Entrepreneurship Mindset & CYSE

Summary

AI can out-produce code, but it can’t connect the dots: 

How do you become a great [cybersecurity engineer]? You spend years as a junior, mid-level, and senior developer. You learn by doing, failing, and executing.

What we’ll desperately need are engineers who connect business risk, human behavior, and complex systems to anticipate the attacks nobody has scripted yet.

I’m convinced the answer is Entrepreneurially Minded Learning (EML), the framework developed by KEEN (the Kern Entrepreneurial Engineering Network), built on a simple equation: Mindset + Skillset.

Curiosity (chase the context not given in the prompt). Connections (link technical decisions to other domains). Value Creation (security as business survival, not serverlocking).

Mindset alone doesn’t build judgment. Judgment used to come from a decade of breaking things as a junior.

EML has to do something harder than “teach curiosity”; it has to compress or replace the scar tissue that once came from years in the trenches.

Source: Engineering Unleashed

News

AI can out-produce code, but it can’t connect the dots
Engineering Unleashed , Alexandre BarretoJune 22, 2026

AI can out-produce code, but it can’t connect the dots: Rethinking Cyber Engineering Curriculum through Entrepreneurially Minded Learning (EML).

The other day, I was chatting with my daughter, who is an architect. We were discussing the anxiety around AI taking over tech jobs.

I told her, “I don’t think software architects are going anywhere. But developers? Many of their traditional roles will likely vanish.”

Then the real problem hit us.

How do you become a great architect? You spend years as a junior, mid-level, and senior developer. You learn by doing, failing, and executing.

If AI eats the bottom of that ladder, where does the next generation of senior strategists come from? This is exactly the crisis facing Cybersecurity Engineering.

We probably won’t need armies of pentesters who memorize standard attack tooling; AI already generates that faster than any human can type.

What we’ll desperately need are engineers who connect business risk, human behavior, and complex systems to anticipate the attacks nobody has scripted yet.

I’m convinced the answer is Entrepreneurially Minded Learning (EML), the framework developed by KEEN (the Kern Entrepreneurial Engineering Network), built on a simple equation: Mindset + Skillset.

Curiosity (chase the context not given in the prompt). Connections (link technical decisions to other domains). Value Creation (security as business survival, not serverlocking).

AI owns the Skillset now. The Mindset is the part that’s still entirely human, and it’s the part most curricula still don’t teach on purpose.

But I’ll say the hard part out loud instead of skipping past it: mindset alone doesn’t build judgment.

Judgment used to come from a decade of breaking things as a junior. If that decade disappears, EML has to do something harder than “teach curiosity”; it has to compress or replace the scar tissue that once came from years in the trenches.

That’s the real test, and it’s the one I think most programs claiming to “future-proof” students aren’t actually solving. I believe it’s solvable. I don’t think it’s solved yet, anywhere, including in my own classroom.

So here’s my challenge to this network: if junior execution roles disappear before students graduate, what builds the judgment that used to come from trenches?

I’ll defend EML as the right starting point. I want to hear why I’m wrong, or what’s missing. Educators, CISOs, hiring managers: disagree with me in the comments. That’s where this gets useful.

#CybersecurityEngineering #HigherEducation #KEEN #GMU #CYSE

Transforming cybersecurity classes into a podcast with AI (Applying EML)
Engineering Unleashed, Alexandre BarretoJune 15, 2026

Transforming cybersecurity classes into a podcast with AI (Applying EML)
Anyone in engineering education knows that the best way to solidify a concept is often to have a lighthearted conversation about it. To put this to the test, I created an experiment using NotebookLM to generate a podcast focused on discussing the topics we cover in my cybersecurity classes, but in a completely casual and informal tone.

The idea goes beyond simply feeding content to an AI and letting it speak. I define the focus, the angle, and what I want to explore in each episode; the AI executes it, but I actively guide the pedagogical curation.

The main idea of this project is to transform heavy theory into a dynamic experience and connect students to the real-world applications of these concepts, explicitly applying the connections from the EML (Entrepreneurial Mindset Learning) approach.

The goal is to increase students’ understanding and stimulate ongoing debate, demonstrating that simple solutions can generate enormous value in learning.

