Sophie and Jenay are joined by Wendy Battles and Ben Woelk live at the EDUCAUSE Cybersecurity and Privacy Professionals Conference to share practical ideas for the essential, yet challenging, work of building cybersecurity awareness in higher education.
Takeaways from this episode:
- The best cybersecurity awareness strategies go beyond meeting compliance requirements to helping institutional communities feel informed, supported, and confident in their decision-making.
- Changing individual security habits requires surpassing one-time training to build sustained, creative campaigns that understand the realities of student, faculty, and staff work in higher education.
- Strategies for effective cybersecurity awareness include focusing on high-risk groups, adapting to changing threat landscapes, understanding both quantitative and qualitative user feedback, and regularly updating training campaigns.
View Transcript
Sophie White: Hello everyone. Why don't we get started? Thank you so much for joining us for this live podcast recording of EDUCAUSE Shop Talk. Today we're going to be discussing the Swiss Army Knife of Cybersecurity and Privacy Awareness. So we'll have a conversation with our guests here today and then we will be posting this online as part of the EDUCAUSE Shop Talk series. So thank you all for joining us at the EDUCAUSE Cybersecurity and Privacy Professionals Conference. I'm Sophie White and I'm a content marketing and program manager at EDUCAUSE and one of the hosts for today's discussion.
Jenay Robert: And I'm Jenay Rober and a senior researcher at EDUCAUSE and I'm your other co-host.
Sophie White: And we're so excited to have two guests with us today. We have Wendy Battles, Yale University Cybersecurity Awareness Advisor, and Ben Woelk, Rochester Institute of Technology Governance Awareness and Training Manager with us. So I'll introduce Wendy and Ben and then we'll jump into it.
Wendy Battles is the cybersecurity awareness advisor for Yale's Information Security Office where she leads engaging awareness campaigns, training and communications that help faculty, staff and students build safe cyber habits. She transforms complex cybersecurity topics into approachable actionable guidance for the Yale community. Wendy's also the co-host of Yale's Bee Cyber Fit podcast. That's B-E-E Cyber Fit, where she helps make cybersecurity relatable and accessible. Thank you so much for joining us, Wendy. And I know that you also host your own podcast on the side outside of Yale. So we're really excited to have you today to chat about cybersecurity awareness.
Wendy Battles: Nice to be here.
Sophie White: Ben Woelk is a CISSP CPTC and the governance awareness and training manager for the Information Security Office at Rochester Institute of Technology where he's developed a leading information security awareness program. Ben is a member and former co-chair of the EDUCAUSE Internet Two Security Awareness and Training Group of the Higher Education Information Security Council.
He's also a fellow and past president of the Society for Technical Communication and an adjunct faculty at RIT teaching classroom and online courses in cybersecurity policy and law, technical communication and introverts and leadership. Thanks for being with us, Ben.
Ben Woelk: Thanks. I appreciate the opportunity.
Sophie White: And I think you also have a podcast called Hope for the Introvert. Is that right?
Ben Woelk: That's correct. Not actively recording right now, but there are thirty-plus episodes available on all the major podcast platforms.
Jenay Robert: And thirty is plenty for an introvert, right?
Ben Woelk: It's an interesting format because the idea of taking... The idea of doing a podcast as an introvert is absolutely terrifying. But when you have a guest who had a conversation, it just really flows well.
Sophie White: Absolutely.
Love it. It's very meta. We could talk about podcasting on the podcast. But no, I love that. And thank you for sharing that too because I think this topic, cybersecurity awareness training, we could talk so much about things like communication strategies and social media and all of these things that I think tend to be associated more with extroversion. And I think it's really important to think about how we can all bring our own skills and personalities to this kind of work. I know that anyone at this conference, there's also a social media marketing conference that has been happening in Anaheim. And I walked in the first day after getting off the plane and saw this massive group of people who were at that conference and so loud and I immediately ran away. So I feel like social media can get kind of that rap, but it also communications could be a really thoughtful way to intentionally train on cybersecurity and privacy awareness too.
Jenay Robert: Yeah. I mean, that's a good segue, right? We should do case for running. That's great. That's a good segway of thinking about creative leveraging of communications or raising awareness. What are some of the most recent things that are top of mind for you or things you're trying out, funny stories, fun facts around that? Fun stories. Fun stories.
Ben Woelk: That's very good. Yeah. You can start because I guess we need more time to think.
