In this episode of CampusIDNews Chats, Tatiana Tomley, Marketing and Business Development Manager for SECANDA, discusses the company’s expansion into North America and explains how its flexible campus identity platform supports both traditional cards and mobile credentials.
Tomley explains that while SECANDA may be newer to the US and Canadian markets, the company supports hundreds of universities across Europe along with enterprise clients including Philip Morris, Merck, and Bosch.
Rather than forcing institutions into a one-size-fits-all solution, she says SECANDA focuses on adapting its technology to each campus’ unique needs and existing systems.
It’s never going to be a fully mobile solution. It’s a hybrid future.
“We want to work with you to solve your specific campus problems,” Tomley says. “We’re not going to change you to fit us.”
A major focus of the conversation centers on mobile adoption and evolving campus credentials. Tomley explains that SECANDA developed its own mobile wallet instead of relying on third-party providers like Apple or Google, helping institutions avoid additional licensing and transaction fees.
Drawing from nearly a decade of mobile deployment experience, she says campuses are moving toward hybrid environments where physical cards and mobile credentials work together.
“It’s never going to be a fully mobile solution,” she says. “It’s a hybrid future.”
TRANSCRIPT:
Hi, I'm Tatiana Tomley. I'm the marketing and business development manager for SECANDA, Inc.
You may or may not have heard of us. We are a company out of Europe. We were founded in 1978 in Germany. Then we grew into Switzerland. We grew into Spain and Italy. And now we've come to the United States and Canada.
We are incorporated in New York City, and also we’re in Toronto for our Canadian clients to be able to invoice directly in Canadian dollars.
We manage 500 total clients. We don't just do universities though that is our bread and butter. We also have really big clients like Philip Morris, Merck, Bosch, and hospitals as well.
We have 380 universities in Europe, so we may seem like the little guy here. We are a big guy. We have a lot of university experience. We manage 500 total clients. So we don't just do universities though that is our bread and butter. We also have really big clients like Philip Morris, Merck, Bosch, and hospitals as well.
We know how to do really big and we know how to do really small.
We started as one card. So that is something we know really well, and we've grown it by really focusing on the person as the main identity of that credential.
So with this, we connect to anything.
We are open to integrate to your existing campus partners and whoever your future partners are, whatever new technologies come in.
We're really great at incremental adoption. So you can start with your grad students. You can start with just your freshman class with us. You can start with just your teachers, whatever works for you.
We’re the most customizable and flexible solution on the market. We want to work with you to solve your specific campus problems. We know there's no one size fits all solution, and we're not going to change you to fit us. We want to adapt our technology to your school.
We have our own wallet and we don't have a middleman – a third party partner like Google or Apple – which would charge you additional licensing fees and transaction fees.
Another thing that sets us apart is that we have our own wallet. So our app is how we make you mobile. We are great at classic one card. We know how to do that. We connect with NFC, with Bluetooth, with this great QR code we have.
And our wallet is our own wallet. We don't have a middleman, a third party partner like Google or Apple, which would charge you some additional licensing fees and additional transaction fees. None of that with SECANDA.
We've developed this really great product in Europe. We had to cut out all the fat, no nickel and diming over there. We have this great, very secure GDPR compliant products. And that's higher than what we have for standards over here in the US. So, you know that we do security well.
About 80% of our schools have at least some mobile element. For them we're seeing 55% of the user population use the mobile option.
With our wallet, we do $240 million dollars in transactions already, and our clients love us. We have a 99% high retention rate. For mobile adoption stats, we first went mobile in 2015, and our schools have been mobile for a decade in some cases.
We've seen the future of mobile adoption, and we're seeing that of those mobile schools, about a little more than 80% of our schools have at least some mobile element. For them we're seeing 55% of student user population, including teachers, too, use this mobile.
It's never going to be a fully mobile solution. It's a hybrid future.
We're seeing a hybrid campus that ties together a really great one card, working with your legacy one card, to elevate it to a new, modern one card that we offer. And this mobile that enhances what you already have.
