"Hotline: Cybersecurity and Privacy" tackles the philosophical, moral, strategic, and organizational quandaries related to higher education cybersecurity, privacy, and data. This month, Mike answers your questions about building cyber skills in the age of AI, shaping cybersecurity habits, and selecting a cybersecurity framework.
Building Cyber Skills in the Age of AI
Dear Hotline: As artificial intelligence (AI) becomes more prevalent and cybercriminals become increasingly sophisticated, how can AI be leveraged for both offensive and defensive purposes at our higher education institutions? How will these factors change what skills a cybersecurity professional will need to be equipped with?
Sunny and 75
Dear Sunny: I'm hoping by "offensive and defensive purposes" you don't mean you intend to go on the attack! As tempting as that might sound, it's undoubtedly a violation of some institutional policy and may be outright illegal. We are, however, witnessing a rampant blossoming of cyberattacks that leverage AI, although the blooms we're seeing are anything but lovely.
For example, I recently read a study from MIT claiming that 80 percent of ransomware attacks are now mediated by AI.Footnote1 The spam, phishing, and smishing I'm seeing of late (all basic forms of social engineering) are far more polished, due to AI, than we've grown accustomed to. Of course, the fact that bad actors can harness AI to write obfuscated malware or orchestrate entire dynamic attack chains is pretty frightening.
But the news isn't all bad. Many of the tools commonly used by cybersecurity professionals use machine learning (and have for years). Anti-spam services, for example, often train on identified phishing messages and apply the pattern-matching capabilities of AI to detect new variants. Personally, I'd love to see every email message flagged if it were predominantly written by AI. Intrusion detection, endpoint security, and log analysis tools are leveraging AI capabilities almost without exception in the industry. Of course, there is also a growing market of specialized tools that leverage AI for activities such as penetration testing (pen testing).Footnote2
Your second question about "what skills a cybersecurity professional will need" truly gets to the heart of the matter. A list of today's best tools and tactics might be useless in a year. It's the training and preparation of cyber professionals that future-proofs an organization. Notice that I said, "cyber professionals" and not "cybersecurity professionals." Even those who don't work directly in cybersecurity, such as research facilitators or developers, need to be cognizant of the emergent risks that stem from AI.
While it's wise to bring your traditional cybersecurity arsenal to bear on AI infrastructure, it's equally important to discuss and study the mechanics of AI. Think about mapping the data flow, the handling (and protection) of prompts, and, of course, what emergent capabilities are created by an AI. Preparing for the world we now face requires more than noodling with prompts; it requires dedicated study. I suggest forming topical study or reading groups. If you're a manager, discuss adding some AI professional development to your team's work plans. It doesn't have to be a certification. If, for example, your cybersecurity analysts and engineers spent a few months working through a book on attacks that leverage AI, they'd be ahead of the game (Not with a Bug, But with a Sticker is a favorite of mine.) Hopefully, that's enough to keep you in the sunshine.
Shaping Safer Cybersecurity Habits
Dear Hotline: I love your column. I will be using some variation of it at our institution. I could see setting up a Peanuts/Lucy booth for cybersecurity questions in our cafe once a week during October.
We're in the throes of planning for Cybersecurity Awareness Training Month in October. In the past, I have set up an LCD panel with a laptop in the cafeteria and invited the community to check the strength of their passwords. Any password that takes more than ten years to hack is rewarded with a full-sized candy bar. With a little bit of music, this becomes a cybersecurity party.
What is your favorite activity that you believe changed user behavior for the better?
Party Animal
Dear Party: Thank you for the kind words and for sending this very timely question. It does sound like you're already well on the way to changing user behavior with a full-sized candy bar. People are like my dog: food motivated. At least I am.
Unfortunately, this is a difficult question to answer. Even though IT and cybersecurity professionals have been telling people about the importance of strong passwords for nearly forty years, the most common password is still "123456." Footnote3 And yet when faced with the dizzying number of newsletters, services, and websites that require a user name and password pair, even the most diligent of us deserves some slack and understanding. As for those using "password" as their password, they reap what they sow.
But consider this: Why do we expect users to change? They didn't create this problem; it was created by the various applications. What you're accomplishing through your party approach is user awareness and reinforcement via activation of their neural-candy-bar reward center. If your goal was merely "stronger passwords," you could handle that through stronger password or passphrase formation rules and a mechanism to check the strength of each password as it's created. On a previous team, we integrated a password checking service with Active Directory and essentially eliminated weak passwords.
