Campus Technology Insider Podcast April 2026

Episode: Every Cyber Threat Is Now an AI-Driven Threat: How AI Is Reshaping Cybersecurity in Higher Ed
Host: Rhea Kelly, editor in chief, Campus Technology
Guest: Ed Skoudis, president, SANS Technology Institute

Episode Overview

In this episode, Rhea Kelly and Ed Skoudis talk about emerging cyber attack trends and their impact on higher education, the future of cybersecurity and AI, and more.

Key Questions & Takeaways

How is AI changing the cybersecurity threat landscape?
AI is now a driving force across all five of SANS’s top emerging attack trends, including zero-day exploits, supply chain attacks, operational technology threats, and increasingly fast attacks that put pressure on traditional defenses.

How should higher ed respond to faster AI-enabled attacks?
Identify critical systems and patch them within a day or less, and use AI to accelerate incident response and analyze logs and other indicators of compromise.

How can institutions prepare to respond quickly to cyber incidents?
Establish an emergency response team that includes technical and institutional decision-makers, and conduct tabletop exercises at least once or twice a year using scenarios that reflect the speed of current attacks.

What AI skills do cybersecurity teams need?
Train security professionals to use AI within their specific roles, including threat hunting, incident response, digital forensics, and penetration testing, rather than simply buying products labeled as AI-enabled.

How should institutions build AI into their cybersecurity strategy?
Give teams access to vetted AI models, maintain the flexibility to switch models or providers as capabilities change, and develop a clear AI strategy for the IT and cybersecurity organization.

Topic Index

00:00 Welcome and Guest Intro
00:29 Ed Skoudis Background
01:00 Steampunk Office Tour
02:24 Antiques Meet IoT
03:25 AI Drives Attack Trends
05:01 Higher Ed Under Fire
05:49 Five AI Shaped Attacks
09:51 Lessons from Finance
12:05 Speeding Up Response
15:32 Training for AI Defense
18:00 AI Toolkit and Model Flexibility
22:01 Budget Priorities Patching First
25:39 Crystal Ball Rough Years Ahead
29:53 Zero Vulnerabilities Vision
31:22 Prepare with AI Strategy
34:16 Closing and Where to Listen


Transcript

Rhea Kelly  00:08
Hello and welcome to the Campus Technology Insider Podcast. I'm Rhea Kelly, editor in chief of Campus Technology, and your host. And I'm here with Ed Skoudis, president at SANS Technology Institute, to talk about how AI is reshaping cybersecurity.

So Ed, let's start by just having you introduce yourself and your background.

Ed Skoudis  00:29
Well, thank you, Rhea. It's a delight to be here again and talk with you. It's been a couple of years since we last spoke, and I do love what you do in support of higher education. So as you mentioned, I'm Ed Skoudis with the SANS Technology Institute College. It is a fully accredited institution at both the undergraduate and graduate level. We have about 2,500 students. The college was formed 20 years ago to focus on cybersecurity, higher education, and I have been president of the institution for four-and-a-half years now.

Rhea Kelly  01:00
Now, people can't see it, but you have the coolest office that that I've ever seen, really. So can you describe it for people, because it's so interesting?

Ed Skoudis  01:08
Sure, my office is done in what some people call it a steampunk style. So if you imagine that the technology and design aesthetics of the 1880s or up to say 1912 or so didn't stop, but they were kind of transported into the modern era. So you've got sort of the technology of today, but sort of with a Victorian kind of steampunk view to it. So it kind of looks like I'm sitting in a combination of, you know, an antique library and a sort of mad scientist's laboratory. So that's where I am, and I've got a collection of actual antiques from over the years here in my office. I've got an Enigma machine that was used in World War II. I've got several other antique cryptographic devices. I have a leaf, a single page of the original printed Gutenberg Bible, that's about 600 years old, a little less, but, but right around there. So I love collecting things associated with technological advancement and revolution, specifically in the realms of communication and the realms of cybersecurity and encryption. That's kind of my, my thing.

Rhea Kelly  02:24
Some of those things you've managed to, like, hook them up to sort of an IoT setup, is that right?

