How higher ed CIOs are redefining their enterprise role
Technology now touches nearly every institutional function, but the CIO’s expanding role is not simply about owning more systems. Higher education CIOs are increasingly helping leaders redesign operating models, weigh institutional risks, and decide how technology investments can advance campus priorities.
In September, EAB convened chief information officers and senior technology leaders for a virtual conversation on the CIO’s expanding enterprise role. Brandon Bernier, Vice President for Information Technology and CIO for Colorado State University–Fort Collins and the Colorado State University System, and Nish Malik, Chief Information and Digital Strategy Officer for the San Francisco Bay Region Network, shared how they are adapting their organizations and leadership approaches as their responsibilities grow.
Their institutions differ in scale and structure, but their experiences point to the same lesson: CIOs create more value when they help the institution make choices about how work is organized, governed, and supported. Four themes from the conversation stood out.
Institutional pressures are pulling CIOs deeper into strategy
Financial constraints, enrollment shifts, cybersecurity exposure, and rising expectations for AI are changing what institutions need from IT. Malik noted that his calendar now includes far more time with leaders in finance, human resources, and academic affairs than it did five years ago. He remains the technology leader, but much of his work now centers on how three universities should operate together and where digital transformation can improve their shared work.
Bernier described AI as both an opportunity and a source of organizational strain. Faculty, staff, and students want to move at different speeds, while institutions still have to address privacy, security, accessibility, cost, and data governance. AI is exposing seams in infrastructure and decision-making that CIOs cannot resolve through technology alone.
This shift has pushed the CIO’s contribution beyond running systems or responding to requests. CIOs increasingly help institutional leaders examine processes, investments, risks, and the broader operating model.
Design the operating model one capability at a time
Both panelists cautioned against treating centralization as the goal. The more useful question is which capabilities benefit from enterprise scale and which depend on local expertise, relationships, or mission.
Colorado State is using a core, common, and unique framework to guide that work. Services such as networks and email belong at the enterprise level. Other platforms may be shared by several units but not the entire institution. Highly specialized systems, such as the electronic medical record used by the university’s veterinary school, need to remain close to the clinicians and technical experts who use them.
The San Francisco Bay Region Network is applying the same principle as it builds one regional IT organization for San Francisco State University, Sonoma State University, and California State University, East Bay. Cybersecurity, enterprise platforms, infrastructure contracts, architecture, and specialized technical expertise can benefit from regional scale. Other functions require campus-level knowledge and presence.
The real design question is not, what do we centralize and what do we not? It is, what is the right operating model for each capability that we have in place?
Nish Malik, Chief Information and Digital Strategy Officer
San Francisco Bay Region Network
For CIOs considering a new service model, this capability-by-capability approach offers a practical starting point. Standardize where variation adds little institutional value, and preserve local ownership where campus context matters.
People determine whether alignment works
Malik drew an important distinction between organizational consolidation and operational integration. Reporting lines can change quickly. Building shared processes, service expectations, governance, trust, and accountability takes much longer. If a new model improves efficiency but reduces responsiveness, campus partners may experience the change as something being taken away from them.
Colorado State is addressing that risk by giving distributed IT leaders seats on the senior leadership team and asking central and distributed colleagues to co-lead the workstreams designing the next phase of alignment. The division is also prioritizing internal candidates for key roles and investing in leadership development, change management, and communication training.
The people architecture, the systems and processes of how you bring people together, matters more than an org chart would.
Brandon Bernier, Vice President for Information Technology and CIO
Colorado State University–Fort Collins and Colorado State University System
The early results show why this work matters. Colorado State’s alignment with its Pueblo campus strengthened its cybersecurity posture, helped the campus obtain cyber insurance, and saved more than $1 million on a network replacement. Staff at Pueblo also gained opportunities to lead services across the system. Malik reported that the regional network reduced its IT management structure from more than 20 roles to 10 and saved a few million dollars during its first seven months, largely through attrition and avoided backfills.
Shared governance keeps enterprise decisions aligned
A broader portfolio does not mean the CIO should own every function that uses technology. Malik suggested starting with accountability for the outcome. Human resources should remain accountable for HR outcomes, and enrollment leaders should remain accountable for enrollment outcomes, even when technology is essential to achieving them. IT should ensure that decisions fit together across architecture, security, data, integration, risk, and investment.
The same principle applies to AI. Teaching and learning leaders should guide pedagogy, research leaders should guide research use, and functional teams should shape applications in their areas. IT should provide the foundation, including data platforms, enterprise tools, security, privacy, identity, integration, vendor management, and AI literacy. Malik described the model as centralized governance with distributed ownership and innovation.
Enterprise risk also requires shared accountability. The CIO and CISO should make cybersecurity, third-party, data, operational, and AI risks visible and understandable. The appropriate institutional or functional leader must then decide which residual risks to accept. As Malik put it, compliance is the floor, not the strategy.
That model depends on relationships. Bernier emphasized spending time with deans, cabinet members, faculty, and campus partners before problems become crises. CIOs cannot be in every room, so they also need credible academic and distributed IT leaders who can bring campus perspectives into decisions and carry shared priorities back to their communities.
Stay connected to the CIO community
The September discussion showed the value of comparing operating models, sharing early results, and naming unresolved tradeoffs. No single structure will fit every institution, but CIOs can help one another ask better questions about scale, local expertise, accountability, and change.
EAB will continue the CIO Conversation Series with another CIO Spotlight event in the coming months. To learn about upcoming conversations, connect with one of the panelists, or explore IT Strategy Advisory Services, contact your Strategic Leader or [email protected].
More Blogs
3 ways IR leaders are rethinking their data strategy
What CIOs are saying about the future of higher ed IT