The Cultural Challenge Beneath the Architecture
By Henry Jenkins, MBA, Executive Director, Enterprise Infrastructure & Operations, UC Irvine
When enterprise CIOs discuss Zero Trust, they typically focus on network segmentation, identity verification, and continuous verification. In higher education, those same concepts collide with a very different reality: a culture defined by openness, autonomy, and shared governance.
At a public research university like the University of California, Irvine (UCI), cybersecurity isn’t just a top-down technical discipline. It’s a negotiation between academic freedom and institutional responsibility. Our job in senior IT leadership is to protect discovery itself without breaking the spirit of collaboration that makes discovery possible.
Why Universities Struggle
Higher education is paradoxical since it uses one of the world’s most porous digital ecosystems while housing some of society’s most sensitive data, including student records, clinical research, and federally financed initiatives. With each new term, thousands of unmanaged devices connect to campus resources; labs are generating new insights even as they run legacy operating systems integrated with multi-million dollar equipment purchased a decade ago; faculty use grant funds to put their precious findings on physical storage systems hidden under desks or cloud-based storage under a click-through agreement.
It’s a textbook target-rich, resource-poor environment. Unlike a corporation, a university can’t simply issue mandates and expect everyone to go along. Faculty governance and research independence mean controls require a reasonable level of advice and consent – ideally reaching consensus or at least getting past objections. That’s what makes Zero Trust both necessary and disruptive. The idea of “never trust, always verify” sounds reasonable in an enterprise; in academia, it can sound like heresy.
Because in the end, cybersecurity isn’t about how little we trust – it’s about how wisely we rebuild it.
ZotDefend: Aligning Culture and Control
At UCI, we recently had a short runway to implement the University of California’s Presidential Cybersecurity Mandate. This mandate was a multipronged set of requirements, including multifactor authentication, endpoint protection, awareness training, and technical controls to ensure compliance. As a member of central IT, I was a co-sponsor of the implementation initiative we dubbed ZotDefend. With a short timeline, we gave more weight to execution than consultation. The shift in compliance was measurable: endpoints protected by ZotDefend have risen from the low 40 percent range to more than 80 percent in academic units, and security-awareness training compliance now exceeds 98 percent every month. These significantly shrank our vulnerable points. However, we found the proverbial watermelon problem at play: green on the outside but red within. Metrics looked great, but sentiment told a different story. Endpoint protection, however well-intentioned, was seen by many faculty as an intrusive surveillance tool striking at the heart of academic freedom. That last mile – rebuilding confidence in the intent behind the controls – is proving to be the most critical step.
Academic Freedom Meets Zero Trust
This hard work begins by changing our mindset and weaving what started as compliance chores into acts of institutional habits. By pivoting this cybersecurity initiative into an operational and cultural partnership rather than the result of a mandate, we’re beginning to get traction in faculty adoption.
To engender trust, ZotDefend is now evolving into a change effort resting on three pillars: transparency, collaboration, and resilience.
- For transparency, we published how endpoint protection works: what it has access to, what it doesn’t, how we watch the watchers to address surveillance concerns, and how we get notified if government agencies subpoena the data. Using this as a starting point, we’ve extended this kind of documentation to other technology solutions we provide for faculty data (e.g., Google Workspace, Microsoft 365).
- For collaboration, we have more consistently reached out to the academic community, presenting updates to the appropriate Academic Senate councils and academic unit administrators.
- For resilience, we have increased the emphasis on how ZotDefend protects faculty intellectual property and university data.
The toughest conversations weren’t about technical knobs and levers; they were about trust. Faculty were highly concerned about surveillance and loss of autonomy. “Do you really need to see my research traffic?” was a common question.
We restarted our outreach by meeting resistance with empathy and data. Unfortunately, cases where peer institutions lost weeks of research to ransomware are all too common. As we counter the perception of surveillance with shielding and stewardship, the narrative is beginning to change. Security is no longer unequivocally stifling; it is starting to be seen as preserving.
The truth is that academic freedom and cybersecurity aren’t opposites; they’re interdependent. Freedom without security is fragile; security without freedom is sterile. Zero Trust, done right, doesn’t restrict free inquiry; it sustains it safely.
This shift is reframing our story: we’re not limiting what scholars can do; we’re protecting their ability to keep doing it.
What We’re Learning
Implementing Zero Trust in a university means re-engineering both networks and norms. Three lessons stand out:
- Transparency earns more progress than policy alone.
- Enablement framing (“faster compliance,” “continuity of research”) beats enforcement framing.
- Culture moves at the speed of trust, not at the speed of technology.
Those insights likely apply far beyond academia. Any organization with distributed authority, whether global enterprises, hospital systems, or public agencies, faces the same tension between assurance and autonomy.
A Question for Every C-Suite
Universities have spent centuries cultivating trust: trust in knowledge, in inquiry, in each other. As cyber threats grow and perimeters dissolve, that very trust becomes both a vulnerability and a competitive advantage.
So here’s the question I leave for fellow executives: What must institutions that prize openness do to truly achieve Zero Trust?
Because in the end, cybersecurity isn’t about how little we trust – it’s about how wisely we rebuild it. In academia, Zero Trust must be less about control than about redefining what trust means; it’s not a framework as much as an organizational negotiation. Compliance may drive short-term results, but a culture of trust will determine the next decade.
