The Human Side of Cybersecurity

min read

EDUCAUSE Rising Voices | Season 4, Episode 8

How much of cybersecurity is really about understanding people? This episode explores the human side of cybersecurity and institutional resilience, discussing how higher education institutions prepare for and respond to major disruptions.

Listen on Apple Podcasts Listen on Spotify

View Transcript

Sarah Buszka: Welcome to the EDUCAUSE Rising Voices Podcast where we amplify the voices of young professionals in higher education. I'm Sarah Buszka, and I'm joined by my amazing, the incredible, the singular, the perfect co-host that we could ever have on the show, Wes Johnson. Wes Johnson. There it is. There you go. Yeah. Yay, there we go. And we're members and friends of the EDUCAUSE Young Professionals Advisory Committee, also known as WIPAC. So today's topic, I'm excited about. I say that about every topic, which is great because I'm excited to talk about all the things we do on the show. We're really thinking about cybersecurity and institutional resilience today. And the topic is timely and apropos just given, well, frankly, everything that's been swirling around in 2026, but especially I would say for higher education, the recent Instructure Canvas LMS outage that impacted everyone globally. And I think from my lens, I'm typically seeing things from the higher education lens. However, this happened throughout K-12, throughout higher ed, frankly, anyone who's using this tool. And I think it's a very global and significant impact. And so I think for the show today, we're getting a little curious and we're seeing and trying to talk a little bit more about what does that impact actually look like and what are young professionals' roles in those types of impacts, whether it be the cybersecurity impact or even an institutional resilience strategy and planning too. So I think from the EDUCAUSE lens, we've heard a lot about how EDUCAUSE has responded to this instant, and I should say maybe EDUCAUSE member institutions specifically, but we really want to dig deep a little bit today and learn more about the broader lens and maybe what this looked like from a K-12 lens too. So with that, Wes, would you be willing to introduce our guests?

Wes Johnson: Absolutely. We will kick it off with Hannah McClarnan. Hannah is an analyst with seven years of experience in cybersecurity across education, healthcare, and tech. She serves as a cybersecurity analyst and program manager at Baylor School, an independent six through 12 school in Chattanooga, Tennessee. I haven't said that word in a little while. Welcome, Hannah. And then we also have Amir Lawrence. Amir is a cybersecurity analyst from the Friday Institute at NC State University, supports cybersecurity efforts for 200,000 North Carolina K-12 employees at over 300 plus public school units. He uses his background in both cybersecurity and psychology to lead various statewide initiatives focused on security awareness and skills training. Wow, 200,000. Shout out to you, Amir. It's great to have you both. Welcome to the show. And I'll stay on you, Amir. We're going to kick it off with maybe the most important question on the show. What is your superpower?

Amir Lawrence: I think when I look at it, it's probably going to be that dual background in psychology and cybersecurity, or just the humanities in general in cybersecurity, just because I think that feels really technical. But when you look at things like security awareness training, how people are affected and respond to these incidents, the human is a really core part of it at every step of the process. So make sure you understand the human mind and why are people making decisions they do and how are they affected by these incidents that happen really helps inform how to better serve them from a leadership perspective.

Wes Johnson: Yeah, totally agree. That's a great superpower. Now I want to jump on board and say that I went to school and did cybersecurity and sociology - Oh, nice. For a very similar connection. Yeah, yeah, for sure. Hannah, any questions for you?

Sarah Buszka: I want to jump on board too because I - Oh, you want to jump on? Yeah. Because I studied psychology and neurobiology as part of my undergrad and Russian language and literature. So I agree. I think understanding the human side, how human behavior works, the human brain, the human mind, superpower, absolutely. So we got really great folks on the show. I'm biased, but.

Wes Johnson: Hannah, what is your superpower and your major now? We got to put you on the spot.

Sarah Buszka: Yeah.

Hannah McLarnon: My major was computer science, and I'm going to say something crazy. I took a couple psychology classes. All right. There you go.

Sarah Buszka: There we go. I love it. I knew it. Had a feeling.

Hannah McLarnon: Yep. Great minds think alike, I think.