Ed Skoudis  02:29
Yes, I did. Yes, I've got a, I've got a telegraph key from the 1860s that types out things in Morse code. It used to follow me on Twitter, so anything I tweeted, no matter where I was in the world, it would fetch the tweet and then type it out in Morse code, so you could hear it in my office. However, Elon Musk changed the Twitter API and end-user agreement, so it's not allowed to do that anymore. But I can make it type out whatever I want, and I have a whole bunch of other things. I've got an antique fan over there from the 1930s that I can turn on with my voice. It's, it's all very AI and IoT, Internet of Things enabled. My brother said, "Oh, let me, let me understand this. So you took all this technology before we had modern safety standards against burning things down or, you know, catching on fire or harming people, and you hooked it all up to the internet, you know, what could go wrong with that?" So, yeah.

Rhea Kelly  03:25
So AI is kind of a nice segue into our conversation because at the recent RSAC conference, SANS noted, I think in a keynote address, that all of the top emerging cyber attack techniques are now being shaped by AI in some way. So can you talk a little bit about what that means?

Ed Skoudis  03:44
So SANS has been doing a presentation at RSAC Conference, gosh, I think it's 17 years now, 18 years, something like that. And it's been 10 years on the keynote stage. And it's, it's very simple formula. What are the top five attack trends that we're seeing at SANS, and what do people really need to do about it? I'm the host of this panel of SANS faculty members, and this year one of the, the major things we noticed is that AI isn't just a piece of a few of the trends; it is actually a driving force in all of the trends. If you go back last year, you know, maybe three of our five had an AI component. The year before that, maybe it was two of the five. The year before that, it was, it itself was one of the five. Now all of the five are being pushed by AI. And I, I even said to the audience when we were there, you know, if we were to tell you that AI is not associated with one of these trends, we'd be lying to you, because AI is a tool that the attackers have embraced that is driving everything forward relentlessly. There are no trends in the attack space that don't include AI at some level, because the attackers are relying on it.

Rhea Kelly  04:55
It's fascinating and kind of terrifying at the same time.

Ed Skoudis  05:00
Yeah.

Rhea Kelly  05:01
So, how would you say these evolving threats are impacting higher education in particular?

Ed Skoudis  05:06
So, higher education is such a unique kind of technological environment because it tends to be very diverse with respect to the technologies that we use. Lots of different kinds of devices and operating systems. It's also quite open because we need that, our students expect it, and also our researchers want that. It also tends to be cutting-edge, especially with the research that's happening in our organizations. A lot of it happening on AI. So, higher ed has a much harder realm to defend, and also our budgets tend to be kind of constrained and focused. So that's tough too, especially with changing funding priorities from government and so forth. It's, it's hitting hard, especially in the higher ed space. But if you look at the five trends, the, the five big attacks that we're talking about, I mean, let's, let's think about how each of these touches higher ed. First is zero-day exploits. A zero-day exploit means it's brand new. It's just been discovered. Nobody has a patch for it. There's no fix for it. It's brand-new way to exploit given software. These used to be very rare. AI is able to discover them now on its own, and these are now becoming plentiful. So there's so many more ways that we can get exploited, and if you think about that diverse infrastructure in higher education networked environments, they're aiming for us.

Next is, our second attack was supply chain risk, which is not only are you vulnerable based on your software vendors, but those software vendors have their own vendors, and their own vendors, and you pull in the whole vendor chain. So Joshua Wright from our team calls this, supply chain risks, your vendors' vendors' vendor, and again that impacts us as well.

The next one maybe doesn't impact us so much. So there's good news here, Rhea, and that is if you look at operations technology, OT, they call it. That's a fancy way of talking about the machines that control industrial production, power grids, water. What we're finding there is attackers are using AI, of course, to leverage that. But the attacks and the environments themselves are getting so complex, it's really hard for us to keep up with. Now, I mean, that would manifest itself in most higher education institutions by the lights going out. So, so the news isn't great, but the defenses there are primarily in a sector outside of our, our sector. And one of our panelists who's named Rob M. Lee, he presented at the RSA conference saying he's involved with a lot of large-scale outages, you know, power outages and such. And he said oftentimes they will not be able to determine, because it's so complex, the, the environment, they're not able to determine whether it was a cyber attack or not. And what happens then is the government hears that and says, "Okay, it wasn't a cyber attack because we can't show that it was," because they don't want the, the population to be too worried about that.