We just released Chapter 2! You can see how the experiment is evolving here: https://www.youtube.com/playlist?list=PLz9ls-KwHLoGxSqhqgxPau3EPpxjezl83

I am currently working on an Engineering Unleashed Card to detail the process and the pedagogical curation behind this experiment, but I wanted to share these early results with the community first.

Have any of you experimented with NotebookLM or similar AI tools to create new formats for educational content? I would love to hear your thoughts and potentially incorporate some of this discussion into the upcoming Card.

About

Overview

AI can out-produce code, but it can’t connect the dots: Rethinking Cyber Engineering Curriculum through Entrepreneurially Minded Learning (EML).

The other day, I was chatting with my daughter, who is an architect. We were discussing the anxiety around AI taking over tech jobs.

I told her, “I don’t think software architects are going anywhere. But developers? Many of their traditional roles will likely vanish.”

Then the real problem hit us.

How do you become a great architect? You spend years as a junior, mid-level, and senior developer. You learn by doing, failing, and executing.

If AI eats the bottom of that ladder, where does the next generation of senior strategists come from? This is exactly the crisis facing Cybersecurity Engineering.

We probably won’t need armies of pentesters who memorize standard attack tooling; AI already generates that faster than any human can type.

What we’ll desperately need are engineers who connect business risk, human behavior, and complex systems to anticipate the attacks nobody has scripted yet.

I’m convinced the answer is Entrepreneurially Minded Learning (EML), the framework developed by KEEN (the Kern Entrepreneurial Engineering Network), built on a simple equation: Mindset + Skillset.

Curiosity (chase the context not given in the prompt). Connections (link technical decisions to other domains). Value Creation (security as business survival, not serverlocking).

AI owns the Skillset now. The Mindset is the part that’s still entirely human, and it’s the part most curricula still don’t teach on purpose.

But I’ll say the hard part out loud instead of skipping past it: mindset alone doesn’t build judgment.

Judgment used to come from a decade of breaking things as a junior. If that decade disappears, EML has to do something harder than “teach curiosity”; it has to compress or replace the scar tissue that once came from years in the trenches.

That’s the real test, and it’s the one I think most programs claiming to “future-proof” students aren’t actually solving. I believe it’s solvable. I don’t think it’s solved yet, anywhere, including in my own classroom.

So here’s my challenge to this network: if junior execution roles disappear before students graduate, what builds the judgment that used to come from trenches?

I’ll defend EML as the right starting point. I want to hear why I’m wrong, or what’s missing. Educators, CISOs, hiring managers: disagree with me in the comments. That’s where this gets useful.

#CybersecurityEngineering #HigherEducation #KEEN #GMU #CYSE

Source: Engineering Unleashed

Web Links

Videos

Analysis Paralysis: Why the DREAD Model Failed (Audio)

June 15, 2026 (21:19)
By: CYSE Cyber Security System Engineering

In this short audio debate, we dive into the complexities of quantifying cybersecurity risk. We explore the Microsoft DREAD threat-ranking model and discuss its fatal flaw: subjectivity.

You will learn how relying on qualitative labels (like “High” or “Medium”) often leads to “Analysis Paralysis”. This subjectivity causes endless, opinion-based debates and friction within engineering teams instead of actual problem-solving. Finally, we introduce modern, objective alternatives such as CVSS and CWSS that decompose risk into granular, measurable attributes to address this dilemma.

Why listen? This episode is a great primer for understanding how the industry actually prioritizes web threats in the real world. Listen in to see why objective metrics matter when dealing with complex vulnerabilities!

Why does JavaScript scare Python developers? (Audio)

May 14, 2026 (08:14)
By: CYSE Cyber Security System Engineering

Welcome to Talk Nerd to Me, our new audio study series where code, security, and developer brain rewiring meet in podcast form.

In this first episode, we kick things off with JavaScript Fundamentals for Python Developers.
The idea is simple: if you already think like a Python developer, JavaScript may look familiar at first, but it plays by a very different set of rules. And in web applications, those differences are not just academic. They can become real security problems.

This episode brings a dynamic debate on the mental shift from Python to JavaScript: asynchronous execution, var versus let and const, implicit type coercion, truthy and falsy values, silent error handling, and the golden rule of web security: never trust the client.

