"Hotline: Cybersecurity and Privacy" tackles the philosophical, moral, strategic, and organizational quandaries related to higher education cybersecurity, privacy, and data. This month, Mike answers your questions about planning for security incidents, building future-focused strategies amid rapid change, and navigating financial challenges.
Planning Proactively
Dear Hotline: I'm exhausted by the trope: "It's not if you have a breach, it's when." What are better ways to approach planning for the inevitable?
Zero Day Zen
Dear Zero Day: I knew the day was coming when someone would ask this. I should have planned better. In my distant past, several of us in the same office would have a "prediction lunch." We'd meet, gossip, make any number of catty predictions about individuals or projects, and seal them in an envelope. A year later, we'd open the envelope and see how we did. Of course, the more cynical the prediction, the more likely it was to be correct. As fun as this activity was, it is not the way to plan for a breach. But running around repeating that exhausting trope has pretty much the same vibe: somewhat cynical, somewhat condescending. So, to achieve that moment of Zen, we need to reframe how we get across the idea of inevitability.
The message I've been giving leadership is that our goal in cybersecurity is to build resilience in an organization. While the definition of resilience can include every aspect of the NIST Cybersecurity Framework (identify, protect, detect, respond, and recover), for me, the critical aspect of resilience is the ability to withstand an event without undue harm to the organization. This doesn't mean we'll prevent everything we can and plan for the worst, but rather that we'll ensure our cyber rigor is sufficient to allow us to operate, regardless of what is thrown at us.
Usually, executive leadership views a "breach" as the event they're dreading. They typically don't understand that every modern college and university is under continuous attack and probably suffering minor breaches every day. It's no different than your body facing a daily onslaught of cold- and flu-causing germs and viruses. Cybersecurity operates as the organizational immune system, fighting to prevent or minimize an infection. Perhaps we need to change how we talk about security events by downplaying their episodic nature and emphasizing their continuous nature.
But to answer your question more fully, I need to clarify whether you are asking how to plan or how to get your organization to recognize the need to plan. I suspect you mean the latter, since planning is fairly mechanical, whereas recognizing the need to plan is cultural. It's much harder to get off the sofa and go to the gym than it is to exercise once you're there. In my experience, the most effective way to build a culture of cybersecurity planning is through tabletop drills. These are not one-and-done exercises but instead occur at regular intervals, depending on the audience. Review the operational hierarchy of your organization, increasing the frequency of the drills as you descend from the top. Within the security office, consider conducting a micro-tabletop drill every couple of weeks, with each drill focused on a specific event type (e.g., an account compromise or a ransomware event). Run drills four times a year for the IT shop and twice a year for major organizational units. Target your most senior leadership annually. Habits build health, and the beauty of a tabletop exercise is that it demonstrates the need to plan and creates resilience through exercise.
Navigating Rapid Change
Dear Hotline: As Ron Swanson from Parks and Recreation might say, "I'd prefer a strategy that didn't involve panic and last-minute scrambling." But here we are. So, how do we build meaningful, future-focused strategies when everything around us changes so quickly?
Burned Out But Visionary
Dear Burned Out: I'm reminded of a line from Blade Runner: "The light that burns twice as bright burns half as long." Perhaps you're burned out because you've been shining so brightly. Your insightful question surely suggests that.
It does feel at times like we're pieces of fruit embedded in a plate of Jello, shaking back and forth every time someone decides to pass us around the table.Footnote1 Four states just revised their privacy laws, and institutions are grappling with what to do about artificial intelligence (AI) and whether to implement Zero Trust. Issues like these are disrupting our strategies.Footnote2 The days are long gone when we could simply continue our steady rollout of a security standard and be satisfied. My instinct is that we're thrashing because we're thinking about "strategy" on the wrong timescale. I think we've entered an era where major shifts in cybersecurity and privacy approaches occur regularly. This may also be true for the IT organization writ large. Consequently, if we're looking for stability, perhaps we should return to the values, goals, and ideals that inform our strategies, and accept that the "how" of what we do will change. It's the "why" of what we do that we hope will remain constant.
