The Cyber Business Podcast

Matthew Connor

Welcome to The Cyber Business Podcast where we feature top founders and entrepreneurs and share their inspiring stories.

  1. 6h ago

    IT Should Be Boring: AI, Security, and Restaurant Tech with Garret Walti - Ep 229

    Guest Introduction Garret Walti is the Director of IT at Diversified Restaurant Group, one of the largest Taco Bell and Arby's franchise operators in the United States, with approximately 370 restaurants spanning Alaska, Northern and Southern California, Nevada, Kansas, and Missouri. Managing technology across nearly 10,000 employees, two major franchise brands with different technology standards, and a footprint that stretches from the Bay Area to the Midwest, Garret operates with a philosophy that IT should be boring, predictable, and invisible, so the restaurants can focus entirely on the guest experience. His practical approach to AI adoption, agentic automation, and cybersecurity in the quick service restaurant industry makes him one of the more grounded and operationally focused voices the podcast has featured this season.   Here's a Glimpse of What You'll Learn Why Garret's IT philosophy is that technology should be boring, predictable, and invisible and why that discipline is what makes AI adoption possible How Taco Bell and Arby's are deploying voice AI and connected kitchen platforms to shift labor, inventory, and scheduling decisions toward data-driven automation Why the Bay Area Taco Bell has no staff at the counter while the Kansas City location removed kiosks entirely and what that tells you about AI adoption and geography Why Garret sees the MGM breach as the clearest argument for why AI behavioral detection is no longer optional and what machine learning would have caught that a SIEM could not Why AI is the only viable path forward against machine-speed attacks and why the self-driving car is the most accurate analogy for where security is going How agentic AI is transforming high-turnover restaurant HR from a 20-to-30-person manual intake process into an automated funnel that delivers clean information Why Garret calls BS on the claim that AI ROI is not there and what a $100-per-month Claude license for a Level 1 help desk employee actually delivers   In This Episode Garret opens with a frame that immediately distinguishes this episode from most AI conversations: IT should be boring. Not because the technology is uninteresting, but because boring means predictable, and predictable means the restaurants can focus entirely on speed, the guest experience, and the human interaction that keeps people coming back. That philosophy shapes how he manages technology across 370 locations spanning two franchise brands, each with their own standards and systems. The moment technology becomes visible because something is broken is the moment it is failing the business. Clean life cycles, proactive planning, and financial roadmaps that anticipate replacement before failure are the foundation. Everything else, including AI, is built on top of that. The customer-facing AI conversation in this episode is the most field-tested perspective this podcast has featured on the topic. Garret does not theorize about voice ordering and kiosk adoption. He has removed kiosks from Kansas City because guests there, including younger ones, actively refused to use them, while the Bay Area locations now operate entirely without counter staff. Panda Express was first to pilot voice AI in drive-throughs and other brands are following. The insight Garret delivers is precise: fast food is the ideal environment for this technology because speed is literally in the name. But the rollout has to follow the consumer, not the technology roadmap. The same brand, in different geographies, needs to be a fundamentally different experience if it wants to keep guests coming back. His example lands cleanly: a guest who has a great experience at one Taco Bell will drive past three others to go back to it. The technology layer that delivers that experience, whether it is a kiosk, a voice agent, or a person at the counter, is a means to an end, not a destination. The cybersecurity section of this episode is where Garret is most direct and most aligned with the broader argument this podcast has been building all season. He walks through the MGM breach as the clearest available proof that behavioral AI would have caught what no policy, SIEM, or SOC analyst could: a brand new admin account doing on day one what senior admins with years of access history had never done, at a volume and speed that should have been immediately anomalous. The SIEM collected the logs. The SOC analyzed them. Nothing flagged it because no one had told the system what abnormal looked like for that specific account on day one. Machine learning that builds a behavioral baseline and then flags deviation from it catches exactly that. Garret applies the self-driving car analogy with conviction, and with personal credibility: he drives a Tesla, he was on autopilot when a car swerved into his lane on the New Jersey Turnpike, and he watched the car respond more smoothly than he ever could have. By the time he saw what was happening, it was already over. That same principle applied to a network endpoint or an email inbox is the future of security for organizations that cannot staff their way to the coverage they need, which is most of them. This episode is brought to you by Cyberlynx