Our fourth attack is that AI can be used irresponsibly in digital forensics and incident response. There's, there's great lessons for us there. As everybody moves to leveraging AI on the defense, which we're certainly supportive of, you have to put some limits on what you let AI do, especially when it comes to determining human guilt and attribution and, you know, causation. There's really good stuff in data analytics and figuring out, you know, the nature of an attack that AI helps with. And Heather Barnhart from our team, she presented on different use cases in digital forensics and incident response and what you can let AI do and what you should never let AI do. So I think that was a good one with a lot of lessons learned for us there. And Heather is in the process right now of publishing some frameworks for AI usage and incident response, and AI usage and digital forensics, and I can't wait because, and we're giving them away for free just to help people, right?

And then the final one was done by Rob T. Lee. So our panel actually had two Rob Lees on it. There was Rob M. Lee who was talking about, you know, industrial control systems and such, and then we had Rob T. Lee, and his point here was attacks are moving so fast that we have to use AI on the defense. So Heather was like, "Be careful! Don't use it for too much," like, you know attribution and determining human guilt. But Rob was like, Rob Lee was saying, essentially, if we don't get AI involved in the defense, we're going to lose, because the attackers are moving so quickly. They're moving in the space of minutes, and we're moving in the space of days or weeks or months. And there's plentiful lessons in higher education for that, specifically with regard to patching, getting our systems patched against software flaws faster, and incident response. Sorry, that was a long answer, but I wanted to go over each of the five and how it impacted higher ed.

Rhea Kelly  09:49
Definitely, I'm glad you did. Yeah, are there any lessons that higher ed should be taking from other sectors? Like you know, like we should be less like higher ed and more like finance, or something like that?

Ed Skoudis  10:02
You know, it's interesting you mentioned finance because we didn't coordinate this at all. But you know, the financial institutions have been the targets of attacks for, for quite a long period of time. Why? Because it's like Al Capone said: Why do you attack? Why do you try to rob banks? Because that's where the money is. So they do try to attack banks a lot. So they they've gotten ahead on their defenses, and I think higher ed can learn from that. And while there's a lot of money in, in finance, higher ed needs to learn from what finance has done specifically in accelerated patching processes, because remember our first one was all, our first attack was all these zero day exploits. So if your organization gets critical patches out in the space of a month, which used to be common practice, or even a week, you're going to get snowed under. It's going to be really bad for you. So that's, that's one area we can learn from, from the financial sector is to get patches out quicker. If it's a, so, to do this, you're going to need to know exactly what your most essential systems are, which ones are absolutely vital, what software is installed on them, operating system, applications, etc., and then make sure you can patch them within a day or less, which I know is a high, difficult ask, but you're going to need it.

And the second thing we can learn from the financial sector is about applying AI on our incident response and digital forensics, which I think Heather Barnhart and Rob T Lee had some really good stuff to say about that. Specifically, leveraging AI to do analysis of logs, leveraging AI to give advice on handling incidents, not determining, you know, who it is, and trying to, you know, go for prosecution of them, but instead just quickly making sense of logs and other indicators of compromise in our environment. So those are two things that the financial folks have gotten out ahead of everybody on, and I think we can learn from. It's the patching, and then incident response and digital forensics.

Rhea Kelly  12:05
You mentioned how AI is speeding up attack timelines. How can institutions rethink their approach to defense and response with that need for speed?

Ed Skoudis  12:17
It's, it's happening so quickly now that you, you really need to make sure you have an emergency council of decision-makers that can be assembled very quickly when an attack is underway. So whoever that is from your particular organization, it probably should include, you know, good technical folks, maybe a chief information security officer, maybe as needed pulling in the president or provost to help make high-level decisions when needed. You probably should have, should have somebody from public affairs or marketing on there to craft your message. Don't make it just a technology group, because, you know, the attacks may be somebody has gotten in and stolen all of your student records, or maybe even student records associated with immigration or something. I mean, you can imagine the scenarios. That's another thing you should do. In addition to pulling together that emergency response team to make decisions and help handle the incident, you should conduct tabletop exercises at least once a year, maybe twice a year, or, or more often, where you have a scenario that somebody has created for you, or you've created for yourselves, and you walk through the decision-making process, who makes what decisions, how are you going to react, and base it on real-world attacks that are happening now. So, so that's a vital thing that organizations need to look at. And notice, I'm talking about, these are sort of operational, right? Having this emergency response team, having tabletop exercises — we call them TTXs in our industry because everything has to have an acronym — but tabletop exercises, and then also having a good knowledge of attacks that are happening. You know, trying to stay up with the news because there's just so many attacks. This can be done, you know, with some commercial subscriptions for, that we call it in our industry cyber threat intelligence, trying to stay ahead of it. But I like, I think there's plentiful free sources of cyber threat intelligence that are available, like my feed on Twitter or X, whatever you want to call it, is actually pretty good at that for me. But, but also we try to publish that stuff from SANS for free, giving it away to the world at the Internet Storm Center, which is available at isc (Internet Storm Center) .sans.edu. So our college, you know, hires the, the people that run that, and we make that a free service for the whole world, not just educational institutions. But I think educational institutions will get a particularly good use out of it, and it's all free.

