Cyber Business Podcast

Why UNICEF USA Is One of the Hardest Security Jobs with Andrew Nuxoll - Ep 232

Written by Matthew Connor | Aug 31, 2026, 10:56:21 AM

Andrew Nuxoll is the Managing Director of IT Operations and Cybersecurity at UNICEF USA, the United States fundraising arm of UNICEF Global, a children's charity founded after World War 2 that supports education, clean water, and opportunity for children throughout the world. In his role, Andrew oversees both technology operations and cybersecurity for an organization that sits at the convergence of financial, political, and ideological threat vectors simultaneously, making it one of the more uniquely complex security environments featured on this podcast. He brings a career that moved from building and repairing custom computers to help desk to network engineering to cybersecurity leadership, shaped throughout by a conviction that the human element is more important than any tool. 

 



Here’s a glimpse of what you’ll learn: 

 

  • Why UNICEF USA faces a uniquely complex threat profile sitting at the convergence of financial, political, and ideological motivations most organizations never contend with simultaneously
  • Why Andrew believes AI-powered defense is no longer optional and why waiting while attackers are already using AI is a position he cannot understand
  • Why user awareness is the foundational starting point for any security posture and why layered security without it is a structure missing its most important floor
  • Why insider threat is almost always accidental rather than nefarious and why the entire industry misunderstands this at significant cost
  • Why analysis paralysis is the enemy of a better security posture and why incremental improvement always beats waiting for the perfect solution
  • Why building leaders around you and surrounding yourself with people who think differently are the two most important career moves any technology leader can make
  • Why cultural fit is not about hiring people like you and what it actually should mean when you are building a team



In this episode…

Andrew opens by framing what makes UNICEF USA a fundamentally different security environment than most organizations. A financial institution is targeted because of money. A government agency is targeted for political reasons. UNICEF USA sits at all of those intersections at once, collecting donations at the scale of a bank while also being a high-profile global brand that draws ideological opposition from threat actors who disagree with the mission it supports. Andrew is direct that this is not a theoretical concern. The attempts are real, they are constant, and the AI-powered threat environment has changed the calculus in a way that makes the old answer of strong firewalls and current patches insufficient. His position on AI in security is unambiguous: you cannot wait while attackers are already using it. The organizations that are holding back are not being cautious. They are falling behind in a way that is increasingly difficult to recover from, and the cost of that gap grows every day the decision is deferred.

The security philosophy Andrew articulates in this episode is built on two principles that reinforce each other throughout the conversation. The first is that user awareness is the most important and most cost-effective starting point for any security program. Not because tools are unimportant but because the end user is the real choke point in every successful attack Andrew has seen. The MGM breach is the example he reaches for: an organization with significant security investment, defeated not by a technical exploit but by social engineering that put a new admin account inside the environment doing things no legitimate admin would do on day one. His second principle is layered security, which is the architecture that catches what user awareness misses. The two are not in competition. They are the foundation and the structure built on top of it, and missing either one creates a gap that no amount of spending on the other can fully close. Andrew's additional reframe of insider threat is one of the most practically useful moments in this episode: most insider threat is accidental. The employee who clicks the wrong link, picks up a thumb drive in the parking lot, or falls for a phishing email is not a bad actor. They are a victim of the same social engineering that defeats organizations far more sophisticated than they are, and treating them as a threat to be managed rather than a person to be educated is how organizations end up with the worst of both worlds.

The career and leadership section of this episode lands with the same weight as the security conversation. Andrew spent years interviewing and hiring hundreds of people and describes a shift in how he thinks about cultural fit that is worth sitting with. Early in his career, he cared whether a candidate was a good fit for his personality. He does not anymore. What he looks for now is hard work, kindness, the ability to collaborate professionally, and a willingness to think differently from the people already in the room. The organization he watched implode years later did so because everyone in it thought exactly the same way. No new ideas, no fresh perspectives, no productive friction to generate better decisions. His two principles for building a career and a team are equally direct: build leaders around you and give people opportunities without fear that developing them diminishes you, and surround yourself with people who do not think like you because those are the people who will show you parts of a problem you could not see from your own vantage point.

 

 

Resources mentioned in this episode

 

Matthew Connor on LinkedIn
CyberLynx Website
Andrew Nuxoll on LinkedIn
UNICEF USA Website
Darktrace Website
Abnormal AI Website

 

Sponsor for this episode...