Wendy Battles: Sure. I would say that we're always trying to be innovative at Yale in how we engage our community because we all are so overwhelmed with information coming at us from every direction from email to Slack, or Teams, to our personal phones, all things throughout the day. So I feel like it's getting hard to get people's attention just to build awareness about things that are important, let alone trying to encourage people to change their behavior to more CyberSafe. So we're always trying to figure out new ways to do that. And a few years ago we introduced this idea of Boola, or Cyber Bee, which is both a graphic and people know Boola. Boola has many different posters.
It's designed for different campaigns with different things. So sometimes we're doing campaign Boola by be on a lotus because Boola is thinking about relaxive before responding to a deficient move out. So it got really creative and using Boola. And now people really recognize Boola on campus. They're like, oh, you're the B wallet. When I run into people, because we teach a lot of webinars and things like that where I can't necessarily see everyone, they could see me cocoas tea something. So that's become part of what we do. It's recognizable and memorable. And we over time introduced a monthly tip with Boola, our newsletter, our podcast. But recently something we've done that's different and new is that we decided to introduce a video series. So we wanted to sort of animate Boola and wanted to do it in, again, short ways. Attention is so short, you have a few seconds to grab people's attention before they move on to the next thing.
So we do, I would say ninety seconds videos with Boola about key cybersecurity topics, things we want people to know about. So the things that people can't do. So always kind of seeing that with behavior change, but in some way that grabs people's attention. And so we work with our internal team, our pretty publishing team that produces the video scores and that's really fantastic. It's just a fresh take on things because I think that sometimes when we do the same thing again and again, they get stale and we can't always expect people to act on that or to pay attention to that. So we'll always try to find a little something different to grab people's attention in a way we could be really engaging that will hopefully broaden their thinking about cybersecurity awareness and their own behaviors. So that's really...
Ben Woelk: Speaking nothing. No. It's funny though because there is always that push to be innovative and creative and to getting people's attention for more than five seconds is really, really art. But I think there's a larger context around it in terms of that we're trying to change culture and that doesn't happen overnight. It doesn't happen with one or two innovations for things like that. So it's not necessarily telling everyone the exact same thing the exactly the same way all the time, but there does need a consistent message over time so we focus on that. Interestingly, Yin Min mentioned that Boola has costume and everything and may walk around and you get people to wear your student orders, which is a little trickier. We have a fish costume, which actually I think it's supposed to be a bass. It's this kind of hulking fish costume. And I was going to say part of our student review program in terms of behavior doing those don't really try to see will they fit the costume, but it's kind of there in the background.
And there should be a willingness to I think be silly. And honestly you don't lose in the costume most of the time anyway. But it's interesting with trying to change culture. And I try to look at this as strategically as what can we accomplish over time. The tricky part is what have we accomplished over time and how do we measure that? And I think that still needs to be a bit of a struggle.
Sophie White: Are you measuring it at all? I know that's a tricky question, but how do you evaluate in some sense the success of your campaigns?
Ben Woelk: So we're like -
Wendy Battles: That is a question. And it's hard. I think that measuring awareness effectiveness is very difficult and we're always struggling with that. There's only so many quantitative measures to figure out effectiveness. And there's such a debate even about even if you do phishing simulations, if we don't even do at Yale, there's two sides to that story. Some people say that you can do them all you want, but when it comes to an actual email, it doesn't necessarily need people will click on it. So I think that for all of us, it's a struggle to figure out how will we best measure the effectiveness of our programs. We put a lot of effort into things. We're trying to be strategic, but we also want to feel like there's some payoff for this and things are shifting. So I would say that we measure quantitatively in terms of how many people have registered for campaigns that were today.
What is the participation in different webinars or events that we're having? Can we see that difference over time and is it growing? I mean, it still doesn't tell you how engaged people are. It still doesn't tell you, well, okay, they came to a webinar. Did that change things? But I think we also then use qualitative information to help us. And one thing I happened to look at my email this morning at six in the morning, it's nine o'clock back east. And it was someone who had come to a webinar that we've done. We just did this great short campaign called Protected Because It's All Connected, which was just all about this idea that whether it's at Yale or at home, all of our information is really connected and that we have to really be thinking strategically about how we protect ourselves in both places. So she said she'd come to some different webinars and she said, "I have to tell you that my mother who is older had gotten into some trouble and someone had scammed her and she lost a bunch of money."
