Alexander opens with a framing of his role that is broader than most CISOs on this podcast have offered. He has been consulting to small and micro businesses since 1993, which gives him a ground-level view of what cybersecurity looks like, and mostly does not look like, for organizations that have no IT department and one QuickBooks machine. The pool guy who called him after getting ransomed and losing $35,000 in payroll from a single locked machine. The accountant who had no idea they were required to follow specific data regulations. The law firm sharing client documents through Dropbox with no vetting of who accessed them. These are not hypotheticals. They are the pattern Alex has watched repeat itself across 30 years of consulting, and the through-line is always the same: the business survived long enough to believe it was not a target, and then the environment changed around it while the business stayed still. His argument is precise and difficult to dispute: walking through lightning storms holding a rod works until it does not, and the environment has changed so dramatically in the past two years that the historical odds no longer apply.
The AI and education section is where Alexander's position at Educate 360 gives this episode a perspective unavailable elsewhere this season. He is not just using AI. He is building it into the training products his company sells. One brand, TRACOM Group, which focuses on behavioral styles and how people communicate across personality types, has trained agents to simulate the other side of a conversation so learners can practice real interactions with a realistic conversational partner. The implications for professional development, compliance training, and cybersecurity awareness extend well beyond a single course. He also makes one of the clearest statements about vibe coding and its limits this podcast has featured: giving Claude a general description of what you want to build is not materially different from giving a human developer a general description. Requirements, architecture, and feature definition have to come first. The developers who succeed with AI coding tools are the ones with 35 years of context about how software actually gets built, what the edge cases look like, and what it means to release something that other people depend on. The vibe coders who fail are the ones who discover the $4,000 bill, the broken production system, or the leaked credentials after the fact.
The most forward-looking and provocative exchange in this episode is Alex and Matthew working through the economics of AI-powered cybercrime. The current subsidized pricing environment means organizations are building dependencies on capabilities they may not be able to afford at full cost. More unsettling is the calculation around criminal organizations: groups that have accumulated hundreds of millions of dollars through ransomware and fraud could acquire the hardware needed to run a capable open source model locally, at a price point that represents a rounding error against their reserves, with no access restrictions from Anthropic or OpenAI to worry about. That observation, made in real time during the conversation, is one of the most candid and practically alarming moments the podcast has captured this season. Alex closes where he begins every conversation on this topic: an eternal optimist who believes the good guys will ultimately win, but who understands that the win only comes to organizations willing to bring AI to a fight that was already being fought with AI by the other side.
Resources mentioned in this episode
This episode is brought to you by CyberLynx.
CyberLynx is a Bethesda managed IT and cybersecurity company. Local techs you know, not a call center. Month-to-month. 24/7 intrusion detection.
We help growing companies with managed IT, help desk, backup and recovery, and a fractional CIO.
Talk to us at https://cyberlynx.com/contact, info@cyberlynx.com, or 301-798-9170.
AI Agents and the Truth Engine for Human Health with Matthew Matturro - Ep 230
CMMC, M&A Integration, and AI Upstream Defense with Bobby Barts - Ep 228
Physical Anchors and the Data Age: How Manufacturing Wins in AI with Chris Stierle - Ep 227
CISO
Educate 360
Matthew Connor: Matthew Connor here, host of the Cyber Business Podcast. Today we're joined by Alexander Tushinsky, CISO at Educate 360. Alex, welcome to the show.
Alexander Tushinsky: Thank you very much. Happy to be here.
Matthew Connor: Happy to have you. Before we get too far in, a quick word from our sponsors. Hackers are getting smarter — is your security keeping up? Cyberlynx sells industry-leading, AI-powered cybersecurity solutions that detect threats in real time, so you know about an attack before the damage is done, not after. Learn more at cyberlynx.com. And now back to our show.
Alex, for those who aren't familiar, can you tell us about Educate 360 and your role there as CISO?
Alexander Tushinsky: Sure. Educate 360 is a professional development and training company. We focus on teaching technology skills — primarily to working adults who are looking to upskill, change careers, or deepen expertise they already have. We deliver training across data science, AI, project management, cybersecurity, and a range of other technical domains. We work with individuals, but a large part of our business is partnering with enterprises to upskill their workforce. As CISO, I'm responsible for our entire security posture — protecting our data, our systems, our learner and client information, and increasingly, making sure our AI initiatives are governed in a way that's trustworthy and secure.
Matthew Connor: That's a great combination — a company whose core business is teaching technology skills, with a CISO who's navigating the AI governance challenge at exactly the moment the industry is figuring it out. Let's start there. Educate 360 teaches AI skills. How has AI changed what you're teaching, and how fast is that curriculum having to move?