Sarah Buszka: Absolutely.

Hannah McLarnon: As for a superpower, I would say that my passion for security is probably my biggest one. It's more something I'm compulsed to do is share my passion with others and try my best to make it relevant to them and make them excited about it. I try and make it relate to whatever is important to them. And anytime someone comes up to me with, "I recognize this scam before it could get me," or, "I saw something strange, so I changed my password," which I get all the time, I feel just so excited that they recognize the importance of security and not only protected themselves, but are excited about it.

Wes Johnson: Awesome. Awesome. Do I note some musical passion as well with the guitars in the background?

Hannah McLarnon: More like trying to be. Okay. I love music. I'm trying to learn how to do it myself, but there's definitely some musical fashion

Wes Johnson: There. That's awesome. A shared passion of mine as well.

Sarah Buszka: And Amir too, because Amir plays guitar a little as well. Yes. We're Connected. The universe put this episode together right here. Yeah. Okay. Well, actually, I want to pick up the thread of psychology for a moment. So I know I'm going a little off script here, but since we have these shared interests, I'm really curious to hear maybe from you, Hannah, starting and then Amir, if you're willing to pick it up, how do you use that psychology lens in your everyday work? Where does it come and show up? How do you bring it to bear? How are you leveraging that to move goals of your institution forward, especially with respect to security?

Hannah McLarnon: Well, I would say some of the greatest cyber threats are social engineering based. It's getting someone to trust you enough to give them information about you or guessing what someone might do based on common human behavior. Anytime someone comes to me with, "Hey, I messed up. I clicked this link. Hey, I talked to this person I shouldn't have and gave them too much information." I never blame them because that's human nature. They pray off that. It's completely reasonable because they're expecting you to be human.

Sarah Buszka: Right. Absolutely. Agree. Amir, what would you add to that?

Amir Lawrence: I think my perspective, since I'm kind of dealing at it from a more dispersed lens and actually in an individual district, what I see at least is that if you don't have a psychology background, or I guess a human-centric approach, you then kind of miss out on the fact that at least in K-12, it's not just the issue of people doing the right thing, but you have to understand what are their goals? What are the things they care about? And in K-12, it's not really technology or cybersecurity, it's teaching students. So then from my perspective, it really plays this role in that when I talk to someone, it's not just, all right, hey, I need you to do this training. I need you to avoid this phishing. But it's really like, okay, I want you to turn on MFA. You really don't want to. What can I say to you? And what is your reason with the friction point to not just make it this thing you have to do because your tech team says it, but you understand, no, this protects me, this protects my community, it protects my home. I think just being able to really connect with people at their actual pain points and not the perceived arbitrary of our IT team says we have to do X, Y, and Z. I think it gives you a bit of a finesse to how you approach it, which I think definitely proves valuable in long-term engagement of changing their behavior and their awareness of things.

Sarah Buszka: Absolutely. I like how you frame that, that finesse.Because sometimes I think for us who work in technology security, there's kind of this about it to get users to actually do the things that would actually make them safer. And I think that's a great way to capture it, Amir, is that finesse. And I really think that psychology lens that, at least I'm hearing, helps give you that.

Amir Lawrence: Yeah, for sure.

Wes Johnson: So starting with you, Hannah, what is it like when that major incident hits on the ground? You get the call, major system's been compromised, we need to figure out what we need to do. What is it like on the ground for you?

Hannah McLarnon: Yeah, so that heavily depends on how prepared the organization is. Best practice in an ideal world, there is extensive documentation telling you exactly what you need to do. There's people's phone numbers, who exactly you need to call and when. There's step-by-step instructions with screenshots, locations on how to access these tools, backup people, if that person isn't available at this time. And in an ideal world, these are practice regularly, in-person. They call it disaster recovery training. It's extremely important. Unfortunately, the reality is that, especially in education, a lot of schools just don't have the resources to take care of all of that. It ends up being long hours, juggling tasks, miscommunications, the destruction of evidence, increased cost, or recovery in general.

Wes Johnson:bAmir, would you say anything different or add to that?

