This blog post is part of a series based on a webinar series of the same name conducted by Vantage in partnership with EDUCAUSE. The insights shared here are based on the robust conversations we had during that webinar series. We’d like to extend a special thanks to our panel members: Donna Kidwell, CISO, University of Toronto; Josh Callahan, CISO, California State University, Office of the Chancellor; and Marcos Vieyra, Executive Director and CISO, University of South Carolina. This conversation was hosted by Vantage team members Joanna Grama, Senior Principal and Partner, and Valerie Vogel, Senior Strategic Consultant.
The role of the Chief Information Security Officer (CISO) in higher education has evolved significantly over the years. Once seen as a purely technical position, today’s CISO must be a strategist, a trusted advisor, and a leader who understands risk at an institutional level. For those aspiring to step into this role, the journey can be complex—but also rewarding.
Understanding the Unique Role of the Higher Ed CISO
Higher education CISOs operate in a unique environment—one that values openness, academic freedom, and decentralized decision-making. These leaders must balance the need for robust information security programs with the institution’s educational and research missions. The role is about much more than managing firewalls and antivirus software; it’s about mitigating risk, building partnerships, and helping the institution navigate an increasingly complex digital landscape.
The higher ed CISO must consider multiple stakeholders: students, faculty, researchers, administrators, and more—each with different security needs and expectations. Colleges and universities also collaborate extensively with other institutions and government entities. This requires that CISOs maintain the collaborative spirit that drives academic progress while deftly balancing issues of risk, access, and regulatory compliance.
As cybersecurity threats continue to grow, and criminals target higher education institutions for their stores of valuable research data and personally identifiable information, CISOs in this sector must constantly adapt to new threats and implement innovative risk mitigation strategies.
Career Milestones and Essential Skills
One of the things we hear over and over from those who have made the leap to the CISO role is that there is no single path to get there. Some come from technical backgrounds, others from risk management, policy, or audit roles. The field has its fair share of musicians, archaeologists, historians, and businesspeople, too. The key is to build a professional skillset that meets the evolving needs of the role. Some of the most critical skills for an aspiring CISO include:
- Leadership and communication skills: CISOs must be able to convey complex security issues to non-technical stakeholders to be effective. Building relationships with university leadership and faculty can smooth the process of integrating security considerations into institutional decision-making.
- Crisis management experience: CISOs need to rigorously prepare their campuses for emergencies and maintain a calm, strategic approach when disasters occur. Regular testing and refinement of incident response plans are essential for ensuring the CISO is always prepared to lead a coordinated, effective response on behalf of the institution.
- Strategic thinking: The best CISOs understand how security aligns with the institution’s broader goals and can advocate for security investments in business terms.
Challenges and Opportunities
Aspiring CISOs should be prepared for both challenges and opportunities along the way. One major challenge is that higher education institutions are often resource-constrained, requiring security leaders to be creative in implementing solutions. However, this also presents an opportunity to collaborate, influence policy, and drive meaningful change.
A key strategy for career advancement is saying “yes” to leadership opportunities outside the security realm that help build and strengthen connections. Serving on committees, engaging with faculty and research teams, and offering to help with university-wide initiatives can build both the relationships and visibility necessary for a leadership role.
Furthermore, CISOs must navigate institutional politics and work within governance structures to secure buy-in for security initiatives. Effective CISOs build strong partnerships wherever they go to ensure information security remains a top priority.
Stay Curious
Given the complexity of the role, CISOs must also invest in continuous learning. Engaging with associations such as EDUCAUSE, participating in leadership development programs, and obtaining certifications like the CISSP or CISM can enhance career prospects.
The higher education sector will continue to evolve, and the demand for skilled, strategic security leaders will only grow. Whether you’re just starting your journey or positioning yourself for the next step, the key is to remain adaptable, build strong relationships, and continuously expand your knowledge and expertise.
For those considering this path, the advice is clear: Stay curious, take on new challenges, and embrace the squiggly career trajectory that often defines the road to becoming a higher ed CISO. By developing a well-rounded skill set and building a network of peers and mentors, aspiring CISOs can navigate the challenges of the role and make a meaningful impact on their institutions.
Key Takeaways
If you take away any lessons from this blog post, we believe these are the most important things you can do on your journey to becoming a CISO:
- Understand the higher ed landscape and its attendant cybersecurity risks
- Take advantage of opportunities to build relationships, visibility, and influence
- Seek out opportunities to improve your knowledge, abilities, and skills, especially those related to communication
This post is the first in our “Empowering the Modern CISO” series and was co-authored by Senior Principal and Partner Joanna Lyn Grama, JD, CISSP, who works with clients to examine and improve their technology governance, compliance, information security, and data privacy programs; and Senior Strategic Consultant Valerie Vogel, who advises clients on information security program development, information security and privacy awareness programs, and IT organizational assessments.
Need Help?
Our team of higher education experts is available to facilitate strategic planning and other services with your organization.