Shared Governance in the Age of AI: Keeping the Institution Safe with Bill Guerrero - Ep 240
Bill Guerrero is the VP of IT at Sacred Heart University, a private, faith-based, residential institution in Fairfield, Connecticut with roughly 10,000 students, 50 buildings, and nearly 2,000 cameras across campus. A proud alum who earned his master's there in 1999, Bill brings an unusual dual background to the role, having started his career at Gartner before spending years as a CFO, a financial lens he now applies directly to how the university budgets for AI. He joins the show during the first week of a new semester to talk through a live third-party security incident his team resolved in real time, why token and credit costs deserve the same budget scrutiny as any other line item, and why he believes the new professional standard is AI-assisted work refined by a human, not work produced by a human alone.
Here’s a glimpse of what you’ll learn:
- How Bill's team resolved a third-party zero-day breach affecting a campus vendor in just 24 hours
- Why Bill treats tokens and credits as a budget item universities can't afford to leave unaccounted for
- How Bill uses Claude with read-only access to run low-cost internal pen tests against the university's own framework
- Why Bill believes the new professional standard is AI-assisted work with a human review layer on top
- How Sacred Heart's shared governance model keeps AI adoption fast without letting any department run rogue
- Why Bill still uses AI for the small, personal tasks in his life outside the office, including coaching baseball
- How a real, current incident at a major learning management system provider shaped Bill's own continuity planning
In this episode…
Bill opens during the exact week cybersecurity pressure peaks for any university, the first week of a new semester, when thousands of students and their devices hit the network at once across a campus with door access systems, high end classroom technology, and nearly 2,000 cameras. He describes a proactive approach built around education before problems start, emailing students, faculty, and staff ahead of time with what to expect and what scams to watch for, while his cybersecurity team, led by his own CISO, works to keep pace with a threat landscape he compares to a constant game of ping pong against attackers who are also upgrading every day. He's candid that Sacred Heart isn't trying to be a bleeding edge leader, running as a Copilot enterprise shop for the past three years, but that shared governance lets academic leaders, faculty, and cybersecurity students get meaningful access without compromising the institution's data.
The conversation turns sharply concrete when Bill describes a live incident from the exact weekend of the interview: a third-party vendor supporting the university's mobile credential printing system was hit by a zero-day exploit. Because of layered security defenses including CrowdStrike, Bill's team caught and remedied the breach within 24 hours, and in a notable twist, it was Sacred Heart's own team that first alerted the vendor to the intrusion. He connects this to a broader shift he's watched happen in real time, referencing a recent incident at a major learning management system provider that affected 900 universities, one Sacred Heart avoided, as a reminder that continuity plans written months ago need to be revisited constantly rather than treated as a one-time compliance exercise.
The back half of the episode gets into how Bill actually manages AI adoption without letting cost or fear derail it. Drawing on his background as a recovering CFO, he explains why tokens and credits function like a printing budget that can quietly run out, an unbudgeted surprise if leadership isn't paying attention, and why total cost of ownership needs to include this line item explicitly. He describes using Claude with carefully scoped, read-only access to walk through the university's own firewall and network settings, comparing it against Sacred Heart's existing framework to run what amounts to a no-cost internal pen test rather than paying six figures for an external one. He closes on a personal note entirely outside of IT, describing how he used AI to rebuild a baseball practice schedule for a coaching role he's returning to after years away, tweaking the output himself rather than accepting it wholesale, a small example of the exact philosophy he argues the whole university should adopt: let AI produce the polished first draft, then apply the human judgment that makes it genuinely yours.
Resources mentioned in this episode
CyberLynx Website
Bill Guerrero on LinkedIn
Sacred Heart University Website
Darktrace Website
Abnormal AI Website
Sponsor for this episode...
This episode is brought to you by CyberLynx.
CyberLynx is a Bethesda managed IT and cybersecurity company. Local techs you know, not a call center. Month-to-month. 24/7 intrusion detection.
We help growing companies with managed IT, help desk, backup and recovery, and a fractional CIO.
Talk to us at https://cyberlynx.com/contact, info@cyberlynx.com, or 301-798-9170.
Check out previous episodes:
Playing With Fire: Securing AI Without Shutting Off the Stove with Nakeea Neischer - Ep 239
Build Versus Buy: The Risk of Vibe Coding Your Security Stack with Andrew Dutton - Ep 238
The Security Sidecar: Wrapping Code in Real Time Defense with Aby Rao - Ep 237
Transcript:
Cyber Business Podcast
Bill Guerrero
VP of IT
Sacred Heart University
Matthew Connor: Matthew Connor here, host of the Cyber Business Podcast. Today we're joined by Bill Guerrero, VP of IT at Sacred Heart University. Bill, welcome to the show.
Bill Guerrero: Hi, Matt, thanks for having me, really appreciate it.
Matthew Connor: Well, thanks for coming on. Before we get too far in, a quick word from our sponsors.
Sponsor Break — CyberLynx: Hackers are using AI to conduct machine-speed attacks. Is your security keeping up? CyberLynx sells industry-leading AI-powered cybersecurity solutions that detect threats in real time, so you know about an attack before the damage is done, not after. Learn more at cyberlynx.com. That's cyberlynx.com.
Matthew Connor: And now, back to our show. Bill, for those who aren't familiar, can you tell us about Sacred Heart University and your role there as VP of IT?
