Close

New Research from CDW Explores AI and Cybersecurity

Learn how AI is helping IT teams manage risk and improve resilience.

Aug 12 2026
Security

Centralized Cybersecurity Operations Keeps Community Colleges Protected

Community college systems move IT and cybersecurity systems out of siloes and into centralized hubs of efficient, cost-saving operations, bolstering defense along with their bottom line.

As the largest single-district community college system in the nation, Maricopa Community Colleges educates more Arizona residents than its three large public universities combined. 

The system operates 10 main campuses across the Phoenix metropolitan area and more than 30 satellite sites, serving nearly 100,000 students and employing 14,000 faculty members and staff in the 2026 spring semester. 

Those superlatives and numbers are all familiar to Jamie Spradlin, MCC’s CISO. When he took his position in June 2024, his first order of business was to establish a cybersecurity program capable of protecting the entire sprawling system. Up to that point, each MCC location had been largely on its own when it came to securing the traffic on its network. Campus IT teams had little communication with the technology leaders within the district office, and that meant they had little insight into their individual cybersecurity plans. 

Click the banner below to read the latest CDW Cybersecurity Research Report.

 

“Some colleges bought separate ISPs, had different data centers, used different technologies from different vendors,” he says. “There wasn’t any kind of holistic strategy; the colleges did whatever they prioritized.”

In a government role before he came to MCC, Spradlin had established a security (SOC) to manage cybersecurity across multiple state agencies. He decided to take a similar approach here with an eye toward improving both effectiveness and efficiencies. “We’re funded with taxpayer dollars and tuition payments from local residents,” he says. “We don’t have the resources that most of the four-year universities have, so we have to be thoughtful and very strategic about ROI in everything we do.”

With that in mind, he and his team hatched a plan to standardize cybersecurity, and last year they began with the deployment of several tools designed to improve visibility. They turned to CrowdStrike, for example, to monitor the system’s 25,000 endpoints, and they’re now using Tanium for asset discovery and vulnerability management and patching. They’re in the planning stages for standardizing their network so that all core infrastructure is maintained within the district office, and they’re assessing their 19 data centers spread across Maricopa County.

Spradlin says they’re now relying on Cloudflare to consolidate security, performance and reliability into one edge network, reducing vendor complexity and infrastructure costs. And the district recently deployed Elastic, a security information and event management solution, to combine and analyze network telemetry across the entire organization. Not long ago, an employee at one of the colleges had their credentials stolen in a breach, and soon after, the attacker started moving laterally, looking for other vulnerabilities. “We were able to investigate and very quickly isolate and mitigate the threat,” he says. From there, they fully shut down the attack by pulling the device out of its virtual environment. They then moved on to what he describes as the most important part of their cybersecurity strategy.

DISCOVER: Quantifying cyber risk can help IT leaders justify security investments.

“Education is an area with plenty of room for improvement,” Spradlin explains. His team is standardizing that aspect of its program by working to create strong security policies and standards that are easy for staff to follow. It doesn’t matter how many best-of-breed solutions an organization has, he notes, “you also need good cyber hygiene — for people to understand how to minimize their risks.”

Centralizing With a Cybersecurity Hub

That MCC is taking steps to consolidate cybersecurity comes as no surprise to Isaac Galvan, community program director of cybersecurity and privacy at EDUCAUSE. “When the colleges in a system work together, they multiply their capabilities,” he says.

Collaborative cybersecurity topped the list of EDUCAUSE’s 2026 top 10 list of what higher ed leaders are focused on for the year ahead. For a community college system, Galvan explains, that may include connecting its IT and security policies to the organization’s business needs to improve its overall security posture. “Like everyone else, they’re dealing with thousands of vulnerabilities and breach attempts every day,” he notes. “The more they can centralize and coordinate their efforts, the better they can make informed decisions about their security investments and risk mitigation strategies.”

