“Some colleges bought separate ISPs, had different data centers, used different technologies from different vendors,” he says. “There wasn’t any kind of holistic strategy; the colleges did whatever they prioritized.”
In a government role before he came to MCC, Spradlin had established a security (SOC) to manage cybersecurity across multiple state agencies. He decided to take a similar approach here with an eye toward improving both effectiveness and efficiencies. “We’re funded with taxpayer dollars and tuition payments from local residents,” he says. “We don’t have the resources that most of the four-year universities have, so we have to be thoughtful and very strategic about ROI in everything we do.”
With that in mind, he and his team hatched a plan to standardize cybersecurity, and last year they began with the deployment of several tools designed to improve visibility. They turned to CrowdStrike, for example, to monitor the system’s 25,000 endpoints, and they’re now using Tanium for asset discovery and vulnerability management and patching. They’re in the planning stages for standardizing their network so that all core infrastructure is maintained within the district office, and they’re assessing their 19 data centers spread across Maricopa County.
Spradlin says they’re now relying on Cloudflare to consolidate security, performance and reliability into one edge network, reducing vendor complexity and infrastructure costs. And the district recently deployed Elastic, a security information and event management solution, to combine and analyze network telemetry across the entire organization. Not long ago, an employee at one of the colleges had their credentials stolen in a breach, and soon after, the attacker started moving laterally, looking for other vulnerabilities. “We were able to investigate and very quickly isolate and mitigate the threat,” he says. From there, they fully shut down the attack by pulling the device out of its virtual environment. They then moved on to what he describes as the most important part of their cybersecurity strategy.
DISCOVER: Quantifying cyber risk can help IT leaders justify security investments.
“Education is an area with plenty of room for improvement,” Spradlin explains. His team is standardizing that aspect of its program by working to create strong security policies and standards that are easy for staff to follow. It doesn’t matter how many best-of-breed solutions an organization has, he notes, “you also need good cyber hygiene — for people to understand how to minimize their risks.”
Centralizing With a Cybersecurity Hub
That MCC is taking steps to consolidate cybersecurity comes as no surprise to Isaac Galvan, community program director of cybersecurity and privacy at EDUCAUSE. “When the colleges in a system work together, they multiply their capabilities,” he says.
Collaborative cybersecurity topped the list of EDUCAUSE’s 2026 top 10 list of what higher ed leaders are focused on for the year ahead. For a community college system, Galvan explains, that may include connecting its IT and security policies to the organization’s business needs to improve its overall security posture. “Like everyone else, they’re dealing with thousands of vulnerabilities and breach attempts every day,” he notes. “The more they can centralize and coordinate their efforts, the better they can make informed decisions about their security investments and risk mitigation strategies.”
