Skip to main content

Cybersecurity as a Leadership Practice

by Phil Redfern

Today’s Tuesday Reading is from Phil Redfern, Director, Security Engineering at the University of Nebraska, and a MOR program alum. Phil may be reached at [email protected] or via LinkedIn.

Cybercriminals count on more than weak passwords and outdated software. They count on hurried decisions, unclear expectations, and cultures where people hesitate to speak up.

October is Cybersecurity Awareness Month. Each year, organizations remind people to use stronger passwords, enable multifactor authentication, install updates, and be cautious of suspicious messages. These are practical and important steps. At the University of Nebraska, the theme this year is straightforward: Don’t make it easy for cybercriminals.

Over the years, I have seen sophisticated safeguards undermined by a moment of urgency, an unclear expectation, or a well-intentioned decision to make an exception. I have also seen potential incidents that were contained because someone felt comfortable pausing, asking a question, and reporting what happened. Those experiences have convinced me that cybersecurity is not only a technical discipline. It is a critical leadership skill. Leaders create the culture in which secure decisions become everyday habits.

Cybersecurity Lives in Ordinary Moments

Most cybersecurity decisions do not feel significant in the moment.

A multifactor authentication prompt arrives while someone is rushing into a class. A software update appears while they are preparing for an important presentation. An urgent email appears to come from a senior leader. A colleague asks whether a normal process can be bypassed “just this once.”

In each moment, convenience and urgency compete with good judgment. Cybercriminals understand this. They need only one person, on one busy day, to approve an unexpected prompt, bypass a safeguard, or respond before verifying a request.

This is why cybersecurity cannot exist only in technical controls, annual training, and policies. It must live in everyday small, repeated practices that shape how work gets done.

Leaders Set the Pace

Employees watch what leaders prioritize.

If a leader routinely asks others to work around a security process, the message is that security matters only when it is convenient. If a leader treats questions as interruptions, employees may remain silent when something doesn’t look right. If a person who falls victim to a phishing message is publicly shamed for “falling for it,” others may decide not to report the next one.

The opposite is also true. Leaders strengthen cybersecurity when they follow the same safeguards expected of everyone else, give people permission to slow down when something feels unusual, and respond to mistakes with accountability and learning rather than blame.

In my experience, one of the most effective leadership phrases for building a strong cybersecurity culture is, “Help me understand what happened.”

That question does not remove accountability. It creates space to understand why the action seemed reasonable at the time.

  • Was the request unusually urgent?
  • Was the process unclear?
  • Did our leadership behavior reward speed over assurance?

When we understand the conditions, we can improve the system rather than merely warn the individual.

Make the Secure Choice the Supported Choice

Telling people to “be more careful” is not a strategy. Leaders must make it clear that the secure choice is the supported choice.

Here are five practices I try to reinforce:

  • Make room for a pause. Verifying an unexpected or urgent request is appropriate, even when it appears to come from a senior leader.
  • Model the basics. Follow the same security practices expected of others. Credibility is weakened when leaders hold others to standards they do not follow themselves.
  • Normalize reporting. Thank people for speaking up. Early reporting gives the organization more time to respond.
  • Ask what is getting in the way. If people repeatedly avoid a security process, ask whether it is unclear, unnecessarily difficult, or poorly aligned with the work.
  • Connect security to the mission. Protecting accounts and information safeguards the people, research, instruction, services, and organizational identity that technology supports.

None of these practices require a leader to become a cybersecurity expert. They require the leader to make expectations clear and reinforce them consistently.

The Practice Ahead

Cybersecurity Awareness Month gives us an opportunity to revisit familiar actions: using strong passwords, enabling multifactor authentication, keeping devices and applications updated, and pausing before responding to suspicious requests.

I am grateful to my University of Nebraska colleagues who developed this year’s Cybersecurity Awareness Month campaign and made a complex subject practical, approachable, and relevant to our university community. Their work reinforces a broader lesson: awareness is most effective when familiar security guidance is connected to the decisions people make every day.

The campaign reflects an important truth: cybersecurity is not fundamentally a technology challenge. It is also a people, culture, and leadership challenge. Leaders play a significant role in creating environments where those behaviors become routine.

For leaders, the questions are simple:

  • Do the environments we create reinforce secure choices?
  • Do people feel safe asking questions and reporting concerns?
  • Do we treat taking a moment to verify as good judgment rather than an obstacle to productivity?

Effective cybersecurity measures require participation from everyone, but leaders shape the environment in which decisions are made.

Additional Resources

The Cybersecurity Awareness Month campaign developed by the University of Nebraska does not stand alone. The campaign is aligned with annual guidance and resources from the National Cybersecurity Alliance and reflects awareness practices used by peer institutions, including those across the Big Ten Academic Alliance.

Which leadership practice can you strengthen most this week to improve cybersecurity with your team?

Last week, we asked about the biggest barrier to connecting talent to needs across your institution.

  • 79% said trust and relationships
  • 10% said us versus them mentality
  • 6% said structure and reporting lines
  • 5% said we haven’t been intentional about it

Wow! A huge common thread for us collectively. Trust and relationships are the biggest barrier to connecting talent to needs across our institutions, with four out of every five of us experiencing that barrier. Now what? Where do you see the biggest need to connecting talent to needs? Building on this week’s reading, what will you do to take the needed initiative?

MONTHLY ARCHIVE