Building Security by Default in a Decentralized Institution: Lessons from Our University

Wednesday, April 29, 2026 | 2:30PM–3:00PM PT | Pacific Ballroom A, Second Floor
Session Type: Breakout Session
Delivery Format: Presentation/Panel
Universities rarely operate under centralized IT models, making security by default challenging to implement consistently across diverse academic, research, and administrative units. This session shares how the University of Virginia has embedded secure by default principles into its distributed IT landscape through a combination of governance, risk assessments, vendor due diligence, and practical workflow design. Instead of relying on mandates, UVA focuses on processes that make secure choices the easiest, most natural option for campus partners. Attendees will learn strategies for aligning decentralized units around common security baselines, integrating security early in the procurement and system onboarding process, and supporting academic and research needs without compromising risk posture. The session offers real examples, challenges, and actionable tools that institutions of any size can adapt to improve their own security-by-default practices.

Presenters

  • Brandy Smith

    IT Policy and Compliance Analyst, Senior, University of Virginia

Resources & Downloads

  • Building Security by Default in a Decentralized Institution Lessons from Our University by Brand

    Updated on 4/21/2026