Bill Guerrero: Sure, sure. Hopefully more and more people are getting to know Sacred Heart University. We're a private, residential, faith-based, really comprehensive institution in Fairfield, Connecticut. We have about ten thousand students, and probably one of the most beautiful campuses throughout the country. I'm a proud alum, I got my master's here back in 1999, so certainly dating myself, Matt, but the changes from 1999 to now, when I walk on this campus, first and foremost it makes you super proud, second, it makes me wish I had a son or daughter to send here. With the challenging industry this university is in, it's just doing great, all of our academic programs are top-notch, certainly including our cybersecurity program, but all our programs are top-notch academically. And then we have some amazing athletic facilities and athletic programs at the Division One level. So it's a great school, and hopefully people get to know it more.
Matthew Connor: I love it. I think IT, when it comes to a university, is kind of its own separate beast, unlike most organizations where you're just securing the people working there, the staff. You've got the staff, and then all of the students, and you don't control or own those devices, so that opens up a whole new, it's like the world's largest BYOD nightmare, because you've got to give them access to resources, and how are you securing all those devices? For the uninitiated, can you walk us through how you go about tackling that problem at the university level?
Bill Guerrero: Yeah, certainly a great question for this period of time. This is our first week of opening of school, and this is the moment when cybersecurity professionals, IT professionals, everybody wants that first-year, first experience of returning and new students, parents dropping off, and all the anxiety of, just make sure the Wi-Fi is working, all my devices. It's so much different now, everybody has so many different devices, and then we have so many different devices all over the campus, the classrooms have high-end technology, we have cameras, door access, so many different ports. But one of the things we do, I have an awesome cybersecurity team led by my CISO, and we do a lot of proactive work, a lot of proactive strategies, like emailing everybody out initially, hey, here's what you should know beforehand, here's how you test it, these are some of the things we like to do to make sure your experience is not only safe, but hey, here's all the things people fall for. So we have a lot of awesome tools that really help our students, faculty, and staff protect our university while making sure they have the appropriate access. Everyone has multiple devices, four or five devices, but we have more devices on this campus, when I said ten thousand students, we have fifty buildings, really comprehensive infrastructure, we have almost two thousand cameras, more applications than you'd imagine. But then when you think about the infrastructure behind it, it's a lot of work for my cyber team to keep us safe.
Matthew Connor: That's amazing. Well, I'm curious, in the day of AI, where do you land on this topic of AI and cybersecurity? There are so many places we can go with AI when we're talking about universities, between the students and how they use it versus studying, on the IT side, on the cyber side. But let's look at the cyber side, I think this is where things get really interesting and exciting, and we're early days, obviously, with AI, it's September 2026 right now, and it's a whole different world now than it was just a few years ago. And when you're looking at cybersecurity, the bad guys are using AI, where do you stand on this, in terms of using AI in cyber?
Bill Guerrero: Yeah, so from a cyber perspective, specifically with our cyber team, we're very, very careful, very mindful on a variety of fronts, where certainly we're not trying to prevent it in any shape or form, but we're trying to do it to protect our data. Protect our data when we talk about FERPA, a higher-ed education term, and HIPAA, to protect those health records, student records, so we really, really are mindful on access to data, and we take a mindful approach on that. But with any new recommendations, and we get inundated obviously from all aspects on new applications, or just renewals of applications that may have an injection of AI, some new module or attribute to the contract, so we do a lot of education with our variety of stakeholders, to make sure my cyber team, they feel like they have law degrees now. You know how many things they need to keep looking at every single day, and they get inundated all the time, but they get it, they're trying to keep our institution safe, but we're not trying to slow down teaching and learning, and really hopefully finding efficiency and effectiveness of work. But we do a great job here at our university, and again, we're not saying we're leaders or even fast followers, as you said, it's over three years now since it's kind of rolled out, we're a Copilot enterprise shop, but that doesn't mean we don't have our ways to give access to our academic leaders or faculty, and some of our students, specifically the ones in cybersecurity, or in AI, in those academic programs. So we do a lot of shared governance within our institution to protect our data, but also to allow for those aspects. But when you're talking about what our cyber team is doing, besides the labor, it's really just trying to keep up with it, it's like playing ping pong, everyone's upgrading, updating, the bad guys, and then we have to do better on our end, so it's going back and forth constantly, every day we're working on it.
Matthew Connor: Yeah, I think it's fascinating, for me this is one of the most interesting times, I think, in the history of time, we are living in the most exciting time, and of course tomorrow will be even more exciting. But I think it gets really exciting because as the bad guys are using AI to attack, I think we see things like all the zero-day exploits that are occurring now in large numbers. In the past we used to be able to comfortably, as IT leaders, say, we're keeping up with patches, and we could feel reassured that the firewall is secure because it's up to date, our software is secure, our operating systems are secure, because they're fully patched, great. Well, that's no longer the case, and I think we're now in a day and age where we can no longer trust our infrastructure is safe just because it's up to date, because we know the bad guys are finding exploits at alarming speeds thanks to AI. And these aren't even advanced guys, right, in the past you had to be some elite hacker, and as long as you weren't bothering some elite hacker's targets, then you were fine, because they're coming after somebody much bigger, it's not a problem. Now some kid who doesn't even know how to code can get a zero-day simply by talking to AI, and so I think this opens up a whole new era for us when it comes to security. I don't think we can rely on traditional methods and tools like we used to, I think it changes the landscape completely, I'm curious your take on that.
