Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Information Security topic

No spam. Unsubscribe anytime.

UNC information‑security leaders outline three‑pillar strategy: accountability, faster detection, common controls

AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Vice Chancellor Mike Barker and Assistant Vice Chancellor Paul Rivers told trustees the university will pursue three pillars—measured accountability, detect more/respond faster, and expanded common controls—while rolling out endpoint detection upgrades, stronger multifactor authentication and planning identity 'uplift.'

Vice Chancellor Mike Barker and Assistant Vice Chancellor and Chief Information Security Officer Paul Rivers delivered the university’s annual information‑security update to the Audit Committee on Jan. 23, framing the program around three strategic pillars: measured accountability; detect more and respond faster; and expanded common controls.

Barker described the update as “more than just checkbox” reporting to the system office and said the written privileged document provided to trustees is “canonical.” He noted the security program’s emphasis on strengthening routine operational practices and expanding community engagement across campus and affiliated entities.

Rivers reviewed 2024 accomplishments and planned 2025 priorities. Among achievements, he told trustees the university completed an institution‑wide HIPAA security risk assessment with no critical observations, and migrated its endpoint detection and response platform to a new vendor while increasing device coverage, identity correlation, and response speed. Rivers said the result was faster remediation: attacks that previously took days to address are now handled in hours or minutes.

On short‑term 2025 goals, Rivers highlighted plans to harden digital credentials and caller identity proofing for service desks, and to expand phishing‑resistant multifactor authentication. Medium‑term work includes privileged‑access management; a longer term initiative will overhaul digital‑credential strategy.

Asked whether the university had experienced breaches in 2024, Rivers said, “We had no breaches,” adding the detection and response team has seen increasing case volume driven by improved centralization and visibility. On phishing testing, Rivers said the institution has not run a campus‑wide simulated phishing exercise since the last broadly distributed campaign, though some units have run local tests; he emphasized that “you will not be able to train your way out of phishing” and pointed to multifactor authentication as the strongest mitigant.

Barker and Rivers also discussed emerging federal rulemaking: Health and Human Services issued proposed changes to the HIPAA security rule on Dec. 27, and the presenters said UNC is in a comparatively strong position because it has already implemented written HIPAA security policy updates in 2024.

Ending: Committee members asked for further quantitative KPIs that the security office said it would begin phased reporting on in 2026; trustees were invited to request a closed session if follow‑up questions require privileged detail.