While I can only speak for myself, I find it invigorating to engage with these elements. There's something ennobling about connecting your day-to-day world to values such as personal privacy, building resilience, or helping to mitigate existential threats to your organization. Consider holding a short retreat with a broad swath of senior and mid-level managers at your institution. During the event, detail your privacy and security program (ostensibly asking for input), but explicitly call out the values, assumptions, and ideals that each element supports. The goal is to coach institutional stakeholders to recognize these connections and motivations. Most likely, managers in other domains will recognize the same elements in their work streams, which can help build relationships and allies.
Budgeting for Security
Dear Hotline: When everything is getting more expensive, but our budgets are shrinking, what are we supposed to do—secure the campus with good vibes and expired licenses? What are some actual strategies for managing this financial squeeze?
CISO (Cutbacks Intensifying, Still Operational)
Dear CISO: Congratulations on remaining operational. Perhaps we can move you toward Constantly in Search of Options and away from Calculating Impact, Suppressing Outrage. I applaud you for asking this question, as I've seen too many people react angrily to this challenge and not planfully. There are two distinct approaches worth discussing. The first is how to change your program in light of current or future budget cuts. The second is how to make a better case for sustaining (or increasing) funding for your program.
I suspect you have a better sense of the first than you're giving yourself credit for. You probably have a product that you've deployed but is providing a low ROI, or you have two products that are essentially doing the same thing. Redundancy is good from a security perspective (for example, having multiple similar threat feeds), but these are reasonable targets for cost savings. Some of your initiatives can probably be delayed. Use and trust your risk-informed instincts and experience, and make any cuts with the full support of your leadership. They are the ones asking for cuts, so they have to accept the resulting risk.
Making a case for sustaining or growing your budget is trickier because everyone else on campus will be making the same case, and they have just as good a case as you do. Institutional leadership is hearing about the damage of cuts from every business and academic unit. Unfortunately, we in the cybersecurity and privacy professional community aren't great at making the case for what we do. But quantifying increased risk isn't easy either.Footnote3 What does it really mean to say you're now 10 percent more likely to have a ransomware attack?
You have one ace up your sleeve, though. Remember that much of what a security shop does is lower the risk of operational collapse in other business units. Ransomware protections can help build resilience in hospital operations and in student enrollment. With federal research dollars shrinking, faculty will need more IT and cybersecurity support, not less. Students and academics alike are being strained by the flood of AI tools, and developing an institutional posture for AI will require deep participation by both cybersecurity and privacy professionals. I argue that the scope of cybersecurity in supporting the digital ecosystem of a campus is as broad as, or broader than, any other activity on campus. Leverage this in your talking points, presentations, and budget requests. Budget requests are significantly enhanced when they're accompanied by support from other units.
Keep in mind that you're not facing this alone. I can't imagine a better topic for lunch with colleagues, birds-of-a-feather meetings at the EDUCAUSE Annual Conference, or even with managers in non-cyber domains at your institution. The camaraderie of survival is powerful.
Have a cybersecurity or privacy dilemma you'd like Mike to unpack? Submit your question through our anonymous form.
Note
- I cherish my mother, but this was an unfortunately common experience of my childhood.Jump back to footnote 1 in the text.
- Alysa Z. Hutnik, Alexander I. Schneider, and Meaghan M. Donahue, "Fragmentation of Privacy Requirements Accelerates as Four States Amend Nascent Laws,"KelleyDrye, July 2, 2025.Jump back to footnote 2 in the text.
- For more on this, see Michael Corn, "Are We Really That Special?"Michael Corn (blog), Substack, April 2, 2025.Jump back to footnote 3 in the text.
Michael Corn is an Executive Strategic Consultant at Vantage Technology Consulting Group.
© 2025 Michael Corn. The content of this work is licensed under a Creative Commons BY-NC-SA 4.0 International License.