About this session
Raphaelle Gauriau, Information Security Strategic Execution Manager at the University of Toronto's central IT, and John Stewart, information security program manager at UTSC, describe building the university's opt-in security awareness and training program across three decentralized campuses. They open with the why: human factors as a security risk, strong staff demand for training, and protecting sensitive data and reputation. The foundations project targets staff first, using a vendor training platform customized with the university's branding and a risk score per user, plus custom modules built with departments such as the Faculty of Medicine. They name four recurring challenges, opt-in onboarding per unit, sustaining engagement, running phishing simulations without eroding trust, and measuring success, and answer each with seven tactics: positive guiding principles, simple executive buy-in, roughly 50 cross-campus champions meeting quarterly, transparent monthly phishing simulations with no penalties, visible rewards, platform customization, and lead rather than lag metrics. Results after about a year include 46 units, 12,000 users onboarded, and a report rate well above the sector benchmark. Q&A covers credential harvesting, mandatory versus opt-in policy, and healthy competition between departments.
In today’s digital landscape, cybersecurity threats loom large, and educational institutions are no exception. At the University of Toronto, we embarked on a journey to foster a culture of security across our three campuses. Join us as we share our strategies, challenges, and successes in implementing a comprehensive Security Awareness and Training Program (SATP). This presentation will highlight the power of collaboration across teams and divisions via strong partnerships, and provide some useful tips to foster community engagement and continuous improvement. We are Secure, Together.
Key takeaways
- Make phishing simulations transparent (tell users they will happen monthly) and never penalize or assign remedial training for a click, research shows punitive approaches erode trust and don't work.
- Get executive buy-in with the simplest possible ask: two sentences at a town hall drove more sign-ups for one campus than any formal communication plan.
- Recruit and meet regularly with cross-unit champions (quarterly, in this case) to get direct feedback from the community and adjust the program.
- Track lead metrics you can influence directly (users onboarded, modules completed, completion rate) rather than lag metrics like incident counts you don't control.
- Customize the platform and its emails with your own branding so users trust the 'report phishing' button is really coming from their own security team.
Speakers

Former employee at Gosecure from 2011 to 2014, Raphaelle brings a wealth of cyber security knowledge and experience accumulated over a decade of work in the private and public sectors. In 2020, she became the Information Systems Security Manager at… Read moreRead less
Former employee at Gosecure from 2011 to 2014, Raphaelle brings a wealth of cyber security knowledge and experience accumulated over a decade of work in the private and public sectors. In 2020, she became the Information Systems Security Manager at SciNet, the supercomputer at the University of Toronto, where she led the strategy and execution of SciNet’s cyber security program in strong partnership with the Digital Research Alliance Federation of Canada (Advanced Research Computing). In September 2022, she became the Information Security Strategic Execution Manager, accountable for driving the implementation of the Information Security strategy. Raphaelle holds a master’s degree in computer science and a CISSP certification.

John Stewart is the inaugural information security program manager at the University of Toronto Scarborough (UTSC), where he leads all risk management, training and other cyber security matters for UTSC, partnering with different departments to… Read moreRead less
John Stewart is the inaugural information security program manager at the University of Toronto Scarborough (UTSC), where he leads all risk management, training and other cyber security matters for UTSC, partnering with different departments to execute the tri-campus strategy. With nearly two decades in IT, John has worked on an array of portfolios, including leading network infrastructure at the campus, as well as progressively senior roles at a managed network service provider.

