
Loading summary
A
You're listening to the Cyberwire Network, powered by N2K.
B
There's pros and cons to supporting a vibe coding world. I mean, ultimately, the joke to travel is everyone's going to be assistant developer. I don't think we're going to be able to avoid that. If your role touches technology at some point in the near future, you will become an AI developer.
A
Hello and welcome to Data Security Decoded. I'm your host, Caleb Tolan, and in this episode I sat down with Kevin Mortimer from the University of Reading to discuss the importance of community tied to his work. The threat landscape as it relates to higher education and research universities, and the AI realities for education.
C
Let's get into it. Well, welcome to the podcast. I'm really excited to have you on and I know you've spent your entire career in technical roles and I'd really love to hear more about that journey and what led you to leading a technology team at a university.
B
Yeah, cool. Well, first of all, thanks for having me. And so I've been in technical roles now for around 25 years and most of that as leadership competitions as well. I. When I first left uni, I actually went to a local isp. That's still a quite big thing because broadband hadn't really kicked off at this point and. But I learned a lot of the raw skills around. I learned how to support teams and how to work with teams. But also the actual ISP had a payment gateway platform and they won the few payment payment gamma parts of like worldpay and something a few others. So I learned a lot about infrastructure and security in that point. That really kind of sort of set the scene for me. So I joined in 2017 and we were one of the first Nutanix customers, from the first Rubric customers, one of the first MIST customers. So we've got quite a few firsts across the infrastructure space. And I'm always looking for new technologies come in and be disruptive and see how we can get that value from those early days of interactions as well. You can really help shape the product to what you need that way. And all those companies I've mentioned there, we have done some really good stuff with. And that's for me, what really excites me to say, that's why I go to work every day. It's not about how can we be better, what are we going to do? And my team of 25 always trying to do things better.
C
Right, right. I love that. I love that. And I know you do a lot of volunteering outside of your technical roles and your traditional 9 to 5 job, leading cub Scouts on Tuesday nights, serving as chair of governors at your local school board. These are some of the things that you mentioned me, what, what draws you to that kind of community investment and how does it shape your role at the university?
B
I, I think for me it's about, you know, being better at something and, or helping others be better and by me giving. So a lot of it's based around my, my children and, and I want to kind of give them some really good morals in terms of life's bigger than them and I want them to really focus on how they going to help people and, but by helping them, by not doing things for people but actually being better and helping guide and bringing in different levels of expertise and supporting people through that. So they're the sort of things that I really enjoy through for doing the volunteering pieces.
C
Right, right. I love that mindset. Well, let's dive into some of the, some of the nitty gritty of the cybersecurity aspects of your job. And so I believe it was about seven or eight months ago at the end of 2025 and PwC put out a report that labeled higher education, obviously the sector that you work in as a prime target for espionage and cybercrime, cyber events in particular. From your seat, what does that threat reality actually look like day to day?
B
The main difference for me is the diversity of the type of customers, whether staff or students that we have, the levels of tech savviness that they have. Some people are really good at spotting things like phishing campaigns, some really aren't. So it's about building the tool tools out to try and stop them getting through in the first place, but also trying to ensure that our customers actually have the right tools themselves to be able to identify things. So at the moment they know they can report things to us if they believe they've got a suspicious email. Those suspicious emails sometimes are genuinely suspicious. Often they're just not expecting it. But they feel that confidence they can ask the question and I think that's for me the value piece that we're trying to add had there. But because it's such a vast level of experience we have across the people using our technology, we've got to create, allow for the lowest common denominator but not hold back people back there. Let them grow if they want to grow as well. I mean a lot of research is pushing boundaries with AI and some of the research. So we need to make sure that we're supporting them but also keeping everyone safe underneath that.
C
Right, right, absolutely. And you've been in your role for nearly 10 years now. We're approaching that and over the time we've seen a lot of shifts in geopolitics, we've seen a worldwide pandemic happen and you're at a university that has a lot of valuable research data. So what did that period of time where like during COVID you had, like I said, some of the most valuable research data out there. Was there a spike in espionage activity? Was there like what was the cyber landscape like for you and how did you respond?