In this episode of CampusIDNews Chats, Anthony Condo, Director of Campus Services at Swarthmore College, discusses NACCU’s SAGs (Standards and Guidelines) program – how it helps institutions and administrators identify campus card best practices to evaluate and improve their card office operations through a structured industry assessment.
The SAGs program is a 10-month online course made up of 12 modules covering topics such as marketing, finance, leadership, legal considerations, and technology. Participants meet roughly every three weeks and complete assignments designed to assess how their institution aligns with current industry standards.
Rather than serving as a “how-to” course, the program is intended to help institutions embark on a deeper exploration of their existing operations.
Rather than serving as a “how-to” course, Condo explains that the program is intended to help institutions embark on a deeper exploration of their existing operations.
“It’s meant for you to evaluate your program,” he says. “You’re really taking an internal look at what you’re doing – what you do well and what you have to work on.”
A major part of the program is the executive summary participants complete at the end of the course. The summary highlights operational strengths, identifies areas for improvement, and can help institutions justify requests for additional funding, staffing, or resources.
The institution benefits most because you're really taking an internal look at what you're doing, what you do well, and what you have to work on.
Participants are required to provide documentation supporting their assessments, including marketing materials, policies, and technology plans.
Condo recommends the program for professionals who already have some industry experience and enough time to fully engage with the coursework. While SAGs does not provide a formal certification, he says the knowledge gained through the process can provide long-term value for both individuals and institutions.
TRANSCRIPT
The SAGs program was developed by NACCU faculty and staff as a means to evaluate card office programs. SAGs stand for standards and guidelines.
It's an online course. It lasts roughly ten months. So normally it starts in late May and it'll run through February.
There are modules that you work through, basically looking at all aspects of a card office operation.
You're going to you're going to have a unit on marketing a unit of finance and technology, and legal. Anything that has to do with the card office you're going to have a module on that. It meets, roughly every three weeks. There's a down time, a month of August, normally just to allow schools to get to, to let their students come back and everything. Then it'll start right back up again.
The ultimate goal is you're going to write an executive summary, so you know how you've done and how you've rated your program. Maybe pull out the outliers, the things you're doing really well, maybe things that you need to work on because you want to have something to present to your leadership to show them, hey, we do really well in this area, but these are some areas that we need to focus on based on what the industry standards are.
Hopefully if you need to get resources or funding, you can use this as backup to get whatever it is that you need.
So again, there's modules.
You're looking at marketing and it'll ask you things like where can you find information about your meal plans or where could you find information about how to upload your photo? Or give your headshot or your office hours and where are your offices? Finance, maybe it'll ask you to explain how funds are allocated for your program. Do you have enough funding
There's a module on leadership that'll look at your office structure and what your reporting structure is and who's in charge of your office. Who is the leader of your card office program and how long have they been in that role?
You know, legal that's a huge module, because there's a lot of aspects to a card office program with regard to legal issues. Technology is another one, it'll ask you what kind of card readers you're using, and what kind of servers and how you back up your servers etc.
We’ve gone through eight SAG cohorts. We're about to start the ninth cohort.
Then one thing that we've been talking about the past few years is we've had all these people go through the program and put in all this work, and what can we do next with them?
So that's probably something that's on the horizon, starting to reel everybody back in and say, tell us about how your executive summary went and what were some of the challenges that you noted that you had to address and where you're able to address them?
Were you able to get the funding that you needed or the staff that you needed? I think we're going to be seeing more of that coming down the pike.
I think who benefits most is the institution, because you're really taking an internal look at what you're doing and what you do well and what you have to work on. We always like to tell the students going through SAGs, it's not a poor reflection on you.
If there's a certain area where you didn't meet the standards, you're not going to fail. It's just good that you were able to recognize that and now you have some points that, you have to work with.
I think you can certainly justify it to your leadership because the ultimate thing is you're going to really take an introspective look at your program with the goal to make sure that you're meeting the industry standard.
