Skip to main content
NC State Home
Cybersecurity

Get to Know CISO Nicol Lewis in 4 Questions

Nicol Lewis stands in Hunt Library
Nicol Lewis

Now in her second month as NC State’s chief information security officer (CISO), Nicol Lewis is getting acquainted with the university. Here she shares her thoughts about joining the Wolfpack, the importance of relationship building and her top cybersecurity tip.

Four Questions for Lewis

What first drew you to NC State and what have you learned so far?

NC State’s core values were a significant part of what attracted me to this role. The emphasis on community, collaboration and integrity aligns closely with how I think about cybersecurity leadership. This work is not just about technology — it is about people and trust.

The university’s mission and the depth of its external partnerships also stood out. Securing a research institution at this scale requires a different kind of thinking, and that challenge is genuinely energizing. What I have learned in these early weeks is that everyone here is deeply committed, and that commitment creates a strong foundation to build on.

You are the university’s second CISO following Mardecia Bell, who retired from the role after a 40-year career with the Wolfpack. How do you plan to build on that strong foundation?

Mardecia Bell’s tenure speaks for itself. Forty years of dedicated service to this institution is a remarkable contribution, and I have a great deal of respect for what she built. My approach is not to replicate what came before but to understand it deeply first. I am still in the early weeks of listening and learning. What I can say is that strong programs are built on relationships, trust and consistent execution. Those are values I bring with me. My job is to take this program forward in a way that continues to serve NC State’s mission, meets current demands and anticipates where we are headed. 

Where did your interest in security come from and what motivates you in your day-to-day work?

I came up through almost every area of IT over the course of about 30 years, starting at the help desk, moving through networking, business continuity and eventually into security. The one thing I never did was programming, so I like to say I played in just about every corner of this field. That path gave me something I value deeply — the ability to see cybersecurity not as an isolated function but as something that touches every part of how an organization operates. What motivates me now is the same thing that motivated me at the help desk. I am a solution provider at my core. The scale and complexity are just considerably greater now. 

What’s the number one cybersecurity tip you would give to students, faculty and staff?

Pause before you click. It sounds simple, but our biggest threat is not a sophisticated technical attack. It is phishing and social engineering, and those attacks work because they are designed to create urgency and bypass your instincts. That one second of hesitation, asking yourself whether this email or link is legitimate before you act on it, can be the difference between a near miss and a serious incident. Your awareness is one of the most powerful and valued security controls we have.