Institutional signals
It’s important to realize that all signals are not equal
Throughout a handful of posts, I’ve been exploring the idea of cybersecurity norms - wrestling with just what norms are, and what it means to have norms in the first place. In the most recent piece, where I posit a modest list of norms, I argue that despite the daunting challenge of establishing norms across an entire sector or nation, we have more agency than it may appear. Essentially, the starting point in establishing norms is to simply start talking about them; talking leads to changes in practice, messaging, and ultimately informal agreements and beliefs. Ideally these form a precondition for the codification of norms in law, treaties, and similar durable frameworks.
I came to this belief not through a linear path from an analysis of norms to a pattern of practice, but organically. As I’ve described elsewhere, it gets exhausting listening to people complain about organizational culture, all while normalizing the very culture they’re complaining about. Similarly, I’ve written critically about strategy documents, having said that, if you want to truly understand an organization’s “strategy,” examine its budget. Institutions don’t reveal their priorities through strategy documents - they reveal them through signals: what they codify, what they fund, what they tolerate, and what they ask.
Most recently I started thinking about how an organization “signals” anything, and specifically, norms. That is, what I want to call institutional signals are the externally and internally visible manifestations of how an organization operationalizes norms - revealed through decisions, structures, language, and behavior under constraint.
It’s important to realize that all signals are not equal. Some are cheap, some are costly. The costly ones are more trustworthy. For example, writing a policy strikes me as a cheap signal. Publishing a report is a tad costly, a medium signal. Reallocating budget, on the other hand, is an expensive signal. Meanwhile, revoking a policy exception or changing behavior is a very expensive signal.
Which leads me to propose that signal strength is defined by the cost of deviation from that signal. That is, a signal is strong to the extent that it is costly for the institution to violate it. The strength of a signal isn’t about how loudly it’s stated - it’s about how painful it would be to act against it.
I want to use this post to explore institutional signals—because if we, as a community, are going to find our voice and establish durable norms, we need a consistent and recognizable set of signals for how we engage with each other and with society.
We should start by looking at what it is we actually say. I’m thinking of explicit statements of intent and identity. Statements that signal “here is what we claim to value.” Three distinct examples come to mind. Obviously, a signal could be the codification of norms and policies. Fairly weak, but still a signal. Another example might be a transparency report. I’ll expand on these in a later post, but I think they represent yet another relatively simple, but impactful, opportunity for collective action and norm establishment. Finally, you’ll see statements about regulatory alignment that sound great, but are truly more performative than not. Statements about HIPAA compliance within the health sector, or privacy compliance in the commercial sector. Especially within the U.S., most cybersecurity and privacy regulations are floors - bare minimums that are able to be enacted despite our pay to play legislative system. Treating the floor as a statement of high institutional value is the very definition of a cheap signal.
We should next consider what we actually value. Perhaps “allocative” is the proper adjective here. What we fund and prioritize - allocative signals - would include budgetary proportionality. As we’ve all noticed, our organizations invest the vast majority of cybersecurity funding into enterprise systems; while largely neglecting the truly existential research mission. While we are beginning to see cybersecurity inserted into research proposals (at least sufficiently to cover mandated security controls), this is still rarely done institutionally and at most schools it is rather ad hoc. Nevertheless, it feels like an issue of proportionality, an allocation of effort, so I’ll leave it as an example here.
I can think of two additional classes of signals: what we do under pressure and signals that reveal how we think and frame reality. I’ll label these behavioral for the former, and interpretive for the latter.
Behavioral signals reveal what our preferences are when under constraint - essentially signaling how we behave when tradeoffs are real. For example, when we make an exception to a policy or a norm we are exercising exception discipline. While exceptions are deeply ingrained in cybersecurity (through the notions of a compensating control and risk acceptance) they do surface how an organization balances competing demands, perhaps more clearly than any other signal.
Similarly, how an organization chooses to participate in sector activities is another form of behavioral signal. Any reader of this blog knows that I feel this is an area we - the higher education sector - are not giving enough attention to. Though that in itself is a deafening signal. I’ll say more about this in a moment.
The final class of signals, interpretive signals, demonstrate how we (usually management and leadership) understand a problem space1. As I’ve discussed in earlier posts, the intellectual style of executive inquiry and the use of reductionist language are massively important - and loud - signals to our organizations.
I want to pivot somewhat from a theoretical discussion of signals, towards concrete steps we, as individuals and organizations, can take. Can we inventory a set of organizational signals that could be used to advance the establishment of cybersecurity norms, and thus, the practice of cybersecurity writ large? The purpose of my classification of signals is to provide a framework for just such an analysis - to bring a little discipline to the subject.