But she said that she came to this workshop and she learned so much and she was able to go home and share that with her mother. And together they really kind of talked through what happened. And it wasn't going to bring back the thousands of dollars she lost. Luckily it wasn't like her whole life savings, but we've all heard stories or we know people and we know the impact of this. But I thought it was really interesting that she was so grateful to gain this information and to literally apply it right away, to be able to have conversations, to know what to even say to her mother, to start that dialogue so that they could prevent that from happening again. And in a way that was not threatening, not like, " Yeah, maybe you did this mom. "But you have to meet people where they are.
So to be able to have this very compassionate conversation with her mother who feels so bad and ashamed about what happened and embarrassed. And so I thought that's just an example of how we try to collect information qualitatively that helps us also understand sometimes the impact of the work that we do.
Jenay Robert: So creative.
Ben Woelk: Yeah. And I think with that messaging, I mean you talk about it being relevant to your mother. That wasn't your target audience, but we're looking at, we've always tried to give our community information that helps them stay safe and helps them help others stay safe as well. So there's been had a much kind of stronger focus on these are the things that you can do that are going to... I didn't mean cyber hygiene as a term or anything like that, but it's what are those key things that they could be doing? And I'm not big on coming down on the compliance side. You have to do this because such and such. And a lot of what we've done really is a lot. It's interesting. There's a lot of building relationships and that may not seem to make sense on a mass communication basis, but there is always the, we want to be available as a resource.
We're very consultative with staff, faculty when we can get faculty to remember we're there. But we're awesome. But we also try to be helpful. We try not to be the office of No. And I know as when you're at cybersecurity, the assumption is that is what you're going to do is tell people what you cannot do or take away something that they want to do. So we've really focused on, okay, yes, do you want to do that? How can we help you do that securely in a way that's going to protect whether it's privacy or confidentiality or any of those things.
Wendy Battles: That's so true. I keep talking about this idea of culture change that takes time and try to transition from the office of N-O to the office of K-N-O-W. And I always feel like that's a work in progress in trying to build these relationships and speaking on different ways. One more thing I do want to mention, you mentioned that first question, what are you doing that's fun? And I just remember that it both kind of combines something that's fun and engaging, but also helps us with metrics. And that's that we started a Viva Engage channel. So for any of them that has a Microsoft shop, Viva Engage used to be Yammer, which was this application to use, I don't know, back in the 20 teens. And we're not sort of a social media kind of organization where people are, it's that, but basically it's an app with the Microsoft Suite and it's sort of like social media for whatever you might be doing.
We have the Verge for groups at Yale. And so we said, well, what if they started this Viva Engage channel but was branding with our bee, Boola? So it's called The Hive because it's with The Hive, Yale Cyber Buzz. And that has been a fantastic way for us to engage the community. It's a different way to communicate. It's a different channel since of course people are busy. People could become and they get notifications so they could see when we've posted, whether it's daily or it's weekly. But one of the things I love about that is that there are fantastic metrics that we can glean because it's always so hard to measure this, but you can measure engagement, how many people are engaged over a period of time, et cetera. So that's been really helpful for us to be able to have something very specific. So we have goals for how we want to increase it by a certain number of members.
And my goal when I started, I thought, oh, we can get 300 members to a cybersecurity readiness one. Because I thought it'd be so easy if people would just join and we did all those publicizing, but of course people are busy. Living their lives and doing work. And I think again in the month I did 150. So I still kind of was pretty good for half my goal and we're still working on it. But I think that's just another tool. Always think about you, we don't have money. And I know budgets are tight these days. So how can we get creative or limited resources to engage people and also measure things? And that's a really great way for us to do that.
Jenay Robert: I think another part of this is because we don't have unlimited funds or unlimited staffing. We're also risk managers. So it's not a case of we just need an awareness program. We have to see which groups are going to be targeted. What can we do for those specific groups? And it's been really interesting because it varies year to year in general. It's like, okay, the students aren't high risk to the university, but wait a minute, they're being targeted. And now accounts are getting compromised and they're putting in refund requests. The attackers are putting a refund request for tuition. And it was how do we approach that? Because you've got many stakeholders, which as you can imagine, it was really difficult to get consistent messaging when you got eight or nine different people who want to determine what to say with it. But it ended up being a combination of we're going to have communication around it.