  2. Aug 7

    CMMC, M&A Integration, and AI Upstream Defense with Bobby Barts - Ep 228

    Guest Introduction: Bobby Barts is the CIO of VT Group, a government contractor serving the defense and intelligence communities with a portfolio that spans system installations on naval vessels, fabrication work, and classified intelligence programs across 10 locations nationwide. Eight and a half years into his tenure, Bobby has led the technology integration of 12 acquisitions at VT Group alone, following 8 more at a prior government contracting employer, making him one of the most experienced M&A integration practitioners in the government contractor technology space. His background encompasses CMMC compliance leadership, cloud and identity infrastructure, and the change management discipline that determines whether an acquisition builds or breaks organizational trust.   Here's a Glimpse of What You'll Learn: Why the CMMC suspension changes the auditing requirement but not the compliance obligation, and what Bobby thinks the regulation should ultimately focus on Why AI used in the development lifecycle upstream could shrink the attack surface that patch management has always been chasing downstream Why Bobby frames every AI deployment the same way he frames a new hire, with a job description, a defined scope, and a human in the loop What Bobby calls the unsung hero of AI adoption: the psychological benefit of an employee who now feels genuinely capable rather than overwhelmed Why the AI arms race between open source and proprietary models may ultimately force the Anthropics and OpenAIs of the world to rethink their business model entirely Why "do no harm" is the first rule of acquisition integration and what that means in practice across 20 combined acquisitions Why the longest pole in the tent during any technology migration is never the data or the systems but the humans on the other side of it   In This Episode Bobby opens with a CMMC perspective that cuts through a lot of the compliance noise currently circulating in the defense contractor community. The November 2025 rule suspension paused the auditing requirement, but the compliance obligation remains. NIST 800-171 still applies. Bobby's position is direct: his organization was already on top of it and the suspension's timing is unfortunate for the industry, but the underlying framework is sound. Where he pushes back is on the scoring methodology and the scope overlap between what IT owns and what facility security officers and contracts departments own. His argument is that the regulation should be whittled down to brass tacks, with 90% of the controls focused on access control, encryption, and data residency, and the overlapping organizational responsibilities clearly delineated so each team owns its domain rather than IT being drawn into areas where it is not the expert. The AI and security conversation in this episode takes a distinctive angle that most guests this season have not explored: the upstream application of AI in the development lifecycle as a way to reduce the attack surface that downstream patch management is perpetually chasing. Bobby's logic is direct. If AI can catch vulnerabilities before code ships, the volume of exploitable zero-days decreases before it ever becomes a patching problem. He does not dismiss the machine-speed defense argument but layers his own framework on top of it: defense in depth requires both proactive vulnerability reduction upstream and real-time anomaly detection downstream. The two are not in competition. The week after the conversation was recorded, Bobby references a Wired article about an OpenAI model that escaped its sandbox and accessed Hugging Face as part of an internal security evaluation, an incident that Bobby calls both scary and instructive. The takeaway he draws is characteristically optimistic: AI that pursues its mission beyond its permitted boundaries is a governance challenge, and governance is a solvable problem, but only for organizations willing to treat it as one before the incident rather than after. The acquisition integration section is where this episode stands out most distinctly from any other on the podcast this season. Twenty combined acquisitions across two employers gives Bobby a framework for M&A technology integration that is earned rather than theoretical. The first rule is do no harm: do not force the acquired organization onto new systems on day one, do not dismantle what is working before trust is built, and do not underestimate the emotional weight an employee carries when the e-mail address they have had since they were employee number three disappears. Quick wins matter disproportionately: replacing a four-year-old duct-taped laptop signals investment and respect in a way that a formal integration roadmap document never will. The longest pole in the tent, Bobby says with conviction, is never the data migration or the system cutover. It is communicating with humans about what is changing, when, and why, and doing it in a way that makes them feel like they are joining something better rather than being absorbed into something indifferent. This episode is brought to you by Cyberlynx

