margin organizations have because the breakout time is as little as twenty seven seconds. And this is why resilience investments, meaning things around backups and restoration testing, are increasingly becoming critical. And on top of that, having a fundamental understanding of your digital crown jewels or your critical assets in an organization and having layered controls, meaning adopting a defense in-depth principle go a long way. Now I do wanna harp on the culture aspect of cybersecurity. One of the highest ROI or return on investment, options that are available to, CISOs and cyber professionals alike is strengthening the human firewall. I believe that technology scales, but culture multiplies. I often tell teams that security awareness should not feel like a checkbox exercise or compliance training.

It should feel like operational enablement. For example, empowering staff, for reporting suspicious activity quickly, rewarding and incentivizing security behaviors, and simplifying escalation paths, and democratizing security knowledge through AI assisted tooling can help. And organizations that normalize cyber accountability across the enterprise recover faster and operate with greater resilience as well. And metrics tell the story a whole lot better. In fact, recent metrics from Proofpoint and Verizon's DBIR say that organizations with strong security cultures are seven times more likely to detect and report phishing attempts earlier than the tools can. And just if I were to just, refer to, the well known quote, culture eats strategy for breakfast. It is very real. In cybersecurity, culture determines whether employees report suspicious activity, bypass controls, or become the control. Now it is often said the human beings are the weakest link in cybersecurity.

I like to turn that around and say that human beings can indeed people can be the strongest asset and element in proactive defense. It's all around collective defense where cybersecurity is felt sport. And what has worked well for me is around also creating an environment of not only recognition and but creating an environment of psychological safety or, no shame or no blame reporting culture because let's be honest, we may all feel victimized when we hit that phishing link and when we lose our and when we lose access to our systems.

So what has worked very well for me is around creating a safe environment where everyone feels empowered and feels safe to talk about anything and everything so we can help them better. Now, moving on to, my the winning formula as I promised. Now when budgets are constrained, first principles matter. I alluded to this earlier, but know your crown jewels. For your university, this will include your LMS, your learning management system, will likely include your ERP or or your enterprise resource planning systems, your research environments, especially ones that involve very sensitive data, identity platforms, and oh, sorry about that.

Identity platforms and sensitive student or health information. And second, I would say, understand dependencies, Meaning, the contagion risk across interconnected systems, I feel, is often underestimated, but that is the one that can really bring up and tell you what your true risk exposure is. The third one, I will say, is rehearse incidents, given. We'll we live in a day and world where they are more often than not. So have regular tabletop exercises and even actually cyber drills, meaning hands on exercises, not only including your technical teams and your executive teams, but include legal, include communications, include your executive leadership and the board as well, Include your external partners, including cyber insurers because when you see that ransom note and when you're sure of it, you are gonna make that call.

So include your external partners, including cyber insurers and critical third parties. Have your breach code services provider, your IR folks, everyone in a room to be able to go through that drill, in advance so that you build the muscle memory so that when the moment a crisis unfolds, everyone has an understanding of what their roles and responsibilities are.

So culture, yes, I alluded to culture here. Now security teams are significantly more effective when they build trusted relationships with the business rather than positioning themselves solely as gatekeepers or naysayers in my mind. My philosophy to cybersecurity is around enabling the business by working with them and really building those trusted relationships and speaking to them in simple language, in a language that resonates with them as to why they should care and making it very easy for them to be able to adopt controls.

And one practical approach, I have seen that serve has served me well is around building cyber champions across departments, across your business functions. And this really decentralizes awareness and creates local advocates for good security practices. Another critical point is, transparency. Board and executives do not expect perfection, and I always like to say this within my teams, don't let perfect be the enemy of good. What they expect is some clarity, prioritization, and really informed risk management all linking up with your organization's risk appetite. Another point I will call out on the slide, the bottom slide, is that leverage the community. There is nothing like community knowledge sharing and collaboration on not only operational challenges, but also around things that you are seeing.

Like, for example, with respect to the with respect to the higher education events and incidents, we have, like, so many collaboration, commune there are so many collaboration communities set up where every CIO and CSO is kind of brainstorming thoughts with each other live. So I will say that, community sharing. And besides, there's a number there's a plethora of cybersecurity, assets, tools, and resources, including EduCos. I'm I'm talking specifically with respect to higher education. There's the MS ISAC. There's the CSaw. There's the FBI guidance. There's the Ren ISAC, Internet tool, NIST guidance, and so on. Now, I'll conclude by saying this. We are operating in an era of continuous disruption and rapid technological evolution. Now the leaders who succeed, will be the ones who can continuously adapt operationally, strategically, and culturally. Cybersecurity is no longer just about reducing risk. It's about enabling institutional trust, operational continuity, digital transformation, and really scaling scaling innovation with confidence.

And perhaps most importantly, our voice has never been in more influential than today, because in cybersecurity, I will say that doing more with less is, it's not a strategy per se. It is, it is our operating reality. It is our job description. Right? We we just I'll I'll just say this in just we didn't we just didn't get the luxury edition. So, yes, we are doing more with less, but in cybersecurity, that's not a disadvantage. It's just it's just normal. It's just reality, and it's just another Tuesday. Okay? So thank you again for your time.