Amir Lawrence:bI think Hannah's spot on. For us, we try to prepare the individual school districts or public school units that we have with things like an initial response toolkit they can use that helps them create the document or a cybersecurity program plan. But really, I think the big thing that distinguishes K-12 from higher ed is like Hannah mentioned, it's that lack of resources. But it's not just when you say that it's like the mind goes to money, but it's like, no, it's a lack of time. It's a lack of bandwidth. It's a lack of understanding from leadership that this is the importance of this issue because K-12 has different goals that it's going for. So for us, it's really a game of, all right, well, with this lack, what community resources or support can we provide to them that would then help support recovering from this incident? And it's really like calling in the calvary. So it's really just a game of getting all the right people there, seeing what support's needed and just seeing, okay, where are you at right now? How bad is it? What's going on in your environment? And how can we help support? But to really focus on their goals because maybe they're just trying to make sure the kids come through their school day and they might not need to get the network on right there today. They have different priorities. And I think understanding that really is sort of the crux of what's going on in K-12 after a really big incident happens.

Wes Johnson: Yeah. Yeah. Interestingly, I would say that if you spoke to most in higher ed, particularly on public side, they would probably share in your lack of resource concern and preparation in a lot of ways speaking on behalf of a public.

Sarah Buszka: No.

Wes Johnson: We definitely share in that thread sometimes. And one of the interesting things, just to kind of go down that rabbit hole of some of the differences, because there's a lot of assumptions I imagine out there from both sides, is on the higher ed side of it, particularly for at least medium, larger, maybe even small, I haven't worked in many small institutions, but there's a residential factor to it in that your students live on the campus. Some of your faculty may also live on the campus. So there's kind of a crossing of lines both professionally as well as expectation. If I can't access this thing because of some outage, I might not be able to access something for my real life. I'm curious, do y'all have that kind of dynamic given that maybe your students and teachers don't live there, but they live in the nearby community. Do you see some of those things blend together in an incident in the way they view them?

Amir Lawrence: You want me to go for a Sam?

Hannah McLarnon: If you have something, go ahead. Yeah, you can go ahead.

Amir Lawrence: Yeah, I was just going to say, I think for us, I mean for a lot of students, especially because we serve a lot of rural North Carolina, so for a lot of those students, school's going to be the only place where they get access to the internet or access to a laptop or maybe even just a good meal and stuff like that. So I think due to the fact that over time schools have become more connected and we have wifi in every classroom and these are really cool developments. The schools then become sort of chained to having a network. So it is a broader impact. I could definitely see a through line between how higher ed has to focus on, well, these students, they run their lives from the campus. For the students in K-12, they might not have to live there. But for a lot of those students, if they don't have the resources that they expect at school, then that radically not only affects them when they go back home, but then that kind of snowballs because, well, if you have a student who doesn't get food at school for a couple of days or the school's down and they can't do their homework for a week straight, well, how do you shift the schedule? And it becomes this big sort of interconnected mess of things failing because we need the network, we need the internet in some capacity to help run these things, how we design them.

Wes Johnson: No, thank you for that. I never made that connection. Hannah, did you add anything to that?

Hannah McLarnon: Amir's spot on. So we are a K-12 institution, Baylor school, but we actually have students that live on campus as well as teachers. So life safety is 100% considered with risk and critical infrastructure that needs to be considered in that if there's a phone outage and there's something that happens on campus and people can't reach out because all phones are down, that brings up risk a lot.

Sarah Buszka: Yeah.

Wes Johnson: I've never made those.

Sarah Buszka: Yeah. Yeah. And I like the threat that we're picking up here too, because in one of my former lives, I used to lead critical infrastructure and cyber infrastructure services for the University of Wisconsin-Madison. And that was disaster recovery, all the things that we're talking about here top of mind. And I think one thing I'm hearing here from the K-12 lens is that same lens in addition to cybersecurity, privacy concerns, risk writ large applies in a K-12 setting, but it's very connected throughout the entire community too. And I think if I'm hearing this correctly too, y'all tell me if I'm wrong, it's difficult to understand where something stops and where it starts. If you have a community with students who are maybe living on campus or maybe whose only point of connectivity to the internet or that good meal is their school. If a ransomware attack happens and school is shut down or they lose access to a certain resource, there's ripple effects throughout the community. Do you two see that too? I'm seeing nods. Amir, do you want to pick up on that?