Rhea Kelly  14:53
I think it's interesting that tabletop exercises, you know, is, is a piece of advice because, I mean, I feel like I've heard that advice for many years. Like, like if institutions haven't been doing those, like what are they doing?

Ed Skoudis  15:10
They're falling behind, they have, yes. But now it's even more important though with these AI threats and how quickly they move. So you, you want to get a good tabletop exercise where the attacker doesn't move over the space of, you know, a simulated hour or day, but this has all happened in a few minutes, and everything's gotten to very high levels of compromise in the first few minutes of the exercise.

Rhea Kelly  15:33
So that actually makes me think about training. You know, what new skills do security teams need, and, and how do, like, institutions need to set up their cybersecurity training plans to sort of keep up with all these new threats?

Ed Skoudis  15:51
Well, I mean, um, you know, I'd be remiss if I didn't mention AI in this, and I'm, I'm sorry that it sounds like it's all AI all the time. However, the only way to keep up with these threat actors leveraging AI is to leverage AI ourselves. So your, your team that is securing your organization or your institution they need to know how to use AI in each of their jobs. If you have an in-house, say, threat hunting team, they need to know how to leverage AI in their threat hunts, looking at logs, etc., etc. You, if you have a in-house incident response team, they know how to, they need to know how to leverage AI in incident response. If you're getting training for them, make sure their training classes talk about how to leverage modern AI to do their jobs. This doesn't mean going out and buying AI-enabled cybersecurity tools. They do exist, but a lot of that's snake oil. I saw a fair amount of that at RSAC conference a couple weeks ago, where almost every vendor says we have AI inside now. And it almost feels like they, they sprinkled magic AI dust over their product and just said, now it's AI. Because they're hearing from their customers who can only buy AI enabled solutions. I'm not talking about that here. What I'm talking about here is to make sure your people have the knowledge and capabilities of leveraging AI in their job roles, and that's the kind of training you should seek for them because it varies. You know, teaching people how to use AI in penetration tests is different from teaching people how to leverage AI in digital forensics or incident response, or cyber threat hunting, or pick any one of your myriad of things, but leveraging AI to do that and doing it in an intelligent way. Which is why I'm super excited about Heather Barnhart's upcoming frameworks, I mentioned them earlier, for leveraging AI in digital forensics and a separate framework for leveraging it in incident response. She hasn't released them quite yet, but they're coming any day now. And I think they're, I mean, it's, it's going to be a great contribution to the industry because she has very carefully thought this out and worked with, you know, lots of cyber defenders to put them together.

Rhea Kelly  17:56
I'll definitely keep an eye out for those and put them in the show notes. So speaking of that cybersecurity toolkit, has it changed at all, like, the, the, what institutions should have in place in the age of AI?