Bill Guerrero: Yeah, I mean, it's almost like you asked me to ask me this question. This was, I mean, when I said this is the opening of the semester, you have everyone trying to get on the network now, you get that massive surge, and we're just trying to make sure there's reliability. But as you mentioned, it's not just your own infrastructure, it's your third parties as well. And we had one, certainly I'm sure you were aware, last semester, or let's say a few months ago, where our learning management system, Canvas, that company was impacted, nine hundred universities out there. We were not one of them, that's not one of our shops, and it's a great company, no challenges with that company, and that just shows you the immense pressure that's happening because of these zero-day interactions. Well, lo and behold, this weekend we had another one, and I mentioned the amount of devices and applications we have, you wouldn't believe it, when you think about your printers, printers on campus, as crazy as that is as a device, we have mobile credentials, and you allow students to print, tap their ID card to print, you've got so many credits, let's say, to print so many copies per semester. Well, we have a third-party vendor, best of breed, third-party partner, and guess what, they had a zero-day, they were hacked this weekend. Luckily for my team, my team was awesome, and with a third party, CrowdStrike, luckily with our security layers, it's stackable layers, not just one, we were able to remedy that in twenty-four hours, and nobody was aware of it. Frankly, in some sense, it was institutions like ours that let that company know, hey, by the way, you guys have been, they found some penetration and some access. And it shows you where the onus is, we're all trying to do the best, and the bad actors are trying, the printers are not where you'd think would be your access point, or building management systems, or wherever. These things are pervasive on these campuses, and we have to monitor all those systems. So my team is great, but it's just a lot of work to keep your institution safe.
Matthew Connor: Yeah, no, it really is, I mean, I think for everybody it's a real challenge, and I think what makes it extra challenging is the fact that it's changing so rapidly. I think the pace of it, it's funny, because I think it's happening for everybody, right. I've got two daughters who are both university age, our oldest is a senior this year, and she's a computer science major, she's a software engineer, and finance, and she spent the last three summers at Bloomberg as an intern, she's almost certainly getting a return offer to work at Bloomberg next year, and she's very excited about that. But the interesting part is, she's one of many, there are so many thousands of software engineers going into the workforce every year, and it's a really challenging environment these days, because AI has really changed it considerably. For a lot of software engineers, it's kind of taken the joy out of programming, because they no longer really get to code like they used to, Claude Code does all the coding for them, and they kind of supervise and give it direction, and that's not exactly what they got into. But here's where it gets really interesting, it becomes so challenging, because the stuff you have to keep up with, in terms of AI, the different programming languages, all these different things, in order to apply for a job, test, and do well. She's super bright, she won't have any problem with this, but I feel bad for the people who aren't at the top of the industry, if you're not the ones at the top, in the middle it's going to be really, really hard, because you've got to keep up with so much. And that's just for people coming into the industry, going into the workforce, now you need to look at all the people already in the workforce, and the cyber leader keeping up with all the changes, everything happening with IT, with cybersecurity, with AI, how that's affecting everything, the organization changing, all this change. I think for a lot of people it's stressful, because they don't know where it goes, where does this take us? So I'm getting to a question here, I think this is a long preamble to it, but I think it paints a picture of where we are in 2026 with all this change. How do people, as an IT leader, how do you deal with the mass, the rapid change, and the stress that comes with it, and help calm people about it, keep them calm knowing everything's going to be okay, we're on a good path? How do you manage everybody's, your own and everybody else's, stress in these changing times?
Bill Guerrero: Yeah, I'd say you're spot on, it definitely can stress you out in any industry. How many job boards can you see where it says, okay, the top ten jobs, which ones are the most protected from AI? Certainly cybersecurity is up there, and believe it or not, accounting is up there as one of the more safe ones. But when you see that kind of challenge, especially in our industry, higher education, how do we make the value still great, so students want to enter it and get the skills. On one side, just on the academic side, for students, we're trying to make sure they still feel like they have the skills to stay up to date, we do internships in-house, not just outside, hey, work with our cyber team, get that experience through your academic program over those four years, so it's kind of like stackable, get your certifications, but stack them as well. So we're working on that in all areas, not just cyber, but all areas of the IT stack. But when you talk about the pressures from leadership and your employees feeling like AI may replace them, you really have to balance those efforts. Shoot, I was just at a job site, true story, early this morning, at a job site, and we're talking about surveillance cameras, on a brand-new building, where do you put your cameras? And there are smarter people than I am sitting out there, literally in the mud at the construction site, and I'm sitting there kind of wearing my jacket, and I'm going to let them just have their conversations. But here I am, taking a picture of the job site, uploading it into the tool I use, and saying, hey, give me an example of where the best cameras can be, pulling data from whatever the appropriate sources are, I add a couple more prompts, and I've got a whole document, numerous pictures, printed out for me, and I send it to my team, not saying anything more than, hey, this is what I did while you guys were talking, and the responses are simple, like, man, you're doing our job. So those are kind of those normal human defaults, but we try to make sure the human element is still part of everything we do, let alone our institution, we're trying to make sure faith is part of it too, that human element, that AI isn't just taking away the humans, but we constantly try to bridge those gaps, utilize the tools so we can do things more and more efficiently. But we also have to make sure that our data is super clean, and you can use it as a baseline, but you still have to perform your job at a high level, you can't just say, hey, this is what AI produced, and whatever the job function is. But open conversations, I think, are the real critical thing, because we all have that anxiety, in some sense, because you want to save money, that's the high-level perspective, let's use AI so we can reduce operational expenses, and I don't think we're there yet, or the ROI isn't there yet, and I'm trying to figure out if AI is working.
