Cyber risk is listed as one of the top risks facing higher education. As threat actors grow more sophisticated and regulatory requirements evolve, gaining leadership support to invest in cyber risk management is essential. Risk Management and Information Security leaders form a critical partnership to help combat risks beyond the cyber insurance renewal.
To equip boards and fiduciaries with strategies to mitigate these risks, I engaged with Priya Mouli, the Head of Information Security and Compliance at Sheridan College. She will share her insights on how IT leaders, Risk Management, and the executive sponsorship at the board level are essential to staying ahead of cyber risk.

Q1: Can you share your journey into cybersecurity? How did you transition into this field?
Pryia Mouli (PM): Sure! I am Priya Mouli, and I am the Information Security Officer at Sheridan College in Ontario, Canada. I have ~20 years of experience in cybersecurity, privacy, risk management and compliance, resiliency, data and now AI governance.
My path into cybersecurity was not linear. Graduating with an engineering degree, I started my career as a software developer. I then pursued my MBA to explore the intersection of technology and business and to challenge myself to become a subject matter professional in another domain of technology.
Subsequently, I landed roles with the Big 4 consulting firms, starting with Deloitte, where I focused on technology risk, cybersecurity, and enterprise resiliency. I have lived and worked in six countries, and my career path has taken me to support global organizations across industries in the public and private sectors, with their cyber and risk management journeys and progressing their maturity.
I am passionate about enhancing security awareness and promoting a culture of risk consciousness within organizations. I speak at global conferences and summits sharing industry insights/perspectives, spreading awareness on cyber risk and DEI topics, and authoring global thought leadership publications.
Tracey Swift (TS): I appreciate that you shared how your path into cybersecurity was not linear. I noticed a similar pattern among risk management professionals. I also like how you integrated the disciplines of cybersecurity, risk management, and enterprise resiliency in your role. In today's risk management landscape, it is essential to address risks in a holistic manner, and your career path exemplifies this evolution.
“Academic institutions are attractive targets for threat actors as they are a gold mine of sensitive data by way of PII and research data, have an ethos of open sharing, and may have low budgets earmarked towards cybersecurity and leaner teams.” - Priya Mouli
Q2: One theme we emphasize in HigherEdRisk is that crossfunctional collaboration plays a critical role in risk mitigation. Who do you view as strategic partners in preventing cybersecurity incidents?
PM: I would like to respond to this question by first looking at the sensitive data that higher educational institutions collect, store, and process. This includes personally identifiable information related to students and employees, institutional financial data, and research data that qualifies as Intellectual Property (IP). So I would say that building relationships across the institution starting with the rest of IT, Risk Management, and other administrative departments (such as Finance, Human Resources, Legal, Communications, and Faculty departments besides Research) are key.
It is important to build these partners and allies beyond IT as “cybersecurity is a team sport.” I have built good relationships across the institution by making cyber security and cyber safe practices easy and consumable for our community members. I have further brought in institution-wide stakeholders and kept them involved in the cyber journey.
Some examples include Sheridan College building our IT Security Roadmap in early 2024 and socializing this across the institution including administrative units and academic/faculty departments as above, while actively involving these stakeholders and soliciting their feedback. I also conducted our first cyber tabletop exercises last year for the technical/operations and executive teams to be able to build the muscle memory of who does what and when in moments of crisis.
TS: Thanks for sharing that cybersecurity is a team sport. We have a similar saying in risk management that “we are all risk managers.” This inclusive approach encourages diverse perspectives to help mitigate cyber risk.
Q3: In your opinion, what are the top three cybersecurity risks in higher education?
I would say that the top three cyber risks are social engineering attacks by way of phishing; network, system, and applicationvulnerabilities; and denial of service (DoS) attacks.
PM: All of these risks can result in ransomware and data breaches/leakage, like in any other industry. These are also the top cyber risks due to the unique environment and the nature of operations in post-secondary institutions.
For example:
having a complex IT infrastructure;
using legacy systems;
handling a vast amount of sensitive data including personally identifiable information (PII), research data, and IP; and
having a diverse population of students, faculty, staff, alumni, contractors, international agents, and donors/patrons that can be subject to social engineering scams.
As a result, controls/measures need to be thoughtful while keeping in mind the institution’s context and risk appetite.
TS: Social engineering, ransomware, and data breaches are often mentioned in the risk and insurance industry as top risks, so it’s important to see that we are aligned.
Q4: When speaking with your peers, what is one tool or resource that you hear repeatedly that executive leadership, boards, and fiduciaries should invest in to help mitigate cyber risk?
PM: Having a budget or resources that allows for a dedicated security operations center (SOC) within the institution would have far-reaching benefits in helping mitigate cyber risk. Academic institutions are attractive targets for threat actors as they are a gold mine of sensitive data by way of PII and research data, have an ethos of open sharing, and may have low budgets earmarked towards cybersecurity and leaner teams.
TS: I agree. In the insurance world, higher education presents unique cyber insurance challenges due to its decentralized IT infrastructure and vast amounts of data. A dedicated SOC sounds like an ideal way to reduce risk.