Amir Lawrence: No, yeah, I would definitely agree. And it's definitely something that I think goes unnoticed, but once you really just think about it a bit more, even to what you mentioned about crow fund structure, just student safety. For a lot of schools, their camera systems, their door systems, like you mentioned, their phone systems. But even obviously payroll, all those things are hyper-dependent on having a connection. And it's just this thing that ideally you'd want the community more involved. So it's kind of like a catch-22 where you want the community to be really involved and you want all these systems to sort of funnel in and out of the school, but you then create this sort of massive pillar, but also a failure point that if it is hit, are you prepared to pivot and find a solution that still is reasonable, but isn't diverting? Again, the main focus of, all right, well, I have to make sure these kids walk across that stage in a few years. So how do we make sure we get back on track for that? But it's definitely just a process that schools have to figure out what works best for them in their community, of course.

Sarah Buszka: Right. Well, building on that, actually, I'm curious, maybe I'll ask you first, Hannah, and then back to you, Amir. How do you do that? You just asked a lot of great questions, I think, which many folks I think would really benefit from hearing. So maybe Hannah, how would you get your community on board to understand the risk better and how it impacts students in the community? And how do you rally folks to get on board and understand what's going on and how they might be able to be a part of the solution whenever an incident does happen?

Hannah McLarnon: Well, something that we're trying to do a little more of is calling out when someone does something good. We had a situation at one point where one person reported an email and they reported it, used our button, and we did an investigation as normal, and other people had received the email. So we removed it and we sent out a communication to everyone saying, "Hey," we got their consent, of course. "Hey, this person did a fantastic job. They did everything they needed to do and saved a lot of trouble for a lot of people because they reported that one email. Just a reminder, if you get an email and you identify it as phishing, please still let us know because other people may have gotten it. "I had a lot of people come up to me afterwards and say," Hey, thanks for that email. That was really informative, "or showing me more emails that they saw. It was really effective, that positive praise that they received just for being aware, see something, say something.

Sarah Buszka: That's great. Yeah. You too can click the report phishing button also.

Hannah McLarnon: Exactly.

Sarah Buszka: Kind of gamify it a little bit. I love that.

Hannah McLarnon: Exactly.

Sarah Buszka: Yes. And I think back to our psychology comment, I think giving folks that recognition and praise publicly really helps reinforce the behavior that you want to see. What would you add for that, Amir? What are you folks doing?

Amir Lawrence: I think, Hannah again, spot on. I really love all the through lines that are happening in the conversation. Anything around spotlighting, positive behavior, gamification, it goes a really long way. Primarily because even for us in the field of cybersecurity, it's a very doom and gloom. There's always an incident. There's always something happening. We're always preparing for something. So when you go even down that to people who aren't really in the field, but they are affected by it, there's this apathy that develops because it's like, okay, well, I don't really know what's happening. I don't really understand all the ins and outs of these actions you're throwing at me. And there's always something that I hear you have to avoid clicking on something or someone does click on something and you get to feel like it's kind of pointless. So even in North Carolina, what I was primarily working on for the past year is creating a statewide cybersecurity ambassadors program. So it's finding those people in the school districts who are championing not only the cybersecurity efforts, but they're displaying good behavior that we can then showcase and highlight, but also then connect them with their other peers. Because maybe for me, I see the value here, but if we can say, "Hey, such and such in this county does X, Y, and Z, maybe you guys should connect and see what you can pull from that." There's just this really good synergy that develops where it becomes a community sort of effort. You know what I mean? And that comes from championing those people and making it a bit more fun. And I think going back to even the original question, which is how do you get people to really understand the importance of it all? It's just for us, it's always been connecting it to them, meeting them where they are at their level. So what are the things that you care about most? And for leadership, it might be like, "Hey, you might think that paying this much money for this cybersecurity service or whatever is a waste of time. But if you get hit and the school goes down, that's going to be a really big hit to your reputation for sure. Just the school's reputation in general, there's going to be a lot of anger or frustration or confusion from parents and families, and you have to deal with that. That is a cost in a way that some would say is more than the $100,000 for a tool or whatever the case is. So it's just helping them understand the bigger picture of this prep might seem kind of moot. Everyone thinks insurance is dumb until you need to use the insurance. It's like, okay, this is really, really good. Or that preparation. But even to their families, it's like when you go home, you have dozens, if not hundreds of accounts. You have accounts with the same password because I do. I did for a long time. I've gotten the whole like, oh, you have a password in 65 breaches. And it's like, okay.

