Bringing together IT staff from distributed units raises the bar for cybersecurity across the institution.

Institutional Profile
The University of Notre Dame du Lac is a private research university in Notre Dame, Indiana. It is made up of 8 schools and colleges and awards degrees in 75 majors. Founded in 1842 by Rev. Edward Sorin, C.S.C., and the Congregation of Holy Cross, the university today serves 8,923 undergraduate students and 4,206 graduate and professional students.
The Challenge
The University of Notre Dame's technology needs are met by a distributed network of IT teams. This "IT umbrella," as Leilani Lauger, chief information security officer, calls it, is made up of a central Office of Information Technology (OIT) and 27 individual units across the university, operating with varying levels of independence. Although a distributed model brings advantages such as more responsive and differentiated services, one challenge is that it is difficult for OIT's small risk team to monitor cybersecurity and consistently improve the university's security posture.
According to Lauren Freda, IT risk analyst, the challenge has at least two facets: the scale of the university relative to the central information security team, and the fact that IT specialists in individual units manage security alongside a broad range of other technology responsibilities. "We believe the strongest security model is one where every unit across the university takes ownership of its own systems, working alongside the central team," she said. "That's why security has to be a shared responsibility. Everyone needs to do their own work securely, and our job is to make sure they have the training and tools to do that with confidence."
Lauger said that OIT had long sought a way to keep improving the university's overall cybersecurity while working within the constraints of a distributed organization. She and Notre Dame's CIO make an annual presentation on cybersecurity for the university's board of trustees, and "the first thing they asked was, 'what's our risk score?'" The board's interest in being able to quantify cybersecurity risk, combined with the need to build knowledge and skills across the IT umbrella, informed OIT's approach to a new initiative at Notre Dame known as Risk School.
The Solution
Risk School is a comprehensive professional development program launched in fall 2025 designed to teach staff in individual IT units how to identify and close the gaps in security programs. In keeping with the distributed model, OIT adopted a "self-assessment plus self-improvement" approach. The core of Risk School is a lecture series for a selection of IT staff. It culminates with each unit writing a plan to improve its security posture. But before those classes start, the process begins with each unit assessing its baseline risk, rather than Notre Dame's risk team going out to evaluate each unit.
To formalize that assessment, OIT developed a survey based on the Cybersecurity Framework (CSF) from the U.S. National Institute of Standards and Technology (NIST). The NIST CSF is a widely recognized set of voluntary guidelines and best practices designed to help organizations manage and improve digital and information security. The NIST CSF 2.0 contains 106 controls, but because not all of those apply to distributed IT units, OIT condensed it to the 23 most relevant topics. "We stuck some things together, we asked bigger, more generalized questions, and we didn't ask about topics distributed IT isn't responsible for," said Freda.
Another way OIT adapted the NIST CSF was to apply a scale to what is essentially a checklist with yes/no answers to facilitate an understanding of the maturity of Notre Dame's existing security programs. Units are asked to rate themselves on each item in the survey from 0 (not performed) to 3 (well defined). They then write a description of that item, defining the unit's current maturity and where it hopes to be in the future.
Michael Mueller, IT specialist, called the work of completing the baseline survey a "tough but rewarding experience" that lays the groundwork for the Risk School. Mueller, currently working in Notre Dame Athletics, began participating in Risk School while in a previous IT role at the university's Mendoza College of Business. He and his colleagues completed the survey during 30-minute meetings held over the course of a month, and the activity was frequently surprising. By the end, they had pinpointed weaknesses and areas for improvement they had not expected. "From that, I was able to build an action plan that really focused on key elements we needed to work on," he said.
The particular goals that the IT team from the college of business identified for the next few years were to secure endpoints, protect data at rest, and develop proper documentation. "That was one of the most eye-opening things," said Mueller. "Even though data was stored in the correct places, we realized we didn't have everything documented properly. That was a big area of opportunity for us."