Think of this podcast as your warm-up before the hands-on labs. You will not just hear about syntax. You will hear how small misunderstandings in JavaScript can lead to broken logic, weak validation, and insecure web applications. So grab your coffee, open your developer brain, and get ready for the first episode of Talk Nerd to Me. JavaScript is about to get nerdy.

Rethinking Innovation Canvases for Cybersecurity Engineering

EM Card 6029 by Alexandre Barreto  summarized below from Engineering Unleashed.

Description

Cybersecurity canvas guides students to frame real system risks. Used in capstone projects, it builds secure system reasoning and mission value insight.

Many innovative frameworks rely on business-oriented canvases to structure ideas and justify investments. These tools work well when value can be expressed in financial return or market advantage.

However, cybersecurity systems engineering operates under a different logic. In many cyber-physical and mission-critical environments, the primary value of a system is not revenue generation but risk reduction, trust preservation, operational continuity, and mission assurance. Traditional innovative canvases often struggle to capture these dimensions because they implicitly assume market-driven value propositions.

To address this gap, I developed the CSEC Canvas – Cybersecurity Systems Engineering Canvas, a structured framework designed to support problem framing and system reasoning in cybersecurity engineering contexts.

This canvas was developed while teaching CYSE 587 / SYST 687 – Cyber Security System Engineering, where students are required to defend system designs in a Shark-Tank-style seminar focused on technical feasibility and mission value rather than financial return.

The approach is grounded in the TDI learning model (Teaching – Deconstruction – Integration). Students first learn core system engineering and cybersecurity concepts, then deconstruct real operational problems, and finally integrate these insights into a coherent system proposal.

The canvas structures this reasoning through key elements such as:

  • problem statement grounded in real operational pain
  • stakeholders and socio-technical context
  • unmet security or trust needs
  • system boundaries and integration limits
  • assumptions and constraints
  • feasibility and system risks
  • success criteria based on improved security or trust

Rather than starting from a solution idea, the canvas forces teams to reason why a cybersecurity system should exist in the first place.

In the classroom, students apply this framework as the first delivery of their capstone project, transforming an observed cybersecurity problem into a defensible system concept that can later be analyzed through threat modeling, architecture design, and risk reasoning.

During this activity, students develop curiosity by investigating real-world operational cybersecurity problems rather than relying on predefined solutions. As they progress through the modeling phase, they build connections by integrating system architecture, operational constraints, and risk analysis. Finally, students demonstrate value creation by proposing strategies that enhance mission continuity and decision-making, rather than focusing solely on technical solutions or profit.

 

Activity Implementation & Methodology

The Cybersecurity Systems Engineering Canvas (CSEC) is not used as a standalone exercise but is integrated into a structured one-week pedagogical cycle designed to shift students from “solution-first” thinking to “problem-centric” engineering.

1. Formal Training: The Framing Workshop (2 Hours)

The activity begins with a 60-minute formal lecture/workshop titled “Systems Innovation & Project Framing.” During this session, students are introduced to the idea that most cybersecurity projects fail not because of weak code but because of incorrect problem framing.

  • Curiosity & Connections: Students analyze historical case studies (e.g., the Equifax breach) to identify how technical vulnerabilities are often symptoms of larger systemic and operational failures.
  • Defining Value: We challenge the traditional engineering mindset by emphasizing that Value ≠ Features. Students learn that in cybersecurity systems, value is defined by risk reduction, improved decision-making for stakeholders, and the preservation of trust.
  • Resource: Systems Innovation & Project Framing.pdf

2. Applied Activity: The Problem-Framing Week (1 Week)

Following the workshop, student teams are given one week to apply the CSEC Canvas to a complex, real-world scenario.

  • Investigation: Students must move beyond “installing a tool” and instead investigate the specific “Unmet Security/Privacy Need” of the proposal problem.
  • Constraint Integration: They must account for non-negotiable operational constraints, such as the need for rapid data access during life-critical outages, which directly conflict with strict privacy regulations (and present a learning opportunity).

3. Deliverable & Assessment

The activity culminates in the submission of a Project Notebook. This document serves as the foundation for their semester-long “Shark Tank” project.