Matthew Connor: Yeah, I think what we've seen over the last, it's been just under four years since ChatGPT came out, and I think it's developed so rapidly that there were a lot of people who early on saw it and were like, oh yeah, that's just a silly little autocomplete cute toy, but I see where it's going, we're not there yet. And I think that held true for a couple of years, and people tried to adopt it very quickly, and you saw big organizations, like Meta, go all in and say we're going to replace all our software engineers with it, and then they had to hire them back on because they were too early, and honestly too shortsighted about how they went about that, it was myopic at best, it wasn't even overly optimistic, it was true Zuckerberg fashion, not caring about the people or the consequences, and just moving. And I stand by that, I don't care if it ticks people off, I think it's a great example of poor leadership, just because we can, we're going to do something, without really considering the actual consequences and seeing it through. But I think where we get to today, specifically today, because I think it's different than it was even four months ago, and I think where we see AI today, the general run of models, like Claude, Grok, even Gemini, the leading models today and what they're producing, it went from, this is better than Google, which is what we got early on, to suddenly people using it as, hey, do my work for me, and it's like, you're not as good as me, move, let me just do that, thanks for trying. Now I think we're at the place where, with any amount of context, it likely does your job as well as you, and in some ways a lot better and faster, but not in a replacement way, and I think this is where we get to why we're in such a great place for quite some time. I think we're in the age of AI really, really helping, not replacing. Will it displace some jobs, will people move into others? I think so, and I think where it takes us is, the new software developers, the new everything, the people you have now are much more productive, they produce better-quality work faster, and it makes their job more enjoyable. For the knowledge worker today, I think it's far more enjoyable to work with Claude as your kind of assistant doing your work. Look at level-one tech support, oh my goodness, the way it just transforms level-one tech support, level two, level three, it's phenomenal, and so much easier. And then you talk about coding, you name it, I can only imagine it applies to basically almost every other job. But I think we're in this place where, as leaders, our job is to tell people, this is your tool, it's not about replacing you, it's about supercharging you, and now you're going to have the productivity of several people, but the enjoyment like never before, your job is about to get so much better. And I don't hear people talking about it like that, and I think that's a real mistake, I think the guys looking for money are fear-mongering, because it brings in more money, but I think it's nonsense, and I think they're going about it the wrong way, and too many people are listening to them instead of thinking about it this way. I'm curious, is that kind of how you see it, or am I just blindly optimistic here?
Bill Guerrero: No, no, I love your approach, your sentiment, your thoughts on this, because I just came back from a conference in Texas, and it was a wonderful conference, they did a great job, but you were also inundated with, I think it was fifty-plus sponsors, business partners, vendors, whatever you want to call them, from startups to established companies expanding their portfolio. And as you said, it could be either from level-one support, tech support, voice, you name it, business processes. And it was, in some sense you could call it speed dating, but it was like speed dating to the point of almost, you better date me or else. And it was definitely very overwhelming, in some sense, because, as you're saying, from the fear-mongering to how can you actually support your institution, who you're representing, trying to find that right balance, because you can't do it all. Because if you do it all, you're really going to put that impact on your personnel, your team, your staff, they're like, oh wow, they're just looking to replace us, without a strategy behind it. So I think there's a tough balance right now, because yeah, there's a lot of money to be had out there using fear, for sure.
Matthew Connor: This is a really interesting point. I think when you talk about these events, and they're so vendor-sponsored, even if they're not, as we talked about AI kind of displacing workers, I think ultimately what happens is there's going to be more and more startups, and we're already seeing it, the AI boom, I'm not going to call it a bubble, because I think it's the natural progression of, here's this new technology, just like we saw with the internet. The difference is, I think the money has gotten smarter, we're not seeing, you know, like Color.com kind of investing in AI, I think it's a lot smarter. And because of AI, these startups, a lot of them don't need a hundred million dollars to get going, thankfully, you can launch it and you just need a little money for the tokens and the servers, we're not talking a lot, so I think interestingly that creates a ton of these little startups. But this brings us to an interesting position, you, as the VP of IT, with a million different options, I think the interesting part is it goes back to that, nobody ever got fired for buying Cisco, right, the great sales line from Cisco. But I think what makes this really fascinating is a time where things are evolving so rapidly, and there are so many new little startups, and they're aggressively selling it as, you either start utilizing this, or somebody else is going to, and you're going to fall behind the times. However, I don't know how an organization takes a bet on a startup, on those, I think you've got either, this is really interesting, I'm really curious your take, but I'm not sure how any organization of any size can gamble on these startups. And I don't know how you do anything other than buy from something like the Gartner Magic Quadrant, where you can say, look, these are industry-leading, that's the only way we know this is fine, they're implementing AI, and I just don't know how you do it, because there are so many, you don't have time to go through and actually test a hundred different products in one category. So you have to use some sort of filter, like Gartner, am I missing something, is there some trick I'm missing? Because I've only got so much time in the day, and I've got to make a decision, I need somebody to filter this stuff for me, because there are just too many options, especially with all these startups, and can I even entertain those? So where do you land on that, how do you do it?
