Why Education Is One of the Hardest Environments to Secure
Michael Anderson, CISO at Dallas College, discusses why education is one of the hardest environments to secure, from open global networks and faculty-owned devices to legacy systems and cultural friction, and why prioritization, layered controls, and resilience matter more than budget size.
Securing education is less about having the biggest budget and more about prioritization: doing the fundamentals exceptionally well, keeping full visibility across on-prem and cloud assets, layering controls so backups catch what primary controls miss, and building resilience through practiced BCP, DR, and IR plans.
Episode Chapters & Full Transcript
Select any chapter or transcript timestamp to begin watching from that exact point in the episode.
Full Transcript
Welcome to Conversations with CISOs, Security Leaders, and Technology Executives, where we sit down with the leaders shaping cybersecurity and enterprise technology. Today I'm joined by Michael Anderson to discuss why education is one of the hardest environments to secure. Michael, thank you for taking the time to join me today. To get us started, could you introduce yourself and tell us a little bit about your background and your current role?
Sure, would love to. Thank you so much for having me on the program today. It doesn't feel like, for the most part, education gets enough time and attention as some of the other trades and corporate classes do. So I'm really happy to be here to represent education.
I'm very, very fortunate to be the CISO for Dallas College. In my last 12 years, I've served in a variety of CISO roles: at the independent school district as deputy CTO and CISO, and prior to that at Dallas County, serving as chief privacy officer and CISO. Before that, I was inside of the corporate world serving as the head of enterprise cybersecurity.
So I'm super duper happy to be here today to dialogue with you on some of the challenges I think all practitioners have, but more so today from the lens of someone who's inside of the educational space.
Excellent. So when people think about cybersecurity in education, they often focus on limited budgets. But what actually makes an educational environment uniquely difficult to secure compared to the traditional enterprise?
Yeah, so budget most certainly is a big deal, right? To the extent that you have budget, there's certainly a greater degree of latitude you have to bring in the tools that you need to safeguard your environment. And when you think about one of the key principles that practitioners like to deploy, defense in depth, that becomes incredibly easier when you have a healthy budget.
But I think there are some common threads and themes between corporate and education. As I think back to when I was in enterprise, I could just shut down, as an example, an entire country and say, "Hey, you know what, if you're not originating on an IP address that's from the US, Canada, Mexico, or the like, I'm just not gonna allow you in." Being here at Dallas College, where we have a global institution, we accept students from all around the world. I don't have that luxury, right? So I have to have a very, very open network. And so the challenge of trying to secure that becomes a much more difficult proposition.
I do believe, though, that there is a way, even without having the most robust budget, to safeguard an environment. And that is really through the concept of prioritization, right? We've gotta really, really fire well on the basics, and make certain that the things we've been taught throughout the years from a hygiene or posture perspective, we do those things and we do them really, really well. I think that then gives us the latitude to think through how we use the rest of the money that we have for more strategic deployments to ready our environments to move into the future.
There's a stark contrast between the corporate enterprise and the educational enterprise. I've given you one example, that some of us have to work on a global basis. I want to offer one more. When you're an educational institution, in the bad actor realm, you are considered low-hanging fruit. What that really means is that when they think about who their easiest targets are, education and government all get lumped into this big box as easy.
So we already have a bullseye on us, and looking at the traffic logs and seeing the number of attempts coming in on a week-over-week basis lends credibility to that idea. I wanted to share that because I don't think there's an appreciation for how real that particular aspect is for us practitioners who are in government and education.
And again, I want to emphasize the big notion here is resilience. That's our ability to do the things that are necessary so that when something happens, we know specifically how we're going to deal with it. And then closing off as many of the doorways, the attack vectors, as possible so that we don't appear to be as easy as they thought we would be.
So that first example actually correlates to my second question, which was that education is built around access, collaboration, and the free exchange of information. How do you balance that mission with the restrictions and controls that security sometimes requires? What are some of the ways education can take steps to secure their environment while still supporting that mission?
Yeah, one of the things that I learned shortly after arriving here was when a couple of my colleagues shared with me, "Hey, we don't supply our adjuncts, our professors, our faculty with PCs. They bring their own devices." And it's like, wow. I didn't know that.