Some advice I would say is you want to have been in the industry, for a couple of years. Or at least have attended the Industry Essentials Institute, so you have some knowledge. You probably don't want to walk into this being brand new in your role. You want to have some card office experience.
You want to make sure that you're going to have some time to do this because there is homework, so every unit you have to do some homework, you have to provide documentation for everything you do. The homework entails rating yourself on the different standards within each module. But you can't just say yes, I meet the standards, you have to prove it. Show us that you meet the standard, show us the documentation.
Taking that into account, make sure you have enough time to get some homework done. If you're if you're going to be working on a larger project, you know, maybe you're going to launch mobile or something, maybe you want to wait till after that.
You have enough time to put towards this program so you can get the most out.
I think you can certainly justify it to your leadership because the ultimate thing is you're going to write an executive summary, and it's going to really take an introspective look at your program with the goal to make sure that you're meeting the industry standard.
I think it's money well spent. Yeah. I wouldn't call it a certification. You get a certificate saying that you completed the standards. You certainly get some bragging rights. I think what you learn going through it and what you discover about your card office – it's not all about finding things that are that are wrong.
You might find things that you do really, really well and you can build on that too. I think the knowledge that you gain going through the program will certainly benefit you.
Customers ordering from a multi-concept dining location in Green Brook, NJ are having their food delivered through the skies. It’s a pilot project between food delivery company Grubhub, its parent company Wonder, and drone developer Dexa.
This spring, customers within a 2.5-mile delivery radius of the Wonder location began opting for drone delivery in the Grubhub app – with food delivered faster and at no additional cost beyond standard delivery fees. The three-month program marks the first time Grubhub and Wonder have offered drone delivery to customers.
Wonder operates a multi-restaurant model, where diners choose from a dozen or more concepts prepared to order from a single location. According to Grubhub, “the blend of culinary variety, quality, and operational efficiency creates a seamless experience that pairs naturally with the speed and precision of drone delivery.”
Campus dining facilities are similar to Wonder locations because food preparation and delivery can initiate from a single point, thus streamlining drone delivery.
The drones are Dexa’s DE-2020, a fully automated delivery aircraft designed to transport goods directly to customers. Dexa is one of four U.S. companies that both manufactures and operates Federal Aviation Administration–certified delivery drones.
According to Dexa, it is transforming last-mile logistics through autonomous commercial aviation to help restaurants, retailers, and enterprise partners deliver products faster and more efficiently via airborne delivery. By combining advanced aircraft design, FAA-certified operations, and deep operational expertise, Dexa is making autonomous drone delivery a practical, everyday reality.
Before each flight, Dexa’s flight crews verify that orders are packaged to meet food‑safety standards.
Using “advanced autonomy and secure communications technology … deliveries follow approved flight paths designed to prioritize safety and minimize noise and disruption to surrounding communities,” says Grubhub.
We are fully autonomous, but we always have a pilot at the controls ... monitoring and able to steer the aircraft.
When the drone reaches the delivery point, it places the order on the ground via a tether system.
Company officials say the drone goes about 40 mph but add safety comes first, says a CBSNews report. "We are fully autonomous, but we always have a pilot at the controls, always monitoring the aircraft, and always able to steer the aircraft," says Joe Houghton, Dexa COO.
In the same way that it does with traditional or robot delivery, the Grubhub platform tracks orders and communicates with customers. Diners and restaurant staff receive real‑time GPS tracking, estimated arrival notifications, and order confirmations.
“By connecting Grubhub’s marketplace expertise, Wonder’s innovative mealtime platform, and Dexa’s expansive drone technology, we’re proud to introduce a faster and more efficient [food delivery experience],” says Abhishek “PJ” Poykayil, SVP of Customer Delivery Operations at Wonder and Grubhub.
Grubhub drone delivery coming to campus?Grubhub says that following the three-month test program, it will explore expanding drone delivery.
