
Episode #240
Shared Governance in the Age of AI: Keeping the Institution Safe with Bill Guerrero - Ep 240
Guest Introduction Bill Guerrero is the VP of IT at Sacred Heart University , a private, faith-based, residential institution in Fairfield, Connecticut with roughly 10,000 students, 50 buildings, and nearly 2,000 cameras across campus. A proud alum who earned his master's there in 1999, Bill brings an unusual dual background to the role, having started his career at Gartner before spending years as a CFO, a financial lens he now applies directly to how the university budgets for AI. He joins the show during the first week of a new semester to talk through a live third-party security incident his team resolved in real time, why token and credit costs deserve the same budget scrutiny as any other line item, and why he believes the new professional standard is AI-assisted work refined by a human, not work produced by a human alone. Here's a Glimpse of What You'll Learn How Bill's team resolved a third-party zero-day breach affecting a campus vendor in just 24 hours Why Bill treats tokens and credits as a budget item universities can't afford to leave unaccounted for How Bill uses Claude with read-only access to run low-cost internal pen tests against the university's own framework Why Bill believes the new professional standard is AI-assisted work with a human review layer on top How Sacred Heart's shared governance model keeps AI adoption fast without letting any department run rogue Why Bill still uses AI for the small, personal tasks in his life outside the office, including coaching baseball How a real, current incident at a major learning management system provider shaped Bill's own continuity planning In This Episode Bill opens during the exact week cybersecurity pressure peaks for any university, the first week of a new semester, when thousands of students and their devices hit the network at once across a campus with door access systems, high end classroom technology, and nearly 2,000 cameras. He describes a proactive approach built around education before problems start, emailing students, faculty, and staff ahead of time with what to expect and what scams to watch for, while his cybersecurity team, led by his own CISO, works to keep pace with a threat landscape he compares to a constant game of ping pong against attackers who are also upgrading every day. He's candid that Sacred Heart isn't trying to be a bleeding edge leader, running as a Copilot enterprise shop for the past three years, but that shared governance lets academic leaders, faculty, and cybersecurity students get meaningful access without compromising the institution's data. The conversation turns sharply concrete when Bill describes a live incident from the exact weekend of the interview: a third-party vendor supporting the university's mobile credential printing system was hit by a zero-day exploit. Because of layered security defenses including CrowdStrike, Bill's team caught and remedied the breach within 24 hours, and in a notable twist, it was Sacred Heart's own team that first alerted the vendor to the intrusion. He connects this to a broader shift he's watched happen in real time, referencing a recent incident at a major learning management system provider that affected 900 universities, one Sacred Heart avoided, as a reminder that continuity plans written months ago need to be revisited constantly rather than treated as a one-time compliance exercise. The back half of the episode gets into how Bill actually manages AI adoption without letting cost or fear derail it. Drawing on his background as a recovering CFO, he explains why tokens and credits function like a printing budget that can quietly run out, an unbudgeted surprise if leadership isn't paying attention, and why total cost of ownership needs to include this line item explicitly. He describes using Claude with carefully scoped, read-only access to walk through the university's own firewall and network settings, comparing it against Sacred Heart's existing framework to run what amounts to a no-cost internal pen test rather than paying six figures for an external one. He closes on a personal note entirely outside of IT, describing how he used AI to rebuild a baseball practice schedule for a coaching role he's returning to after years away, tweaking the output himself rather than accepting it wholesale, a small example of the exact philosophy he argues the whole university should adopt: let AI produce the polished first draft, then apply the human judgment that makes it genuinely yours. SPONSOR FOR THIS EPISODE: This episode is brought to you by Cyberlynx CyberLynx is a Bethesda managed IT and cybersecurity company. Local techs you know, not a call center. Month-to-month. 24/7 intrusion detection. We help growing companies with managed IT, help desk, backup and recovery, and a fractional CIO. Talk to us at https://cyberlynx.com/contact , info@cyberlynx.com , or 301-798-9170.