We also have to get specific ethical controls in place. So I'm kind of in this governance policy training development awareness space. So I'm not doing anywhere near the amount of awareness I'd like to be doing, but it does get me into a space where I can look at policy, do we need to change things there? What are the different things around messaging? But in terms of higher risk places, we have done specific campaign things following our office or our, what's called university advancement at this point in time because they're targeted. They have access to financial information or finances and doing campaign type things for them limited time, not forever, but doing limited campaign type things and meeting with them and explaining value and targeting them has really been helpful because I do think they look at us for as a partner in helping the university again and rather than so you can do that.
Sophie White: Yeah. I love that take. You hear so much at this conference about risk assessment. And I think you've heard about maybe putting controls on specific really sensitive data or thinking about how to separate systems, federate data so people have access. But I hadn't heard about it in relation to the awareness space of how do we actually do risk assessments in terms of our communications. So thanks for sharing that.
Wendy Battles: Yeah. And it really feels like, well for both of you, your awareness efforts are integrated and diversified in very interesting ways. It seems like something that's being done effectively needs to be happening from different angles and different modalities at different times. Can you talk about that approach?
I think you're so right that it's a multi-layered approach to reach people. I will, that one of the things that we learn when we go to take CS courses, they have a course that created some security awareness program. And one of the things I tell them a lot about is the top down approach, that you always have to have support from the top for what you're doing, which is really anything we're doing, whether it's around cybersecurity or organizations. And that is really important, but I think an effective program has different approaches to reach people and yes, top down is important, but we also know that not every leader is as invested. All our leaders are going to be busy like all of us are. So getting their attention is difficult. Sometimes in case an incident or something happening or it's often something happens at a peer organization that a light bulb goes on for us at Yale, we're like, oh my goodness, they've had this problem and we want to try to prevent that problem so that can motivate us.
So yes, the top down is important. So for example, we got people into our past robust program with YubiKeys in the office of development and in finance based on things that have happened at other places. And that was an imperative and those leaders were all bought in on that. But that can't be the only strategy because not every theater, they might think it's important, but a lot of things are important and other things that are urgent and important and that's where their attention is going. So we could chop what we want, but it doesn't mean we can motivate them to raise that as a priority, the public needs to be out there pressing. So I think we also have this buy your top approach, this grassroots approach and sort of middle approach. So the grassroots approach part of that is using The Hive at Viva Engage to try to engage people and to get people to come to our webinars.
And one thing we've done that's been really creative is that we've partnered with Harvard to do a series of webinars. In fact, right there who's presented today is also a bit that's one of the facilitators at some of our webinars, but we've tried to find creative ways to take the limited resources we have and engage a larger group of people. So by doing this joint endeavor, we've gotten people or people to come, new people that hadn't been part of our program. And maybe having a tech in an event we've done will then become part of our list that we then like email and encouraging you to join our mailing list for upcoming events. So it's sort of that creative approach to get people to engage with us that I think has been helpful so show top down and so on.
Sophie White: Sounds like stakeholders engage you on stakeholders across the institution and also outside of the institution to partner as a field as well.
Ben Woelk: So I think it's interesting because we all have a lot of constraints whether it's staffing, funds kind of tie in right together for some reason. But it's tricky because we rely heavily on student employees and we always have a co-op position in our office which is a non-technical cybersecurity position. So I'm typically looking for communication students who can understand technical and contextualize and explain it for the community. But we also tend to rely on what their specialties are. We had a student who's absolutely brilliant on the social media side, loved doing a bunch of little short clicks, wearing a fish costume. We'd be doing ridiculous things. And really I think he was increasing the social media fall. The tricky part is that the next semester we have much different priorities of things we have to get done and then some things start dwindling and we have to figure out how to kind of build things back up.
But one thing I wanted to mention, we absolutely have the don't waste the crisis part of it. But that's interesting because we're really trying to build that culture so we don't have as many crises. But again, if something happens, absolutely need to leverage it. But that also makes us reactive and not proactive. So part of I think the goal is to figure out that there are a whole bunch of cybersecurity threats that come in. It's always the thing around phishing, credential compromise, that sort of thing. But recognizing that we've got that wide span of different types of attacks, we need to make sure we're talking about that to some degree all the time. And then kind of focusing on the, we got to do something about this problem. Quick look. It's interesting because we do custom training because I do have an instructional design background and I understand content so I can build a training, but we tend to rely on it too much.