Ed Skoudis  18:11
Yeah, I think, I think it has. I think your, your folks need to have access to an AI that has been vetted by your technical team that they feel comfortable with, one of the major frontier models would be very useful here to be able to interact with it and just get its input and advice. You can't blindly trust it. They still do occasionally hallucinate or say silly and dumb things, the AIs do. But for the most part, it can be a trusted sidekick to help your team and help it move forward. Also, you know, gathering the latest intelligence. Now, it, it flips all the time. People ask me constantly, which one should we use? Which one should we, should it be, you know Anthropic's Claude? Should it be OpenAI ChatGPT? Should it be Copilot? Should it be this? Should it be that? And it, it, it changes all the time. My team, they leverage many of them, and they find that they vary so widely. Another one is Google's Gemini, right? And they leapfrog each other constantly. So if you go back way, way, way back to two weeks ago, way back to two weeks ago, Claude, you know, by Anthropic, was probably the best one at writing code. But just in the last week or so, Claude has changed significantly, and a lot of my friends are saying that it's just doing lousy quality code right now. And they've changed just in the last few days, they've changed their subscription, so that if you, if you use it a lot, you're going to fill up your token expenditures super quick and run out. So some people are moving to other solutions like Gemini 3 from, from Google or Codex with ChatGPT and OpenAI. So it's just in constant flux. So, and, and if somebody's listening to this a month from now, it'll be different again. So it's really hard to give advice on what model to use. But I will give you this: Because of this constant change, whatever AI-centric workflows your team creates, you need to ensure that you can change out the underlying model quickly and easily. For my team, we've done that, So that if Claude gets stupid overnight, it happens, right? We can switch out to, say, an OpenAI solution, or if OpenAI goes crazy or just won't talk to us because it thinks we're trying to do something that is offensive in cybersecurity, we can move it and change to, say, Gemini 3. So, so that's really important. If your, if your workflows get too centered on specific AI companies and models, you could get stuck in the middle of an attack. So you got to make sure you have the ability to dynamically do that. And the tooling we've created within my organization, we're able to just dynamically change a model within the same provider. So instead of saying, you know, this version of Claude Opus, we're going to go back to Sonnet or a different version of Opus. We can not only change the model within the provider, we can actually change the provider. So that's something to keep in mind, especially for the more technical folks in your audience. Notice, I'm not saying model independence, but I'm saying the ability to shift models dynamically is important.

Rhea Kelly  21:28
Yeah, I love that idea of building in that flexibility, and it's almost like it's modular on the back end.

Ed Skoudis  21:35
And, and, you know, I'm sure the people who are building such products like that hate to hear that from us because we're essentially saying, "Look, your intelligence is a backend commodity, and if I can't buy oranges at you know the, the levels I would like from one place, I'll buy my oranges somewhere else. That's what you are — you're oranges, and I need some orange juice for breakfast. So, right, don't get stuck on one orange juice supplier.

Rhea Kelly  22:01
When you think about sort of the funding uncertainty in higher education today, and also like enrollment declines, teams are looking at limited budgets and usually sort of under-resourced staffs. So, what should higher education security teams be prioritizing right now?

Ed Skoudis  22:20
Yes, that's such a good question, and it comes back, to me, to those top five things that we, this is what SANS is seeing in the trenches, what we're hearing from our, our faculty, our students, et cetera, et cetera. And it comes down two main things I want to emphasize here: patching. I've said it already, but I'll say it again. Very rapid patching, patching like you've never seen before. And then optimize incident response with AI driving it. And on the patching side, you know, in, in this industry, we see, you know, a need for a critical patch, maybe two or three of those a month. Okay? Right, somebody discovers some major flaw, attackers weaponize it, and two or three times a month you have to patch this or that. Sometimes it's maybe the underlying operating system. Sometimes it's a virtualization environment. Sometimes it's something else. You got to patch it. With AI doing vulnerability research and discovering these flaws, we are going to face a week where on Monday you have five critical patches. Not just in a month, but in one day. And then Tuesday you're going to have 15. Wednesday there'll be 30. They take it easy on us on, on Thursday, we only get four because they're saving them all up for Friday to ruin our weekend. So on Friday we get 47, and it's like good luck patching that. And, and you see this idea of patching within a month. No, it, it's going to be patching within a day, and sorting out those patches, understanding. And you might not even be able to deploy all 47 patches, but you want to make sure your critical systems keep running, like registration systems, financial systems. So that's why I suggested you create that priority list for your patching. And then second is the incident response capabilities and gaining AI insight to that. And one of the things that I've seen on that is AI systems are able to track different elements of it in a way that humans can't keep it all in our heads at once. AIs do have a limited context window, but if you leverage the AI carefully, it can remember all the different issues associated with an incident that you're handling and make suggestions to you about the most effective way to respond. But you need to have humans there to ensure that those issues actually make operational sense. You know, there's a, the SANS Institute has a new CEO, James Lyon. He took the job over just in the last couple of weeks. I'm super excited about it, and he, he said this, which I thought was really interesting. You're gonna love this, Rhea. Attackers have AI, right, and they're leveraging it. Defenders have AI, and we need to increasingly leverage that. But what this means is when both sides have AI, it's the people who matter again, right? And, and having those people ready to go, well-trained, well-equipped, that's what it's going to come down to. So we've got this AI arms race, which will eventually work its way to a stalemate, and then suddenly you need to have smart, focused, capable, clever people defending your environment. And I actually really like that idea and that outcome. I think that's a good thing. It comes back to the people.

