Skip to main content

Customer story · Cyber Heat Map

Pima Community College Replaces Ad Hoc Security Planning With Data-Driven Boardroom Strategy

Isaac Abbs · Recorded 10/13/2025

0:000:00
Captured on
Share One · October 13, 2025
Content fingerprint
1024343bac6f87f2
FNV-1a-32x2 over this page's video URL, capture timestamp and transcript — recompute it to confirm nothing was altered after publication.

Isaac Abbs of Pima Community College uses Cyber Heat Map to transition from ad hoc security planning to a defensible, data-driven strategy. By leveraging automated tool mapping and peer benchmarking, his team identified tool duplication and established a three-year roadmap. Abbs highlights the platform's ability to articulate strategy to the board with minimal administrative effort.

At a glance

Primary Use Case
Boardroom reporting and strategic roadmapping
Reported Result
Identified tool duplication and sunsetting opportunities
Time to Value
Low effort, one-time initial lift for 3 years of data
The effort to get meaningful data quickly, the effort is very low. And I think what people would quickly find is the value is very high, especially for those presenting to boards.
We were able to determine duplication of effort in some cases... there's an opportunity to potentially sunset a tool in favor of one that is already doing the purpose.
I think this one is low cost with tremendous value. And so... for a low investment, it's definitely worth the effort to try.

The interview

What is your overall impression of Cyber Heat Map's value?

It's a no-brainer. I mean, it's bang for the buck, absolutely, it's worth trying it out. The effort to get meaningful data quickly, the effort is very low. And I think what people would quickly find is the value is very high, especially for those presenting to boards, right? We use the data, we use the charts when we present to our board.

What was the hardest part of managing your security program before using this tool?

I think the hardest part was actually tracking all the stuff we had. We have quite a bit. We're doing a lot of really great things, but now having a place to track it has become much easier. Having our eyes on all the different technologies, and the capabilities they map to, which allows us now to better understand blind spots and roadmap for the future.

How did your planning process change after implementation?

We were doing what we were doing. We were doing a really good job of it. We would identify things we wanted to do next, but it wasn't based on any particular strategy. It was pretty just, kind of like, ad hoc. And so this allowed us to better get that under control, and clean it up from there. We weren't able to really articulate to the board what we wanted to do from a strategy perspective.

How does the tool help you handle board inquiries regarding budget and peer standing?

As budgets are getting tighter, boards are now asking the right questions of, 'Well, why this?' And now we're able to go in and say, 'Look, this is where we stack up with our peers. This is what we're gonna do.' It doesn't always align with the prioritization cause there's other factors outside of the tool, right? There's just, what are we seeing in the threat landscape at the moment?

What are the primary benefits you've realized after three years of use?

I'll say three things—benchmark against peers, benchmark against ourselves... and then I think the third thing is really identify those opportunities to continue to evolve our program based on improvement recommendations, and capabilities that maybe we're not as mature of as we'd like to be. We've made a lot of changes, and a good chunk of those have been in alignment with recommendations from Cyber Heat Map.

What was the implementation process like for your team?

The biggest 'lift'—and I'm gonna say that in quotes because it wasn't that big of a lift—was identifying all the tools. We didn't even have to align them to the business capability, right? You pick the tool, the tool's already mapped to a business capability. So now it's filling out, are you using it heavily? Not using it, does it need to be refreshed, sunset, whatnot? And once that's done, the rest is super straightforward.

Frequently asked

Is Cyber Heat Map too cheap to be effective?

Isaac Abbs addressed the perception that value is tied to high cost in the security space, stating that Cyber Heat Map is a 'low investment' with 'tremendous value' that is not too good to be true.

How much work is required to set up Cyber Heat Map?

Abbs noted the effort to get meaningful data is 'very low' because the platform automatically maps tools to business capabilities, requiring only a simple confirmation of usage levels.

Can Cyber Heat Map help with budget justifications?

Yes. Abbs uses the platform's peer benchmarking data to answer board questions like 'Why this?' by showing how the college stacks up against its peers as budgets tighten.