Sarah Buszka: I've never had that. I'm guilty of it too.

Amir Lawrence: So it's like, hey, so we know we all have this through line of our experience, so maybe don't view it as IT team making me do dumb stuff for work. But it's like, no, this is something you can take home and you can send it to your. This can help your partner, your parents, your kids, because all of them are users to some capacity and they all have a digital footprint. And when you make it that salient, that tangible, it goes from being this nebulous cloud to, okay, I definitely see how I'm having that impact. So when you get into reporting, phishing, you see that it's not just a button that goes to the IT team, but it's like, no, I'm protecting my community. And that really makes it something solid.

Sarah Buszka: Absolutely. I like how you highlighted the opportunity cost too, because I think it's so easy to think about things in terms of a dollar amount, especially I think in the environments that many of us operate in, public institutions that are dealing with funding challenges often. So framing it as in terms of the opportunity cost, I really like because we always are trading off something. So that's great. Thank you.

Wes Johnson: So Amir, I'm going to stay on you for a second. We talked a little bit about, I like at least what I took from Hannah's framing and what you kind of carried with it is you kind of empowered the community in a way. I gave them some agency by highlighting someone who took an action and they had an immediate impact, which I think is great and something I'm going to take back to my own teams. But I'm curious for you, so has there been a moment that you realized like, "Hey, I actually have more power to influence my institution's cybersecurity posture than I thought originally?" Has there ever been a moment where you were in a room and you realized they were all looking at you for the solution or the next step or you had that opportunity to do something?

Amir Lawrence: Yeah, actually. So I've been at my current position for about three to four years now, but I'm the only person on my team who has a humanities background. So what I'm noticing now, and I've noticed over the years really, because we've been shifting towards, not shifting, but we're more so adding on a more human-centric approach to the technology that we already have. But in a lot of these rooms now, the conversation isn't more about, okay, do we need this firewall or that firewall? Do we need this antivirus? It's more so, okay, we have all these tools, but people just aren't engaging. They don't seem to care. How do we make that happen? So that's where I'm kind of becoming the subject matter expert. I have been the subject matter expert is because I think, again, going back to that original point that we were talking about earlier, Sarah, the finesse. It's just like, how do you talk to someone who doesn't understand really what you're trying to get at? They think it's pretty dumb. You're trying to take away from the time I have to go teach these kids. It's interesting I like it because I can't really explain some of the techniques I take. It's more of just it feels. Even in the sense of, okay, when we are asking a school district to send out phishing emails for simulated phishing training, there's a lot of feedback of like, all right, people are coming and saying, all right, I have to teach 50 kids this subject and you're asking me to do this training and you're trying to trick me and phish me and get me to click these bad links. So it's like, okay, maybe let's sit them down and see where they're coming from, but then let's actually have them work through some of the simulated education emails, if they can spot the red flags and talk to them there. And they might be like, "Why don't we just mandate this? And if you don't do the training, you get ticked off the network and they say, okay, you can use the stick, but the carrot will be a lot more smooth and people won't be angry at you." And they'll believe in it and they actually will want to do better. And that, again, goes back to bringing in the community because I might not know what the right incentive or explanation is for a teacher because I'm not a teacher, but if I can find a teacher who does care about cyber and has that insight, I can put them on that platform. And then I get to step back and we still get the growth we need, but you don't end up with this sort of big brother is making me do cybersecurity. It's for us, it's by us.