We have already examined three examples of declarative signals:
Establishing a policy
Releasing a report (the result of an analysis)
Performative regulatory compliance.
And we’ve all seen how these signals get amplified - for example, when one institution models a policy on another’s. Unfortunately, that amplification is rarely one of directed or community action. It happens by passive diffusion, i.e., informal adoption of a policy in broad strokes, rarely even with public acknowledgement2. But without that signal of acknowledgement - of declared shared belief - what does it really accomplish? Recall that my goal is to encourage the establishment of norms, which raises the bar considerably. It’s no longer enough to say “everyone has a policy on AI,” but rather, “can’t we develop a sector-wide AI policy for general adoption?” Or perhaps, given pressure to fold research activities into a research security program, could we develop a framework for such a program under the auspices of an organization such as AAU or APLU that is broadly used to shape local programs?
The value of this approach is not just in the establishment of a norm, but to demonstrate to external regulators, federal sponsors, and society at large that we have the maturity to act cohesively. Essentially I’m hoping we can move beyond observation (“here’s what we see among our members”) to sector agency (“we came together and agreed on a norm.”)
While declaring and speaking is powerful, acting has much more impact. Here we move to consider examples of allocative signals. Obviously, expecting institutions to reallocate massive capital overnight toward research cybersecurity - where the vulnerability is most acute - is unrealistic. But we can create the conditions that apply pressure for re-allocation of resources and signal those. I can imagine goals being set and metrics collected on one or two dimensions of cybersecurity related to resources. Perhaps something along the lines of “percentage of operating budget devoted to research cybersecurity.” Or, “percentage of grant proposals that include funding requests for cybersecurity elements.”
I’m not going to hazard a guess as to what those percentages should be - but a public commitment to achieve some community agreed upon percentages would be a tremendous forcing function. To anyone who’s rolling their eyes: remember, it’s the absence of metrics and commitments like these that gave birth to programs like CMMC and NSPM-33’s cybersecurity requirements. We are quietly reaping what we’ve sown3.
It’s reasonable to be skeptical that establishing these goals and publishing progress metrics will result in any actual reallocation of resources. Yet, organizations are competitive; donors, agencies, and legislators will see those metrics and ask about them. What’s important in this scenario is not just the selection of a goal for each metric, (though the work to develop these is valuable); that is merely a declarative signal. What pushes this into the allocative class is the publishing of performance metrics and the pressure that results from that visible signal4. After all, if we want norms, we need shared signals. If we want shared signals, we need shared metrics. And metrics only matter when they create consequences.
It’s hard to imagine a point in time when behavior under constraint is more relevant. We’re seeing school after school wrestle with the contraction of Federal funding, the open assault on academic freedom, and aggressive censorship - the complete politicization of the academic sphere. Any discussion of institutional signaling would be incomplete without pointing out that there is a deep fear of signaling due to the current administration’s actions. Signaling can put a target on your back. This is to say, that while there is a cost to signaling, there’s also the cost of signaling under political pressure. In fact, it is the highest-cost signal: signaling when the penalty is external, not internal.
Be that as it may, I can think of a few behavioral signals worth adding to our inventory. I mentioned exception handling; basically the curation of exceptions to policies and standards. While the nature of research activities will necessitate exceptions (either through compensating controls or risk acceptance), institutions will need to adopt via policy a stance that 1. exceptions must be treated as first-class objects with lifecycle management, not informal accommodations, and 2. regulatory and policy interpretation must be owned by a single authoritative function, not negotiated ad hoc.
But those are local matters - for the purposes of this post, I’m more interested in how behavioral signals are created. Are we prepared to take action as a sector on questions of cybersecurity? Some of these should be fairly straightforward to build consensus around, for example, the deployment of staff or expertise to assist peer institutions during active incidents, or a willingness to loan tooling, licenses, or infrastructure capacity during crises5. This could include a commitment to participate in cross-institution incident response exercises. But all of these rest on the presumption of pre-established mutual aid agreements for cybersecurity response.
Imagine the impact of a consortium agreement, especially in light of our current budget crisis, that pledged the protection of baseline cybersecurity funding during institutional budget cuts.
Some behavioral signals seem obvious to pursue. Such as participation in joint development of frameworks (not just their adoption), or a willingness to publicly endorse and align with sector-wide baselines. Are schools prepared to contribute to open security models, playbooks, or reference architectures? Though I’m not sure how we capture whether institutions deviate silently or openly challenge and refine shared norms.