Once each unit participating in 2025 (the first of three cohorts over three years) had completed its cybersecurity self-assessment, a representative from each unit was selected to attend Risk School. Those participants commit to 25 one-hour classes every two weeks for nearly a year. The sessions are a mix of in person and online.
The 23 topics addressed in the self-assessment form the organizing structure for the classes. Individual sessions cover topics such as suppliers, inventory, data, and incident response. For each class, Freda draws on the university's subject-matter experts as guest presenters, which connects Risk School participants directly with specialists who can help them.
"We have people across the university who are the best at securing the network, managing our data classification systems, handling archives and data retention, and running our inventory systems," Freda said. "Bringing them in as guest presenters means participants get expertise straight from the source, rather than a secondhand version of it."
As the Risk School concludes, the last step for each cohort is developing a roadmap for improving their security posture. "We dedicate one class to walk through a reminder of the 23 topics we've covered and say, 'Please take this back to your whole team, discuss what matters the most in your area and what you have resources to tackle, and create a roadmap,'" said Freda.
The goal of the roadmaps goes beyond each IT unit planning remediations and security-focused projects, said Paul Drake, IT risk associate director, who leads risk management at Notre Dame. Roadmaps also help OIT with IT governance and coordination of larger IT projects. "We want visibility into the challenges that distributed IT has and the security risks they're addressing so that when there are commonalities, we can either get them together or help them," he said. "If we know multiple units are going to be working on data lifecycles, we can prepare for that, schedule resources, and start planning around the rest of the campus. The goal is visibility, coordination, and support in terms of the larger IT governance."
Lessons Learned
As of this writing, the first of three annual cohorts of Risk School is nearing the end of its classes and the roadmapping exercise, but units have not been waiting for that to initiate new projects in response to what they have been learning. For example, one of the subject-matter experts active in Risk School is Joseph Caudle, data governance and policy program director. Since his presentation on data classification, participants have asked him for help in classifying some of their own units' data, with a goal of improving the score on that item in their self-assessment.
That suggests progress on Freda's goal of connecting participants to existing security resources at Notre Dame that they may not be aware of. "We want the people in Risk School to know what tools they can use, what policies we have, and who their subject-matter experts are so they can get extra help," she said. "Then participants can bring that knowledge back to their units."
Over the next two years, the second and third cohorts of distributed IT units will receive their baseline surveys and go through Risk School. After that, in Freda's long-term vision, the cycle will start over again so each unit continues to keep up with new technology and evolving cybersecurity threats.
One unanticipated benefit of Risk School is that it has been pushing the professionals in OIT to make sure their work is up to date and user friendly. Faced with responsibility for leading a class, subject-matter experts have been brushing up documentation, implementing long-intended changes to online forms, and ensuring that the workflow of central IT services is responsive to the needs of distributed IT units. As Drake explained, "When you tell a central service provider, 'Hey, you need to go in front of 13 IT people and explain how to engage with your service,' they clean house a little bit. It's a chance for them to reevaluate the front door to their service. When you're just running a service day to day, you don't necessarily get that opportunity."
Nearing the end of 25 sessions for the first cohort, Lauger said participants have been extremely engaged. "The feedback I am surprised to hear is that attendees are asking for deeper dives into technical information," she said. "They wanted more, not less."
As of June 2026, all the units in the first cohort are still highly engaged, and in fact, there's at least one extra student. When Mueller transitioned to his new position in the athletics department partway through Risk School, his new supervisor was already its representative. Mueller decided to keep attending anyway. "It's been pretty great," he said. "There typically are at least one or two guests from some area of the university discussing their area of expertise. So there's always some new subject area to learn more about. There's usually a good takeaway from those sessions."
Mueller also values that networking aspect of Risk School. "I like learning about what people in other areas on campus are doing and where they're having struggles," he said. "That's been the most rewarding thing—just learning from each other."
A.J. O'Connell is a writer with McGuire Editorial & Consulting.
© 2026 EDUCAUSE. The content of this work is licensed under a Creative Commons BY-NC-ND 4.0 International License.