Bill Guerrero: Yeah, first and foremost, my career started at Gartner, believe it or not, so I'm a Gartner guy in some aspect, foundationally, when I was much younger, with much better hair. But yeah, certainly Gartner, and there are a lot of other great companies like that, that could provide that stamp of approval, in the Magic Quadrant, as you mentioned. And it's nice when a company, in this emerging category, let alone, this is relatively emerging, if it gets enough, or there's enough research to get into the Magic Quadrant, and you're in there, yeah, it's helpful for someone like myself in that position, to have to do that. But when you're being inundated every day by emails, phone calls, and I get it, I appreciate that other side of it, that you're trying to solve problems for institutions or industries, but to sift through which one makes more sense, I'm very mindful, let alone with my own team, because I don't want my team constantly vetting as well, they don't have so much time to attack one solution versus another. So I'm very mindful of that, because I get it on my side too, it gets squeezed different ways, let alone your current partners, they're like, hey, by the way, in their process of upselling, we have a brand-new tool that can actually do X, Y, Z, and you've got to be mindful of that as well. But how I try to do it is really just trying to figure out, almost like, hey, what's the biggest problem out there that we have, how can we attack that one first? Not to say I'm a Pareto guy all the time, but when you try to attack your biggest issues, you mentioned one specifically, we talked about level-one support, it's an easy one to attack initially, not to say it's easy, but it's an easy one to attack initially. And then there are other, you just find your pain points within your industry, so that could be clunky processes, maybe you have disparate different databases, and you're trying to merge that to provide easier solutions that fall slightly outside of your ERP, so you're trying to get that data cleaned, and once it's implemented, you'll actually have very happy, satisfied internal customers, because you're not replacing them, you're just trying to make their jobs easier. Once you set that up, it can be wonderful, so that's kind of how I'm approaching it with my team, but you are inundated, it's overwhelming, no doubt. And again, one other point I think is really important, that you're probably aware of, but to make sure your audience is aware, is the concept of tokens and credits. Because, as you probably know from some of my background, from a finance perspective, that fiduciary hat I have as a recovering CFO, this concept of tokens and credits, if you don't understand that, all of a sudden it's going to be a budget item, or an unbudgeted item, that's going to really surprise your institution. And when I'm talking about higher ed, and being inundated with all these solutions out there, we don't have unlimited money, obviously, like most organizations, but our industry has to be really mindful with our resources, to not only do our best to keep tuition down for our students, and produce a great product that students want, we can't just keep throwing darts and see what might work, and we have no problem failing, don't get me wrong, that's what's great about our institution, we have no problem failing and working fast on some things, but it doesn't mean it's unlimited. And so when we add the concept of being mindful of tokens and credits, and think about total cost of ownership, that I believe is the new aspect of TCO that people aren't even thinking of, that's more enlightening, because when you start realizing, hey, you don't have that in your budget, and you can't say we didn't know about it. So I opened up with that printing scenario, like, Matt, you've got five hundred dollars to print in the fall semester, and if you run out, guess what, your son or daughter's going to have to ask you, hey, can you put another hundred dollars on my card so I can print, whatever it is, if they're still printing, that's going to be the same thing with tokens and credits, or it's just going to be unlimited, and those bills are going to come, and for these institutions that are financially challenged, and they're trying to be great with AI, they're going to get a bill they weren't aware of. So those are kind of two aspects I think of trying to manage.
Matthew Connor: I think we're seeing that financial adjustment at a lot of organizations, where they're heavily utilizing AI, and now they're reducing their workforce slightly to compensate, because the productivity and output have increased. But I think the smart organization trims the fat from the bottom, and says, look, every large organization has some people who are just kind of coasting along, and historically that's kind of hard to find and filter out, it's just part of the nature of the beast of a large organization, it's not the same as a five-person startup, where if one of the five people is slacking, it's hurting everybody. If one of ten thousand people is slacking, even ten of ten thousand, the boat still floats. So I think we're starting to see that adjustment in a lot of organizations that are heavy AI users. And I'm curious, when it comes to problem-solving internally, now you have this power you've never had before, where you basically have, I don't want to say godlike powers, because that's kind of a lot when we're talking to Sacred Heart, a faith-based place, but in terms of IT, these are amazing powers we've never had access to before, where now it's like having a team of Microsoft experts, a team of coding experts, and you can very quickly develop solutions we'd never have been able to even consider doing, because of the amount of people you'd have to hire, and then what, for one job, and then what, you're going to let them go? So I guess my question is, now that you have this power at your fingertips, where do you land, do we grow this internally, solve this internally, or go externally and look for a solution, can we just code this up ourselves? Where do you land on that, is this something where you've started taking on projects that were historically unfathomable?
Bill Guerrero: Yeah, I'd say less the latter, doing work in-house, frankly, there are probably some amazingly talented students or faculty who probably can do this, whatever that problem is, if it's a project, a capstone, or whatever it might be, so we haven't tapped into that fully, as far as I'm aware. I know with my current staff, we don't have the bandwidth, in some sense, to be able to do that. But when it comes to external, one of the things we do really, really well, that I'm proud to be part of, and there's one part people don't realize in higher ed, you have this concept called shared governance, and sometimes it slows things down, because you need to get everyone's buy-in, in some aspects, and a degree of transparency. But with AI, and trying to make sure you're protecting the institution and everyone's not going rogue, especially with your data, we have a great governance structure that's separated by an academic side, on the teaching and learning side, where I obviously support the pedagogy and support the faculty with the tools, and support the students with their learning, so that's its own kind of pathway of challenges, that can really answer that second question, like, hey, can you do it in-house? That can help. But then the other side, the administrative side, where we're not running rogue, if there are new ideas, new applications that want to utilize an additional AI tool, or if someone wants to go outside of Copilot and ask, why don't we have an enterprise license with whoever, we go through our governance committee to make sure we're not running rogue, to protect our institution. So we look at that side externally, but certainly if we look internal, I think there's definitely some intrapreneurship out there that could really happen, because you have super-smart faculty, especially in computer science, but that doesn't mean it's just solely in computer science, there's a lot of processes in all institutions, but definitely higher ed, that are like, oh man, can I just figure this out to make this much easier? It could be a simple change request, like, what is the process to get a change request approved, does it require five forms and seven people to sign off on it? You could probably create a tool pretty quickly with numerous prompts, and follow that process much more easily than spending money on an external partner. So those are kind of the things, that's how I look at it.