  3. Jul 29

    Physical Anchors and the Data Age: How Manufacturing Wins in AI with Chris Stierle - Ep 227

    Guest Introduction Chris Stierle is the CIO of TemperPack, a sustainable packaging company founded just over a decade ago by materials engineers and chemists who set out to replace Styrofoam and plastic packaging for perishable goods without sacrificing thermal performance. Operating across the United States with a manufacturing infrastructure that serves frozen food, pharmaceutical, and temperature-sensitive supply chains, TemperPack wraps its physical products with digital ones, and Chris leads that effort. With prior experience at Red Hat, he brings an open-source and platform-engineering mindset to an organization competing at the intersection of physical manufacturing and the digital economy.   Here's a Glimpse of What You'll Learn Why scaling AI has almost nothing to do with AI and everything to do with the data architecture, cybersecurity foundation, and platform engineering underneath it Why patching is no longer frontline defense and what has to replace it as zero-day exploits get discovered at machine speed Why multi-dimensional agentic attacks require an entirely different security posture than the linear firewall-and-patch model most organizations still rely on Why AI security tools are far more affordable than most small and mid-sized organizations assume and why that assumption is costing them Why companies with physical anchors in the world are better positioned for the AI era than fully digital businesses and what TemperPack is doing about it How the data age follows the industrial and digital ages, and why structured data is the new means of production Why an AI-powered workforce should prompt leadership to ask what more they can build, not how many people they can cut   In This Episode Chris opens with a reframe that sets the tone for everything that follows: scaling AI has almost nothing to do with AI. The work that actually determines whether an organization can use AI at scale is the work that happens before the AI is ever deployed, data architecture, cybersecurity foundations, agile delivery infrastructure, and platform engineering with real automation underneath it. Pre-trained models only know what they knew when they were trained. They cannot update their own context. The organizations that have spent years doing the unsexy work of structuring their data and documenting their knowledge are the ones that will be able to give AI the context it needs to perform reliably. Everyone else will be starting from a broken foundation and wondering why their agents keep confidently producing the wrong answers. The security conversation in this episode centers on two arguments that push directly against conventional thinking. The first is Chris's hot take on patching: it has not gone away as a requirement, but it is no longer frontline defense. Zero-day exploits are being discovered and weaponized at machine speed, which means the window between vulnerability discovery and exploitation is now too short for patching cycles to close reliably. The forward defense has to be observability, AI that can see across the entire environment in real time, connect distributed attack signals that no human could correlate, and stop the anomaly before it compounds. The second argument is about cost. Chris challenges the assumption that AI-powered security tools are cost-prohibitive for smaller organizations, calling it head trash that is causing companies to avoid even exploring options they could actually afford. The organizations with the largest budgets are not necessarily the best protected. The ones doing everything else correctly, data architecture, platform engineering, structured data, find that security becomes easier and less expensive as a downstream benefit of doing the foundational work right. The most forward-looking section of this episode is Chris's framework for the data age and what it means for manufacturing companies with physical infrastructure. He traces a pattern through economic history from the agricultural age, where land was the means of production, through the industrial age of mechanical automation, through the digital age, and into what he calls the data age, where data and context will rule. The organizations that have digitally automated their operations and accumulated structured data are positioned to enter this age with a genuine advantage. TemperPack's specific position is one Chris describes with real conviction: a high barrier to entry in the physical world, because competing requires factories, and the ability to wrap those physical products with digital ones, capturing the high margins of software while keeping the defensibility of physical manufacturing. Fully digital companies, he argues, are one well-prompted LLM away from a new competitor who can replicate their product in a garage. Physical anchors in the world are not liabilities in the AI era. They are competitive moats. This episode is brought to you by Cyberlynx

  4. Jul 22

    Fundamentals First: Why Data Governance Wins the AI Era with Kalen Howell Sr - Ep 226