 

This episode is brought to you by CyberLynx.

CyberLynx is a Bethesda managed IT and cybersecurity company. Local techs you know, not a call center. Month-to-month. 24/7 intrusion detection.

We help growing companies with managed IT, help desk, backup and recovery, and a fractional CIO.

Talk to us at https://cyberlynx.com/contact, info@cyberlynx.com, or 301-798-9170.

 

Check out previous episodes:


Vibe Coding, Micro Businesses, and Fighting Fire with Fire with Alexander Tushinsky - Ep 231

AI Agents and the Truth Engine for Human Health with Matthew Matturro - Ep 230

CMMC, M&A Integration, and AI Upstream Defense with Bobby Barts - Ep 228 

 

Transcript: 

 

Andrew Nuxoll

Managing Director of IT Operations and Cybersecurity

UNICEF USA

Matthew Connor: Matthew Connor here, host of the Cyber Business Podcast. Today we're joined by Andrew Nuxoll, Managing Director of IT Operations and Cybersecurity at UNICEF USA. Andrew, welcome to the show.

Andrew Nuxoll: Thank you, Matthew. It's great to be here.

Matthew Connor: It's great to have you. Before we get too far in, a quick word from our sponsors. Hackers are getting smarter — is your security keeping up? Cyberlynx sells industry-powered, AI-powered cybersecurity solutions that detect threats in real time, so you know about an attack before the damage is done, not after. Learn more at cyberlynx.com. And now back to our show.

Andrew, for those who aren't familiar, can you tell us about UNICEF USA and your role there?

Andrew Nuxoll: Sure. UNICEF USA is the United States national committee for UNICEF — the United Nations Children's Fund. Our mission is to support UNICEF's global work on behalf of children in over 190 countries and territories. We do that primarily through fundraising, advocacy, and public engagement here in the United States. A lot of what we do is make it possible for UNICEF to do what it does globally — whether that's delivering vaccines, providing clean water, supporting children in conflict zones, or responding to humanitarian crises. It's a meaningful mission and one I'm proud to contribute to.

As Managing Director of IT Operations and Cybersecurity, I oversee our technology infrastructure, our security posture, and increasingly our AI governance efforts. We're a nonprofit, so we operate with real resource constraints — but those constraints don't reduce the sophistication of the threats we face or the obligations we have to protect our donors, our data, and the integrity of the work we do.

Matthew Connor: And I think that point about resource constraints not reducing the threat level is so important. Nonprofits, schools, healthcare organizations — people assume they're not targets because they're not profit-generating. But from a threat actor's perspective, you have donor data, payment data, personal information, and in UNICEF's case, the reputational and operational impact of an attack on a children's organization would be significant. The bad guys don't discriminate by mission. How have you navigated building a security program in a resource-constrained environment?

Andrew Nuxoll: It requires a very different approach than what you'd take in a well-funded commercial environment. You can't buy your way to security with a nonprofit budget, so you have to be strategic about where you invest and relentless about getting the most out of what you have.

The first principle I operate from is prioritization by risk. Not every risk deserves equal attention or equal investment. I spend a lot of time thinking about what would actually hurt us most — what are the scenarios where a successful attack causes the greatest harm to our mission, our donors, or the people UNICEF serves? Those scenarios drive our investment decisions. Everything else gets managed with lower-cost controls or accepted as residual risk.

The second is leveraging the ecosystem. There are significant benefits available to nonprofits through programs like Microsoft for Nonprofits, Google for Nonprofits, and others — deeply discounted or free access to enterprise tools that would otherwise be cost-prohibitive. We've built much of our security stack on top of those programs. The Microsoft security stack in particular has matured significantly — Defender for Endpoint, Defender for Identity, Microsoft Sentinel — these are enterprise-grade tools that we access at nonprofit pricing. That changes the math dramatically.

The third is building relationships in the security community. The CISO and security leader community is genuinely collaborative in ways that other professional communities aren't. People share threat intelligence, share lessons learned, share what worked and what didn't. For a nonprofit security team, that peer network is a force multiplier that doesn't cost anything except time and engagement.