Matthew Connor: Yeah, it's really interesting, because when you start looking at the organization as a whole, and even at the cybersecurity side, I think if you take traditional tools and you're not yet venturing out into, let me know what we need, we need AI to be monitoring our email, monitoring our endpoints, monitoring our network. I'm a huge believer that's where we are today, that you have to have something in place to see, wait, we've been breached, because the SOC may not even pick it up, because there was some zero-day exploit, and somehow Adobe is doing this, and if nothing's able to catch it, then what happens, they're in there, they do their thing. However, I think where it gets really interesting is, even if you're using traditional tools and going about it, working some framework, I think AI, let me be more specific, you can use something like Claude to say, hey, look, I'm going to give you read access, let's take a look at our firewall, let's take a look at our network, let's take a look at all of the settings, all of our stuff, and I want you to marry it up with our framework and tell me, where are we weak, what do we need to be doing here? It's only got read access, so now it's really hard for humans to hold that much information, to be able to see all the settings, you can't be an expert in everything. So I think this is something an organization can do today, that's very low risk, you don't have to worry about where's my data going, you've only given it read access to your stuff, you walk through it together, even if it's just through the browser, through the Chrome plugin with Claude, and you're walking through it together, like, okay, let's take a look at our firewall, let's take a look at our switches, let's take a look at all of it, and now tell me, where are we, what are we missing, oh, we misconfigured that, well, I didn't even notice, it's been working just fine. I think these are the things where it's those little gaps in security that can easily be picked up, be like, hey, how do we do a no-cost pen test, how do we pressure-test our system without going out and spending six figures on a third party to do it, and now you've saved that money, well, you know what, we're going to run our own pen test, because why not? You've got Claude that can run the pen test for you, or at least help you and give you the directions, and then you run it, why not save a fortune, if you're strapped and you still want to meet these requirements for the pen test and everything? And yeah, maybe the reason it has to be a third party is a requirement, but can't you say, no, we're going to do it internally, and audit it ourselves, why not?
Bill Guerrero: Yeah, spot on, on so many levels, when I think about that process, number one is, hey, what a great way to have your students in a cyber internship program, as they gradually learn how to then remedy, write incident reports, whatever it might be. But we do our pen tests, as you can imagine, I'm still in the CFO world in some sense, and one of my keynote speakers, we're talking about that kind of stuff as a keynote speaker, talking about pen tests, talking about emergency response game scenarios, whatever it is. Because I think a lot of our institutions, because you're so caught up in today, aren't really prepared, because when you think about emergency response plans, those are typically focused on active shooters, those scary things. But we're dealing with scary things all the time, when you're talking about ransomware and stuff like that, how are you responding to it, what's your access point? So from a pen test that's low-cost, that you just referenced, to the ones where, yes, I don't want to spend six figures on an external party, but certainly, as we walk through our own auditors, our annual audit, and talk about what we do to safeguard our assets, and then, certainly, when you get into your cyber insurance, shoot, you probably remember, five years ago, maybe less, those insurance policies were kind of a rubber stamp, hey, do you have MFA, yeah we do, okay, you guys are great. That was free money for insurance companies five years ago, not anymore. It was like, when the applications were pretty easy to complete and fill out, now, super, and rightfully so, super sophisticated, to make sure you do what you say you're doing, and so all of that, including the pen test, is part of a comprehensive plan, I'm certainly lucky I have a great team that gets this stackable kind of protection, it's not just, hey, it's our third party managing it, giving us alerts, or whatever, there are numerous ways. So it's going back to the very beginning, literally us sending out an email Sunday night, because school started Monday, so all the students were back on Sunday, we sent an email to all our students, faculty, and staff, kind of a list of how to protect their data, protect our institution's data, and protect our network. So all good stuff.
Matthew Connor: Yeah, it's interesting, because you take a look at products like Darktrace email, their security awareness that they do is so personalized, because it ties in so nicely, and you get this based off all the email that's coming in, and how it's done, it finds your weak spot, and then tests it via email. And so mind-blowingly cool, but I can't help but think, why not do the same thing, a brand-new idea, feel free to shoot some holes in this, but why not do the same thing when it comes to the organization's security, when it comes to, as you were talking about, incident response, doing a tabletop exercise, instead of it being a generic, hey, we're going to do a generic ransomware one, and then, oh yeah, all the stakeholders are like, yeah, ransomware's a real thing, we need to, yeah, that's useful. But after so many, it's like, well, we've already prepared for that, we've already got that in place. But now I think the next level is, you feed in your incident response, your SSP, everything you've got going on, into Claude, and now you get a personalized, where are we weakest, what are we missing, because I see it from my vantage point, and everybody at the table sees it from their own, but what are we missing? And then you get this very personal, oh crap, didn't even see that, marvelous, now you're kind of poking those holes in it and finding something very personalized and specific, that's just one example, but I think that could be phenomenally powerful, to be like, wow, we totally overlooked this aspect of it.