B
So one of the things that I've always been really fortunate about is our CDA Sherpur has always been very supportive of me and what I've been trying to do and bringing things in. The day of lockdown, when everyone went home, we had a conversation. So we need to turn on MFA for everyone and make it mandatory. There's no option. This is a Saturday morning call we had and we jumped straight onto the call with the exec board and just got their approval too because it's quite a big changed people as well.
C
What was that conversation like? Was it a difficult one?
B
So with the board it was. Yep, absolutely. Just get it done. That was the, the, the university are very supportive of what we're trying to do to keeping safe. I think most organizations have cyber risk. They're top of the risk register now what that means will vary across organizations but it's, it's really about how we then kind of use the, the situation that we're in to kind of highlight that and then use those make to make decisions. We're not being too reactive to a trying to be actually more thinking forwards of how can we mitigate a risk rather than wait till something happens. But during COVID generally there was an opportunity for us to bring in some better measures. We rolled out our protection, how we manage our protection within rubric change as well. So rather than doing NAS cloud direct, but painting to our own Azure tenancy, we actually put our research data into the Rubrik cloud default platform which meant that we had a degree of separation from the data. So if we were compromised, we knew that even the data, the data would still be protected and be secure. And instead of examples, I guess that we're always trying to look at how we can improve things and not be happy that something's working. If something better comes along, let's go for it and give it a go. Right?
C
Right. And as a higher education institution, many organizations were affected by the canvas attack and it really kind of shifted how or it highlighted how attackers goals have really shifted over the years. It wasn't about locking down systems, it was about extracting student data to fuel targeted spear phishing campaigns. Are you seeing that pattern more broadly? Is that something that you see in your role regularly?
B
No, there certainly wasn't. Certainly still is to be fair. I direction of trying to stop the university working. It's not always about the data. Sometimes it is kind of a DDoS style kind of approach, just let's shut organization down. But I think one thing that has really shifted in recent months is actually the move to the supply chain for education. Some of those providers that provide student data records, they've now been been targeted more than actually the universe themselves. Once that data has then been extracted from that, that's then been turned to then attack the universe itself. So there have been examples where data from a third party compromise has then been used to actually target students to try to get some money out that way. So it's a secondary attack that they're looking to now go for. So in there it's getting more and more complicated and more convoluted. And we are fortunate in the UK that we have some great partners with JISC and Microsoft supporting us through that piece across the whole sector as well to give us that visibility.
C
Wonderful, wonderful. And we have to talk about AI. I have to know what your AI implementation is looking like. And I know you're looking at building some anomaly detection response playbooks where you're leveraging some AI agents to detect something suspicious, spin up a live mount, defend against the anomaly, defend the environment. Where are you on that journey and what does building that kind of autonomous response look like in practice?
B
So I guess we're at the early stages. For me it's about looking forward about where you want to go and have that vision around things. We have an AI policy we haven't adopted too widely across the organization yet. I think there's been a lot of trouble like how the financial and commercials around that looks like as well as then the data sovereignty question. How are we going to govern that data? What those guardrails looks like? These challenges are being worked through. So the scale part is hard. We have some researchers that we know we're actively using AI for example, but then there's guardrails around what they can and can't do, the actual agents themselves. This is for me where with Rubrik it's not just a standalone tool. I want to bring in all of the technology across my infrastructure that I'm supporting. So if I get a security detection from our firewall, I can then use that to then interface with Rubrik and then Rubrik can tell me maybe there might be suspicious activity from a couple of days prior which can then feed back and give us to add no signpost as to where in the firewall logs to maybe go back to, which then can shut down certain paths if we detect there's certain activity happening, influence our micro segmentation and how we interface with the hypervisor. So it's the ecosystem that I'm really interested in as individuals, systems and people that's very difficult to actually orchestrate with. Introduction of Vibe coding and MCP platforms, having something to bring all together and have an agent to agent communication, that is where we're going to get the value and scale to be resilient with our systems and services. Because these systems, they're great in isolation, but as a collective they're even more powerful and data very rarely only exists in one place to highlight these security issues.
C
Right, and you already touched on a couple of my next questions, so we'll go ahead and shift into those. So I'll start. You mentioned mcps and we also have talked a little bit about token management and things like that. So in a university where you have researchers, students, staff, tons of different universities are huge organizations. They all have varying different needs and risk profiles as well. So how are you approaching the governance question of token management and what MCPS you're actually looking to deploy?