Assessment Strategy: The effectiveness of this activity is measured through a structured, 100-point technical rubric that evaluates the student’s ability to frame a complex cybersecurity problem. Rather than grading purely on technical “features,” the assessment prioritizes the Engineering Logic and Entrepreneurial Mindset (EM) applied to a realistic problem.

The rubric is divided into nine critical dimensions:

  • Problem Statement (15 pts): Evaluates if the problem is evidence-based and described through the lens of stakeholder “pain” rather than a pre-determined technical solution (Curiosity).
  • Stakeholder Analysis (10 pts): Measures the identification of technical, human, and regulatory parties, focusing on how security affects their specific mission (Connections).
  • Unmet Security/Privacy Need (10 pts): Students must articulate why existing controls fail and demonstrate a deep gap analysis of current systems.
  • Value Proposition (15 pts): This is a core EM component. We assess how persuasively the student explains how the system reduces uncertainty and preserves trust (Value Creation).
  • System Boundary & Scope (10 pts): Evaluates the technical rigor in defining authority, limits, and integration constraints within the healthcare domain.
  • Assumptions & Constraints (20 pts): Assesses the realism of technical, legal, and ethical limitations that shape the feasible design space.
  • Feasibility & Risks (10 pts): A critical engineering check on whether the system can function under stated constraints and identifying potential failure modes.
  • Success Criteria (10 pts): Requires students to define observable, measurable indicators (e.g., reduction in detection time or investigation workload) that demonstrate the system actually improves security outcomes.

Evidence of Assessment: The complete rubric is embedded in the Deliverable 1 Notebook provided in the resources, ensuring that any educator adopting this card has a clear, ready-to-use grading framework.

  • Resource: Project Notebook (Deliverable 1).pdf

Also, to support reuse and experimentation with this approach, the materials used in the course are provided below:

  • CSEC Canvas – Cybersecurity Systems Engineering Canvas Template: the framework used by students to structure their project proposals.
  • How to Use the CSEC Canvas – Cybersecurity Systems Engineering Canvas: a short guide explaining the purpose of each element of the canvas.

These resources are intended to help cybersecurity engineers, educators, and researchers structure complex system problems in which value is defined not by profit but by security, trust, and mission impact.

Ultimately, cybersecurity engineering is not only about building secure systems, but it is also about justifying why those systems must exist in the first place.

Instructor Tips

This canvas works best when students apply it to realistic or complex system scenarios rather than abstract cybersecurity problems.

Instructors can introduce the canvas after students have learned basic cybersecurity concepts such as threats, vulnerabilities, and controls. Students should then be encouraged to:

  • Start by clearly describing the operational problem or mission context
  • Map the system components and interactions involved in the scenario
  • Identify potential security concerns emerging from system dependencies
  • Discuss possible mitigation strategies while considering operational feasibility

The canvas is particularly effective for courses in:

  • Cybersecurity Systems Engineering
  • Secure Systems Design
  • Cyber-Physical Systems Security
  • Risk and Mission Impact Analysis

It can also support team-based exercises in which groups analyze the same system but propose different system-level security strategies.

EM Educational Outcomes

Curiosity

Demonstrates constant curiosity about our changing world

Students begin the activity by analyzing a real-world cybersecurity scenario involving a complex system or cyber-physical environment. They must investigate the operational context, stakeholders, and mission objectives in order to frame the problem correctly. This process encourages students to explore how cybersecurity challenges emerge from evolving technological and societal systems rather than isolated technical vulnerabilities.

Connections

Integrates information from many sources to gain insight

During the System Reasoning stage of the CSEC Canvas, students integrate multiple sources of information, including system architecture, operational constraints, threat models, and mission requirements. By combining these perspectives, students develop the ability to connect cybersecurity mechanisms with broader system-level dependencies and interactions.

Assess and manage risk

Students use the Feasibility Assessment stage of the canvas to evaluate potential security strategies and analyze their impact on system operation. They must consider risk, trade-offs, and implementation constraints when proposing mitigation strategies. This encourages structured reasoning about cybersecurity risk within complex systems.

Creating Value

Identifies unexpected opportunities to create extraordinary value

Through the canvas exercise, students often discover alternative ways to improve system resilience that go beyond traditional security controls. By reasoning about system architecture and operational goals, they identify opportunities to design security strategies that improve both system protection and mission performance.