Bill Guerrero: Yeah, why not, totally agree. And I'd just say, I mentioned, and again, not to put a negative light on the Canvas incident, the LMS incident, I took it to my team, I was like, hey, are you guys aware of this? Because you know what, that could have been us, so let's take advantage of this opportunity to make sure we're protected, what's our continuity plan? And my team was super responsive, they were awesome, creating a continuity plan, working with the stakeholders on it. But what was written six months ago, is that still valid? So why don't we, through whatever engine, whatever it might be, because as everything is evolving, the bad actors are getting smarter, obviously, how do we continue to evolve it, so it doesn't become like any other emergency response plan that sits on a shelf collecting dust, those normal metaphors. But I think what you're saying is spot on, not only just doing pen tests and trying to do those scenario-planning exercises, I think every institution needs to be doing these, and not haphazardly, with intent, and it's not just a rubber stamp, like, okay, we did it last year on September fourth, we're good. You've got to take advantage of the tools you're talking about, and shoot, you probably know better than I do, just the timelines of certificate updates, and how that's shrinking, why don't we do the same thing with our continuity plans, or our pen tests? Because if everything else is shrinking, and everyone's getting smarter, the engine, everyone's getting smarter, we've got to continually keep evolving, as opposed to just every twelve months, or whatever it is, because it's audit time, or insurance renewal, or whatever.
Matthew Connor: Yeah, it's funny, because I think as you think about these frameworks, it's a great idea, and if you actually practice it, well, that's basically your whole job, and now you're constantly living in this framework, trying to keep it up, and yet you have another job, your job can't just be that. And it's supposed to feed in, it's supposed to be part of it, but it's so daunting, an SSP is so much information, sometimes it's hundreds of pages, that's a lot, right, that's just for a human being, a lot of stuff, and we're not good at it, and yet it takes less than a second for your LLM to read that and be like, ah, got it. It's no contest, right. And so as you go to implement these things and maintain them, I think that whole pencil-whipping, rubber-stamping, yeah, we did it for the auditors, that's a natural byproduct of going through it and being like, that was a lot, thank god we can get back to our job. But I think if we leverage the tools we have now, these large language models, throw that in there, and be like, great, now it's doing the heavy lifting, it's worrying about that, it's updating that, it's doing that, and now we get to play general instead of the troop in the trenches trying to do everything, now it can be the general kind of guiding it, and it becomes so much less burdensome to manage the entire framework. I haven't heard anybody really talking about it that way, but I think that's how you do it, it's so much information, why not let the computer do that, let the LLM do what it's great at, with lots of language, because that's a huge document, manage it, let's talk about it, what can we be doing to improve this, here's our system, why not? Is that where we are today, and people should be doing that, or am I just being overly Pollyanna about AI use?
Bill Guerrero: Yeah, I think you're spot on. I think there's probably still hesitancy in multiple ways, because it's almost like, if I do this and I perform that function in a fraction of the time, am I becoming obsolete as a person, like, hey, anybody could do this. And so I think there's probably hesitancy in that, as opposed to being more efficient and effective, and then adding in the human qualities of critical thinking, and being industry-specific, but definitely there's hesitancy. Shoot, we just had that with our contract review process, and you look at, for me, there are certain clauses I look at, my CISO looks at certain specific ones, my legal team looks at certain specific ones, and you can find those pretty quickly, in some sense. But yeah, you could drop this into any model, and certainly Gartner has one, you drop it into Gartner's model, and it works great, and spits out comparisons, like, okay, this is the benchmark, this is the industry, this is what you're missing, sort of, hey, it's up to you on your risk levels, what makes sense for your industry, and it's up to you. So you still have the human element, like, hey, you probably should add this to your indemnification clause, for example, I don't think so, because I don't think that partner's going to go for it, we're going to lose it, whatever it might be, but you still have the human element, and it saves a significant amount of time. Does it mean my job's going to go away because I dropped the contract-review part of my job into it? Now I'm just more effective and efficient, and as we become more, work isn't going away, there's a lot of work everywhere, and if we could be smarter and more effective using any of these AI tools, I think we should be taking advantage of them, for sure. But I think there's hesitancy, still.
Matthew Connor: Well, and I think this is awesome that you brought that up, because it's another thing I don't hear people talking about, and yet it's like how these stand-up comedians find these things, like everybody's got it, and they can put a voice to it, and you've put a voice to this, and maybe I've just not heard it, but this is fantastic. That hesitancy to not use it, or not tell people you're using it, because it happened so fast, and people are feeling like, well, am I being replaced? And I think it's a matter of reframing it, and I think this goes back to the fear-mongering, people are worried they're going to lose their job because AI is going to replace them, but I don't think that's the case at all. In fact, going to the contract review, you become so much more efficient, you basically have, they're not a legal expert, and it says that at the bottom every time it reads the contract, it's not giving you legal advice, but boy, did it make reviewing that contract so much more efficient, so much easier, and then it points out things you probably would have missed, because you're not an attorney, you don't think in those terms, and you would have missed that. And then to have paid an attorney, that slows down the process so much, but so much better for you to run it, leverage the tools you have, put in your two cents, and then run that past the attorney, who's also doing the same thing, and then great, now you've kept the human in the loop. And that's the thing, I think at the end of the day, it's not about replacing our judgment with AI, it's about getting AI input so we can make that decision, just like your example with the insurance, you may or may not want to take this on, this may be a liability, and for business reasons, you decide you're going to assume this risk, you're going to make this business decision. Yeah, it can't do that for you, even if it understood the business, it can't make that judgment call, it can advise, and say, hey, I'd like, what's it, it knows a lot of information, but it still lacks the artistry of human intuition, understanding all the personalities at play, the finances, all the dynamics of the institution. So, as the leader, I'm going to make this call, but at least you get that input so you can make it. And I think people are missing that, that even at the lowest level, whether you're talking about level-one tech all the way up to the CIO, getting that input and having that assistance makes you better, not replaceable. And are we not making that clear enough to people, in the day-to-day and in the media, so that there's this general fear of, hey, who even am I if I'm not the one doing the job?