B
We've got a very limited official AI kind of toolset at the moment that we are supporting as an organization. I think a lot of that comes down to kind of the price model and how we're going to manage that licensing and which tools should we shouldn't be using. Personally, I want to use a tool that's great for code to looking at Claude and Codex. They're the ones that my teams are going to get value from because those tools aren't geared up for that sort of capability. Whereas if you, if you look at Copilot, that's great for managing your productivity data and they sort of. So he's trying to find the right tool for the job, but then putting the governance around it and educating those in those governance roles about how AI works and what that means. It's very easy to read the horror stories and some of the, some of the fake news that's out there and there's a lot of AI washing as well to contend with. So how do you know what's true and not. So these are all the things that we kind of working through at the moment. Now I'm using CLAW to help write just some scripts at the moment to allow me to achieve things. I have a few private instances in my own personal labs of different technologies that I've started to interface with with the MCP part of it. But that's my own personal data at that point, just to kind of get a feel. So as soon as we come for those governance steps, we can then take those concepts and bring them in internally. But like, yeah, it's quite a complex world of trying to. Of education really about how AI works and what things mean and don't mean. Right, right.
C
It's not a straightforward question.
B
It's a very long answer. Sorry.
C
Yeah, no, no, no, it's very good. And you mentioned Vibe coding earlier as well. So now that we have these tools that can help anyone become a coder to some extent. And as somebody who cares so deeply about security, how does this democratization really outweigh new risks or does it just move the problem elsewhere?
B
There's pros and cons to supporting a Vibe coding world. I mean, ultimately the direction of travel is everyone's going to be assistant developer. I don't think we're going to be able to avoid that. If your role touches technology at some point in the near future, you will become an AI developer. You want to be an AI creator, not an AI consumer is definitely the concept that I want to hold myself to financially generate income, not spending. So that's kind of the approach that we're trying to think about things with. But it's just bringing all those bits. Bits together. And for Viper coding itself, so the examples that I'm using with Viper is to use proof of concepts and do some scaffolding on projects. So I've been looking at a mobile application for universities. Not just a student one, but an overall one, but building into it things that can interface with our timetabling system, with our networking tools. Not doing those integrations directly, but just building the capability that by plumbing in some variables, it would less allow us to connect and do the bits. For me, that's those proof of concept pieces which I think Vibe coding is great at. As soon as you want to take that into a product that you're managing, that's when you need to put the better controls running. You need to have quality assurance around things. But yes, I think Vibe coding is great for proof of concepts. Hone the PET projects soon as you go on to get in scale, that's when you just need to have more eyes and on things and have a bit more validation.
C
And who even knows between the time when we're recording this and when the episode goes out? At the time of recording this, Fable was just released and then retracted. Mythos, we've been hearing about it for weeks now and its capabilities. So when Anthropic releases even more sophisticated models, when OpenAI releases these like more frontier models, then more of that's just going to become easier and more accessible for that vulnerability scanning and all of that as well.
B
Well, so I just. So I think Shadow IT has been around ever since there were IT teams. Right. And I think with Shadow AI as well now coming in, the accessibility of it though is what is quite dangerous. I think around that data governance and with Mythos and Fable, and we always seem to be talking very much around the US based organizations that are creating AI tools. If we look the other direction around the world, there's less guardrails in place, there's less of those controls. The intentions around removing Fable from the marketplace might be different to the outcome it was trying to achieve, but you won't get that from a Chinese product. It'll just be opened up. And I think the more we try to control these AI tools, the more people that have lesser intentions will just find a way around them and it'll be consuming. We shouldn't say they open a floodgates and let people fill the booths. But how to find a happy medium is definitely a challenge there.
C
Right? A little hot take sprinkled in there. I appreciate it. So as we're kind of rounding out, what are three actionable steps that you want every IT and security leader that's focusing in higher education to take right now before the next attack hits?
B
I think the. There's a couple of key points people can do. I think first and foremost make sure your permissions are right, your data. So look across your data sets, understand who's got permissions to that, then start monitoring those permissions as well. If you're not, if you don't know who's got access to things and how they've been accessed, you don't know what anomalies look like. Those two things themselves are massive. And I think the final thing really is just looking at about how those attack services are going to come in. And there are already some really good AI tools out there that can look at public recordings of people's videos and voice, particular senior leaders who often have those Sort of public presentation and kind of roles and I've then been turned into ways to attack an organization to try and extricate money and other things. So I, I think educating people around how to identify spots, some of the deep fakes and having those maybe some tells and some secrets that you only you know with people, if you is is the way forward, how you then manage that and govern that, that's a whole different challenge. But there's some. The basics around data management essentially I think is where people need to be investing in first, right?
