Every CISO knows they need to do more with less. Fewer analysts, tighter budgets, more obligations. Matthew Martin has led security through all of it in two very different worlds: 20 years in financial services, and now in higher education at Western Carolina University.
After two decades with enterprise budgets and every tool available, Matt made a deliberate choice to take on higher ed with different constraints and a decentralized structure. In our latest #StrategicCISOs conversation, he shared what his time in financial services taught him, and what still surprised him about the move.
What emerges across the conversation is an approach Matt calls “creativity within constraints”. It’s the idea that the tightest environments often produce the sharpest leadership. Here are five key lessons from that approach.
1. Know your real constraints (it’s not always budget)
Matt walked into the university setting expecting that budget would be his biggest problem. He was wrong.
Matthew Martin
CISO, Western Carolina University
“I thought I was dealing with constraints around dollars. It turned out the dollar constraint was actually one of the smaller constraints.”
Structural and cultural differences were a bigger challenge. Faculty don’t report to the CISO. Departments are autonomous. “Higher ed feels like family,” as Matt put it. That creates real trust and shared purpose, but also means security has to be built through influence and relationships, not mandates.
Financial services CISOs know a version of this. Regulatory complexity, business units running their own tech, risk ownership stretched across the enterprise.
Look beyond budget for the constraints that actually shape your program.
2. Listen before you fix
Matt’s first month in higher ed was a lesson in what not to do. He walked in ready to fix. Within weeks, he’d opened too many tickets and asked too many people to change too many things.
Matthew Martin
CISO, Western Carolina University
“I did not make a lot of friends.”
Your instinct to fix things is likely the drive that got you the job. But security in a new organization isn’t a technical problem on day one. It’s a relationship problem. You can’t fix what you don’t understand, and you can’t understand it from the outside.
Now, Matt would tell any new CISO to go in with the intention to learn, not to fix — to sit with the environment, ask questions, and document what you find before you touch anything. Yes, technical skill matters. In a regulated, resource-constrained environment, you can’t lead only from the strategy layer. But if you skip over listening, even the right technical decisions won’t land the way they should.
3. Approve use cases, not individual people
Once Matt started listening, he noticed a pattern. The same access decisions were being made over and over, one person at a time, with no consistent rationale tying them together.
Matthew Martin
CISO, Western Carolina University
“You would approve something for some person to do this thing, but then you’d also evaluate and approve another person to do the exact same thing. Because it was based on a person versus based on a specific use case.”
Person-by-person decisions don’t scale, because each one is a fresh judgment call. Over time, you end up with a security program that’s effectively a collection of one-offs. It’s impossible to audit cleanly or to defend when something goes wrong.
Use-case thinking flips the model and asks: what’s the use case underneath this request, and what’s the right policy for it? Once that’s defined, the decision applies consistently to anyone who fits the pattern. It’s documented and defensible, a key benefit of continuous control monitoring.
4. If you do risk well, compliance comes free
Risk or compliance, which one should you start with? Matt didn’t hesitate to answer.
Matthew Martin
CISO, Western Carolina University
“If you do risk well, compliance comes free.”
Starting with compliance forces you into a checkbox mindset. Focusing on risk gives you a framework for prioritization and a language your leadership can actually engage with.
For new CISOs, the practical starting point is a real risk register, not a spreadsheet collection. With a risk register, you can accurately prioritize updates and policy changes with evidence, rather than responding to daily concerns. Matt described it clearly: “putting the risk register in correctly and starting to report on it — we were able to say, hey, here are our biggest risks and here’s what we can point to.” That structured foundation also provides shared language and evidence to guide every conversation with your board, auditors, and other stakeholders.
5. Scale with continuous control monitoring
For Matt, automation isn’t just a strategy. It’s essential.
Matthew Martin
CISO, Western Carolina University
“I can’t go hire a team of risk analysts. The only way I could do that was to embrace technology.”
Continuous control monitoring offers high value to CISOs like Matt. It replaces the traditional model that most security teams still live inside:
- Annual or quarterly control assessments that catch problems long after they start
- Point-in-time audits that give you a snapshot, not the full picture
- Self-attested evidence that’s only as reliable as the person filling out the spreadsheet
Matt was clear: “self-attestation is not an option here.” The cost of finding out a control has been broken for nine months is too high. And when a small team needs to chase it down with manual evidence collection…the stakes are too high.
Continuous monitoring flips the model:
- Controls are tested automatically, on an ongoing basis, against verifiable evidence
- Findings surface in real time, not at the end of an audit cycle
- You get time back to focus on remediation, not evidence collection
- The board and auditors can see the same ground truth as the security team
Matt sums up the payoff: “we’re behaving more like a mature security organization.” Higher ed isn’t the only industry heading this direction. Financial services, healthcare, and SaaS are too.
Four principles for leading security under constraints
After years of leading security across two very different industries, Matt’s approach comes down to four principles:
- Be part of the community you serve
- Understand the real risks, not just the ones written down
- Embrace automation — self-attestation has reached its limit
- Stay open to change
There’s a fifth Matt would add, and it’s the one that separates the CISOs who thrive from the ones who burn out: “if you come in and you’re like 100% security or bust, you won’t last long in higher ed.”
That principle applies well beyond higher ed. In environments like this, a CISO who succeeds will make the organization safer without slowing it down.”
Watch the full Strategic CISOs conversation with Matt Martin on demand.
FAQ
What can financial services CISOs learn from leading security in higher education?
Financial services and higher ed CISOs share more structural challenges than they realize. Both lead security in regulated, decentralized environments where influence matters more than authority. The important lessons: name the real constraint before fixing, listen before acting, replace person-by-person decisions with use-case-based policies, and treat automation as essential rather than optional.
What's the biggest mistake new CISOs make?
Fixing before listening. The pressure to demonstrate value in the first 90 days pushes most new CISOs to start changing things before they understand what they’ve inherited. The strongest new CISOs reverse the order — they listen, document, and build trust first, which is what makes the harder changes possible later.
How do CISOs in resource-constrained environments use automation?
Automation closes the gap between what a security team is responsible for and what it can deliver with limited headcount. The highest-leverage applications are continuous control monitoring (replacing point-in-time, self-attested assessments), automated workflow routing, and AI-assisted triage. In environments where hiring more analysts isn’t an option, automation isn’t a preference — it’s the model.