Though there has been no specific reference to campus expansion, the higher ed model fits well with the New Jersey pilot.
In both cases, food preparation and delivery can initiate from a single point – Wonder’s multi-concept restaurant or a campus multi-concept dining facility. In normal food delivery scenario, however, orders are picked up from locations spread throughout a city or region. In this scenario, drones would have to be dispatched to the field for pickup, then delivery, then ultimately returned to the operations center. This adds significant complexity and cost.
The tight geographic delivery area also makes a campus ideal for drone delivery. The current pilot is limited to a 2.5-mile radius. Limiting the flight distance keeps aerial delivery costs down, potentially making the business model competitive with other delivery modes. The compact area of a traditional campus fits this profile perfectly.
Keep your eyes to the skies.
The University of Arizona (UA) pioneered a different approach to managing credentials as well as the integrations with downstream services such as access, housing, dining, events, and parking. Instead of relying on systems primarily controlled by a single vendor, they sought a more agnostic approach that put the university at the center.
The success of the project led to the formation of a private company, intent on bringing the solution to other campuses.
The project leaders – both from UA’s auxiliary IT team – Senior Director of IT Joe Harting and IT Project Manager Chris Augustine – traded in their university hats to found FutureState. Harting is the new company’s CEO and Augustine serves as Head of Development.
The company announced that two new hires, each well-known from their successful careers on the vendor side of the industry.
Tim Nyblom, who most recently served as HID Global’s Director of Higher Ed End User Development, is FutureState’s new Head of Business Development.
“Tim is one of the most knowledgeable and genuinely respected names in credentialing and physical access security,” says Harting. “He doesn't just know the industry, he knows the people in it, and they trust him.”
Outside vendors controlled the integration layer and this handcuffed the institution. At Arizona, we are the first university to not use a one card provider for our mobile IDs.
Jeff Staples is the company’s new Head of Market Development. Staples has been instrumental in numerous pioneering campus card initiatives, including Transact’s (then Blackboard) development and launch of the industry’s first mobile credential offering.
“Jeff understands this industry inside and out – the platforms, the politics, and the possibilities,” says Harting. “His decades of experience bring the structure, focus, and executive-level frameworks that will help us scale without losing what makes FutureState different.”
The team at Arizona created a software layer that sits between its credential issuance systems and the various services that consume the physical card or mobile credential. What is unique is that typically this function falls to outside vendors, which Harting says leaves institutions beholden and locked in.
He’d experienced it throughout his 20-plus years in university IT leadership at both Northern Arizona University and UA. One card vendors and access control providers controlled the integration layer, he says, and this handcuffed the institution.
“We wanted to break this cycle and what we did gave us flexibility in our mobile credential rollout as well,” he adds. “We are the first university to not use a one card provider for our mobile IDs.”
At UA, when a mobile ID is issued the credential manager passes the information to a software layer called CardSync. When a physical card is issued, the same process is triggered.
In addition to this tie-in for credentials, CardSync serves as the connection point for cross-campus service integrations. The various departments on campus continue to manage their own systems – adding and removing users and privileges – but their data is now linked in real time through CardSync.
When you change a vendor, the old integration is replaced – via an API – with the new one, and no other systems are impacted.
“Because every system connects through CardSync, the university avoids vendor lock-in,” Harting explains.
When a department changes a vendor, the old integration is removed and replaced – via an API – with the new one. No other systems are impacted, and the process can take just days.
According to Harting, this ability to replace vendors even extends to the credential manager and transaction system provider. These too are simply connections to CardSync just like housing, dining, or the array of other services.
The second piece of the solution, CardPulse, provides dashboards and views into the CardSync data. CardPulse is a single point for admins to manage credentials across the enterprise. Users can view credentials to troubleshoot issues, populate credentials into newly onboarded systems, make exceptions to rules, and generate metrics.
While the FutureState solution is ideal for mobile credential implementations, institutions don't need to be undergoing an immediate migration for this to work for them.
