The Governance Hack: Pair Policy With Action To Fight AI With AI
Most universities I talk to are still stuck in governance mode. They’re writing policies while their attackers are already operating at an algorithmic pace. Governance is essential, but if we’ve learned anything this year, it’s that the urgency to move from thinking and writing policies to taking action is real. You don’t have time to wait, and that’s a blind spot.
Some organizations are sticking their heads in the sand. About 7% of the organizations we surveyed have not taken action to secure their AI initiatives. They are basically hoping the problem goes away. That shocked me. It’s like my grandson when he closes his eyes and says, “You can’t see me, right?” The problem is still there.
From Alert Overload to Actionable Intelligence
Start with reducing the noise. Most security automation platforms with embedded AI can autonomously resolve or deprioritize low-priority alerts and escalate only what is truly critical. If you can eliminate 90% of the alerts, that’s a game changer for a small team.
GET INSIGHTS: Read the full 2026 CDW Cybersecurity Research Report.
Then there’s enrichment. AI can pull context from past tickets and data sources: Have we seen this before? Where? What was the impact? You start to turn down the false positives and get from hype and hyperbole to the actual and the actionable.
The next step is automating playbooks. With agentic AI, you can build out response playbooks and let senior leaders approve the ones that are low-risk, high-reward. You keep a human in the loop. In some cases, you’ll put a human in the loop too; if the next step is rebooting a production system to cleanse malware, AI shouldn’t do that on its own. It brings you the forensic analysis and impact assessment, and a human makes the final decision.
Don’t Assume You Have Everything You Need In-House
Many leaders have small teams and are already stretched thin. But universities can fall into the trap of believing they have everything they need inside the institution to solve the problem. In many cases, they don’t.
A good advisory and strategic services consultation can help you build out your roadmap, if only to refine your thinking. CDW’s Global Security Strategy Office functions as a dedicated think tank, with its own research and development, and a tech lab focused on where the threat landscape is headed three to five years down the road. Why not validate your roadmap against the expertise of people who do this every day?
DISCOVER: How does agentic AI work?
On the operational side, modernizing your security operations center with a managed security service provider is a strong use case. The provider already has the tools, training, talent and reporting. You buy it by the slice. Your internal team becomes the Tier 3 experts — the ones with tribal knowledge who focus on strategy, oversight and holding the MSSP accountable.
Understand the Basics First
AI is now the primary mechanism universities need to use to defend themselves. The risk has grown exponentially because attacks are operating at machine speed. But AI is not a silver bullet. If you’re not brilliant on the basics — such as full lifecycle account management for human and nonhuman identities, configuration management, vulnerability management, isolating riskier systems, and protecting your data — then all you’ve done with AI is expand your attack surface.
I tell people I’m still learning every day. You can get aged out quickly in this industry if you stop learning and increasing your awareness and understanding. The same is true for institutions. You can’t stick your head in the sand and hope AI goes away. You have to get humble, get help where you need it and start using AI as part of your defense.