In a world where you can control the narrative from an endpoint perspective, you can hand all of your constituents a machine that's locked down, so to speak. It has all of the right patches on it, software that's free of CVEs, and good endpoint protection that gives us visibility into what's actually going on. It also provides some fail-safes, so if somebody does click on something, don't worry, there's an application that's going to save you. When you can do that, it becomes much easier to sleep deep at night.
But when you hear something like what I heard, that some of my primary users are bringing their own devices, I don't know any of the things I just mentioned. I don't know if these are old Windows machines. I don't know if they've ever been patched. I have no idea what's running on them, or if they even have any protection. And I've got to allow those devices to connect to the network, right?
So we use a variety of different tactics to safeguard the network. At the network layer, we have protections that we've deployed. So when these particular asset types do connect, they get a nice screening, a bill of health, before they're allowed to move about and interact with network resources, whether they need to provide instruction or provide access to the students who are in the exact same bailiwick from an asset perspective.
So think about it in terms of tiers, right? At the network layer, we've introduced controls that help us understand what's going on when someone connects and what the health of the asset is. At the server level, we also have additional resources, again, that layered approach, where we're looking at the types of connections being introduced to our servers. Do they have any anomalies? Is the particular person, from a behavior standpoint, doing something they've never done? And then finally, down to the literal assets themselves: how well are they protected, and if not, what fail-safes have we deployed across the breadth of the network so that if something were to take place with one of those assets, nothing bad happens inside of our network?
And then walling off and segmenting is also something that we practice so that the blast radius is confined. So, a lot of information there, but the big idea is that it's a layered approach. It allows for primary controls to fail and then backups to save the day.
All right. So education institutions, as you laid out, have everything from modern cloud applications to decades-old systems and specialized technology. How do you manage that risk when the technology environment itself is so broad and decentralized?
Yeah, for the most part, I think this particular challenge isn't unique anymore. The pace of change is moving at such a rate that what was in vogue, what was popular and trending last year, it's like, "Oh my god, you got that computer last year? That processor is so old now." The lifespan of tech is much different than it was ten years ago. So I think we're constantly accounting for that, right? And when we have these opportunities to really avail ourselves of protections, I think that's the time we should actually do that.
Tell me once more what the end part of the question was, 'cause I want to make sure I dial this in.
How do you manage the risk when your technology environment is so broad and decentralized?
Yeah, so thank you for the latter part. I appreciate that. Whenever there's a disparity or a gap between the new stuff and the old stuff, and the old stuff is still very relevant in the environment, I think there are a couple of things that practitioners think about. Is there an opportunity for us to limit the amount of access the legacy equipment has? Is there a way for us to section it off? Is there an opportunity for us to maybe even virtualize it? All of these things come into play to create a set of circumstances that reduce the overall risk for the legacy equipment.
But then you might say, and you alluded to it in your question, what if you're a hybrid environment, where you have assets in the cloud and you have assets on-prem? What do you do in those cases? In the same way that, years and years ago, we had a collection of tools around the data center to give us full visibility, we have to do the exact same thing, except now it has to be an extension of what we had in our data centers. It also needs to cover the cloud.
All the practitioners that I speak to on a regular basis, we all are of the same opinion. Irrespective of where you have your assets, you still must maintain full visibility of all of those assets. You still have to have an accurate inventory. You can't protect what you don't know about. There's still an absolute need for you to have a strong vulnerability management program.
And to the extent that you're cloud first, you really have to have a very good accounting for who's responsible for what. They call it a shared responsibility model, but so often it gets abused because organizations like mine go, "Well, I put that in the cloud, so that's their responsibility," and it really doesn't work like that. We see this failing very, very often when we do the breach forensics. There's just a literal breakdown in communications and in the understanding of who owns what.
So as we try to have environments that are hybrid, that deploy old and new technology, I think the central theme is the same safeguards that we've always used throughout the years. We need to do those, but we need to do them at scale so that we have full visibility of our cloud environments, full visibility of our on-premise data environments, as well as who is connecting to those assets and why.
So on the prioritization side, which you alluded to earlier in your opening, education needs to really focus on how it prioritizes exposures. With so many systems, users, vulnerabilities, and attack paths, how should education institutions determine which risks deserve attention first?