Matthew Connor: That Microsoft nonprofit licensing point is one I don't think gets enough attention. The tools available through those programs are genuinely enterprise-grade, and organizations that aren't taking full advantage are leaving real capability on the table. And the peer network point — I've heard this from security leaders across the board, and it's one of the things that distinguishes the security community from a lot of other fields. There's a shared interest in making the whole ecosystem more secure that creates a generosity you don't always see in competitive industries. Let me ask about the specific threat landscape for UNICEF USA — what are you seeing?

Andrew Nuxoll: We see the full range. Phishing is persistent and it's getting more sophisticated — AI-generated phishing attempts that are contextually aware and harder to catch with traditional filters. Business email compromise targeting our finance team, which is a perennial concern for any organization that processes significant financial transactions. We've also seen increased targeting of nonprofit organizations specifically, in some cases from actors who are motivated not by financial gain but by the desire to disrupt or discredit organizations that are doing humanitarian work globally.

The donor data dimension is significant. Our donors trust us with their personal and financial information, and they make that trust decision based in part on the belief that we're responsible stewards. A breach of donor data isn't just a compliance problem — it directly undermines the trust relationship that our fundraising depends on. That framing — donor trust is an operational necessity, not a nice-to-have — is how I communicate the business case for security investment to leadership.

And then there's the reputational dimension. UNICEF is a globally recognized brand. An attack that compromises our systems, or that uses our brand for fraud or disinformation, creates harm that extends well beyond our organization. We take that responsibility seriously.

Matthew Connor: Donor trust as an operational necessity — that's exactly the right framing for a nonprofit. It connects security directly to the mission in a way that a technical risk argument doesn't. And the reputational brand risk angle is real — you can imagine how bad actors might try to exploit a trusted name like UNICEF for social engineering or fraud. Has that been something you've actively had to address?

Andrew Nuxoll: Brand impersonation is a real and ongoing issue. We see attempts to impersonate UNICEF in phishing campaigns — emails that look like they're from UNICEF soliciting donations that are actually fraudulent. Most of that isn't targeting our systems directly; it's exploiting public trust in the UNICEF name to defraud well-meaning donors who have no relationship with us. We work on this collaboratively with UNICEF's global organization, reporting fraudulent domains and working with email providers to identify and shut down impersonation campaigns.

It's a difficult problem because we don't control the internet, and bad actors can stand up convincing impersonation infrastructure quickly. What we can do is make our legitimate communications clearly identifiable, educate our donor community about what legitimate UNICEF USA communications look like, and be responsive when impersonation is reported. DMARC, DKIM, and SPF configuration — the email authentication standards — are fundamental here. If we have those properly configured, we reduce the risk that our actual domain gets spoofed, which is a different and more directly harmful variant of the impersonation problem.

Matthew Connor: Email authentication is one of those foundational hygiene items that's been around for a long time and still isn't universally implemented. And it's not complex — it's just discipline. Getting DMARC to enforcement mode in particular is something a lot of organizations stop short of because they're worried about breaking legitimate email flows. But if you've done the work to identify all your legitimate sending sources, enforcement mode is where you actually get the protection. It's the difference between having the lock on the door and actually using it.

Andrew Nuxoll: Exactly right. And the AI layer is making email-based attacks more dangerous in ways that those authentication controls don't fully address. DMARC tells you the email came from an authenticated source — it doesn't tell you whether the content is malicious. A sophisticated phishing email that comes from a legitimate-looking domain that was registered specifically for the attack, properly configured with all the authentication headers — it passes every technical check and still represents a real threat. That's where behavioral machine learning comes in, looking at content, context, and patterns rather than just technical provenance.

Matthew Connor: And that's exactly where products like Darktrace and Abnormal have made real advances — the machine learning layer that understands not just the technical header but the meaning and context of what's being communicated, and what the behavioral history of this sender-recipient pair looks like. It's qualitatively different from rule-based filtering, and it catches things that rules never could. That's the right AI for email security — not an LLM that introduces prompt injection vulnerabilities, but machine learning that builds genuine contextual understanding over time. Are you using machine learning-based email security today?

Andrew Nuxoll: We are. We use Microsoft Defender for Office 365, which has machine learning capabilities baked in, and we've supplemented that with additional controls in specific areas. The quality of what's being caught has improved meaningfully — the false positive rate has come down, which matters because false positives have a real cost in user friction and IT time. And the things that are getting through have changed character — they're the genuinely sophisticated attacks rather than the commodity phishing that the tools are now reliably catching.