Institutions can start with physical card production, and when the time is right onboarding the mobile credential manager of choice is simply one more integration.
“CardSync and CardPulse deliver value today,” says Harting. “Institutions can start with physical card production and begin pushing credentials downstream in real time, monitor the health of their systems, apply lifecycle management rules, and troubleshoot or fix issues for individual cardholders.”
Once this foundation is in place, when the time is right onboarding the mobile credential manager of choice is simply one more integration into CardSync.
According to the company, the success of the UA project has led to significant attention and interest in FutureState’s offerings, with strong interest and strong pipeline growth, including high profile institutions from across the country.
“Over the past several months, interest in FutureState has grown faster than even we had anticipated,” says Harting. “As we move to meet that demand, I'm thrilled that we will soon announce successful early funding rounds, additional new hires, and outreach to campus colleagues in a major way.”
CampusIDNews is celebrating its 25th year supporting the campus ID and auxiliary service industry. It would not be possible without all the campus and vendor friends we've come to know over the years, so come out and join us for an evening of fun and camaraderie. The venue is an indoor pickleball facility with great viewing areas, a bar, and a private room for hanging out. If you play or want to learn, bring athletic shoes and clothes (we will have paddles, balls, and people to help you learn). If you prefer to watch and socialize, come on out for some food and drink.
Tues., April 21 | 6:30-9:30 pm
Pickle Lodge Lunken Landing (indoor facility)*
669 Wilmer Avenue | Cincinnati, Ohio 45226
*The location is 8 miles from the convention center. There are multiple Pickle Lodge locations so be sure to specify Lunken Landing.
If you can attend, please RSVP to [email protected] with your name and the names of any guests. The more the merrier.
Share your story with colleagues and peer institutions by participating in a 3-5 minute video interview during the NACCU Annual Conference. The CampusIDNews team will be conducting interviews with campus representatives in our exhibit hall booth (#116). Brag about your program, share something interesting your team has done, describe a challenge you are facing, or think of another subject that would interest card office and auxiliary service professionals. And while you’re at it, grab your $50 Visa gift card.
Vendors – you are invited to join in as well. We will be conducting these interviews at your booth. It’s your opportunity to share thought leadership or show off a new product.
All interviews will take place during exhibit hall hours:
Reserve your 15-minute slot at the links below. If you know your topic, add it now. If not, grab a slot and we can coordinate topics before the event.
https://calendar.app.google/zAhRkcA9mp5Xjc8t6
https://calendar.app.google/4pru7puHQipkzaFC8
The Security Industry Association (SIA) released its Corporate Credential Design Guide, a new resource produced by their Credential Design Working Group. It specifies recommended practices for the design and implementation of credentials and badges by card issuers and security teams.
Though the document is geared toward corporate issuers, it is also highly relevant and beneficial for higher education issuers.
It covers key topics in physical credentials, identity verification, badge production, data security, counterfeiting protection, technology options, and more.
Modern attackers exploit human behavior, oversharing on social media, and advances in image replication to reproduce badges with alarming accuracy.
Identity credentials are key to modern enterprise security and operations, but the credential ecosystem is fragmented and increasingly vulnerable to new forms of attack. The guidelines shared in the report are intended to establish a vendor-neutral framework for designing secure, interoperable credentials.
In the section titled Security Awareness in Badge Design, it explains that design should not be viewed aesthetics, but rather as a core security effort to reduce exposure to social engineering, unauthorized access and credential misuse.
“Modern attackers increasingly exploit human behavior, oversharing on social media, and advances in image replication to reproduce corporate badges with alarming accuracy,” says the document. “As a result, the design of corporate credentials must include intentional and measurable security protections that help prevent forgery, misuse and unauthorized entry.”
Until now, no dedicated guidelines have existed to help organizations design IDs with both security and usability in mind.