Well, you might have heard, Sullivan, that there are AI agents that were in confined environments that found a way out of those environments and into other people's environments, and they did things that they shouldn't do. I'm going to a dinner later today where I'll speak to more practitioners about this particular subject, and I think the consensus is that everyone is looking for an edge, right? They're looking for a piece of software, a solution, a combination of solutions and software that will allow us to enter into a world which we predicted would take place ten years ago, where we have machine-speed attacks and machine-speed defenses.
So if I'm prioritizing for my future, that's what I'm thinking about. I know a lot of my peers here in the Dallas Metroplex are saying the exact same thing. But here's the deal. If we're doing a really, really good job with the prioritization of our CVEs, our vulnerabilities, our operating systems, these are still the tenets from back yonder that we must bring forward and have a healthy appreciation for. Because even if the AI agent is moving at machine speed, if there's no vulnerability for them to manipulate, then they're gonna go on over to the next network that's not as prepared.
So I think vulnerability management, patch management, CVE management, cloud configuration management, and identity management, whether that's machine or non-machine, all of those things come together to form what I believe is the new nucleus. If we look at our environments retrospectively and put each of these into buckets, our environments will tell us, with just a little bit of testing and just a little bit of tooling, where we should spend our resources, our time, and our attention, and what we should do first to reduce our risk signatures.
So how much of the challenge with securing education is those technical pieces that you laid out versus the organizational side of things?
That's a tough question. My observations today would suggest that it's at least twofold. In the educational space, because it's not corporate, and it's not tied to a stock ticker or an entity's ability to produce high levels of return year over year, where if you don't, there's a huge penalty, we don't have those stressors like the corporate sector does. We still have to report out. It's still a big deal, but the way it's measured is different. And so when we think about how we deal with that, it's just one of those things where, if you're not really dialed in, you won't really get it.
Tell me the last part of the question so I can make sure I answer this completely.
Yeah, so basically it's just how much is technical versus organizational.
Yeah, so here the cultural element is very, very different from what I ever saw in the corporate enterprise. It's just really, really different. I won't say that it's lax, but it's so different that it would be easy for the people who have been here a really long time to become accustomed to doing things a certain way, where that particular way might not be the most secure, where it might not have some of the safeguards that you would have in corporate. Some of the assets, as an example, might be able to connect even though we don't know their health or disposition, right? So there are elements here that make it radically different from a cultural perspective.
And then it seems to me that the tactical piece requires a good degree of rigor as well. As I think about what it took for me to get something from concept to execution to production in corporate, versus what it takes me to do that in government and now at my second educational institution, it's much more time-consuming to do something in education, because there are several more gates that I need to pass through in order to get it done.
So when you think about it from a two-pronged perspective, the cultural piece and the technical piece, sometimes there's a bit of a collision there. Now, I'm fortunate in so much as I've been able to see this movie before, and I kind of know the steps to take to maneuver around them. But at the same time, it's still an issue that I and many of my colleagues face when trying to do something expeditiously. That can be a challenge for sure.
So what are some of the ways to move through the challenges that come up when the technical and the organizational or cultural pieces clash? What are some things you've found useful?
I think education is really important. The college is really good at soliciting different people who have not been a part of education before. They're coming from various walks of life and other organization types, and they're very good about grafting those people in to bring in new insights. With those new insights, I believe there's an opportunity to change some of those norms, right? To alter some of the behavior and put a bend in what was the typical curve or culture, to start leaning it more toward those best practices, more toward those acceptable use cases that are known good to reduce risk.
I also think any good salesman is really good with communication. Working with a number of senior leaders, I see that there's an appreciation for a little bit of over-communicating. What I mean by that is I don't wanna wait until it's time to start doing something that's on my twenty-four-month, twelve-month, or six-month roadmap. I wanna share that months ahead of time, so they've already heard it. They've already felt the adrenaline spike. We've already had conversations. They're already in the know about what it's going to take, and whether there are any sacrifices or any huge changes to workflows or how we typically do things. Getting in front of those really, really early and garnering support for whatever the initiative is ahead of it being launched is, I think, incredibly helpful to reduce the amount of friction it takes to get something conceptually into production and buttoned up with the win.
And then the last thing is having relationships. I know it goes quite hand in hand with the comms piece, but I have found that the more time I spend with people, helping them gain an appreciation for how I manage, for how I lead, for what's on the vision, and allowing them to even have input into the vision, the more receptive they are when it's time for me to present that to a body, a council, or a governance entity, whatever the case is. However we need to get that approved, people are much, much more amenable. So relationships and communications are the two biggies on the non-technical side that really allow you to rack up some wins when you're trying to change elements inside of a large, complex institution.
