Higher education·Oct 8, 2026·3 min
Think Campus Cybersecurity Is Just IT's Job? Think Again.
Campus cybersecurity still gets framed as a data-center problem. Firewalls, EDR, ticket queues, and a CISO slide deck. Then a faculty member forwards a grant phishing link, a student worker shares a registrar password, or a contractor account stays live after the project ends, and the institution discovers the hard way that humans are part of the control plane.
IT owns the stack. The campus owns the behavior.
October's Cybersecurity Awareness Month is a chance to stop treating "be careful" as a plan. Awareness emails are cheap. Practice is what protects enrollment, FERPA obligations, and the systems that keep the semester running.
Why "be careful" fails on a busy campus
Urgency is normal in Higher Ed. Registration holds. Grade deadlines. Research submissions. Travel. Password resets right before class. Attackers use that urgency. A warning poster does not compete with a message that looks like it came from the help desk or the dean's office.
If your only human control is an annual training completion percentage, you have a compliance metric, not resilience.
Who else has to own this
Identity and access. Stale roles, shared accounts, and MFA exceptions are not "IT cleanup." They are operational risk owned by the departments that demand exceptions.
SIS and LMS owners. When those systems are the target, the people who run registration and teaching must know the runbook, not just IT.
Communications. Someone has to speak to students and parents when the inbox becomes the incident. That person should practice before the incident.
Leadership. Funding and priority freezes decide whether Exposure Management findings get owners or age into next semester's breach.
The campuses that handle phishing waves cleanly already treat cybersecurity as shared operations, not an IT-only queue.
What shared ownership looks like in practice
-
One phishing or social-engineering tabletop per semester that includes faculty affairs or academic leadership, not only security staff.
-
A written rule for money, wire, or sensitive data requests: second channel to a known number, never the number in the message.
-
Identity cleanup with named department owners and a finish date, not a perpetual backlog.
-
A Monday SIS/LMS outage card with decision, technical, and communications owners.
-
NIST 800-171 and FERPA evidence work scheduled as operating work, not as a scramble after a finding.
Awareness month without the theater
Posters are fine. Pair them with one practiced scenario. Measure whether people report, not only whether they completed a module. Retire the shared mailbox passwords that everyone pretends are temporary.
Cybersecurity is not just IT's job. Pretending it is guarantees IT gets the blame when behavior fails.
What IT should stop owning alone
IT should stop being the only group asked to "fix awareness" after a click. Awareness without department owners for access exceptions is theater. IT should also stop being the only group blamed when a faculty mailbox becomes the path into SIS-adjacent systems.
Hand departments a short list: which roles need MFA exceptions, which shared accounts still exist, which vendors still have admin. Ask communications to draft the student-facing message for a phishing wave before one lands. Ask academic leadership to sit through one social-engineering scenario a year.
That is not pushing work downhill. That is matching ownership to where urgency and exceptions actually live.
Where NewPush fits
Shared ownership improves how the campus handles human risk. Fluency practice belongs in the same room as phishing practice: people who can use AI under institutional control are harder to fool with AI-assisted lures.