However, if you're talking about changing user behavior, specifically around passwords, I'm in the "there is no answer here except to abandon passwords" camp. I used to believe passphrases were a gateway to better user behavior, but getting traction with them has been difficult. What's more, no matter how excellent a job you do at your institution, in real life, users are still confronted with managing too many credentials. While your password party is commendable (and I hope others copy your approach), at best, you're influencing only a small percentage of your population. For an organization, mandating single sign-on (SSO) and supporting integrations with mobile technologies such as Face ID, combined with aggressive use of a password manager or passkeys, is probably the best you can do. It is impressive how rarely you need to type a password on a phone these days, if properly configured.
If you're looking for ways to get individuals to be more cyber-responsible citizens, that's a much harder challenge. I know some institutions have been dipping their toes in the digital citizenship and digital literacy pools.Footnote4 It has long struck me that aligning cybersecurity with core institutional initiatives in that space could be far more impactful than working in isolation. In my experience, the student services staff and faculty teaching these courses have welcomed such engagement.
Sifting Through the Alphabet Soup of Cybersecurity Frameworks
Dear Hotline: What is the most widely adopted cybersecurity framework within higher education: NIST CSF, ISO 27001, or CMMI Cybermaturity?
Frazzled by Frameworks
Dear Frazzled: Rare is the CISO who doesn't maintain a giant mapping of frameworks and control sets. Unfortunately, as soon as you choose one, some new agency or regulatory scheme arrives at your doorstep. Got a healthcare system? Welcome to HIPAA. Got a DoD grant? Welcome to CMMC (Cybersecurity Maturity Model Certification) and DFARS (Defense Federal Acquisition Regulation Supplement). One small piece of advice, based on years of experience: Do not ask the IRS for data; those folks know regulations. The fact that you're frazzled simply means you're paying attention.
I don't have any hard data on this, but I can tell you what I see from talking to colleagues. There seems to be a trend to embrace NIST standards in general, and the NIST Cybersecurity Framework (CSF) specifically. The documents NIST publishes can be a bit daunting at first. There are a lot of them, and they are almost overwhelmingly comprehensive. But as more federal agencies try to harmonize their regulatory approach to cybersecurity, more universities and colleges are turning to NIST. To be honest, NIST is the gold standard.
The NIST CSF is also attractive in that it's easy to digest. The structure is logical and easy to understand, and the framework itself offers plenty of opportunity for flexibility in application. With the NIST CSF, you gain Quick Start Guides, alignment with enterprise risk management, and a fairly accessible and achievable assessment methodology.Footnote5
One aspect of the NIST CSF that you may find attractive is that its "domains" are understandable without reference to any cybersecurity terms of art. Govern, Identify, Protect, Detect, Respond, and Recover make for excellent categories on a single diagram showing the maturity level of your program. This can make for an effective conversation tool with your leadership about how far a program has to go to reach a maturity goal.
Selecting the NIST CSF certainly won't defrazzle you, but it will put you in good company. After all, "A man may break a word with his friend, but not with his company." Footnote6 Surely, we can all agree that cybersecurity progresses furthest when we stand together as a community.
Notes
- Michael Siegel et al. Rethinking the Cybersecurity Arms Race: When 80% of Ransomware Attacks Are AI-Driven Cybersecurity at MIT Sloan Working Paper Series CAMS25.1114 (Massachusetts Institute of Technology, April 2025).Jump back to footnote 1 in the text.
- See, for example, PentestGPT.Jump back to footnote 2 in the text.
- You can find a "List of the Most Common Passwords," discovered in various data breaches, on Wikipedia.Jump back to footnote 3 in the text.
- For a good jumping-off point, check out the EDUCAUSE "Digital Literacy" library page. Jump back to footnote 4 in the text.
- See the National Institute of Standards and Technology's CSF 2.0 Quick Start Guides.NIST also provides links to third-party assessment tools.Jump back to footnote 5 in the text.
- A common modern rephrasing of Dromio of Syracuse's line in Shakespeare's The Comedy of Errors. Jump back to footnote 6 in the text.
Michael Corn is an Executive Strategic Consultant at Vantage Technology Consulting Group.
© 2025 Michael Corn. The content of this work is licensed under a Creative Commons BY-NC-SA 4.0 International License.