Banner Image

From the Archives: How CAUDIT became a convenor of the sector’s collective cyber defence

For 50 years, CAUDIT has provided a unique forum for the sector’s technology leaders to come together, identify shared challenges, and act collectively. That convening role is one of CAUDIT’s greatest strengths: creating the conditions for members to move beyond individual institutional responses and build sector-wide solutions.

The Australasian Higher Education Cybersecurity Service (AHECS) is a powerful testament to that model. What began as a shared recognition that cybersecurity was an escalating sector risk has grown into a trusted service, community, and knowledge network that helps institutions strengthen their cyber posture together.

Responding to a shared sector challenge

At the 2018 CAUDIT Members’ Meeting, Member Representatives identified cybersecurity as a strategic priority. Universities presented an attractive target for cyber threat actors due to the high volumes of personal data, valuable intellectual property, and research activities, and the complex digital ecosystems they operate in. At the same time, cyber capability, maturity, and resourcing varied widely across the sector, affecting institutions’ ability to manage risk. 

The sentiment was clear: investing in cybersecurity would be costly, but not investing would cost more. CAUDIT funded a dedicated resource to progress the business case, leading the work with AARNet and AusCERT. Once the program was endorsed, AAF and REANNZ were invited to join, and the Australasian Higher Education Cybersecurity Service (AHECS) was born.

CAUDIT led the initiative and established the Director Cybersecurity role to provide focused sector leadership and coordination. The early years focused on maturity assessment, tactical response, good practice guidance, webinars and events, online study tours during COVID-19, UFIT guidelines and building the relationships needed for trusted collaboration.

As CAUDIT CEO Greg Sawyer, who was Cybersecurity Director at the time, reflects:

“Long before cybersecurity became a board-level issue, CIOs across the higher education sector recognised the growing risk and took collective action through AHECS. Their leadership created a trusted forum for collaboration, capability building, and intelligence sharing. The strength of the sector’s cyber resilience today is built on foundations laid by CIOs who understood cybersecurity was not a competitive issue but a shared responsibility.” 

Turning trust into tangible progress

By 2021, the work had matured into a structured program spanning threat intelligence, analysis, benchmarking, awareness, training, engagement, and the ongoing scoping of new services. The 2023 Sector Cyber MOU, signed by 34 universities across Australia and New Zealand, further embedded this collective approach and reinforced the sector’s commitment to supporting one another in times of crisis.

The impact of that shared approach is visible in practical improvements across the sector. One example is identity and access management. Following an identity-related incident shared within the CAUDIT CISO group in 2021, institutions were able to learn from the experience and strengthen their own approach, including the adoption of multi-factor authentication for student accounts which was previously not widely seen as a priority. Today, institutions report a 91% MFA rate for staff, up from 54% in 2022, and 75% for students, up from 21% in 2022.

Benchmarking has also made the sector’s progress visible and gives institutions a way to understand their own posture, compare it against peers, and identify where to focus next. CAUDIT’s benchmarking program has grown since 2018 and now includes an annual CAUDIT-funded NIST CSF assessment, twice-yearly surface-level exposure scans, an annual baseline and system measure, and numerous ad hoc and member-led surveys.

Since 2020, sector cyber maturity assessments have demonstrated continued uplift across every assessed domain including governance, controls, and operational capability. 

Convening the sector’s cyber knowledge and expertise

The CISO group and broader cyber community have been fundamental pillars of AHECS’s success. Through these communities, CAUDIT convenes the expertise, relationships, and trusted channels that enable members to share threat intelligence, exchange practical knowledge, discuss emerging risks, and support the ongoing development of the program.

The scale of that community reflects its value. CAUDIT’s cybersecurity and identity and access management communities now include more than 1,000 members. In 2025, 67 cyber webinars attracted more than 4,900 attendees. 

The recent Canvas incident showed the value of this community in practice. In partnership with the National Office of Cyber Security, CAUDIT and the AHECS community brought people together quickly to share information, coordinate approaches and support a sector-wide response, not only within the CAUDIT Membership but across the wider education sector including Australian K-12. 

“International colleagues commented that they were in awe of the collaborative incident response demonstrated in the Australian and New Zealand space” said Nikki Peever, Director, Cybersecurity, CAUDIT. 

This response was possible because of years of investment in trust, relationships, and shared practice. CAUDIT’s convening role gives the sector a place to come together before, during and after incidents, helping ensure knowledge can be shared openly and acted on collectively.