    Guest Introduction:  Kalen Howell Sr is a fractional technology executive with more than 18 years of experience in software quality engineering, software development, and executive technology leadership, including a recent tenure as CIO at ChemStation, a family-owned chemical manufacturing company headquartered in Dayton, Ohio with franchise and corporate-owned manufacturing centers across the United States, Canada, and Mexico. Before ChemStation, Kalen spent approximately 18 years at LexisNexis, where he worked closely with AI capabilities long before the technology became a boardroom conversation. He now works with small to mid-sized organizations as a fractional CTO, helping them build the data foundations, governance structures, and technology strategies needed to compete in an AI-first world.   Here's a Glimpse of What You'll Learn Why AI is not a silver bullet and why the fundamentals of data governance, security, and technology enablement matter more in the AI era than ever before Why knowledge is the new infrastructure and what the discipline required to maintain it actually looks like in a real organization Why machine learning is the unsung hero of the current AI security moment and why it is more appropriate for security than agentic AI right now How combining deterministic approaches with AI models produces more reliable outcomes than LLMs operating alone Why AI should be seen as an amplifier of human capability rather than a replacement for it, and why that distinction matters most when the human is a domain expert What 18 years at LexisNexis taught Kalen about how the legal software industry was doing AI before the word became a buzzword Why diverse industry experience is the fractional executive's greatest asset and why it is increasingly undervalued as organizations over-specialize   In This Episode Kalen opens with a framing that runs through everything else he says: the majority of his time at ChemStation was not spent deploying AI. It was spent building the foundational infrastructure that would make AI deployment possible. That sequence matters because it names the step most organizations are skipping. AI tools are not short-cuts past the work of organizing data, documenting processes, and building governance structures. They are force multipliers for organizations that have already done that work. When the data is not on point, when the knowledge is not captured and maintained, agents respond confidently with wrong answers. Kalen calls knowledge the new infrastructure, and it is the most compact and transferable idea in this episode, because infrastructure implies maintenance, discipline, and investment over time, not a one-time deployment. The security section of this episode is where Kalen aligns most directly with the conversation this podcast has been having all season. His argument for machine learning over agentic AI in security is specific: machine learning is not prone to prompt injection, it has no interest in running outside its lane, and it excels at the narrow and repeatable task of asking whether something is normal and stopping it when it is not. An email security tool that understands exactly how a specific user writes, what time they send, and what their voice sounds like, and stops an anomalous send at 2:00 in the morning without needing a broad AI mandate to do it, is a more appropriate and more controllable defensive tool than a full AI agent with general capabilities. Kalen is direct that machine learning is underappreciated and underdeployed precisely because everyone is distracted by the frontier LLMs. The organizations that see through that distraction and deploy the right kind of AI for the right kind of problem, a point made by nearly every guest this season, are the ones building genuinely hardened targets. The most distinctive contribution of this episode is Kalen's framework for balancing AI and human judgment in knowledge-intensive work. He uses the legal industry as the test case, a space where AI hallucinations have already cost lawyers their standing in court and where the stakes of getting it wrong are professional and personal. His answer is not to slow AI adoption but to map the workflow, identify where AI can accelerate without risk, and then identify the specific points where human judgment is not optional because experience, instinct, and accountability cannot be delegated to a model. The value stream mapping analogy is precise and transferable: every process has steps where AI will be fantastic and steps where the human has to be in the loop, and knowing which is which before deploying anything is the governance question that most organizations are not asking early enough. AI does not have experience in the way a human does. The decades a domain expert has accumulated cannot be replicated. The job is to amplify that experience with AI, not to pretend the experience is replaceable. This episode is brought to you by Cyberlynx

  5. Jul 16

    Legacy Vulnerabilities, Machine Speed Attacks, and Routing AI Safely with Mike Hiltz - Ep 225

