How one Alberta library leader strengthened her cybersecurity skills with LevelSec – Digital Nova Scotia – Leading Digital Industry
How one Alberta library leader strengthened her cybersecurity skills with LevelSec

July 28, 2026

How one Alberta library leader strengthened her cybersecurity skills with LevelSec

A Digital Nova Scotia Success Story

Stephanie Thero didn’t come from a traditional technology background.

She planned to become a children’s librarian.

Today, after nearly 17 years working in libraries, she leads technology services for Yellowhead Regional Library in Alberta, supporting 44 library locations across central-west Alberta.

Cybersecurity is now a key part of her role. But after years working in technology, she realized there was one area she still wanted to strengthen.

“I understood the technology side and the awareness side, but being able to speak to executives, think about risk assessments and risk analysis—that was where I was looking to develop.”

That search led her to Digital Nova Scotia’s LevelSec: Advancing Cyber Leaders program. Funded by the National Cybersecurity Consortium and delivered in partnership with WatSPEED at the University of Waterloo, the program offers two streams: Cybersecurity Governance and Risk Management and AI & IT Security Systems.

Looking beyond the technical

Thero’s path into technology wasn’t a traditional one.

“My educational background is not in tech,” she said. “A lot of it has been on-the-job training and constantly learning.”

As her responsibilities grew, so did her interest in cybersecurity leadership. When she began looking for professional development opportunities, she found plenty of technical courses—but very little focused on governance, risk and executive communication.

“The technical, hands-on information is more available,” she said. “Finding the leadership and governance piece—particularly in a course—there’s less out there.”

After searching online for cybersecurity leadership training in Canada, she discovered LevelSec.

“It was built for someone who is working,” she said. “Having the live sessions and the recordings as a backup offered a really nice flexibility.”

The course also challenged Thero to think beyond what she knew best. One assignment asked participants to complete a cybersecurity risk assessment based on the healthcare sector rather than their own industry.

“If I had chosen an example, I would have chosen something I was comfortable with,” she said. “This challenged me to stretch my thinking, go outside my comfort zone and think about risk differently.”

A new lens on leadership

Back at work, Thero began applying what she’d learned almost immediately.

“The risk assessment piece is now a lens I’m using to look at the organization,” she said. “Mapping out what we’ve done, communicating that to leadership and focusing on what comes next.”

Libraries may not be the first organizations people associate with cybersecurity, but Thero says every industry faces the same fundamental risks.

“Cybersecurity spans all industries,” she said. “It doesn’t matter whether you are small or large—the risks are always there.”

She also believes governance and risk management shouldn’t be viewed as skills reserved only for technical specialists.

“You don’t have to be a technical person to communicate risk and understand governance,” she said. “Does it help? Absolutely. But it isn’t something you absolutely need.”

More than new skills

For Thero, one of the biggest takeaways wasn’t technical at all.

It was confidence.

“When you’re the person leading this work, you sometimes live in that question of, ‘Am I doing a good job?'” she said.

Completing the program, building a cybersecurity risk assessment from start to finish and receiving positive feedback gave Thero reassurance that she was on the right track.

That confidence has carried back into her day-to-day work. But in cybersecurity, Thero knows the learning never stops.

“Especially with cybersecurity, if you’re not continuously learning, you’re behind,” she said.

It’s one of the reasons she’s already recommending LevelSec to other professionals.

“It was really well laid out. It’s great for people who are working, it’s completely manageable, and it sets you up for success.”

For professionals looking to strengthen their understanding of cybersecurity governance, communicate risk more effectively or grow into leadership roles, applications for the next LevelSec cohort are open through September 25.

Thero’s experience is a reminder that professional growth doesn’t always mean becoming more technical.

Sometimes, it means learning to see the bigger picture.