39%

The percentage of respondents who said their institution is planning or considering consolidation of distributed/central IT as a cost reduction strategy in the 2025-2026 academic year

Source: EDUCAUSE, "Quick Poll: Technology Budgets and Staffing," April 21, 2025

One cybersecurity leader who can attest to that is Hsiawen Hull, CISO at the CCC Security Center at the College of the Canyons in Santa Clarita, Calif. Funded by state grants administered by the chancellor’s office at California Community Colleges, the center serves as the cybersecurity hub for the system’s 73 districts and 116 colleges.

The CCC Security Center’s role, according to Hull, is not necessarily to unify cybersecurity operations but to unify the processes required for districts to effectively run their own cybersecurity programs. “We create the procedural documents and policies that the districts follow, and we buy and provide the tooling and other resources they need,” he explains.

The center prioritizes CCC’s compliance with federal laws and standards, such as those from the National Institute of Standards and Technology, pertaining to cybersecurity in higher ed settings. It does so by providing them with access to a platform tailored to external attack surface management and third-party risk management, and to a separate solution that offers on-demand cybersecurity training. The center also serves the system’s SOC, with a volunteer team of students that provides free vulnerability assessments and follow-ups.

When an organization such as the Multi-State Information Sharing and Analysis Center issues a threat alert, or a newly identified zero-day vulnerability is reported, for example, “we’ll evaluate whether or not it applies to us, and if does, we’ll send it out to the system,” Hull explains. Earlier this year, students noticed that a district had accidentally left a critical access point open to the internet. The vulnerability could have allowed attackers easy entrance to a range of IT assets, he says, “but as soon as we saw it, we contacted their CTO and had everything shut down immediately.”

Bolstering Security With Shared Services and Resources

On the other side of the country, in Richmond, Va., IT leaders with Virginia Community College System are also working to consolidate cybersecurity. In their case, says Don Frank, the system’s recently appointed CISO, centralization has proceeded in stages over the course of nearly two decades.

In the beginning, around 2008, Frank and his team were focused primarily on improving business efficiencies and centralizing administrative functions. More recently, an updated strategic plan emphasized the need for better unity across the system’s 23 colleges, and with that, cybersecurity has evolved to “trying to centralize everything,” Frank says.

The way the program is currently structured, each college has its own “security point of contact,” he notes. For the larger institutions in the system, that point of contact is responsible for implementing the security policies and strategies provided by the central office, while smaller colleges benefit from what he calls a “shared information security officer program.” Officers on his team, he explains, are each assigned three colleges to support. The colleges each pay a third of that person’s salary, and in return, “they have someone available to help them anytime they need it.”

For all VCCS colleges, functions such as identity and access management and managed detection and response are centralized through the system office. The services are delivered by external vendors under systemwide contracts, ensuring 24/7 coverage while reducing overall costs by leveraging economies of scale.

WATCH: IT leaders share best practices for incident response readiness.

Frank says he regularly hears from campus IT leaders who say they’re glad to have his team on their side. When they don’t have the time or skill sets required to resolve their cybersecurity problems, they never hesitate to leverage his office’s resources — or, at a minimum, its recommendations and guidance.

Frank credits VCCS’ success in consolidation so far to its systemwide effort to bring together leaders and staff from across its campuses. “It’s never been, ‘This is how we do it at the top and everyone has to accept it,’” he explains. “It’s really all about communication and collaboration and depending on everyone being involved.” On the other hand, he says, the system could do better in certain areas, including in its use of technology. “Our solutions right now, our footprint is too big; we’re too spread out, with too many different tools.”

He’s hoping to change that soon through more communication and information sharing. He recently started scheduling regular monthly meetings for all campus security leaders, and he’s planning to use them to gather feedback on what’s working and what’s not. “Our goal is to reduce the process gaps and keep the program moving forward,” Frank says. “We definitely want to continue to centralize but always in ways that will help us improve.”

Photography by Steve Craft