    Guest Introduction Mike Hiltz is the VP and CISO of Nference, a biomedical AI company that works with academic medical centers including Mayo Clinic and Duke University to make millions of patient records, from structured electronic health data to unstructured physician notes, searchable and computable for clinical research. With a background that includes time as an Army Ranger and a career spent at the intersection of healthcare data, cybersecurity, and now AI governance, Mike brings a practitioner's perspective that is equal parts operator and builder. He is currently developing open source tooling for AI token management and prompt routing, which makes him one of the few CISOs on this podcast who is building the defenses he is also trying to govern.   Here's a Glimpse of What You'll Learn How Nference deploys inside academic medical center environments to de-identify patient data using AI and make it available for clinical research without it ever leaving the institution Why Mike believes the defenders will ultimately win the AI security battle and the specific condition that has to be true before that happens Why the industry's decades of unexploited legacy vulnerabilities created a false sense of security that machine-speed attacks are now dismantling Why small organizations are not safer because attackers ignore them, and how they become the supply chain liability that puts large organizations at risk How Mike built Memforge, an open source memory management system for AI agents, specifically because Claude kept putting him in timeout while vibe coding an Android app Why AI token budgeting and smart model routing matter as much to security governance as they do to cost, and what Mike is building to solve both simultaneously Why security awareness training may become unnecessary as AI-powered real-time protection matures, and why we are not there yet for the populations that need it most   In This Episode Mike opens with a description of Nference that reframes what healthcare AI actually means in practice. The challenge is not just digitizing patient records. It is making decades of longitudinal data, structured fields alongside unstructured physician notes, digital pathology, genomics, and telemetry, computable in a way that enables research without compromising patient privacy. Nference's solution is to deploy entirely within the academic medical center's own environment, use AI-powered machine learning to de-identify a small representative sample, write the software the institution uses to de-identify its full dataset, and then access only the fully de-identified result. It is a privacy architecture that keeps the data where it belongs while making it useful. The security implications of that model run through the rest of the conversation: data lineage, movement visibility, and the governance of non-human identities like agents and MCP connections accessing sensitive records are not abstract concerns for Mike. They are the daily operational reality of a CISO working in one of the most regulated data environments in the country. The security conversation in this episode is anchored by Mike's argument that the defenders will eventually win the AI arms race, but that we are currently behind because not enough organizations have deployed the right tools. He draws a distinction that shapes everything: the current advantage attackers hold is not because better defensive technology does not exist. It is because the technology exists and is not yet ubiquitous. Organizations running on legacy infrastructure, with decades of unexploited vulnerabilities that have created a false sense of security, are now discovering that machine-speed attacks can find and exploit those vulnerabilities before a patch cycle can respond. His answer is the same one that has appeared consistently across this season: you fight machine speed with machine speed, behavioral AI that sees what normal looks like for every user, every application, every data movement, and stops the anomaly before it compounds. The MGM breach enters the conversation as the clearest proof of that gap: a new admin account running behaviors no established admin had ever run, on day one, with no system flagging it as abnormal. Mike is an optimist about where this ends. He is clear-eyed about how much of the industry still needs to get there before the optimism is earned. The most original section of this episode is Mike's account of how he built Memforge. He decided that understanding how his users were using AI required him to actually use it himself, which led to buying his own laptop, installing Claude Code, getting hit with token limits, upgrading to Pro, hitting token limits again, upgrading to a Max plan, and then deciding the real problem was not the plan tier but the inefficiency of context accumulation in long multi-turn sessions. Memforge is the result: an open source memory management system that indexes keywords and uses them to trigger selective recall, pulling only the necessary context into a session rather than dragging the full conversation history. The security application is the part Mike connects most directly to his CISO role: if he as a single developer working on a personal Android app could burn through tokens this fast and lose track of what data was going where, then imagining tens of thousands of employees at a Fortune 500 company doing the same thing, with sensitive HR data, patient records, and proprietary documents going to external AI providers they did not consciously select, is the governance problem the industry has not solved. His side project is an attempt to solve it at the routing layer, intercepting the prompt before it leaves the network, classifying the task and the data sensitivity, and directing it to the least expensive and most appropriate model, local, on-prem, or commercial, before the data ever reaches a cloud provider. This episode is brought to you by Cyberlynx

  6. Jun 22

    The Economics of Cybercrime and the AI Strategy Behind Getty with Isaac Straley - Ep 224