Wes Johnson: No, that's great. What about you, Anna? Ever had that moment or anything to share on that? Anything to add?

Hannah McLarnon: Definitely what I mentioned earlier about, oh, people really are responding well to this regarding calling people out for their good work.

Sarah Buszka: It sounds like you've had a lot of opportunities and situations where you really have influenced a lot of your institutional strategy for resilience. And I'm hearing that from Amir too. So as I'm switching gears a little bit here, because I think I've heard a lot of great examples, maybe I'll ask you Amir first and I'll go back to you, Hannah. If we have another audience member who's listening, who's in a similar situation as you are right now, in similar place as you are in your careers, is there any even smallest piece of advice that you can give them that they could take even in one day to have some institutional impact in terms of institutional resilience? What would you recommend?

Amir Lawrence: What I'd say is the biggest thing really is to always be fighting that voice in your head. That's the imposter syndrome that's telling you that maybe, especially for me because I came right out of college into this role. So it's like there have been conversations, and going back to your last question, there've been meetings where I hear what's going on, I hear leadership talking about what they should do, and I'm like, "Okay, this seems like we're really over complicating it. And if we just did X, Y, and Z, we'd be right where we need to go." But I've intentionally muted myself because well, I'm new here or I don't have the 20 or 30 years of experience to do that. But I think really the beauty of having young people in these paces, these conversations now, especially right now, is that young people have a very unique perspective on the world due to going through not only university during the time, at least for me with COVID and things like that. But then when you just see this is a people issue and as a student or a former student, you're closest to what it's like to not understand cybersecurity. So for me, I'm thinking about it as, okay, if it was five years ago and I had no idea about all this technical jargon I have to understand now in a business continuity plan, IR tabletop and this and that, it's okay, well, what do I do to get to that person? And I think that's such a unique thing because I can tell even now it's happened to me, I think it's a natural occurrence that not you get jaded, but you just become engrossed in the work and you forget who you're serving. And I think even especially because I do a lot of work with higher ed, even though I'm not serving high ed heavily, there's still this ivory tower of sorts that we forget that we're in because we're able to work and be in higher ed and serve in these spaces. So when you're dealing with rural communities where, again, people have, this school is all they have. They are being severely underpaid and they are severely overworked. So I shouldn't be coming at you all heavy and top down with all this like blah, blah, blah, blah, blah. I should approach you from, all right, well, I was in college and I get this kind of confusing and it doesn't seem like it makes that much sense, but when you get past that imposter syndrome, you really get to showcase your unique perspective. And that diversity and perspective and voice is really what pushes us forward towards a more longstanding cybersecurity culture that's a bit more holistic to all the population we'll be serving.

Sarah Buszka: Yeah, absolutely. I think that's a really important point that I just want to double click on because I think imposter syndrome, and I'm speaking from my own personal experience here, is real. And I think especially for being a young professional in a career and in a setting where many of your peers are a decade or two, you're senior and you're the only one in the room who might be in the age range of 20s having recently graduated from college. I think it's a natural, according to human behavior. It's a natural and easy kind of lens to start keeping on often, which is that imposter syndrome and walking into spaces and feeling like, oh, I don't belong and so I don't really have something to add here because there's someone who has 20, 30 years experience. So what value could I possibly add? I think it's very easy to say that to ourselves and some of the easiest lies to believe They're the ones we tell ourselves. And so you made a really good point of, no, actually I do have value here. Everyone else does too. That is all valid. And since I'm so close to this population that I am serving, having just stepped over the line here, how can we look at that as a strength and see that I'm a bridge here too? And that we can create more of this holistic experience because of that, not in spite of it. So thank you for bringing that up. I think it's a really important point that young professionals and professionals of any age experience and go through. And I like that we're talking about it because it's important. So switching gears to you, Hannah, we're kind of rounding out the show here talking about some advice, but if you had a young professional staff member who is listening or even on your team and really wants to influence institutional resilience strategy, cybersecurity, privacy, what is the smallest next step that you would suggest for them to take that would be realistic that would lead to some type of impact?