The 72-page document is comprehensive but easy to navigate and digest. Users can skip between sections to focus on specific topics they need. As a whole, it defines a robust set of best practices covering the entire credential life cycle, including:
“Until now, no dedicated guidelines have existed to help organizations design corporate IDs with both security and usability in mind,” says Teresa Wu, vice president, head of Smart Credentials and Smart Integrate at IDEMIA Public Security. “The Corporate Credential Design Guide reflects SIA’s mission to lead with standards that shape the future of identity in the enterprise.”
The Corporate Credential Design Guide is available for free downloaded on the SIA website.
The bill that would enable students at virtually all Virginia universities to donate their unused meal plan credits fell just short of passing this year. State lawmakers voted to continue debating the proposal – supported by the nonprofit Swipe Out Hunger organization – in the 2027 session.
The bill was introduced by Senate Democrat Danica Roem and would have allowed students to voluntarily donate their unused meal swipes. The meals could then be distributed to other students for redemption at campus dining halls or on-campus food pantries.
The proposed legislation hoped to build on Roem’s 2025 legislative success that established the Hunger-Free Campus Food Pantry Grant Program. It provides funding to support campus food pantries at public and qualifying private higher education institutions in the state.
The new bill would have required universities to allow students to donate meal swipes in order to receive funding from the state's Food Pantry Grant Program
In both 2025 and 2026, the grant program distributed $500,000. In 2026, pantries at 48 different institutions received between $6,000 and $15,000 awards.
Had the new bill passed, it would have required universities to allow students to donate their swipes in order to remain in the Food Pantry Grant Program and receive funding.
The efforts were shaped and supported in part by the ongoing work of the nonprofit organization Swipe Out Hunger. Largely via student engagement, Swipe Out Hunger works with institutions and legislators to address student food insecurity. To date, they have facilitated the provision of more than 20 million meals at 900 campuses throughout the country.
Two thirds of Virginia’s public colleges report that 25% to 50% of their students experience food insecurity, but just 40% have any funding for resources and services.
On the advocacy front, they have helped a dozen states pass Hunger Free Campus legislation. These include:
According to the organization, two thirds of Virginia’s public colleges report that 25% to 50% of their students experience food insecurity. Still, just 40% have any funding allocated to student food security resources and services.
Despite passing unanimously in the Virginia Senate, the bill stalled in the House Appropriations Committee.
Roem attributes the setback primarily to political dynamics between the two legislative chambers rather than concerns over cost.
Students by and large are 18 years and older, they’re adults. Choosing what to do with their meal plans, that’s their choice.
In an article in the Commonwealth Times, she says some legislators took issue with the idea of students donating swipes paid for by their parents.
She dismisses that argument, however, suggesting it assumes all students come from traditional middle-and-upper class families. It ignores the fact that many students put themselves through college with alternative funding sources.
“Students by and large are 18 years and older, they’re adults,” she says. “Choosing what to do with their meal plans, that’s their choice – and if their parent happens to pay for the meal plan, then that’s a conversation they can have with their parent.”
Senator Roem remains committed to continue the effort in 2027 working to get both chambers on board.
The University of Texas at Austin is preparing to launch mobile student IDs beginning in the 2027–28 academic year. The initiative, driven by strong student demand and backed by university leadership, will allow students, faculty, and staff to access campus services using credentials stored in their mobile wallets.
Spearheaded by Student Government leadership, the effort marks the culmination of years of student advocacy. They first began pushing for mobile IDs back in 2018, but recent Student Government legislation formally set the project in motion.
Student Government says the project represents a long-standing student vision now becoming reality through collaboration with university administrators
When the program launches in fall 2027, digital IDs will be delivered through the MyUT platform and integrated into Apple Wallet and Android Wallet. Users will be able to tap their phones to enter buildings, access residence halls, check out library materials, attend events, and make purchases at campus dining and retail locations. Physical cards will remain available at least through a transition period.
On campus, surveys conducted by Student Government show overwhelming support for replacing physical IDs with mobile alternatives – particularly among residential students who rely on their credentials multiple times per day.