Bill Guerrero: Correct. Yeah, you feel almost like a fraud, like, okay, I did this, but I actually didn't do the work, I didn't do the review, so I'm going to do it and it takes five days, and meanwhile everyone's waiting, when you could have done it in ten minutes, and then put your personal human element on top of it. So yeah, I think it's a hurdle, I think we're getting there, but it's going to take a little more work to get there.
Matthew Connor: Yeah, I love that. God, you're so good at bringing out those feelings that people are having, I think everybody has it, it's such a natural human response to this.
Bill Guerrero: Yeah, my example was just this morning, literally, I wasn't goofing around, but I was like, you know what, smarter people deal with it, you're under, at the construction site, doing that, I'm just sitting there being aloof on the outside, taking a couple photos, different angles, putting in some of my thoughts, my experience and background, into the prompts, spit out a wonderful document, let alone photos, shared it, and it was more kind of in jest, but the human element, even joking, like, oh wow, you're replacing me, or I didn't even need to be here, those kinds of quick questions, that's the quick human response, because of the fear or hesitancy of using AI. And for me, I would take those photos, I would take that document as your baseline, because the formatting, the writing, all of that, is much better than I can write, that's for sure. So why couldn't I use that? And you obviously always put that disclaimer, this document was supported or helped with AI, whatever it is, but it's a professional-looking document that could be shareable, and you can make it even better with all your intimate institutional-specific knowledge. So I think hopefully we're getting there, but it's going to take a little more time.
Matthew Connor: I love that you said it should be the baseline, and I couldn't agree more, we have to get people to where the standard is no longer the human-produced product, but the standard should be that impressive AI product that a human has then tweaked and reviewed, and that should be the baseline, and we build from there. If you're getting the purely human version, it's like, well, why didn't you just, did you not leverage AI on this? And it's funny, because there are times now, on the MSP side of the house, you'll see some work, and I'm like, did you not run this, did you not use, because it gets to the solution faster, if you had just run that through like you were supposed to, you would have gotten there. You could do it the old-school way, but that's going to require going through more steps, and instead you would have gotten to the answer faster. So it's really funny, that should be the new baseline, the new standard, and getting people there, I think will be the psychological challenge, because if it comes from up top, from the leaders on down, then there's that fear. But this needs to be kind of a grassroots thing, where it's like, hey, the lowest-level employees are producing amazing product like never before, it's so polished and professional, that's the new standard, look at Jane go, look at Joe go, they're amazing, that's the new standard. But if it comes down from up top, then it's like, then what are we? And how do we inspire it to come from the bottom, I think that's the challenge, how do we get our people to be like, yeah, this is the new standard, look at me go.
Bill Guerrero: Absolutely, yeah, I'll give you one little side, part of my life historically was being a baseball coach, college-level baseball coach, and I'm restarting that part of coaching baseball again, obviously on the side, after hours, there's only so many hours, and I still want to give my students the best possible experience, so I'm all in, doesn't mean I have more hours in the day all of a sudden, so I'm all in, and I've got this going on this weekend, and it's been a few years since I've been in the dugout, that kind of stuff. I've got tryouts, I've got scrimmage, I've got practice schedules, and I have these documents all over the place, in my garage, and it's like, finding it on, as scary as it sounds, a thumb drive somewhere, all this kind of stuff, because it's so long ago. And I was like, hey, pull out, I put my prompts in, hey, run me my tryout schedule, my practice plan, whatever it is, obviously it spits it out in thirty seconds, I was able to download it, tweak it, because now it's like, oh yes, that's what I want to do, that's what I don't do anymore, that's not appropriate, I still had a human element, and edited and adjusted it, I wasn't just going to use what my engine produced. I was able to save so much time though, as opposed to going into my garage or finding wherever that is on whatever drive. But it's a perfect example, I saved so much time and produced something super polished that I'm excited about, with my modifications, and I'm okay with it, it's a hundred percent, so yeah, I love that. So it doesn't mean I'm inauthentic, or that I'm not a good coach. I think here's the thing, we often go to the, there's only so much time in the day, and while that's true, the other thing is decision fatigue, you can only make so many decisions in a day, and if we look at how quickly AI can process the data, make those decisions, and reduce that to where we can quickly make easier decisions, that's enjoyable, right? It's hard when you're digging through all the facts and figures and details, but when you can step back a little bit, have all that work done for you, and make a quick decision, analyze it, great, so much easier. And now, at the end of the day, you're left as a human going home feeling great, this was a really productive day, it was great, I'm not exhausted, I'm not depleted, I've done great work, and you return to your personal life so much better off. I feel bad for people who are trying to compete with AI and trying to perform at that level, you're killing yourself, man.
Matthew Connor: Yeah, I mean, what's the statement that's consistent now? AI is not going to replace you, what's going to replace you is the person who knows how to use AI.
Bill Guerrero: Yeah, exactly.
Matthew Connor: Bill, I think we could do this all day, this has been amazing, I can't wait to have you back on the show, because I think there's so much cool stuff. As AI continues to be a big part of our lives, it's clear you have this really good grasp of the human element, and how that affects people, and I think this is such an important aspect, I'd love to have you back on again as we further explore the human side and the effects of AI, can't wait to have you back on. But before we go, can you tell everybody where they can find out more about you and more about Sacred Heart?
Bill Guerrero: Sure, sure. You can find us online at sacredheart.edu, and certainly you can find me on LinkedIn, that's the only social media platform I'm really on, it's William Guerrero, Sacred Heart, you should be able to find it.
Matthew Connor: Awesome, well, Bill, thanks, and until next time.
Bill Guerrero: All right, thanks, bye.







