Cybersecurity is often viewed as an IT responsibility, yet many of the most significant security risks originate far from the technology department. A single phishing email can affect financial aid operations, expose sensitive student data, disrupt business processes, and erode institutional trust. The question facing higher education leaders is no longer whether cybersecurity matters. The question is how to make it everyone’s responsibility. EDUCAUSE identifies Collaborative Cybersecurity as its top IT issue for 2026, emphasizing the importance of shared responsibility, end-user awareness, and access to security services and support 2026 EDUCAUSE Top 10: Making Connections | EDUCAUSE Review.  

In Ferrilli’s work with colleges and universities, our cybersecurity experts frequently find that challenges are less about technology and more about culture. Institutions often invest in security tools, but responsibility remains concentrated within IT. Faculty, staff, and students may receive periodic training, yet cybersecurity awareness is not consistently embedded into daily operations and decision-making. As a result, institutions can find themselves reacting to incidents rather than proactively reducing risk.  

A common pattern emerges across many campuses. Security policies exist, but ownership is fragmented. Business units rely on technology teams to identify and manage risks, while technology teams often lack the institutional reach needed to influence behavior across the campus community. The result is a gap between security capabilities and security culture. 

For example, Ferrilli has consulted with several institutions that have experienced recurring phishing attempts targeting employees with access to sensitive financial and student information. While technical safeguards reduced some risk, the institutions continued to face challenges because awareness and accountability varied across departments. In these cases, we have advised campus leadership to respond with a holistic solution through establishing a cross-functional cybersecurity committee, expanding awareness training, and clarifying security responsibilities throughout the institution. Over time, the campuses developed a stronger culture of vigilance, communication, and shared ownership. 

Action Steps for Campus Leaders 

  1. Establish cybersecurity as an institutional responsibility, not solely an IT function. 
  1. Create cross-functional governance structures that include academic and administrative leaders. 
  1. Provide regular, role-based awareness training for faculty, staff, and students. 
  1. Make security tools and services easy to access and adopt. 
  1. Incorporate cybersecurity risks into broader institutional planning and business continuity efforts. 

The most resilient institutions recognize that cybersecurity is not simply a technical challenge. It is a leadership challenge, a governance challenge, and ultimately a cultural challenge. Leaders who foster shared responsibility across their campus communities will be better positioned to protect institutional assets, support their mission, and build trust in an increasingly complex digital environment. 

Effective cybersecurity begins when every member of the campus community understands that protecting the institution is part of their role.