The road to digital ID
For student leaders, the initiative is about aligning campus infrastructure with modern expectations. In a statement, the Student Government president and vice president say that the project represents a long-standing student vision now becoming reality through collaboration with university administrators.
At its core, the Digital ID initiative is designed to create a more connected and frictionless campus experience. University officials describe two guiding pillars: improving campus connection and building a technology foundation that unlocks long-term value.
From a user perspective, the benefits are immediate. Mobile credentials reduce the everyday friction of forgotten or misplaced cards and eliminate lost card replacement fees. The system is also expected to improve residential life by minimizing dorm lockouts and strengthening access control.
Beyond convenience, the university says the initiative sets a foundation for broader digital transformation. By consolidating identity, access, and payments into a single mobile experience, UT Austin aims to create a more seamless user experience and technology ecosystem.
They also point to potential cost savings, with reduced spending on card production and fewer replacement fees for students.
The rollout will follow a phased approach. The initiative is currently in a feedback and discovery stage, with design and development scheduled for the 2026-27 academic year. A full student launch is planned for fall 2027, followed by expansion to faculty and staff in spring 2028.
We all know campus card programs generate a constant stream of data, and each interaction creates a digital record. Protecting this data and the individuals involved –our students, faculty, and staff – is a crucial responsibility.
How institutions can best respond to this challenge was the focus of a recent NACCU webinar and article featuring by Erin Williams, Manager of Access & Privacy at the University of Calgary. Her message was clear: protecting data requires more than security controls – it demands strong information governance.
Information governance (IG) is the overarching framework that connects people, processes, and technology across the entire lifecycle of data. It goes beyond security or compliance alone, encompassing how information is created, stored, used, shared, retained, and ultimately destroyed.
“It is how we manage information and data in a way that complies with required regulations and best practices,” says Williams. “Think of it as like the rules of the road or the guardrails.”
Technology evolves faster than legislation, and campuses that lead with strong governance will be better positioned to meet both current and future requirements.
One part of that framework, data governance, focuses on structure and standards that protect individual privacy.
“Data governance is a subset of information governance that focuses on specifics like data quality and access,” she explains. “This role is often housed often in IT because they're usually the ones that manage the infrastructure, architecture, and data warehouses.”
Another part, security, provides the technical and administrative safeguards. While these disciplines are often discussed separately, Williams suggests that they must function together to build trust and reduce risk.
A key takeaway from the webinar was the need for a proactive mindset. Rather than waiting for regulations to dictate action, institutions should adopt best practices early. Technology evolves faster than legislation, and campuses that lead with strong governance will be better positioned to meet both current and future requirements.
Campus card environments are particularly challenging to govern due to their complexity. Both their reach and data are often decentralized, involving multiple departments with varying practices. At the same time, they are highly integrated, relying on third-party vendors and APIs that can introduce vulnerabilities.
Card offices frequently store data for extended periods “just in case,” which expands the potential impact of a breach.
Long data retention practices further increase risk. Card offices frequently store data for extended periods “just in case,” which expands the potential impact of a breach. The combination of decentralized ownership, deep integrations, and large data stores makes campus card systems attractive targets.
The article outlines a pragmatic approach that campus card programs can implement without significant new resources. It begins with creating a simple system and data map that identifies key systems, the types of data they hold, and access controls. This foundational step enables better decision-making across the organization.
Many breaches originate from third-party vendors, so it essential to have clear requirements around data handling and security.
Next, institutions should strengthen procurement and integration processes. Many data incidents originate from third-party vendors, making it essential to establish clear requirements around data handling, security, and breach response.
Reducing unnecessary data retention is another high-impact step. Routine cleanup of exported reports and files, along with defined retention schedules, can significantly limit exposure.
Preparation is equally important. Conducting regular tabletop exercises helps teams understand how to respond to incidents before they occur. These simulations clarify roles, communication pathways, and technical responses in a controlled setting.
To learn more about information governance for your card program and explore a detailed 90-day step-by-step plan to improve information governance, check out the article and webinar.