Alexander Tushinsky: Faster than any other technology shift I've seen. The curriculum for an AI course that was current six months ago may already need significant updates — not because the fundamentals have changed, but because the tools, the capabilities, and the best practices have evolved so rapidly. What we've had to build is a delivery model that can stay current. We have instructors who are practitioners — people who are actively working in the field — so when the field moves, they move with it. That's the only sustainable model for AI training right now.
The other shift is what students are coming in expecting. Three or four years ago, someone enrolling in a data science program was thinking about Python and statistical modeling. Today, even that learner is asking about LLMs, about agentic workflows, about how AI changes the tooling they already know. The baseline expectation has shifted dramatically, and we've had to meet people where they are rather than where we thought they'd be.
Matthew Connor: And from a security standpoint — you're a company that handles learner data, enterprise client data, and increasingly AI-generated content and interactions. That's a meaningful attack surface. I think the education sector broadly is underestimated as a target. How do you think about the threat landscape in your environment?
Alexander Tushinsky: The education sector has historically been under-resourced on security, and threat actors know that. We're not a bank, but we hold valuable data — learner PII, enterprise client information, payment data, in some cases proprietary content that has real competitive value. And we operate in a distributed model — instructors working remotely, learners accessing our platforms from anywhere, enterprise clients integrating with our systems through APIs. Every one of those connection points is a potential attack vector.
What's changed with AI is the sophistication and volume of attacks targeting organizations like ours. The phishing attempts we see are far more convincing than they were a few years ago. Social engineering attempts are more personalized — they reference real details about our organization, our people, our clients in ways that suggest either good reconnaissance or AI-assisted targeting. Both are concerning.
The insider threat dimension is also real in our environment. We have instructors who have access to enterprise client information for their engagements. Managing that access appropriately — making sure people have what they need and nothing more — is an ongoing operational challenge.
Matthew Connor: And that principle of least privilege — giving people exactly what they need and no more — is one of those fundamentals that sounds simple but is genuinely hard to execute at scale, especially in a distributed environment. AI actually creates some interesting opportunities there — tools that can continuously monitor access patterns and flag when someone is accessing things they don't typically need, or when usage patterns shift in a way that warrants investigation. That behavioral layer is where I think machine learning has been quietly doing important work for years, long before LLMs made everyone aware of AI. Products like Darktrace are the best illustration of that — they don't need a specific rule for every possible threat. They just need to know what normal looks like, and then they stop what isn't. How does your security stack approach that problem?
Alexander Tushinsky: We've built a layered approach with behavioral detection as a core component. Our EDR platform has strong behavioral capabilities — it's not just signature matching, it's pattern recognition against established baselines for each endpoint. Our email security uses machine learning to catch what signature-based tools miss. And we monitor our cloud environments — we're primarily AWS and Microsoft 365 — for anomalous activity across both platforms.
What I've invested in building is the visibility foundation first. You can't detect behavioral anomalies in data you can't see. So we've done significant work on logging coverage — making sure we have telemetry from every meaningful system — and on centralized analysis so that signals from different sources can be correlated. A user accessing unusual data at an unusual hour, combined with an outbound connection to an unknown endpoint, is a very different story than either of those events in isolation. Getting that correlation to happen automatically and surface to an analyst with context is where AI adds the most value.
Matthew Connor: Correlation is everything. And the frustrating reality is that in many breaches, all the signals were there — they just weren't connected in time. The attacker sat in the environment for months doing low-and-slow reconnaissance, and individually every data point looked benign. It's only in aggregate, with the full picture, that the story becomes obvious. AI that can hold that full picture in memory and connect the dots in real time is a qualitative leap from what human analysts can do at scale. And it's increasingly available — SentinelOne, CrowdStrike, and others are making that multi-signal investigation something that happens automatically rather than taking hours of analyst time.
Let me pivot to AI governance specifically, because at Educate 360 you're in an interesting position — you teach AI, so you presumably have a lot of internal AI usage, and you're also the person responsible for making sure that usage is secure. How do you govern AI internally when your culture is inherently enthusiastic about adopting it?
Alexander Tushinsky: It's a genuine tension, and I think the honest answer is that you embrace it rather than fight it. If I tried to lock down AI usage in an organization whose core identity is teaching AI, I'd lose immediately — and I should. The goal isn't restriction, it's responsible enablement.
