Nysernet | Articles and Insights

From measuring security to managing risk: How Daemen University is building a more defensible cybersecurity program

Written by nysernet | Oct 5, 2026, 5:32:36 PM

October 5, 2026

With a lean security operation and an institution-wide commitment to cybersecurity, Daemen University has turned to outside expertise not to replace its internal capabilities, but to strengthen them. Through penetration testing, risk assessment, cyber insurance review and professional development, Daemen is gaining additional perspective, validating its progress and identifying practical ways to keep improving.

Building on a strong foundation

Cybersecurity at Daemen University is a team effort.

Chris Pack, associate vice president for information security, leads the university’s security program with support from colleagues across IT. With responsibility for cybersecurity ultimately resting with him, Pack recognized the value of having additional expertise available to complement the work already happening internally.

“I'm only one person running a lean security program. I get help from my other IT colleagues, so it's a group effort. Ultimately, responsibility still comes down to me. We were looking to add Nysernet's expertise as an extension of our team.”

— Chris Pack, associate vice president for information security, Daemen University

That need did not come from a lack of cybersecurity maturity. Daemen had spent years building and strengthening its security program and assessing its progress. The opportunity was to introduce an informed outside perspective that could challenge assumptions, validate effective practices and help the team see where additional attention could make a difference.

It is also part of a broader institutional commitment. Daemen’s 2025-30 strategic plan identifies cybersecurity readiness and resilience as a priority, including continued investment in cybersecurity resources, expanded training and regular assessment of security policies and practices. 

Adding perspective without adding unnecessary complexity

Daemen's work with Nysernet has included several cybersecurity services that complement each other, rather than a single assessment or project.

Penetration testing provided another view into potential vulnerabilities. A broader cyber risk assessment helped examine the university’s security program and priorities. Professional development courses helped support continued technical growth. And a review of Daemen’s cyber insurance coverage identified gaps the university could address as it considered future coverage.

For Pack, the common value across those engagements has been the ability to test Daemen's assumptions and learn where its existing approach is working, as well as where it can improve.

“We like to think we've done a pretty good job over the years as we've built and strengthened our cybersecurity program. Having feedback and, in some cases, validation of what we do well, along with areas we could improve on, only helps us be better prepared against today's cyber threats.”

— Pack

That validation matters for a team that has to make deliberate decisions about where to invest time and resources. Instead of treating an assessment as the finish line, Daemen has used the findings to inform the next set of priorities.

Proof of impact

More capacity for a lean security program
Nysernet expertise serves as an extension of Daemen’s internal team, giving Pack additional perspectives and specialized resources without requiring that expertise to exist entirely in-house.

Coverage gaps brought to light
Daemen's cyber insurance review identified gaps in existing coverage, giving the university information it could use as it considered how to better protect the institution in the future.

Assessment findings turned into action
Daemen has made several security changes following its assessments, strengthening protections while maintaining an approach appropriate for its institution.

Independent validation alongside opportunities to improve
External review has helped Daemen identify both areas of strength and areas requiring additional attention, giving the team greater context for its ongoing security work.

Cybersecurity as an ongoing practice

Pack is quick to point out that cybersecurity cannot be approached as a project with a defined end.

As Daemen has acted on assessment findings, the threat environment has continued to change. New vulnerabilities emerge, attackers adopt new technologies and institutions need to continually reevaluate the protections they have in place.

“Cybersecurity isn't a one-stop review, apply fixes and you're done. As we strengthen our security posture, bad actors use AI to quickly find vulnerabilities and attack through them. This means our reactions need to be almost as quick, or at least keep us aware of the latest exploits.”

— Pack

That mindset has helped shape the relationship between Daemen and Nysernet. Rather than working together only when a specific problem emerges, the organizations can revisit priorities as Daemen's needs and the cybersecurity landscape evolve.

"Daemen already has a knowledgeable, highly collaborative team that takes cybersecurity seriously. What we’ve been able to do is complement that strength with additional expertise and an outside perspective, helping validate what’s working, identify opportunities to improve and support the team as their priorities evolve. Chris has been proud to call Daemen Nysernet’s first cybersecurity customer, and that trust means a lot to us."

— Emilyann Fogarty, chief information security officer, Nysernet

 

A partner that understands the institution

For Pack, the relationship also comes down to how recommendations are made.

Rather than applying the same answer to every organization, he says the Nysernet team takes time to understand Daemen's environment and constraints before recommending a path forward.

“Everyone at Nysernet takes the time to explain and fully understand our position to ensure what they suggest or propose best suits our institution and needs. I've worked with many vendors over my almost 20 years in IT, and I can say there is no one better to have on your side than Nysernet.”

— Pack

That experience has made Daemen an enthusiastic early adopter of Nysernet's cybersecurity services. Pack sees trying new services not simply as gaining access to another offering, but as an opportunity to build on a partnership he trusts.

“I trust Nysernet to bring their best. Whether it is services or offerings, they won't add new services without ensuring they will be a major benefit to members. To me, that speaks volumes not only about who they are as a company, but also that they care about their members. Nysernet isn't just a vendor to me. They're a trusted partner.”

— Pack

For a lean security program facing a threat environment that never stands still, that relationship provides something difficult to capture on an assessment score: more expertise at the table and another team invested in helping Daemen move forward.

About Nysernet cybersecurity

Building a defensible security program takes more than a single assessment. Nysernet works alongside research, education and nonprofit organizations with cybersecurity expertise and services designed around their environments, priorities and resources. From penetration testing and risk assessment to training and incident preparedness, members gain expertise that complements their teams and helps turn security findings into practical next steps.

Learn more at nysernet.org/cybersecurity.