From Tools to Trust: Integrating Technology, People, and Processes for Institutional Cyber Resilience

Wednesday, September 30, 2026 | 4:30PM–5:30PM MT
Session Type: Poster Session
Delivery Format: Poster Session
In a constantly evolving threat landscape, it is becoming increasingly evident that investing exclusively in cutting-edge technology is insufficient to address the complex challenges of cybersecurity. This reality was reinforced by our experience at a public university in Brazil. A substantial investment in state-of-the-art hardware in the past did not result in high maturity and exposing a critical disconnect; sophisticated tools remained underutilized due to a lack of structured governance and standardized processes. This poster session details the transformation from an IT-centric security posture into a holistic ecosystem complemented by three pillars: Governance, Processes, and People. Guided by the NIST CSF 2.0 Governance function, the new approach instituted a Digital Risk Committee to bridge the gap between IT and institutional business objectives, along with a rigorous RACI model to eliminate reliance on people. We explored the implementation of specialized managed services that replaced reactive problem resolution with proactive threat hunting. By standardizing incident response protocols and launching role-based enablement programs, the institution achieved operational independence from individual specialists. Participants will gain insights into how aligning human expertise with managed services and risk-based decision-making can accelerate maturity and foster long-term institutional resilience in complex environments.

Presenters

  • Mauro Bernardes

    Technical Assistant, Office of Information Technology, Universidade de Sao Paulo
  • Fatima Nunes

    Chief Information Officer, Universidade de São Paulo