Back
Andrew Fitzmaurice
Chief Executive Officer, Nord Anglia Education Limited

Insight - Andrew Fitzmaurice

🎥 Apr 18, 2023 📺 CyberLancaster ⏱ 5m 👁 52 views
Insights from the speakers at the 2022 Lancaster University Cyber Leadership Symposium - in partnership with Templar Executives. Andrew Fitzmaurice
Watch on YouTube

About Andrew Fitzmaurice

Andrew Fitzmaurice, CEO of Nord Anglia Education, has described the organization as operating in 28 countries with over 60,000 students and more than 12,500 staff. In welcome addresses to staff for the 2019–2020 academic year, he highlighted the company's "be ambitious" philosophy and its collaborations with Juilliard, MIT, and UNICEF, and stated that one in three Nord Anglia students go on to attend the world's top 100 universities. He said the organization claims to be "the world's leading premium schools organization" and emphasized the importance of both teaching and support staff in delivering an outstanding education. In a 2018 TEDx talk, Fitzmaurice discussed his own experience as a "third culture kid" who attended seven schools by age 13, and argued that frequent moves taught him not to fear new situations. He cited a World Economic Forum statistic that two-thirds of jobs future graduates will hold do not yet exist, and called on students to collaborate across cultures to address global problems. In a 2017 student interview, he said that a CEO's role involves resource allocation and that schools should be "owned by the community that it serves," rather than standardized like a chain. In a 2013 TEDx talk, he described "high performance learning" as not accepting limits placed on individuals, and used his own poor French exam result as an example of how low expectations can hinder achievement.

Source: AI-verified profile updated from Andrew Fitzmaurice's recent appearances. Browse all interviews →

Transcript (4 segments)
A
Andrew Fitzmaurice0:00
Well, Dr. Dan Prince and I have known each other for quite some years. We did sessions in South Africa, actually, amongst other countries, around cybersecurity and teaching, and we've stayed in touch over quite a long period of time. For me personally, I think this has come around because we have seen a paucity of knowledge in the boards for quite some time, and it's been a real frustration of the National Cyber Security Centre and others. The boards just didn't seem to understand or grasp the importance of cybersecurity, and what was really missing was long-term board education. So a study at Durham University showed that the persistence of learning around cybersecurity is only about six weeks. So if I was to take your really bad LinkedIn page or Facebook page and I told you how to do all the proper security settings, unless that's reinforced, actually within six weeks you'll be redoing all the bad habits.
But with a board, it's far more important. They've got to make decisions around their whole organizations, how much risk they wish to take, and they need to understand it. And so consequently, I was really looking for an idea about how we could do some long-term education for a board, which would be of a level seven standard, educational standard, which would resonate and which people would want to sign up to. So I contacted the National Cyber Security Centre and said, 'Who is the best university at the moment at cybersecurity?' And Lancaster was floated immediately, no hesitation, not Manchester and Oxford, but Lancaster. And I thought, that's handy, I know somebody at Lancaster. So I found Dan, we started to have a conversation, and we talked about various things and about supporting us in Morocco, which is one of our centres of excellence we're looking at, and Panama as well, as it happens. We're starting to move that forward, but we really wanted to do something here in the UK. And he actually was the first one to suggest, 'How about a sort of a masters, but a challenge masters?' And what makes this so different is that while we have the academics there, quite rightly, talking about the academic science of cybersecurity, we'll have my team there as well, the majority of which are working across all critical national infrastructures on live issues and problems, to actually say, 'Well, you know what, when we were helping Shell, we thought about that, that's absolutely right from an academic perspective, but actually the reality, this worked better due to international law,' all examples like that. And what that actually then does is, for the individuals who are receiving this course, it's almost like a two-year mentoring program for them, because they can bring life problems that they have to the safety of an executive cyber MBA, talk to those people who are teaching on it, get their advice, and then take it back to their organization. So the whole view is to make the UK PLC far more cyber resilient and actually ensure that we reconnect boards with their organizations around the cybersecurity agenda.
Well, I think people who have come to this event have really obviously liked the idea. I've been very fortunate that a large number of the collaborators here, those who have spoken, taken part in panels, are also Templar people, and they come from every single imaginable critical national infrastructure. So we've had maritime, we've had banks, we've had the NHS, you know, you name it, and they've come here and they're super excited because they are all of them are people who are names in those particular critical national infrastructures. They're well-known, the well-known cyber leaders, but actually you always get to a stage in your life, especially when you get quite senior, that you feel about, what's the next generation going to do? How can we give some of this back and how to ensure that our knowledge and all those scars that you get from being on a board dealing with a myriad of different types of attacks, insider threat, advanced persistent threat, state action, and you've got all that knowledge, how do we actually transfer that to the next generation coming up so that we can pass it on, so they don't make the same mistakes that we do? So I was responsible for our national strategy for many years, and my first national strategy was all just about computers in 2007. The government was just worried about computers: do we have enough computers and a few computer operators? And of course now the current one is so much more about people, processes, and culture. That journey has taken us 13 years to get to a national strategy which really reflects what's required. So we don't want anybody else to go through that journey. So we want them to be able to say, we can give that history to explain the reason why it's evolved to this point, but then we can teach them the later stuff with that background knowledge that they actually know why they're here, and they can take that knowledge and move forward with confidence that it's been tried and tested in the crucible of other critical national infrastructures and other people struggling with some really difficult decisions.
I think the only thing I'd like to say is the Cyber Executive MBA obviously needs to work, and therefore for those people who view me talking about it, please consider sending one of your C-suite or somebody who's about to move into a position where they are responsible for the cybersecurity agenda on this course, and to contact Lancaster University or Templar to learn about it. We would especially look at CSOs, senior CSOs, because they need a career path to go to the board, and at the moment very few boards around the country in any of the critical national infrastructures have CSOs on the board. So we feel it's really important for their career path because there's an MBA attached, Masters in Business Administration, it will give them a fair chance in selection to actually become board members, but also take with them all that cyber expertise as well.