What we've built is a framework that distinguishes between use cases based on the sensitivity of the data involved. AI tools interacting with publicly available information or internally generated content that has no PII — that's a relatively permissive environment. AI tools that touch learner data, enterprise client data, or anything with regulatory implications — those go through a formal evaluation process before anyone uses them. Vendor security review, data handling assessment, a determination of whether a business associate agreement or data processing agreement is required, a look at what the model does with the data it receives.
The policy layer matters, but culture matters more. My team's job isn't just to write rules — it's to help people understand why the rules exist and to make it easy to do the right thing. When someone wants to use a new AI tool, I want them to come to me, not go around me. That means being accessible, being helpful, and being willing to say yes when the answer can reasonably be yes. If security is perceived as the place where good ideas go to die, people stop telling you about their ideas.
Matthew Connor: That's the right philosophy and I think it's one of the hardest shifts for security teams to make — from gatekeeping to partnership. The organizations that get it right are the ones where IT and security are seen as enablers rather than obstacles. And in a world where AI tools are proliferating at an extraordinary rate, the teams that can evaluate and onboard them quickly and safely have a real competitive advantage. The ones that can't either create shadow AI risk or fall behind on adoption. Neither is a good outcome. What does your AI evaluation process actually look like in practice?
Alexander Tushinsky: We start with a standard questionnaire that covers the key dimensions — data handling, model training policies, security certifications, breach notification processes, subprocessor relationships. That's the baseline. For tools that pass initial screening, we do a deeper technical review if the data sensitivity warrants it — looking at API security, authentication requirements, data residency, and what controls exist around output storage.
We've also built in a use case review step that I think is underrated. It's not just "is this tool secure" — it's "what specific problem are we trying to solve, and is this the right tool for it?" That conversation often surfaces alternatives that are already approved, or reveals that the use case is narrower than initially described and can be handled with something simpler. It slows things down slightly, but it means the tools that do get approved are actually being used purposefully rather than experimentally.
On the policy side, we've established clear principles: AI output gets human review before it goes to a client or affects a decision that matters. Data that shouldn't leave our environment doesn't get sent to external models. People are accountable for what they do with AI, not just for the inputs they provide. Those principles sound simple but they require reinforcement — we do regular training and we make the policy easy to find and easy to understand.
Matthew Connor: Human review before anything consequential — that's the right line to hold right now. And the accountability principle is important because it shifts the frame from "what can AI do" to "what are you doing with AI." The tool is a tool. The human is still responsible. That framing matters both culturally and practically — it keeps people engaged and thoughtful rather than passive consumers of AI output.
I want to ask about the workforce development angle, because I think it connects directly to security. We're at a moment where AI is changing job descriptions faster than the workforce can adapt. What are you seeing from enterprise clients in terms of how they're thinking about AI upskilling and what they actually need their people to know?
Alexander Tushinsky: The demand has shifted significantly in the last eighteen months. Early on, enterprise clients were asking for AI awareness — broad introductions, conceptual understanding, helping people not be afraid of the technology. That's still there at the entry level, but we're increasingly seeing demand for applied AI skills — people who can actually build with AI tools, who can evaluate AI outputs critically, who understand how to work with agents and APIs and prompt engineering in a practical way.
The security angle is showing up too. Clients are asking for training specifically on AI security awareness — how do I recognize an AI-generated phishing email, what are the social engineering risks specific to AI, how do I think about data governance when my team is using AI tools. Those are questions that didn't exist three years ago and now they're in real demand.
What I find encouraging is that the clients who are investing in this are doing it thoughtfully. They're not just doing a one-time training and calling it done — they're building ongoing programs, they're tying AI literacy to performance expectations, they're creating internal communities of practice where people can learn from each other. The organizations that approach it that way will build genuine capability rather than just checked boxes.
Matthew Connor: That ongoing model is so much more effective than the annual training paradigm, especially in a domain that's changing this fast. The organizations that build a culture of continuous learning around AI — where people are sharing what they're discovering, experimenting, building on each other's knowledge — those are the ones that will be meaningfully ahead in two or three years. It's the compounding effect of consistent investment versus the one-time event.
Alex, this has been a fantastic conversation. Before we go, can you tell everyone where they can find out more about you and Educate 360?
Alexander Tushinsky: Absolutely. Educate 360 is at educate360.com — you can see our full course catalog, our enterprise offerings, and find a program that fits wherever you are in your AI and technology journey. You can find me on LinkedIn as Alexander Tushinsky — happy to connect and talk security, AI governance, or workforce development with anyone who's working through those challenges.
Matthew Connor: Fantastic. Alex, thanks so much for coming on. Until next time.
Alexander Tushinsky: Thank you. Really enjoyed the conversation.