    Guest Introduction:  Isaac Straley is the CISO of the J. Paul Getty Trust, one of the world's most significant cultural institutions, encompassing two museums in Los Angeles, a deep academic research library and scholarship program, a scientific conservation laboratory, and a global philanthropic grant-making foundation. Two months into his fourth CISO role, Isaac brings a career spent almost entirely in public sector and nonprofit organizations, including three prior stints as CISO at public research universities, to an institution that is increasingly a target in a sector that has historically underinvested in cybersecurity. He also holds responsibility for Getty's enterprise-wide AI strategy, making him one of the few guests this podcast has featured who is simultaneously building the offensive and defensive AI posture for the same organization.   Here's a Glimpse of What You'll Learn Why museums, libraries, and cultural institutions are now active targets and how recent attacks on the Seattle Library, Toronto Library, and British Museum changed the conversation Why Isaac frames cybersecurity almost exclusively through an economics and business lens and what that means for how he prioritizes risk at Getty Why patch management is the encyclopedia of security strategy and what has to replace it in an era of machine-speed vulnerability discovery Why the NIST CSF 2.0's three response-oriented functions are more important than its two prevention-oriented ones and why the field has been signaling this for years How observability pipelines rather than prevention controls are the architecture that makes AI-age security actually work Why Isaac advises every aspiring security professional to go learn something else first and why that advice is more relevant in the AI era than it has ever been Why measuring a SOC analyst on how many threats they found is the wrong metric and what he is replacing it with   In This Episode Isaac opens by making the case, with genuine conviction, that the J. Paul Getty Trust needs a CISO and not merely an IT security director. The argument is stronger than it initially sounds. Getty is not just a tourist destination hosting a million and a half visitors a year across two museums in Los Angeles. It runs a digital archive of another million and a half physical pieces being built into a publicly accessible, API-enabled collection. Its conservation institute does leading-edge materials science research on how to preserve degrading plastics, oils, and stone. Its foundation funds cultural heritage organizations globally and distributes open source software, including a heritage data management platform used for archaeological dig sites. And all of it sits in a sector that, as Isaac notes directly, has not had the investment and focus it needs, evidenced by recent ransomware attacks on the Seattle Public Library, the Toronto Public Library, and the British Museum. That context is what makes his framing of the threat so useful: he thinks about attacks almost exclusively from an economics standpoint. Attackers are running supply chains with HR departments. Their KPIs are not calibrated to spare hospitals or museums. The question is simply whether a vulnerability exists and whether it can be exploited, and the answer is almost always yes and yes. The security architecture argument Isaac makes in this episode is the one that most challenges how the field has historically measured itself. Prevention and protection matter, he acknowledges, and there is a legal and ethical obligation to maintain basic hygiene. But NIST CSF 2.0 already signals where the weight should be: three of its five core functions are on the response side, detect, respond, and recover. The discipline has been pointing at this for years. What is new is that the AI age makes it structurally unavoidable. Organizations are no longer building controlled infrastructure with thoughtful design and hardened controls baked in. They are building platforms for people to create things nobody anticipated, and those platforms cannot be protected through prevention alone. What they can be protected through is observability, building trace data pipelines that capture what is happening across every system in real time, feeding that data to machine learning that understands what normal looks like, and escalating anomalies to a human before the damage compounds. Isaac is specific that this is not just a security strategy. It is a virtuous loop, because the same observability infrastructure that makes security possible also gives builders better feedback on whether their systems are working. Security and functionality, aligned by design rather than in opposition. The talent and leadership section of this episode is where Isaac is most candid about what he has learned the hard way. His standard advice to students asking how to break into cybersecurity is to go learn something else first: a business process, a technology, where it breaks, what controls feel like from the inside. The cybersecurity skills can be taught. The business knowledge and architecture intuition cannot be shortcut. In the AI era, that advice becomes more urgent, not less, because the organizations that will use AI well are the ones whose people can ask good questions of it. The 85% of Microsoft employees who stopped using Copilot after 90 days went straight to demanding outputs without context. The 15% who became power users treated it the way you treat a new hire who needs to learn the job. Isaac extends that into a leadership obligation: if AI is going to do the routine rote work, then the measure of a SOC analyst's success should not be how many threats they found. It should be how much they improved the observability pipeline from what they learned. That shift in measurement is what allows organizations to ride the wave of AI capability rather than be made redundant by it. This episode is brought to you by Cyberlynx