What I watch carefully is the arms race dynamic. As defensive AI improves, offensive AI adapts. The phishing emails that used to be detectable because of odd phrasing or grammatical errors — AI has fixed that problem for the attackers. The tells that machine learning learned to recognize become less reliable as attackers learn to avoid them. This is why the behavioral layer matters — patterns of behavior are harder to fake than surface characteristics of individual emails.

Matthew Connor: You've described the challenge perfectly. It's not a problem you solve once — it's an ongoing competition that requires continuous investment and continuous learning on the defensive side. Which is also an argument for managed services and external expertise for organizations that can't maintain that continuous learning internally. How do you think about the build versus buy versus partner decision in your environment?

Andrew Nuxoll: Heavily weighted toward partner for us. We don't have the internal headcount to do everything ourselves, and the skills required to maintain cutting-edge security capabilities are expensive and in high demand. What we try to own internally is strategy, governance, and the relationships with the business — understanding what we're protecting and why. The operational execution — monitoring, incident response, threat intelligence — we leverage partners for that.

The Microsoft ecosystem helps here because a lot of the operational tooling is managed service or SaaS — we get the capability without needing to run it ourselves. Where we've made additional partner investments is in areas where we need specialized expertise that the Microsoft stack doesn't fully address. Penetration testing is one — we do that with an external firm annually and on an ad hoc basis for significant changes. Red team exercises when the budget allows. Those external perspectives catch things that internal teams miss because familiarity creates blind spots.

Matthew Connor: That external perspective point is crucial. Your team knows your environment — and that familiarity is valuable, but it also means you've normalized things that an outside eye would immediately flag. A penetration tester who's never seen your environment before will find things your team has walked past a hundred times. That's not a failure of your team — it's just how human cognition works. Fresh eyes see differently.

Let me pivot to the AI governance angle, because as Managing Director you're sitting at the intersection of operations and security and presumably being asked to have opinions about AI adoption. How is UNICEF USA approaching that?

Andrew Nuxoll: Thoughtfully and deliberately — which is the right pace for an organization like ours. We have significant obligations around donor data and around the reputational integrity of the UNICEF brand, and those obligations create a higher bar for AI adoption than you might find in an organization with fewer constraints.

What we've done is establish a framework for evaluating AI tools before they go into use — data handling assessment, vendor security review, a determination of what data the tool can and cannot interact with. We've been clear internally that AI tools are welcome, but they go through a process, and that process exists to protect the mission rather than to obstruct productivity.

The Microsoft Copilot rollout has been an area of focus. We have Microsoft 365 licensing, and Copilot is increasingly available as part of that ecosystem. The governance questions — what data can Copilot see, how do we configure it to respect data sensitivity boundaries, what are the retention and logging implications — those are the questions we're working through carefully before broad deployment. The fact that it operates within our existing Microsoft tenant is a significant advantage from a data residency and control perspective.

Matthew Connor: That's the right approach — and the Microsoft tenant boundary advantage is real. When the data doesn't leave your environment, a whole class of data governance concern is addressed. There are still questions about what the model does with data in processing, what's retained in the context window, what audit trails exist — but the fundamental concern about your proprietary data training someone else's model is much more manageable in that architecture.

Andrew, this has been a really wonderful conversation. Before we go, can you tell everyone where they can find out more about you and UNICEF USA?

Andrew Nuxoll: Absolutely. UNICEF USA's website is unicefusa.org — that's where you can learn about our mission, our programs, and how to support the work. If you want to connect with me professionally, I'm on LinkedIn as Andrew Nuxoll — happy to connect with others working in nonprofit IT and security, or anyone thinking through the challenges we've discussed today.

And I'll add — if you're a security professional who is interested in contributing to mission-driven work, nonprofit organizations are always looking for volunteers, advisors, and partners who can bring expertise that tight budgets can't always purchase. The community aspect of security that I mentioned earlier extends to supporting organizations doing important work. It's a meaningful way to give back.

Matthew Connor: That is a fantastic note to end on. Andrew, thank you so much for coming on. Until next time.

Andrew Nuxoll: Thank you, Matthew. Really enjoyed it.