“Sitting in a call with hundreds of cybersecurity professionals from across the sector was a powerful reminder of the critical importance of our work, and how far CAUDIT’s cybersecurity program has come. What began in 2018 as a shared recognition that the sector needed to lift its cyber capability together has grown into a trusted, sector-leading service that can mobilise expertise, share intelligence, and support institutions when it matters most” said Nikki. 

 

A trusted voice for the sector

As AHECS has matured, CAUDIT’s role has extended beyond convening members to acting as a trusted voice for the sector. CAUDIT represents higher education in national conversations, including submissions on cyber legislation and Security of Critical Infrastructure obligations, expert witness appearances, and participation in forums such as co-chairing the Trusted Information Sharing Network.

This helps ensure the higher education context is understood by government and security stakeholders, including Home Affairs, the Australian Signals Directorate, the Australian Federal Police, state governments, ASIO and the Attorney-General’s Department. It also gives members a coordinated voice on complex issues. 

CAUDIT also helps raise the profile of cybersecurity with university leaders, curating a quarterly DVC report to provide senior leaders with clear sector-level insights on cyber maturity, risks and progress, reinforcing the importance of continued investment and sustained attention to cybersecurity across the sector.

CAUDIT’s role as peak body also extends to practical partnerships and shared solutions. The groundbreaking partnership with Toronto Metropolitan University and CUCCIO on third-party risk assessments is an example of CAUDIT working beyond individual institutions, and international borders, to address common challenges, reduce duplication and strengthen cyber resilience across the sector. Through the partnership, 36 Australian and New Zealand institutions and over 200 Canadian institutions share a platform for third-party risk management, surface level analytics, and benchmarking. 

“Coordinated cyber leadership is what turns dozens of individual institutions into a resilient sector, and that coordination doesn't happen by accident – it takes trusted relationships, shared intelligence, and a willingness to act together in the face of common threats. Over five decades CAUDIT has earned its place as a trusted voice for universities and a strong, well-respected advocate with government, consistently bringing us together and ensuring the sector's cyber interests are understood and championed where the decisions are made. As threats grow more sophisticated, that kind of collective leadership matters more than ever, and CAUDIT's 50-year legacy gives us a powerful foundation to build on” said Dr Ross McLennan, Industry Co-Chair, Higher Education and Research Sector Group, TISN; Pro Vice-Chancellor (Research Services), Macquarie University.

CAUDIT is also helping the sector look ahead. Recent work on quantum readiness, including a sector scan and member advice, reflects the program’s commitment to identifying emerging issues early and giving institutions practical guidance to understand the risks, prepare for change and strengthen their long-term cyber resilience.

A network built on trust

For all the frameworks, services and structures developed through CAUDIT’s cybersecurity activities, the real strength of the program lies in its people. The CAUDIT cyber communities have developed a strong sense of camaraderie, a unique “family” feeling, where people know one another, trust one another and share openly because they understand their challenges are shared, and they are stronger together.  

That trust is the foundation of the program’s success. AHECS would not be what it is today without the CISO group, Cyber Community of Practice, Member Representatives and cybersecurity professionals’ willingness to share expertise, lessons learned and time in support of their peers.

“The CAUDIT Cybersecurity Community of Practice has achieved an enormous amount in just 18 months, creating a trusted environment where peers can openly share experiences, challenges, and lessons learned. The relationships built through the community have accelerated the growth of our collective capability, enabling institutions to learn from one another, respond more effectively to emerging threats, and deliver outcomes that would be difficult to achieve in isolation. In a relatively short time, the CoP has become a powerful example of how collaboration can strengthen cybersecurity capability across the sector” said Michael Karich, Cyber CoP Chair, Deputy Chief Information Security Officer - Engagement, University of Auckland. 

A lasting legacy of collective action

CAUDIT’s cybersecurity program is a living example of what collective action can achieve. Over seven years, it has helped the sector move from recognising a shared risk to building a trusted service, a mature community, and a stronger collective cyber posture.

Through AHECS, CAUDIT continues to convene the expertise and networks that help members strengthen capability, respond to emerging threats, and support one another. As cyber threats continue to evolve, that community will remain one of the sector’s most important defences.

The AHECS Cybersecurity Summit is currently open for registrations, with early-bird closing on 17 August 2026. If you’re a cybersecurity professional working in higher education and research, register now (opens in new tab)

Resource Image
Public

From the Archives: How CAUDIT became a convenor of the sector’s collective cyber defence

CAUDIT’s cyber story shows how sector-wide collaboration has strengthened cybersecurity capability, trust and collective resilience.

Original Publish Date

06 Aug 2026

Resource Type

News

Tag

50 Years of Collaboration