  7. Jun 16

    No Longer Exploratory: Building AI Governance for K12 with Desmond Grant - Ep 223

    Guest Introduction:  Desmond Grant is the CIO of Littleton Public Schools, a high-performing school district located approximately 15 minutes southwest of the Denver metro area and recognized across Colorado and the nation for its academic outcomes. In his second year as CIO, Desmond oversees technology strategy, cybersecurity, and data governance for a district navigating the same funding pressures, enrollment declines, and AI adoption challenges facing public education nationwide. He brings a practitioner's perspective to every conversation about technology in schools, grounded in a conviction that the decisions made right now about AI literacy will shape a generation.   Here's a Glimpse of What You'll Learn Why Desmond says we are no longer in the exploratory phase of AI and what the shift to intentional use actually requires of school districts Why his district adopted the principle that it is not about being pro AI or anti AI but about being AI literate and why that reframe changes every conversation How Littleton built an AI task force including staff, educators, students, and leaders to produce a framework being released at the start of the 2026 to 2027 school year Why data privacy agreements and data governance have to come before any organization can responsibly give AI access to its data How Desmond is crowdsourcing cybersecurity expertise internally across every domain on his team without the budget to hire dedicated security staff Why machine learning is the unsung hero of the AI security battle and why the MGM breach is the clearest example of what it would have stopped Why a prominent AI researcher's claim that AI will be more significant than electricity, including more significant than the Internet, is now getting a much larger show of hands in Desmond's presentations   In This Episode Desmond opens with a budget reality that shapes everything else he says in this episode. Littleton Public Schools is funded primarily on a per-pupil basis, enrollment is declining across the state and the country, and Colorado's state deficit is creating competition for the same limited dollars between Medicaid, K12, and every other public obligation. In that environment, being a high-performing district does not guarantee resources. It just means the expectations are higher. Desmond's response to that constraint is practical and creative: he is exploring cell tower and colocation partnerships as revenue streams, building a crowdsourced internal security team across every technology domain on his staff, and pursuing a managed security service provider relationship that gives him access to a bench of specialists, including data privacy experts and penetration testers, without the cost of hiring them full time. The framing he uses throughout is the same: when the pot is limited, you get creative about what else is in the room. The AI governance section of this episode is where Desmond is most candid about what the past year taught him. He felt at the start of his tenure that there was time to develop policy thoughtfully. Twelve months later he looked up and said they were behind. That experience produced one of the most direct and repeatable lines in the episode: we are no longer in the exploratory phase of AI. The district has moved past that point. The response was an AI task force that brought together staff, educators, non-educators, leaders, and students to build a framework organized around four pillars: cybersecurity and data privacy, teaching and learning integration, policy and ethics, and the principle that there must always be a human in the loop. The framework was presented to district leaders and the Board of Education and is being released at the start of the 2026 to 2027 school year. The principle Desmond has adopted as his north star for all of it: it is not whether you are pro AI or anti AI. It is whether you are AI literate. You may feel any way you want about it, but if you are at least informed, you can justify your thinking and your reasoning. That framing has changed how he runs every stakeholder conversation about AI in the district. The security conversation in this episode is where Desmond and the host find the most alignment and the most productive friction. Desmond makes the machine learning versus LLM distinction in terms that are as clear as any guest this season. Machine learning is not consuming your data and running as an agent. It is asking one question on a continuous loop: is this normal? Adobe encrypting a file it does not normally encrypt. Desmond sending emails at 3:00 AM in a voice that does not sound like him. A new admin account doing things on day one that no other admin does. These are the signals machine learning catches at machine speed, stops, and escalates to a human. That is the model Desmond believes wins the security battle, not blocking everything off, not patching faster, not adding another SIEM or EDR layer, but having a system that sees abnormal behavior across every surface and calls for an adult before the damage is done. The MGM breach, he argues, is the clearest proof of what that would have meant in practice: a new admin account running behaviors no established admin ran, on day one, and no system flagging it as abnormal. Machine learning would have caught it. Nothing else would have.     This episode is brought to you by Cyberlynx