C
Absolutely. The fundamentals are always important. It's going to be true. Time and time again I want to ask you two inconvenient truths about AI in higher education where you sit as a technologist. So one that universities need to accept about how they're actually deploying and governing AI today and one that AI vendors and tool builders need to hear about whether their products are truly built for the higher ed environment.
B
So I think from a education lens, every student is using AI tools. Students generally are very switched on with technology. They are also not to care too much about privacy either. If you look at how they interface with social media, they're very open to using those tools where the older generations can sometimes be a little bit more reserved. So it's how do we then the bit that I think everyone's struggling is how do we kind of manage that in the education space? How do we accept that students are using AI but not hold it against them as part of their learning? And there's ways around that in terms of do you allow them to cite AI in their papers? Say, well, actually AI wrote these bits for me. I mean, if they're submitting it, they're submitting it as themselves. If they can put some AI references into those papers, then actually they're recognizing that they're using it and they're saying it's what they believe and they validated it. It's a bit like if they go and pick up an encyclopedia and they go to a certain page and they quote something from there. They're trusting what that encyclopedia has said is true and they're using it as part of their own work. How that maintains itself in. So I think that's going to really transform how education works. If I look even further back from higher education, younger children, this is all going to become normal for them. They're not going to know anything before AI and it's going to be how so they're going to have like everyone did whatever part of technology generation you Are you always had a way around things, and so they're going to find their ways around things as they get older. And the technology and educators needs to be ahead of that game and identifying things and to ensuring what they're producing falls within those governance guardrails. Right.
C
That's a great one. I love that. And then what is your inconvenient truth that you want the AI vendors and tool builders themselves, what's the message you want them to hear that they maybe don't necessarily want to hear about whether their products are truly built and favor higher education? In terms of the use case, I
B
think more generally I want to see vendors explaining how their technology works so they can't just go to and say, oh, we're using this LLM. Okay, great, but how are you doing that? What math model essentially I use behind that there are different. Everything around AI is essentially just using a different mathematical model to get the outcome. So how are they using that data? And when I go to conference, I'm always asking the vendors, so how does your AI work? What math model sits behind that? What do you mean by that? And if they can't tell me, it's probably because they're in a sales role. Yeah, okay. But often I think for me that's a credibility piece. If the vendor can tell you not exactly how it works, but some of the ways and how they think about it and how they bring data efficacy in and how they manage that, it kind of gives you that reassurance they actually know whether it's proper AI. It's not just a badge they're stuck on. There's so much AI washing out at the moment, it's really hard to unpick. And so whenever it says, oh, our tools AI, the first question I said, okay, tell me what math model you use to pick one doesn't have. It doesn't have to be. It won't be just one they use, but just pick one. And they often can't. And I think that for me is a credibility piece. There are some vendors that are very good, have been open about this as well, by the way, so, you know, it's fine. For me, that gives you the reassurance that they actually understand what they're doing and by investing in their product, it's not going to be a hover downstream. Right.
C
You got to filter through the AI tool slop. AI slop. It's happening across content, it's happening across tools, is happening everywhere. So that's a great piece for me.
B
It reminds me of the cloud. Early days, the answer was public cloud. Maybe what's the question? And we've seen a reversal from some public cloud where it's not always appropriate to store things there, usually from a cost basis. To be honest, I think the same thing's going to happen with AI. The moment the answer is AI to everything, it will come to a point. Well, actually AI is great for these sort of things, but we don't need it to do these bits and pieces. We can do that in more traditional ways, but at the moment we haven't worked out what those different ways and rules are around things. But the difference between the cloud piece is acceleration. To get to that point so much faster, it's going to be really interesting. I think that's where it goes into our tokenization. And originally you had a flat fee for using AI tools. Now a few vendors are bringing in tokenization costs and looking at different charge models because frankly, it's not affordable to keep doing it as they have been. But then those. But once you're sucked into that kind of way of working, it's really hard to then go back to what you used to do. And I think it's being open to the fact that this tokenization is a problem and managing your way of using technology to get the best outcomes whilst also being smart, how you're using the tools as well.