So when resources are constrained, as we talked about earlier, the budget within education can be very limited in some circumstances. When those resources are constrained, how do you make a good case for security investment?
When the resources are constrained, are these monetary resources or human resources?
It could be both. Mainly monetary, though, for the question.
What I like to do when I enter an organization, what I will always, always, always do, is ask the leadership team: Is there a cybersecurity framework that the institution, or the entity, has already adopted? Leaders don't want to go after shiny stuff, right? New stuff, per se. Leaders are interested in how tech can help them with the outcomes they want to see. And so as practitioners, we have to really learn the business of cybersecurity, the business of IT. To the extent that we spend time really honing that craft, it really helps us put our stories together in a way that's meaningful, in a way that's persuasive.
If no framework has been selected, I will recommend one based on where they are in that journey, from my own assessment. It's after we have received a formal adoption of that framework that I can call that framework ours. Then I will go out and have an assessment done. And the assessment is not my assessment. It's a disinterested third party that comes in and says, "Hey, on this framework, this is how you scored."
I will then extrapolate how we scored and make that into a roadmap. There are going to be gaps on it, and I'm going to provide dollar estimates for what it's gonna cost to close those gaps. That's on the tactical side. On the human resources side, if they note gaps, shortages, and the like, I'm going to have that in a separate bucket on the human capital side. So, looking at it from that lens, I'm bringing two different issues to the discussion that not I, but we as a leadership team, have to go after. The idea then becomes: If we want to master this framework and reduce our risk, these are the tactical things we're gonna need to do. Here are the pros and the cons, the merits and the demerits of each. And the same thing holds true for the human capital side.
Using that approach, at least in my 12 years of doing this now, has fared incredibly well for me. It has gotten me the results that I need to move the organization from a certain level of maturity to wherever they want to go, or from a baseline cybersecurity framework to mastery of that framework.
So think in terms of the business, and present your cases in terms of the business. Always think of it like this: What do they get out of this spend? What do they gain from this spend? What business objective does this help them secure? If we as technical practitioners are not able to answer those questions, that is why it is sometimes so difficult for us to get the support that we need, because we might not be positioning it from a business case perspective.
Excellent. All right, so as we wrap up, looking ahead, what do you think is going to make securing education harder over the next few years, and where do you see the biggest opportunity for educational institutions to improve?
So the biggest impact is going to remain phishing, and that is number one right now. We have to get really, really good with our tooling to detect it before it hits the box. And then even after it hits an email box, we need another set of tools to make sure that if they click on it, nothing bad happens. It goes in a sandbox, gets exploded, and says, "Oops, I'm sorry, you clicked on that. I know you probably didn't mean to, but that's a malicious link. We can't let you go there." Problem solved, right?
So certainly the age of the agentic AI agent is a concern globally. I don't know if you've ever looked at CNBC or Bloomberg, but it's almost all they talk about now. The world's going to be coming to an end because the agents are going to take over. It's just a bad set of circumstances.
It's going to be Terminator.
Exactly, exactly. So there's that. But I think the real opportunity, as I talk to different leaders, specifically in education, is centered on resilience. Do you have a business continuity plan? Is it up to date? Do you have RPOs and RTOs? Do you have a disaster recovery plan? Are you exercising it and testing it? Do you have an incident response plan? Do you have cyber insurance? Are you working together to ensure that all three of these are in harmony: the BCP, the DR, and the IR?
Does your leadership team understand, if something bad happens, how they are going to interact with the rest of the world for damage control? All of that, even the reputational elements, hinges squarely on resilience: knowing how you're going to deal with something bad if it happens, and having practiced it so well that when it happens, it's just like you're going through another drill.
All right. Excellent. Well, thank you, everybody, for watching. If you'd like to join this conversation, be sure to like, subscribe, and leave a comment with your thoughts or suggestions for future guests and topics. And thank you again to Michael for joining us today.
Thank you.
Conversations With CISOs, Security Leaders & Technology Executives
Hear practical conversations with the executives responsible for protecting complex organizations. Each episode explores leadership, risk management, infrastructure, incident response, governance, and the decisions security leaders make every day.