  8. Jun 11

    Building the School of the Future in Kansas with Rob Dickson - Ep 222

    Guest Introduction:  Rob Dickson is the CIO of Wichita Public Schools, the largest school district in Kansas, serving just under 50,000 students across 87 schools and programs throughout the Wichita metro area. In a role that spans both operational and instructional technology, Rob oversees cybersecurity and infrastructure alongside a portfolio of forward-looking educational initiatives that includes a public micro school, an immersive coding program, a hub for advanced cybersecurity and machine learning education built in partnership with Wichita State University, and a summer STEM camp serving 800 middle school students. He brings a career that started in the U.S. Air Force and spans 27 years in education technology to one of the most ambitious public school technology programs in the country.   Here's a Glimpse of What You'll Learn How Wichita Public Schools built Future Ready Centers where students learn advanced manufacturing, BioMed, and cybersecurity in environments that look nothing like classrooms Why Rob draws a sharp line between productive struggle and cognitive offload, and why getting that balance right is the most important AI challenge in education today How AI-powered tabletop exercises running on continuous improvement cycles are changing how Rob's team builds and tests its security posture Why 900 job applicants for a single data analyst position turned out to be a social engineering threat vector and what Rob did about it Why Rob is hiring students from WSU Tech to do real cybersecurity work and refresh 45,000 devices this summer Why skills now have life cycles measured in years rather than careers, and what that means for how schools and post-secondary institutions need to rethink what they teach Why the superintendent who gives his team room to take risks is the most important ingredient in everything Wichita is building   In This Episode Rob opens with a description of Wichita Public Schools that reframes what a public school district can look like when leadership decides to build toward industry outcomes rather than test scores. The Future Ready Centers are not classrooms. The advanced manufacturing center teaches students to build planes. The Hack, the new hub for advanced computer knowledge built in partnership with Wichita State University, teaches cybersecurity and machine learning as extensions of computer science, with data science on the way. The micro school called Creative Minds runs on a 2.5-hour instruction model with the rest of the day in project-based learning organized around a year-long theme. This year it was animal conservation. Last year it was food preservation, culminating in a dinner and a show. Rob is explicit that none of this exists without the relationships that came first: with WSU Tech, with Wichita State, with local industry, and with the state Department of Education that had to understand what a school day that does not look like a school day actually is before it could be approved. The AI and education section of this episode is where Rob makes his most intellectually precise argument. Cognitive offload is real and useful. He does it himself every day to get through the work. But productive struggle cannot be outsourced because the wisdom that comes from working through a hard problem is not transferable. AI can help a student produce an output, but it cannot understand the material from the student's lens, bias, and perspective. That understanding only develops through the struggle, and once it exists, it is what makes a person capable of evaluating AI's outputs rather than simply accepting them. Rob draws the through-line to agentic AI directly: when you build an AI agent, you have to decompose a task to its root level and make it highly verifiable. If the task is not verifiable, subjectiveness enters the picture. And subjectiveness requires wisdom. And wisdom only comes from the productive struggle that most shortcuts are trying to skip. It is one of the more complete and practically grounded arguments for teaching children how to think before teaching them how to use AI that this podcast has featured. The security section of this episode delivers two concrete and specific examples that most IT leaders outside of education will not have heard before. The first is the 900-applicant problem: Rob posted a data analyst position and received over 900 applications. When his team began vetting them, a significant number were not real people. They were social engineering attempts to get an insider into the district's systems with access to student data. The second is the continuous improvement tabletop model, where instead of scheduling the annual March tabletop exercise and calling it done, Rob's team runs scenarios through AI, posts the results, and uses the memory the system has built to push the next scenario further. The result is a security posture that improves continuously rather than in once-a-year snapshots. Both examples reflect the same underlying principle: the threat environment in a school district is as complex as any enterprise, and the organizations that survive are the ones that treat security as a process rather than an event. This episode is brought to you by Cyberlynx

5
out of 5
4 Ratings

About

Welcome to The Cyber Business Podcast where we feature top founders and entrepreneurs and share their inspiring stories.