Others start to truly bring the pain: those that bring transparency under reputational risk. For example, publishing post-incident reports with meaningful technical detail. I used to have more sympathy for holding this information close to the vest, but I now believe that in our modern threat landscape, this habit works against us. The bad actors already have these details - that’s why they were successful. Hiding this information only damages our community. We must develop the willingness to expose internal gaps or failures publicly.
Behavioral signals are where norms stop being aspirational and become visible. This is because they reveal what institutions are willing to do when cooperation is costly and reputation is at risk, particularly under time constraints. This is why they’re worth more attention - they are quite literally the establishment of norms in action.
I’m going to skip over interpretive signals for the most part, I’ve written at length about them before. But before moving on, let me bullet point the various signals I’ve described into a list with some expanded suggestions.
Declarative Signals (explicit statements of intent and value)
Codifying broad policies: publishing institutional policies on emerging domains, such as AI usage or research cybersecurity governance.
Releasing analytical reports: publishing transparent institutional reports on the adoption and efficacy of security controls within research programs.
Establishing performative regulatory baselines: agreeing upon a sector-wide baseline interpretation for implementing federal standards, such as NSPM-33 controls.
Allocative Signals (resource commitments and visible metrics)
Tracking budget and proposal metrics: formally committing to target benchmarks - such as the percentage of operating budget dedicated to research cybersecurity and the percentage of grant proposals requesting explicit security funding - and publicly publishing progress metrics for both.
Behavioral Signals - Local Discipline (internal governance under constraint)
Standardizing exception management: creating a sector-wide, shared repository of compensating controls and formal risk acceptances tailored specifically to research environments.
Centralizing regulatory authority: codifying in policy that all regulatory and compliance interpretations regarding research security are owned by a single internal authoritative function, rather than negotiated ad-hoc across departments.
Behavioral Signals - Sector Collaboration (costly, active cooperation under fire)
Codifying mutual aid agreements: establishing formal, pre-negotiated cybersecurity mutual aid agreements across systems and regional consortiums.
Operationalizing emergency staffing: creating clear policy and execution mechanisms to rapidly deploy staff and technical expertise to assist peer institutions during active incidents.
Pre-clearing emergency resource loans: standardizing contract language that enables - and explicitly signals a willingness to execute - the loaning of tooling, software licenses, or infrastructure capacity during crises6.
Executing joint exercises: establishing annual, cross-institutional incident response exercises with mandatory participation commitments.
Committing to transparent post-incident reporting: publishing detailed post-incident technical reports as early as technically feasible - potentially allowing a trusted peer partner to draft the report during the incident to expedite its public release.
Not surprisingly, in practice many of the signals from one category are coupled synergistically with others. Behaving one way is something; telling people you’re doing it is another. Coupling the two not only carries operational weight but is almost the definition of creating accountability.
Norms are not created by agreement, rather they are created by coordinated, costly signals that produce consequences. The list above makes no claim to being comprehensive. It’s not difficult to expand upon it. But I offer it up as a model to build upon, a model of institutional behavior change.
It’s worth reminding the reader who isn’t in a senior management role, that this same approach is effective regardless of your stature or role in the organization. If you’re predictable enough to end up on a ‘buzzword bingo’ card, some self reflection is warranted.
I do wonder, now that everyone is relying on LLMs to shape their writing, and LLMs are trained by scraping the public internet, if we’ll find new institutional policies normalizing in content and style due to their common dependency on LLMs. Someone needs to develop an LLM tagging plugin that shows you which LLM wrote most of anyone’s policies.
It’s tempting to see these programs as the result of failing with voluntary compliance. Regulators step in with blunt force when a vacuum of voluntary, measurable accountability is discovered. Having a mature set of established norms would have both reduced the strength of that vacuum and perhaps given regulators a starting point more apposite with institutional practice.
Having worked for a number of years in a system institutional reporting office has given me a sensitivity to how fearful institutions are about releasing activity data. It’s often highly nuanced, yet read without any nuance at all. Publishing metrics like those I’m proposing is a bell that can’t be unheard. But more than fear of misinterpretation, I believe institutions fear metrics because metrics create accountability.
It would make a terrific topic for our procurement experts and attorneys to consider how to add to our procurement contracts the ability to share licenses during another institution’s crisis.
I should acknowledge that mutual aid can feel like a asymmetric drain on high-maturity institutions. It’s worth remembering that true sector-wide norms require framing mutual aid as collective immunity rather than transactional trading.