Full transcript

Isaac Abbs (00:00) It's a no-brainer. I mean, it's bang for the buck, absolutely, it's worth trying it out. The effort to get meaningful data quickly, the effort is very low. And I think what people would quickly find is the value is very high, especially for those presenting to boards, right? We use the data, we use the charts when we present to our board. Hello, Isaac Abbs, Chief Information Officer at Pima Community College. The IT team owns your typical IT shop stuff. So we all own Enterprise software, infrastructure, network, security, telephony, and we're also now in the physical security space. We brief our board on an annual basis. I brief my boss and the chancellor periodically throughout the year. I think the hardest part was actually tracking all the stuff we had. We have quite a bit. We're doing a lot of really great things, but now having a place to track it has become much easier. Having our eyes on all the different technologies, and the capabilities they map to, which, you know, allows us now to better understand blind spots and roadmap for the future. In terms of slowing I don't know if it created extra work. I think what it did is didn't allow us to better prepare for what would come next. We were doing what we were doing. We were doing a really good job of it. We would identify things we wanted to do next, but it wasn't based on any particular strategy. It was pretty just, kind of like, ad hoc. And so this allowed us to better get that under control, and clean it up from there. We weren't able to really articulate to the board what we wanted to do from a strategy perspective. As budgets are getting tighter, boards are now asking the right of, "Well, why this?" And now we're able to go in and say, "Look, this is where we stack up with our peers. This is what we're gonna do." Doesn't always align with the prioritization cause there's other factors outside of the tool, right? There's just, what are we seeing in the threat landscape at the moment? I think the first benefit was very easy to see all the tools we have, and more importantly, the capabilities they cover. We were able to determine duplication of effort in some cases. Sometimes the overlap makes sense. Sometimes it was like, well, there's an opportunity to potentially sunset a tool in favor of one that is already doing the purpose. But I the biggest thing we use Cyber Heat Map for, I'll say three things - benchmark against peers, benchmark against ourselves. You know, I think more importantly, we probably look to be the best version of ourselves versus how we relate to peers, but boards and stuff like that always want to know, what do you look like to your peers? And then I think the third thing is really identify those opportunities to continue to evolve our program based on improvement recommendations, and capabilities that maybe we're not as mature of as we'd like to be. I think we're getting ready to go into year 3 with Cyber Heat Map, and over the course of those years, we've made a lot of changes. And a good chunk of those have been in alignment with recommendations from Cyber Heat Map or conversations with Chris through Campus CISO. Having access to a peer community makes a lot of sense, right? Especially those of us at higher end, we're seeing the same things, we're dealing with the same things, we have the same struggles, and so... the opportunity, whether it's to commiserate or just share ideas and bounce strategy is always helpful. The biggest "lift" - and I'm gonna say that in quotes because it wasn't that big of a lift, was identifying all the tools. We didn't even have to align them to the business capability, right? You pick the tool, the tool's already mapped to a business capability. So now it's filling out, are you using it heavily? Not using it, does it need to be refreshed, sunset, whatnot? And once that's done, the rest is super straightforward. Now you get to leverage the power of the analytics, the data, the improvement recommendations, the benchmarking, and really start charting that course forward. It us data points and the ability to prioritize more easily, and identify where we wanna go next in terms of our roadmap for our security strategy. The threat landscape is ever-evolving, and the product stays up to date with the evolving landscape, the evolving capabilities, and allows you more easily to identify gaps, see where you're doing well, where you're not doing well. And like I said, the effort is low. It's almost like a one-time lift for us now, 3 years of valuable data and insight. ⁓ It's not too good to be true, right? I think sometimes in this space, if it's really expensive, there's value or there's perceived value. I think this one is low cost with tremendous value. And so... for a low investment, it's definitely worth the effort to try. I think what everybody will find is, oh my goodness, the value is unbelievable for the price point. And why didn't I do this sooner?

About Cyber Heat Map

Cyber Heat Map is an analytics engine and strategic planning platform designed to help organizations transition from manual spreadsheets to data-driven cybersecurity roadmaps. It serves strategic leaders in Higher Education and other sectors by providing prioritized recommendations based on cost, effort, and peer benchmarks. The platform enables CISOs to move from assessment overload to a defensible, board-ready plan that can be updated in minutes.

Industry
Cybersecurity Software

Topics

  • higher education
  • cio
  • board reporting
  • benchmarking
  • security roadmap
  • roi

Watch next

How this story was recorded

Where does the transcript for "Pima Community College Replaces Ad Hoc Security Planning With Data-Driven Boardroom Strategy" come from?

It's auto-generated by Share One from Isaac Abbs's recording, then lightly cleaned so it stays readable and searchable. Every Cyber Heat Map story published here gets the same treatment. You can publish your own customer stories the same way at share.one.

Recorded and verified with Share One. Published as recorded — unpaid, unscripted, and attributed to a named person.

Collect your own customer stories at share.one