As colleges and universities expand their use of AI, leaders are facing new questions about trust, governance and risk. Institutions must deliver the seamless digital experiences students and employees expect while protecting sensitive data and maintaining confidence in the systems that support campus operations.

Headshot of David Overton, a man with medium brown skin and a mustache and beard, wearing glasses and a blue shirt.

I discussed these challenges with David Overton, vice president of IT and chief information security officer at Pathify. Drawing on more than 25 years of higher education technology leadership experience, including serving as chief information officer at Charleston Southern University, Overton shared his perspective on digital trust, secure innovation and preparing institutions for an AI-driven future.

Q: Students and employees expect seamless digital experiences, but institutions are also responsible for protecting sensitive information. How can higher education leaders strike the right balance between convenience, innovation and security?

A: One lesson I’ve learned serving as both an institutional CIO and now a CISO is that the biggest challenge in implementing a seamless digital experience isn’t technology, it’s getting the institutional leaders to approach those priorities through a shared lens. Presidents, provosts, CFOs and CIOs naturally evaluate initiatives through the lens of their own responsibilities, and that can create disconnects.

Innovation is essential. I wouldn’t want to visit a doctor who hadn’t learned anything since the 1990s, and higher education can’t expect to serve today’s students with yesterday’s technology. But every new initiative comes with questions that deserve thoughtful discussion. Do we have the expertise to support it? Can we sustain it over time? Does the long-term value justify the investment? Have we accounted for the resources required to secure it?

I think of innovation, convenience and security as a three-legged stool supporting the institution. If you remove one leg, the entire structure becomes unstable. An institution that prioritizes convenience without security increases its risk. One that prioritizes security without considering the user experience slows adoption and frustrates students and employees. Innovation succeeds only when all three remain in balance.

Security should never be the final checkpoint before launch. It should be part of the conversation from the moment an institution begins discussing a new initiative. When leaders build that shared understanding early, they make better investment decisions and create digital experiences that remain sustainable, adaptable and trusted long after implementation.

Q: What practical advice would you offer presidents, provosts and cabinet leaders who want to create a secure foundation for AI without slowing progress?

A: The conversation around AI too often begins with the technology, but it really should begin with a focus around the underlying data. Throughout my career, I found that institutions move faster, not slower, when they understand the data they’re protecting. AI only amplifies that reality, because it depends entirely on the quality, accessibility and governance of institutional data.

The first step is understanding what data you have, where it resides and who should have access to it. Not every piece of information deserves the same level of protection. Public information, internal documents, student records and institutional intellectual property all require different controls. Without clear data classification, it’s difficult to implement AI responsibly.

From there, institutions need visibility into how data moves throughout the organization and a plan for responding if sensitive information leaves approved environments. They should also revisit data retention practices. One piece of advice I often give is “Don’t be a pack rat.” Keeping data longer than necessary expands the attack surface, creates unnecessary legal exposure and makes governance far more difficult than it needs to be.

AI doesn’t require institutions to slow innovation. It requires them to become more disciplined about governance. Leaders who establish those foundations now will have far more flexibility as AI capabilities continue to evolve, because they’ll know exactly what data they’re protecting and why it matters.

Q: Security is often viewed as a safeguard against risk, but increasingly it also influences the institution’s ability to innovate. How should higher education leaders think about the relationship between security and innovation?

A: For many years, information security was viewed as the department that said no. I think that mindset has outlived its usefulness. The best security and IT leaders help institutions accomplish their goals by explaining how to move forward securely rather than simply identifying reasons something can’t be done.

IT and information security begins with relationships. Throughout my time in higher education, I found that the most successful projects weren’t driven by technology alone. They were built on trust between academic leadership, finance and IT. Those relationships allowed us to have honest conversations about priorities, trade-offs and the resources needed to support new initiatives. Technology leaders shouldn’t be invited in after decisions have already been made. They should have a seat at the table while the institution is defining its vision.

When a president says, “We want to improve the student experience,” that’s a strategic objective, not a technology plan. The role of IT and security leadership is to translate that vision into something sustainable by identifying the infrastructure, governance, staffing and security controls needed to support it. Data is the institution’s lifeblood, and protecting it isn’t separate from innovation—it’s what makes innovation possible.

Students shouldn’t have to think about security every time they log in, but they should benefit from it every time they access a service, find information or engage with their institution. That’s what a strong digital experience looks like. When security, governance and technology evolve together, institutions create an environment that’s easier to navigate, resilient enough to support emerging technologies like AI and worthy of the trust their campus communities place in it.