Rhea Kelly  25:31
Yeah, you're right. I love that.

Ed Skoudis  25:34
That's James' line. It's James' line. He said it, and I was like, "Wow, spot on."

Rhea Kelly  25:39
So I'm going to ask you to get out your crystal ball. And looking forward, what are the scariest threats on the horizon?

Ed Skoudis  25:48
Okay, Rhea, I'm going to give you this, and it's going to maybe sound a little scary, and, but, but I really think it's going to happen. And, but then I'll, let me contextualize it after that. Okay? I think we are in the midst of a revolution in cybersecurity. The wheels are coming off. The vulnerabilities that AI is discovering are super deep and super complex. The attacks we're going to face are horrible. The supply chain, infection of systems — it's a disaster. And I think the next year or two are going to see some really bad attacks. Big outages, really, really bad stuff. I mean, I'm not trying to say this to scare anybody. I'm not about fear, uncertainty, and doubt. I'm, I'm about looking realistically at what AI is capable of, and it is able to automate attacks at a speed and a scale we've never before seen. However, I do think this is going to force us to make cybersecurity much, much better in five years, maybe seven. I think we're going to see cybersecurity much better than we ever have, and this actually gets me very excited. I think we're going to have better patching. We're going to have just better software. The software itself is going to become so much more hardened by default, so much more safe and secure, so many fewer vulnerabilities. People at Google and Anthropic and other companies are talking about a coming era within five years where there are no software vulnerabilities at all. They're all gone. The AI has hunted them to extinction. Very brilliant people, very committed people, and I kind of believe them. And it makes me think of a couple things. One is when I first started in this industry, it was 30 years ago, and my officemate was a man who is the age that I am now. But this was 30 years ago. He said to me, "We know how to deal with all these problems. We know how to, we know how to secure software. We know how to do good cryptography. We know how to train users into selecting good passwords." He said, "We are going to beat this problem and fix cybersecurity." We didn't call it cybersecurity. Fix data security, we called it, or information security. "We're going to fix that in 10 years." This is what he told me 30 years ago. And I like to say to people, so I'm, I'm 30 years into my 10-year career, and things are just fine. But they're not fine. And what I think is perhaps his vision was just off. He might have been 30 years off because I do think now we might be within five or 10 years of cybersecurity revolutionizing itself to become so much better. To, to really not be on this sort of rickety infrastructure of software that has all these holes that we have to constantly patch up. Another way to look at it is, I think to myself sometimes, I've spent the, you know, the best, most productive years of my life, and so have many of my friends, working as hard as we could to make the infrastructure as safe as we can. And if you look at it, we've kind of failed. And what I mean by that is we actually have made things more safe and secure. If you look at the security of, say, Windows 11, which is the recent version of Windows, versus, say, Windows 2000 from 20 some years ago, it is markedly more secure. But the problem is the attackers have gotten so much better. So in, relative to the attackers, we've barely been treading water. We haven't gotten way better than they have. No, they've gotten way better, and we've gotten way better, so that they're still hammering us hard. And now they're AI-enabled, so they're hammering us harder. But with our use of AI, we have a chance now, for the first time that I've seen in 30 years, to actually tip the balance and, and make cybersecurity just so more foundationally better. So my prognosis, my crystal ball says, the next year or two are going to be really rough. Don't despair, though, because five years out, maybe seven years out, I think things are going to be so much more secure, and that's going to be a really good thing. So you got to, you got to stay tuned and wait for that.

Rhea Kelly  29:52
The idea of software vulnerability is going extinct is quite the silver lining, I think.

Ed Skoudis  29:58
Isn't it amazing? And, and, and, you know, you say, that just seems fanciful. It seems like nonsense. Well, imagine, if you would, because there's, people are building this stuff right now, where you can go through all existing source code with a brilliant AI, and it finds the flaws and tells you how to fix them, or fixes them itself. You say, yeah, but then we'll introduce new flaws, or the AI itself will write code that introduces new flaws. So they're, they're starting to build these essentially gateways that software developers use to check in their code, and the gateway will do an automatic security analysis using AI before allowing the code to be checked in. And if it, if it finds a flaw in it, it won't let the code go in, and it will even tell you, the developer, how to fix it. So the fancy ways to refer to this is you're going to have an AI inspector of your CI/CD pipeline, and it will only allow you to check in software once it's been properly security vetted by an AI. And that's the kinds of things that people are saying will drive software vulnerabilities down to zero. Look, there's all other kinds of cybersecurity issues beyond software vulnerabilities, like users clicking on links they shouldn't be clicking on or succumbing to social engineering attacks over the phone. So I'm not saying cybersecurity goes away, but if, if software becomes less vulnerable, that will be a huge, huge boost to the security of our infrastructures.