Hannah McLarnon: I think my number one advice to young professionals everywhere in all fields really is ask questions. If you are lost, do not be afraid to ask a dumb question. I ask so many dumb questions all the time. And I've never had anyone get angry with me for wanting to know more. I've only had people be excited to share. And that is what kind of helps me overcome imposter syndrome is putting my knowledge out there, my level of knowledge, and just leaning on my willingness to learn. If I'm feeling like I don't belong somewhere, I lean more on my desire to be somewhere rather than am I trying to fit in? No, I'm trying to learn. But aside from that, I would say if a young professional is trying to be in tune with security and be prepared, read up on any incident response or disaster recovery documentation that your organization has. Being prepared is the number one thing you can do in a high stress situation. Like we mentioned earlier, unpreparedness results in quite a bit of chaos. So it'll make it a lot easier for you if you know what to do in advance.

Sarah Buszka: Absolutely. Because then you end up being able to tell other people what to do because you're prepared and rehearsed, right? And I think that there a little ripple effect there. Yeah.

Hannah McLarnon: And I do have one more thing. Oh, sorry. You

Amir Lawrence: Want to go back? No, I was going to add up to your point, but yeah, go on.

Sarah Buszka: Go ahead. Go ahead, Hannah.

Hannah McLarnon: Sorry. Community is super underutilized. It is one of the most important parts of developing as a young professional and also one of the underutilized parts, especially in this day and age where most people are working remote and kind of isolated. But there's so much you can learn from others that can make learning things you don't know a lot more manageable. I would encourage any young professionals to get involved with a community specific organization or information exchange such as K-126 or EDUCAUSE. They've been incredibly valuable to us in the K-12 sector. And I encourage making friends in your industry and just continuing that communication flow.

Sarah Buszka: Absolutely. Shout out to EDUCAUSE, obviously, especially the YPAC and Young Professionals Community Group. It's a great place to do that and take that next step. Absolutely. Amir, what would you add as a final closing thought for us?

Amir Lawrence: Yeah. I think Hannah dropped a lot of really great gems there, especially on the topic of going out and reading up on things and preparing yourself. I think to take that a bit further, for me, it was really an issue of finding your passion within cyber. I think that's kind of the beauty of it, is that cyber is so diverse in where it can apply in the field. So for me, with the psychology background, I found a true passion in security training and just being on the human side of things. But I think once you are able to find that passion, it makes it a lot easier than be a bit proactive about learning more and being speaking up because then you actually want to do that extra step. And then that goes right into Hannah's other point about just with that community, that validates your perspective that for me feeling like I was the only person who really cared about the humanities and the people of it all, but then going to the EDUCAUSE conference and talking to all the professionals there and really explaining what I'm doing about security training. It's like, okay, I'm not this black sheep on my team who's just trying to be super lovey-dovey in humanities. It's like, no, this is a very big space and there's a lot of cool research and science and practical things you can do there. And I just think whatever that is for you, that'll be sort of the gateway to then you finding your own path because it really is going to be everyone's own path. There's no badgic bullet. It's just at least taking that first step to say, all right, well, I want to do something here as I figure out what it is and how much I care about it. And once you do find that, you're really off to the races.

Sarah Buszka: There we go. Mic drop moment. For both of you actually, compounded mic drop moment. Thank you for sharing your advice.

Wes Johnson: Well, Hannah, Amir, we are just so thankful for y'all joining and sharing your knowledge and perspective on this. I've tooken a couple gyms away to bring back to my team. So thank you for that as well. We are the EDUCAUSE Rising Voices Podcast, and we will see you on the next episode.

This episode features:

Amir Lawrence
Cybersecurity Analyst
North Carolina State University

Hannah McLarnon
Cybersecurity Analyst and Program Manager
Baylor School

Sarah J. Buszka
Director, Applied AI Lab
Waukesha County Technical College

Wes Johnson
Executive Director Campus IT Experience
University of California, Berkeley