“Appreciating cybersecurity as a systemic risk in academic environments, given that we are inherently digital and accordingly allocating a fairly sized budget towards cybersecurity, would go a long way.”
- Priya Mouli

Q5: In the higher education risk management space, we often hear that academic freedom can create barriers to implementing a strong information security program. Do you have suggestions on how to balance academic freedom and information security requirements?
PM: I believe that academic freedom and information security can coexist. As in my response to Q2, building your partners and allies on the faculty side by demystifying cyber security measures and articulating their benefits to them would work well. Some examples that come to mind are having controls around network zoning, having multi-factor authentication (MFA), and using biometric authentication that would offer enhanced security and a seamless user experience.
TS: Biometrics is an interesting proposal. The legal and regulatory landscape around biometric data collection and storage is another area that keeps evolving, so institutions will have to remain informed on changing regulations.
Q6. Higher education typically has lower security budgets than the private sector, yet it faces similar threats. What do you feel is the one risk mitigation that, if implemented, would generate the best return on investment (ROI) in terms of keeping an institution more secure?
PM: I would say that applying protection measures focusing on digital crown jewels (i.e., critical assets) would offer the best ROI in keeping an institution secure. By critical assets, we mean systems and data that are essential for operations and those that are sensitive from a privacy and intellectual property standpoint. Employing a defense-in-depth strategy to protect these assets would go a long way—this refers to layered controls (e.g., network segmentation, application access and vulnerability management, data encryption across data at rest, in transit, etc.).
TS: Thanks for sharing these best practices. Implementing robust layered security controls can mitigate risk and help institutions secure better cyber coverage terms and lower premiums.
Q7. What themes do you see in your industry where you can use more board and fiduciary support to help create a stronger cyber risk posture?
PM: Appreciating cybersecurity as a systemic risk in academic environments, given that we are inherently digital and accordingly allocating a fairly sized budget towards cybersecurity, would go a long way. This, along with periodic involvement in tabletop exercises/cyber crisis simulations, would help enhance the risk posture and cyber event preparedness.
TS: Great takeaways, Priya. As our institutions become fundamentally digital, the exposure to increased cyber threats impacts institutional reputation and financial stability. Having boards participate in risk mitigation strategies such as crisis simulations is a great way to help build cyber risk understanding and drive strategic investment in robust cybersecurity capabilities. Together, Risk Managers and Information Security Officers can help lead that charge. Priya, thanks for your strategic insights. I am sure our readers will find them helpful.
Read more about Priya’s career journey and insights here:
Priya’s recent CISO Award across North America
https://www.linkedin.com/posts/priya-mouli_i-amdeeply-honored-to-receive-thecisosactivity-7244793245048733697-sKeN/
Priya’s story to date and of persistence
https://www.linkedin.com/posts/priya-mouli_heretostayiwd2023-womenincyberprivacyfincrimeactivity-7041767557850169344-HGWU/
Priya’s recent presentation at ISACA on Gen AI
https://www.linkedin.com/posts/priyamouli_generativeai-isacacon-genaiactivity-7298393309750734849-Dm9E/