Learning Objectives

  • Frame cybersecurity problems within the context of complex systems: Students will identify stakeholders, operational objectives, and system boundaries in order to understand how cybersecurity challenges emerge in real-world systems.
  • Analyze cybersecurity issues using a systems engineering perspective: Students will examine system components, interactions, and dependencies to understand how vulnerabilities and threats propagate across complex systems.
  • Integrate multiple sources of information to reason about cybersecurity risk: Students will combine architectural, operational, and threat-related information to develop a holistic understanding of system security challenges.
  • Evaluate alternative security strategies considering feasibility and operational constraints: Students will assess mitigation strategies by analyzing risk, trade-offs, and system impact.
  • Propose system-level security improvements to enhance resilience and mission performance: Students will identify opportunities to strengthen security while supporting operational objectives.

Complementary Skillsets

Design
Determine Design Requirements; Analyze Solutions

Impact
Evaluate Tech Feasibility, Customer Value, Societal Benefits & Economic Viability; Identify Opportunity

Opportunity

Assessment

The effectiveness of this activity is measured through a structured, 100-point technical rubric that evaluates the student’s ability to frame a complex cybersecurity problem. Rather than grading purely on technical “features,” the assessment prioritizes the Engineering Logic and Entrepreneurial Mindset (EM) applied to a realistic problem.

The rubric is divided into nine critical dimensions:

  • Problem Statement (15 pts): Evaluates if the problem is evidence-based and described through the lens of stakeholder “pain” rather than a pre-determined technical solution (Curiosity).
  • Stakeholder Analysis (10 pts): Measures the identification of technical, human, and regulatory parties, focusing on how security affects their specific mission (Connections).
  • Unmet Security/Privacy Need (10 pts): Students must articulate why existing controls fail and demonstrate a deep gap analysis of current systems.
  • Value Proposition (15 pts): This is a core EM component. We assess how persuasively the student explains how the system reduces uncertainty and preserves trust (Value Creation).
  • System Boundary & Scope (10 pts): Evaluates the technical rigor in defining authority, limits, and integration constraints within the healthcare domain.
  • Assumptions & Constraints (20 pts): Assesses the realism of technical, legal, and ethical limitations that shape the feasible design space.
  • Feasibility & Risks (10 pts): A critical engineering check on whether the system can function under stated constraints and identifying potential failure modes.
  • Success Criteria (10 pts): Requires students to define observable, measurable indicators (e.g., reduction in detection time or investigation workload) that demonstrate the system actually improves security outcomes.

Evidence of Assessment: The complete rubric is embedded in the Deliverable 1 Notebook provided in the resources, ensuring that any educator adopting this card has a clear, ready-to-use grading framework.

Authoring Details

The Cybersecurity Systems Engineering Canvas (CSEC Canvas) is inspired by systems-thinking approaches to cybersecurity engineering and by educational frameworks that promote entrepreneurial thinking in engineering education. In particular, this activity aligns with the KEEN Entrepreneurial Mindset Framework (Curiosity, Connections, and Creating Value).

The conceptual structure of the canvas also reflects principles from systems security engineering, emphasizing the integration of mission context, system architecture, operational constraints, and cybersecurity risk analysis when evaluating complex systems.

This perspective is consistent with the systems-oriented security principles described in:

  • Ross, R., McEvilley, M., & Oren, J. (2016). Systems Security Engineering: Considerations for a Multidisciplinary Approach in the Engineering of Trustworthy Secure Systems. NIST Special Publication 800-160. National Institute of Standards and Technology.
  • Leveson, N. G. (2011).Engineering a Safer World: Systems Thinking Applied to Safety. MIT Press.

The author also acknowledges the educational community of the Engineering Unleashed/KEEN initiative for promoting pedagogical approaches that integrate systems thinking, engineering design, and the development of an entrepreneurial mindset.

Discuss

OnAir membership is required. The lead Moderator for the discussions is onAir Curators. We encourage civil, honest, and safe discourse. For more information on commenting and giving feedback, see our Comment Guidelines.

This is an open discussion on the contents of this post.

Home Forums Open Discussion

Viewing 1 post (of 1 total)
Viewing 1 post (of 1 total)
  • You must be logged in to reply to this topic.
Skip to toolbar