


Randy Marchany is the Chief Information Security Officer of Virginia Tech and Director of Information Technology Security Laboratory. He has played a foundational role in advancing cybersecurity practices across higher education and contributed to the development of the CIS Critical Security Controls.
In an exclusive conversation with Cyber Security Review, Marchany shared insights drawn from experience on why cybersecurity failures persist, how universities must rethink traditional defense models, and what security leadership must prioritize as AI reshapes the threat landscape.
What Cybersecurity Still Gets Wrong
I have been in the IT sector for almost half a century. I started in the mid-1970s as an IBM systems programmer, moved through microcomputers, UNIX systems and enterprise infrastructure, and spent most of my career at Virginia Tech. My focus shifted to cybersecurity in 1991, when one of my UNIX servers was compromised by a hacker. The attacker was persistent, and recovery took months. That incident changed how I thought about systems and risk, because it made one thing clear: we didn’t really understand how exposed we were.
At the time, cybersecurity wasn’t a formal discipline. Information was limited, and organizations didn’t talk openly about breaches. We presented what happened, what failed and how we responded. That openness led to my involvement with the SANS Institute, where I helped develop early security courses, and later with the Center for Internet Security. I was also part of the working group that developed Version 8 of the Critical Security Controls (CIS), which we now use at Virginia Tech as the framework for our minimum security standards.
What continues to surprise me is how little has changed at the root. Many of the techniques attackers still rely on today, including weak authentication, poorly written code and SQL injection, were identified decades ago. SQL injection, first documented in the early 2000s, remains one of the most common causes of largescale data breaches. This stagnation is well documented. The OWASP Top 10 has remained largely consistent for nearly a decade. Although we have made progress, we treat symptoms instead of addressing root causes.
Open Networks and Vendor Risks
One of my biggest concerns today is software accountability. Too often, vendors ship products with known vulnerabilities and manage risk through licensing language instead of a secure design. From a security standpoint, that’s not acceptable. That’s why third-party risk assessment has become critical. At Virginia Tech, my office reviews purchased software for common security flaws. We may not block a purchase, but any identified vulnerabilities must be addressed through compensating controls.
We assume attackers may already be inside the network because openness is central to our mission. Instead of relying solely on perimeter defenses, we focus on protecting our most valuable data, an approach that aligns with the foundational principles of Zero Trust Networks. That same mindset guides how we assess thirdparty software.
Critical tools may still be approved, but known vulnerabilities require compensating controls to manage risk. We connected to the internet early, helped wire an entire town for connectivity and built one of the world’s fastest supercomputers using a distributed model. Security didn’t stop innovation but supported it.
AI, Speed and the Kind of Talent we Actually Need
Over the next five years, AI will have a major impact on cybersecurity. We’re already seeing AI-driven attacks that move faster and scale more efficiently. Defense is starting to catch up. I expect AI to play a significant role in log analysis, data analytics and incident response, especially as organizations collect massive volumes of telemetry every day.
Attack speed is increasing, which makes detection and response time critical. Shortening the time between identifying an attack and reacting to it reduces exposure and limits damage, and that is where AI will matter most. It helps organizations process data faster and respond more effectively.
When it comes to hiring talent, aptitude matters more than technical familiarity. Technical skills can be taught, but problem-solving instincts cannot, and some of the strongest security professionals I’ve worked with did not come from traditional computer science backgrounds. What ultimately matters is how someone thinks, how they approach a problem, and whether they are curious enough to keep learning.
That’s what the future of cybersecurity leadership really depends on.