I'm sure all of you know that if you have an annual training, then the assumption is there's nothing else you need to do because you're getting it in front of them once a year. But one thing that we do add to it is we make absolutely sure that if there have been specific new types of scams attacks we've seen over the year, they get folded into the next year's training. So we had a year where we had immigration spams were a big thing. We had students lost almost $10,000 in less than twenty-four hours. And it was a phish type thing, but it came in over voice and they knew about phishing, but they did not expect that somebody could come in and oh look, it's immigration and customs on my phone. It's got to be that's what it says or it's a financial aid office or something.
So we make sure that gets built into the training. And anytime you see something that's different or a concern, at least you've got the ability to do that. So I feel like it's not enough, but we're customizing to make sure we're getting the right messages out.
Sophie White: That's a really interesting point. And I feel like I'm thinking about the generalist session a bit. I'm curious what you all think, but Mike Horn said we're bad at cybersecurity training as a field in general, that compliance would be the floor. We should go beyond that. So I'm thinking about that, I'm curious what you two think. But I'm also thinking about, it sounds like, Ben, from your example, you're working with the team that you have and specific capabilities. You have an instructional and design background, a student with a social media background. I guess, how do you let employees and staff members kind of use those skills that they're excited about and they have the skills in, but also make sure you have a consistent plan for how if you don't have a student with a social media background for a particular semester, you're still getting word out about the awareness training.
Ben Woelk: It's hard because it does have it flow and we do have different offerings, but I am terrible in terms of being a hands-on manager. So we really do a lot of work in the interview process to make sure we're bringing someone that can run and all guided. It's not just a great goal. Please don't ask me every day what you need to do for specific things. So I think a lot of it is a talent acquisition thing. It's just if we're doing it every semester. And so we do get different advantages. It's tricky. Our tools that we've had available to us have changed. There's more that I'd love to be doing more on digital signage. We're probably towards that in the next year. But we had a huge push university-wide stop sending so much email and email to students particularly. And I suspect they may have what's up week from the university where they were.
So it's like the straight email, it's not always greatly effective, but at least you know you're sending it out is part of the vague vehicles, but it's not what it used to be in the passive. It's a challenge. I don't think we've figured it all out yet. It is interesting because I know one of the top end, and I don't know that's segue topic wise a little bit, because you wanted to talk about generative AI and how we're using that cybersecurity awareness. Casey Hennig, who was my partner in the pre-conference seminar we did on Tuesday. The pre-conference seminar is all around thinking strategically about awareness, whether it's privacy or cyber security or a combination of both. And part of what we do is force people to do the work to figure out who their audience is, which isn't as simple as, but really we've got researching teams, we've got this audience, that sort of thing.
We're doing the work to understand what their goals are, what their messaging is, who their audience is, who their candidates' partners are, which is a huge part of getting information out there. So we do the work to do that. We're talking about what works with the gen AI space on that. And part of Casey did most of the work on this part of it, but part of what we did with that was talk about if you're getting the right prompt engineering in there, talking about what you're doing strategically, we've essentially got a word look that comes out of that pre-conference, which could feed into a gen AI tool, but also what university you're at. And it's been interesting because we found out about research. We didn't know we're available putting it into the gen AI. So it's been good in terms of helping create a larger picture around what are the different capabilities we have, but it's also been great for ideation and even things as trite as oh we're supposed to put together a table, an interactive game thing for a cybersecurity fair, which sounds like a really odd thing, especially more as I say it.
But the idea is, what are some games? And throwing that into a tool which we'll be getting ideas back on that. You ever can leverage that. Yeah, we'd love to do the whack-a-moles thing. We don't have the whack-a-mole thing to use, but just in terms of new ideas, new ways to do things, what's been effective? I think it's been really helpful to run to that.
Jenay Robert: Yeah. Your fair made me think about some of the conversations he had around strategic partnerships around campus because I was thinking about when I used to work on a campus and we had a research fair. And so some of our strategic partners included IRB, for example, the offices of NO sometimes we think.
Ben Woelk: I guess the offices though.
Wendy Battles: What's his other podcast? Apple IRB at the time. But yeah, I mean those strategic partnerships are still key to work. What advice do you have? I mean, we're sitting in front of a room full of cybersecurity and privacy professionals, but we also will be sharing this with the broader EDUCAUSE community. And so that's one of the things I see when we do best at EDUCAUSE is opening some of those bridges and partnerships. So where would you like to see some movement in that regard?
