By Jacqueline Molik Ghosen
The alert comes in overnight. By morning, the security team is sorting through what happened, how far it spread and who needs to know. The window for containment is shrinking. Someone has to make the call.
In Kevin Cleary’s classroom, the students making that call are doing it for the first time.
Cleary, a clinical associate professor of management science and systems, spent years as a chief information security officer before moving into the classroom. He sat at the table during real breaches, real negotiations and real fallout. And when he looked at how cybersecurity was being taught, with static cases, outdated scenarios and frameworks discussed in the abstract, he saw a gap that bothered him.
“There’s a tendency to talk about AI in big, abstract terms,” he says. “But this is real. It’s a classroom where students make decisions under pressure, backed by tools that mirror what they’ll see on the job.”
The course, Information Security and Assurance, anchors both the MS in Management Information Systems and the Advanced Certificate in Cybersecurity. What makes it unusual starts before the simulation even begins.
Instead of handing students a prewritten case, Cleary gives them AI prompts and has them build a company from scratch. Students plug in their own criteria — industry, size, regulatory environment, technical infrastructure — and the AI generates a fully realized enterprise, complete with systems architecture, data flows and operational details that would normally take an instructor weeks to draft. Several industry partners were engaged to contribute additional organizationally specific prompts.
“It’s a bit like creating a Mad Lib,” Cleary says. “Students use structured AI prompts and insert their own criteria.”
A team interested in financial services might find themselves defending a regional bank navigating a regulatory notification deadline after a data exposure. Another might be managing the response at a health system where patient records have been compromised. The details change with every team, but the pressure is consistent. This is the company they built. They know the architecture. The question is whether they know it well enough when it counts.
Sometimes they discover they don’t.
Once the environment is set, Cleary launches the tabletop exercise. An incident unfolds in stages. Students work through the indicators, map their findings against industry tech standards, propose controls and decide where to spend limited resources. Then, the scenario shifts as new information surfaces, and the scope is wider than the initial assessment suggested.
“These activities resemble industry-level tabletop exercises, simulations where scenario-based gaming like Dungeons & Dragons meets cybersecurity or any kind of threat modeling,” Cleary says. “Tabletops are a common and, hopefully, frequent approach that organizations take to assess and test their cyber posture.”
Cleary’s not borrowing the format from a curriculum guide. He ran these drills himself, at the enterprise level, for organizations trying to shrink their exposure before something real happened. In the School of Management, he’s brought that same structure into a graduate course, with AI handling the scenario generation so every student team gets an experience tailored to the career they’re actually chasing.
“Professor Cleary’s course was a highlight of my master’s program,” says Suraj Hipparge, MS MIS ’25, now assistant vice president of cybersecurity and resiliency at Barclays. “The tabletop exercises were particularly impactful; by using real-life scenarios and real-time updates, we had to adapt to an ever-changing landscape rather than relying on theoretical or ‘bookish’ solutions.”
Forty-two students have been through the simulation so far. They leave having done something that’s harder to replicate than most coursework: made prioritization calls with incomplete information, under pressure and against a clock.
“The hands-on approach in this course helped me develop the mindset of a cybersecurity leader, which was instrumental in earning my CISSP certification, a major milestone in the cybersecurity industry,” says Hipparge. “Professor Cleary’s class taught me lessons that went far beyond the standard curriculum.”
That experience travels well. Students gain confidence and professional identity. By generating an organization profile that aligns with their interests, such as a certain sector, size or technology stack, they are not just absorbing content; they are rehearsing for their future career.
“And, by engaging with our corporate partners, we were able to showcase innovative uses of these new technologies and give them an insight into how well-prepared our graduates will be to make an immediate impact on their organizations,” Cleary says.
This relevance improves engagement and ownership and transcends simply completing an assignment. In interviews, students can speak with confidence about specific scenarios, tradeoffs and moments when the picture was still unclear and a decision couldn’t wait. They’ve practiced the thing companies spend real money training executives to do.
For Cleary, that’s the point and the proof. Cybersecurity is an organization-wide management challenge that moves faster than any textbook can follow. The cases that were cutting-edge two years ago are already behind the curve.
So he stopped waiting for the curriculum to catch up. He built something that doesn’t have to.