Campus cybersecurity still gets framed as a data-center
problem. Firewalls, EDR, ticket queues, and a CISO slide deck. Then a faculty
member forwards a grant phishing link, a student worker shares a registrar
password, or a contractor account stays live after the project ends, and the
institution discovers the hard way that humans are part of the control plane.
IT owns the stack. The campus owns the behavior.
October's Cybersecurity Awareness Month is a chance to stop
treating "be careful" as a plan. Awareness emails are cheap. Practice
is what protects enrollment, FERPA obligations, and the systems that keep the
semester running.
Why "be careful" fails on a busy campus
Urgency is normal in Higher Ed. Registration holds. Grade
deadlines. Research submissions. Travel. Password resets right before class.
Attackers use that urgency. A warning poster does not compete with a message
that looks like it came from the help desk or the dean's office.
If your only human control is an annual training completion
percentage, you have a compliance metric, not resilience.
Who else has to own this
Identity and access.
Stale roles, shared accounts, and MFA exceptions are not "IT
cleanup." They are operational risk owned by the departments that demand
exceptions.
SIS and LMS owners.
When those systems are the target, the people who run registration and teaching
must know the runbook, not just IT.
Communications.
Someone has to speak to students and parents when the inbox becomes the
incident. That person should practice before the incident.
Leadership.
Funding and priority freezes decide whether Exposure Management findings get
owners or age into next semester's breach.
NewPush works with 75+ institutions supporting 1M+ students
and 100k faculty. The campuses that handle phishing waves cleanly already treat
cybersecurity as shared operations, not an IT-only queue.
What shared ownership looks like in practice
1. One phishing or social-engineering tabletop per semester
that includes faculty affairs or academic leadership, not only security staff.
2. A written rule for money, wire, or sensitive data
requests: second channel to a known number, never the number in the message.
3. Identity cleanup with named department owners and a
finish date, not a perpetual backlog.
4. A Monday SIS/LMS outage card with decision, technical,
and communications owners.
5. NIST 800-171 and FERPA evidence work scheduled as
operating work, not as a scramble after a finding.
Awareness month without the theater
Posters are fine. Pair them with one practiced scenario.
Measure whether people report, not only whether they completed a module. Retire
the shared mailbox passwords that everyone pretends are temporary.
Cybersecurity is not just IT's job. Pretending it is
guarantees IT gets the blame when behavior fails.
What IT should stop owning alone
IT should stop being the only group asked to "fix
awareness" after a click. Awareness without department owners for access
exceptions is theater. IT should also stop being the only group blamed when a
faculty mailbox becomes the path into SIS-adjacent systems.
Hand departments a short list: which roles need MFA
exceptions, which shared accounts still exist, which vendors still have admin.
Ask communications to draft the student-facing message for a phishing wave
before one lands. Ask academic leadership to sit through one social-engineering
scenario a year.
That is not pushing work downhill. That is matching
ownership to where urgency and exceptions actually live.
Where NewPush fits
Shared ownership improves how the campus handles human risk.
Fluency practice belongs in the same room as phishing practice: people who can
use AI under institutional control are harder to fool with AI-assisted lures.
Phase 0 of Project NoéMI is the short AI readiness
assessment that starts that work. You get a Trainer login (the Phase 0 fluency
seat) and a next step for governed AI use, not another console.