C
Talk about mathematical models you have to do. Yeah, absolutely. Well, wonderful. What is the most important message you want to leave with our listeners today?
B
I think the biggest message is to embrace technology change, better understand the value outputs you're getting from that, rather than just being a free for all. For me, that's the tricky part. Getting people to articulate what they're trying to actually achieve and why is often the most difficult thing for people to articulate. Some people might use AI tools, I don't know. But yeah. And that then leads into how you're going to achieve those outcomes, what tooling you're going to use, how are you going to make sure it's secure, appropriate, and that essentially is educating people to get the best outcome they can from their technology stack. Yep.
C
I love that. I love. I was kind of forecasting what you were going to say in my head and I thought you were going to say embrace the technology, don't fear it. But you said embrace the technology but understand the value. And I think that's a really, really critical framing, especially as these AI cost models are changing. It's definitely something that I know more businesses are starting to understand, but even other businesses need to start having that realization as well.
B
So many organizations are still struggling with the OPEX capex models with public cloud, particularly how they're going to cope with tokenization and changing pricing models and AI. And I think that whole financial world if used to going to be hard enough to learn what people are using
C
the tools for right? Well thank you so much. I appreciate it. And until next time, thank you.
A
That's a wrap on today's episode of Data Security Decoded. If you like what you heard today, please subscribe wherever you listen and leave us a review on either Apple Podcasts or Spotify. Your feedback really helps me understand what you want to hear more about. And if you want to reach out to me directly about the show, email me at Data Dash Security Decoded 2 thank you to Rubrik for sponsoring this podcast. The team at N2K includes producer Liz Stokes and executive producer Jennifer Ibin. Content strategy by Mayan Plow Sound designed by Elliot Peltzman Audio mixing by Elliot Peltzman and Trey Hester Video production support by Bridger Kirke Wild and Sorrel Joppy. Until next time, stay resilient.
B
Sam.
Guest: Kevin Mortimer, University of Reading
Host: Caleb Tolan
Date: July 21, 2026
In this insightful episode, Caleb Tolan sits down with Kevin Mortimer, a seasoned technology leader at the University of Reading, to unpack the evolving data security risks facing higher education—particularly as AI adoption accelerates and research data becomes ever more valuable. The conversation delves into navigating complex threat landscapes, implementing resilient security infrastructure, and contending with the rise of "shadow AI," all while balancing innovation with pragmatic risk management. Mortimer’s blend of practical advice, candid reflections, and actionable takeaways makes this essential listening for IT and cybersecurity professionals in education and beyond.
Three steps before the next attack:
On AI democratization:
"If your role touches technology at some point in the near future, you will become an AI developer."
— Kevin Mortimer (00:10, 14:20)
On post-pandemic security pivot:
"The day of lockdown, when everyone went home, ... we need to turn on MFA for everyone and make it mandatory. ... And with the board it was—yep, absolutely, just get it done."
— Kevin Mortimer (05:47–06:17)
On Shadow AI risks:
"Shadow IT has been around ever since there were IT teams. ... With Shadow AI now ... the accessibility ... is quite dangerous."
— Kevin Mortimer (16:25)
On vendor credibility:
"There’s so much AI washing out at the moment, it’s really hard to unpick... Whenever it says, 'our tool’s AI,' I say 'okay, tell me what math model you use.' ... If they can’t tell me, ... that’s a credibility piece."
— Kevin Mortimer (21:56–23:36)
On the future of education and AI:
"Younger children ... are not going to know anything before AI... They're going to find their ways around things as they get older, and technology and educators need to be ahead of that game."
— Kevin Mortimer (20:26)
"Embrace technology change. Better understand the value outputs you're getting ... That's the tricky part—getting people to articulate what they're trying to achieve and why is often the most difficult thing for people to articulate ... That leads into how you're going to achieve those outcomes, what tooling you're going to use, how are you going to make sure it's secure and appropriate."
— Kevin Mortimer (25:17)
For IT and security leaders: Stay focused on fundamentals—data governance, permissions, user education, and threat awareness—and adopt new technologies with caution, clarity, and a relentless focus on meaningful outcomes.