Such a great question. I feel like the landscape is right for even if you already have a bunch of strategic partnerships, you're building, continue to build those relationships, looking at departments maybe where you haven't had a chance to make inroads, looking at high risk areas. And you know how it is, there are areas where we find great relationships with people and it's just like a whole run for both parties. What we've been able to do, like going into departments, as you said earlier, Ben, at doing specific programming or just trying to understand their specific needs, creating things that really need their needs in terms of their stack of faculty. So I think that can be such a win. But of course we all have those areas where we're like, "You have to start" or "I haven't had success in that area. What can I do? " So I think there are ways and can even define one or two departments where we haven't been successful or maybe they have a new leader and beginning to build a relationship with that new leader just sitting down had that meeting with them.
Say, "How could we be of service to you? Here's some of the things that we offer. We'd love to be able to customize based on the needs of your department with your area. How can they best partner with you? " So I think that even sometimes if it's been a No, an N-O from that leader or that department before, maybe there's someone else in the department, maybe the leader's too busy. Maybe we can go to them and say, "Hey, we'd still love to partner with you. How might we do that? " So I think that there are different approaches we can use to even begin to have that kind of conversation with people.
Ben Woelk: Yeah. And it's interesting because we started our standards process many years ago at this point, our internal policies. We had some really available cranks from some of the different colleges and we enrolled them in the process. We invited them in because they had strong views on it. And if you can get them in mold and you can help build a better product, it makes a big difference. So it's also, I think, helping them understand perspective views on things, whether you agree with that or not. But so much of your work, whether it's awareness or any other aspect, it is bridge building and it's maintaining those bridges and not assuming everything is okay if you haven't heard from someone in a while. And I'm sure all of us have been in situations where we've worked with people who are very adept at burning bridges, but it's so difficult to rebuild those things.
So I think that focus relationally is part of why culture change takes time too, because people need to know you're going to be consistent. If you tell them something that you're going to stand behind it, that you're not just going to flip things around on or if you do, which sometimes we have to, that you've got your conversation. And I think to me open, but it's like owing the relationship tier. You can see people once a year, maybe once every five years, but you can also work on what's these relationships going after this and let's have these regular communications. And it is so helpful to be able to bounce ideas off of people with career diversity. And honestly, we do get the very much yes. We're all in the trenches together trying to get this done, but this conference has been phenomenal for making long-term friendships.
Well, last sign of yours.
Wendy Battles: I'll add one more thing to this idea of how do we build these bridges? And it's not always the top down because we could do so much. But one thing that we've done, we have Viva Engage posts. A couple of times a week we have a post and we work on strategy thanks to AI to help us think about acting a strategically make sort of a long term plan about engaging the community. So one of posts they had recently was, do you have a departmental newsletter in which we could post some of our content periodically? And I was surprised by how many people responded. And some people went to their leaders and then they said, "Oh yes, we do. " And I think that's a great entree into departments because one of our ambassadors on the cybersecurity ambassador program, one of our ambassadors has been asking them for a couple of years, "Can we please put something in the newsletter?" And the answer was always no.
Maybe someone to John. But if you're persistent, you have the right approach. We got an email recently and she said, "Oh my gosh, they want us to put something in the newsletter." And so I think that sometimes that grassroots approach for someone who's in the department that maybe is the leader, but has some influence or they can find new ways to approach it and talk to people can be really effective. And so now have that content going into that newsletter. And I think that's again, just another approach to kind of get into the department. And then once you get in, there are other ways that you can leverage to kind of expand your reach.
Jenay Robert: I mean, I think ending on that note of collaboration. I think to me, what I will take from this conversation is that it's a true collaborative effort. It is not, we're going to collaborate by me telling you what you have to do, which we've all been in those collaborative relationships. But hearing that this is a true spirited collaboration, I think it's a great...
Sophie White: Yeah, I completely agree. And I'm inspired that I think in this age of we're talking about AI and mythos and all of these really scary things that are coming out of the world outside of our institutions and trying to attack and to hear how we can band together as an institution and also as a community to really address those collaboratively is inspiring to me. So thank you both so much for all of the work that you do and for sharing these conversations.
This episode features:
Wendy Battles
Cybersecurity Awareness Advisor
Yale University
Ben Woelk
Governance, Awareness, and Training Manager
Rochester Institute of Technology
Jenay Robert
Research Manager
EDUCAUSE
Sophie White
Senior Manager, Program and Content Marketing
EDUCAUSE

