When Mike Forester returned to Regent University, he wasn’t stepping into a mature information security program with an established playbook.
He was stepping into an opportunity to build one.
Regent needed to strengthen its information security program and address the requirements of the Gramm-Leach-Bliley Act (GLBA), including implementation of the NIST 800-171 framework. Mike joined the university with a focused mandate: help turn those requirements into an operational program that could serve the institution well beyond a compliance deadline.
What followed was not simply a compliance exercise. It became the foundation for a more mature approach to cybersecurity at Regent and, for Mike, the beginning of a journey from strategic project manager to CISO.
When cybersecurity becomes an institutional responsibility
Higher education occupies a unique position in cybersecurity.
Universities hold enormous amounts of sensitive information, including financial aid data, Social Security numbers, household income information, payment activity, academic records and other personal data entrusted to them by students and families.
For institutions subject to GLBA, protecting that information isn’t simply an IT concern. It’s an institutional responsibility.
When Regent began its work, Mike says the university recognized that it had ground to make up.
“We were behind on that compliance,” he said. “We missed the mark.”
Rather than treating that realization as a reason to panic, Regent treated it as a reason to build.
Mike was brought in to lead the effort. His responsibilities included implementing NIST 800-171, developing policies and procedures, establishing an Information Security Committee, preparing for the university’s first formal risk assessment and introducing tabletop exercises.
It was a significant undertaking, particularly for someone stepping into a role designed specifically around getting the program off the ground.
But Mike wasn’t starting alone.
Building the foundation, one step at a time
Regent partnered with the team that would become part of DeepSeas to provide the advisory expertise and experience needed to help structure the work.
For Mike, one of the most valuable parts of the relationship was having an experienced advisor who had been through the process before.
The working model was refreshingly straightforward.
“We would meet, have marching orders, we’d go execute, come back, meet, and it was rinse and repeat,” Mike said.
That cadence helped Regent work systematically through a substantial list of policies, procedures and operational changes without losing sight of the larger objective.
DeepSeas provided the resources, experience and advisory support. Mike and Regent did the work of turning that guidance into an information security program built for their institution.
Within roughly a year, Regent had completed the initial implementation and conducted its first risk assessment.
It went well.
More importantly, the work had begun creating something larger than a compliance program.
From project manager to CISO
As Regent’s security program matured, so did Mike’s role.
After leading the initial implementation, Mike moved from his project management role into serving as Regent’s CISO.
Today, the foundations established during that initial effort have become part of an ongoing security program.
Regent maintains an Information Security Committee as a standing governance body. The university conducts recurring risk assessments and tabletop exercises. Mike works through a formal risk register and continues a monthly advisory cadence with DeepSeas.
The relationship has changed as Regent’s own capabilities have grown.
And that’s exactly what successful advisory work should accomplish.
The objective isn’t to make a customer permanently dependent on a consultant. It’s to help build the knowledge, processes and confidence that allow the customer’s own people to lead.
For Regent, Mike increasingly became that leader.
The threat environment didn’t stand still
The security program Regent needed when Mike started isn’t identical to the program it needs today.
The pace of change has accelerated dramatically.
Mike points to vulnerability management as one example. Traditional approaches often prioritize vulnerabilities using severity scores, known exploits and evidence of active exploitation. But as AI accelerates how quickly vulnerabilities can potentially be weaponized, security leaders are being forced to reconsider some of those assumptions.
“The time from a patch release to an exploit used to be measured in weeks, sometimes months,” Mike said. “Now it’s measured in hours.”
For Mike, that compression changes more than the expected speed of response. It challenges a security model built around periodic cycles of identifying, prioritizing and remediating vulnerabilities.
No organization can simply patch everything the moment a vulnerability appears. Updates have to be assessed and tested, systems have different operational requirements, and security teams have finite resources.
The bigger shift is toward security as a continuous discipline: understanding exposure as it changes, reducing the paths that create the greatest risk, containing the potential blast radius of an incident, and detecting and responding quickly when something does happen.
As Mike described it, the assumption increasingly has to be that any vulnerability could become exploitable quickly. The objective, then, isn’t simply to move faster through an endless queue of vulnerabilities. It’s to continuously understand where the organization is exposed and make better decisions about what matters most.
For Regent, that means the security program continues to evolve because the environment around it never stops changing.
Security is a community effort
Mike is also quick to point out that no security leader has all the answers.
His approach to staying current relies heavily on the cybersecurity community around him.
Through groups including VASCAN, the Virginia Alliance for Secure Computing and Networking, and REN-ISAC, Mike exchanges information with other higher education security leaders, learns about emerging threats and helps institutions work through issues together.
That collaboration is particularly important in higher education, where security resources can vary dramatically from one institution to another.
Some universities have dedicated cybersecurity teams. At smaller institutions, the same person responsible for security may also be managing networks, installing access points, maintaining servers and handling any number of other IT responsibilities.
Mike sees an opportunity for institutions with greater resources or experience to help.
“Everybody’s on the same journey together,” he said. “I know a little bit, you know a little bit. There’s a lot of people who know a lot more than I do, so let’s just try to help.”That philosophy now extends beyond Regent.
Mike participates in higher education security communities and is beginning to speak more publicly about the lessons Regent has learned, including the challenges universities face with fraudulent student accounts, identity abuse and other emerging threats.
His goal isn’t to position Regent as having solved cybersecurity.
It’s to contribute what Regent has learned so other institutions can move forward too.
A security program is never really finished
The story of Regent’s security program doesn’t end with a successful risk assessment or a compliance milestone.
Those were foundations.
The work now extends into identity and privileged access management, vulnerability management, security monitoring and the continuing challenge of adapting to a threat landscape increasingly influenced by AI.
The program has matured because Regent has continued investing in it.
And Mike has matured alongside it.
What began as a project to implement a framework became an institutional security program. A project manager became the university’s CISO. An advisory relationship evolved as Regent developed greater internal expertise.
DeepSeas remains part of that journey, providing expertise and support where it can create the greatest value while Regent continues to own its program and its outcomes.
For Mike, that ownership matters.
Cybersecurity in higher education ultimately comes down to stewardship: institutions are entrusted with information belonging to students, families, faculty and staff, and protecting that information requires more than checking a compliance box.
It requires building a program capable of getting better as the threats around it change.
Regent has done exactly that.
And it is still building.