Rhea Kelly  31:22
What should teams be doing now to prepare for what's coming next, and maybe weather those couple of rough years you see ahead?

Ed Skoudis  31:29
Yep, I think ensuring that their training leverages AI for the individual job roles that they have on their team, and then using proper AI enablement within those job roles, giving the team access to some frontier models and/or local models. This is an interesting thing. The frontier models are the big ones, right? The, the Gemini, the Anthropic, Google Gemini, Anthropic, Claude, ChatGPT by OpenAI, etc. But you can also build local models too, and those are quite interesting. But we find that local models are really useful because they're cheap and they also maintain privacy. Well, they're relatively cheaper. You need to have beefy hardware, but the actual software running on it is relatively inexpensive. It's, it's much cheaper to use those in bulk than it is to use a frontier model. That said, the frontier models just know more. They're so much more capable. So, you know, usually a solution involves both of them together. And the small, simple privacy needing stuff you do local with a local model. The more complex, bigger, maybe stuff that you're willing to have a little less privacy on, that goes to the frontier model. So, so understanding those things and, and having an AI strategy for your IT organization and cybersecurity organization is a must here in 2026. You know, I talk to a lot of different institutions and I talk to a lot of different companies, and sometimes their AI strategy is really interesting and useful, and I can see where they're going. And other times it's just a muddied mess. So I mean, do you know what your AI strategy is for your organization? Even, I talk with various higher ed institutions, and, you know, do you have an AI strategy for your own students and their use of it in their courseware? Thankfully, educational institutions are increasingly doing that, but, but not all of them are. And I still talk to some, it's like, you know, we allow each and every professor to create their own AI policy for their course. Which I think there's, there's, there's room for that, but do you give them templates to choose from and, and educate your professors about the implications of choosing those different policies and what it means for their students? That's what we do at the SANS Technology Institute and several other organizations that I, I talk with and work with. But there's still a lot of higher ed that doesn't have at least policy templates for their faculty to rely on and an understanding of them. But if you're not doing it for the students, are you doing it for yourself? Do you have an AI policy and do you have an AI strategy for your institution? Because you need it.

Rhea Kelly  34:16
Well, you've given us so much to think about. Thank you so much for coming on.

Ed Skoudis  34:21
It was a joy, Rhea. Thank you for your time. Thanks for your great questions. This was, this was a lot of fun. I hope it's useful for people.

Rhea Kelly  34:30
Thank you for joining us. I'm Rhea Kelly, and this was the Campus Technology Insider podcast. You can find us on the major podcast platforms or visit us online at campustechnology.com/podcast. Let us know what you think of this episode and what you'd like to hear in the future. Until next time.

Featured

  • Abstract neural network 3D illustration

    Intel® AI EmpowerED: The AI-Ready Campus, Delivered

    Artificial intelligence is transforming higher education, prompting institutions to rethink how they manage infrastructure, security, governance, and workforce readiness. Successful adoption requires a strategic, institution-wide approach that aligns AI initiatives with educational goals, faculty enablement, and scalable operational frameworks.

  • Glowing route lines merging into single gold pathway

    Microsoft Merges Copilot Apps Into a Single User Experience

    Microsoft recently announced it is consolidating its consumer Copilot app and Microsoft 365 Copilot app into a single destination, addressing a fragmented product strategy that has required users to navigate separate applications for AI chat and productivity tools.

  • abstract glowing ai chip on circuit board

    Gartner Marks Enterprise Move from AI Experiments to AI Engineering

    According to Gartner's recent "Hype Cycle for Enterprise Architecture, 2026" report, enterprises are moving from AI experimentation toward a more industrialized approach to AI delivery.

  • Abstract futuristic digital network with glowing padlock icons

    Microsoft Intros New Agentic AI Security Multi-Model Defense System

    A new multi-model agentic AI security system built by Microsoft's Autonomous Code Security team helped researchers find 16 new vulnerabilities across the Windows networking and authentication stack, the company anounced in a recent security blog post.