Macomb Community College
RSI Security helped Macomb CC rethink its cyberdefense with efficient, effective governance.
Any college has quite a few departments, who are often not on the same page when it comes to IT or security. RSI Security met with vendors, partners, and internal staff and made sure everyone understood what needed to happen and how to make it happen.
– Mike Zimmerman, CIO / Executive Director of Communications & IT, Macomb Community College
The Challenge
Macomb Community College is the backbone of Macomb County and other surrounding areas in Michigan. It strives to transform lives through practical education, creating opportunities for economic development at the level of individuals and the larger communities they comprise.
To provide its 200+ degrees and certificate programs to 30,000+ students every year, Macomb CC depends on sound IT and cybersecurity governance. Higher education institutions across the US are frequent targets of cybercrime and other IT threats, in part because of the large amounts of sensitive data and IP they harbor. Macomb CC is committed to keeping its students, staff, and other stakeholders safe, and they made a push to strengthen cyberdefenses in 2022.
However, planning and executing high-level cybersecurity governance is never easy at an institution with such a wide variety of departments—each with unique needs, means, and constraints. Hitting landmarks like Center for Internet Security (CIS) Standards 1, 2, and 3 requires oversight that only a Chief Information Security Officer (CISO) can provide.
RSI Security
Cybersecurity Governance
Peter Phaneuf, who heads up RSI Security’s vCISO program, met with Macomb CC CIO and Executive Director of Communications and IT, Mike Zimmerman, to gauge which technologies and solutions would be most apt for Macomb’s needs. Phaneuf scanned networks and devices across campus to understand gaps in the cyberdefense infrastructure, then created a roadmap for implementation and long-term maintenance that Macomb can follow independently.
RSI Security
Framework Implementation
Phaneuf also developed a plan for implementing CIS Critical Controls across Implementation Groups (IG) 1, 2, and 3 to meet CIS Standards 1, 2, and 3. The CIS Controls are best practices that simplify and strengthen cybersecurity across an entire organization. They create “cyber hygiene,” or greater baseline security, and make complying with various legal and regulatory frameworks much more efficient with uniform controls and reporting infrastructure.
RSI Security
Project Management
Jay Tank, another key member of RSI Security’s vCISO team, worked closely with Zimmerman and others at Macomb CC to ensure smooth project flow through constant collaboration. We facilitated clear, consistent communication between all stakeholders—including internal teams, partners, and vendors—and made sure everyone was on the same page before changes were made. And we created a quarterly review process to streamline approval for future changes.
A Smarter Approach to Cybersecurity
After engaging with RSI Security, Macomb Community College came away with more than a list of security improvements. The college established a practical, long-term plan for strengthening its cyberdefense, backed by a proven framework for prioritizing initiatives and communicating security needs across the organization.
With clearer processes for collaboration between IT, leadership, legal, and other stakeholders, Macomb is better equipped to manage risk as its technology environment evolves. The result is a stronger security foundation the college can continue building on for years to come.
THE CLIENT PERSPECTIVE
“Planning and executing effective cyberdefense is never easy. But working with the team at RSI Security made it feel doable, on our own—both now and into the future.”
Mike ZimmermanCIO / Executive Director of Communications & IT, Macomb Community College
Explore Our Case Studies
USA for IOM
Non-ProfitAccepting digital donations independently meant taking on PCI requirements without a dedicated IT team. USA for IOM turned a complex compliance challenge into a secure fundraising foundation, gaining the knowledge, policies, and processes needed to support future growth.
Epic Games
GamingManaging PCI compliance across a global gaming ecosystem required both immediate changes and a plan for what came next. Epic Games strengthened its architecture, streamlined assessments across international teams, and established a sustainable approach to maintaining PCI compliance long term.
Lumistry
HealthcarePreparing for HITRUST meant turning hundreds of requirements into a manageable security program. Lumistry streamlined the process while building a stronger foundation for ongoing compliance and security.
Turn Your Security Challenges Into Success
Every organization’s security and compliance journey looks different. RSI Security brings the expertise, guidance, and practical support needed to navigate complex requirements, reduce risk, and build a stronger security program around your organization’s goals.