← BACK TO PROFILES

Brett Littrell

Chief Technology Officer·Alum Rock Union Elementary School District·San Jose, CA·

Good security is architecture, not a product you buy

In this interview

In this interview, Brett Littrell argues that good security is architecture, not a product you buy, and that a curious teenager can be scarier than a nation state. He explains why AI is only as good as the question you ask it, and why standing still means falling behind.

Brett Littrell
Brett Littrell

Brett Littrell is the Chief Technology Officer of Alum Rock Union Elementary School District in San Jose, California, where he protects the networks and the personal data of roughly 6,500 children. In plain terms, he runs the plumbing and the locks for a public school system: the internet, the email, the classroom devices, and the student records that sit behind them. He is quick to point out that the fiercest adversary in that job is not a foreign intelligence service but a curious sixteen-year-old, and that on any given day a determined teenager scares him more than a Chinese spy. Defending a school district, he says, has its military-level moments, and he treats the safety of a student's identity as seriously as any corporate breach.

His path into the work was not a straight line. Littrell served a tour in the Air Force loading planes, a job with nothing to do with computers, before spending roughly fifteen years building and defending school district technology starting around 1999, when protecting a high schooler's data already kept him up at night. He later ran security and networking in the private sector, with stints connected to firms like A10 Networks, Pulse Secure, Level 3 Communications, and Coherent, and earned a master's degree in cybersecurity and information assurance. Along the way he walked into networking and security companies that, tellingly, had almost no security of their own, and rebuilt their architecture from scratch. At one, he caught a suspected nation-state intrusion that his own boss had waved off as nothing.

“The most cringe-worthy line I hear is people asking whether this has ever happened before, as if that justifies not doing anything. But that is the whole point: we do not want it to happen the first time.”

Littrell thinks about security the way Donald Rumsfeld once parsed risk, in known knowns, known unknowns, and unknown unknowns, and he places today's AI-driven threats squarely in that last, most unsettling category. His answer is not another product off a salesperson's slide deck but deliberate architecture: layers of compensating controls designed by someone who has asked who, what, why, and when at every step. He argues that AI is only as good as the question posed to it, so a leader who does not truly understand technology cannot know what to ask to stay safe. He is candid that the industry's tidy best practices, like strict separation of duties, collapse against the budgets most organizations actually have. His fix is practical: cross-train IT people to own security too, then build redundancy across them.

What keeps him moving is a refusal to be comfortable. He remembers leaving the school world for the private sector and returning fifteen years later to find that many organizations had not advanced at all, still parked where they were when the threats first became real. That stagnation troubles him more than any single attack, because he believes standing still in this field is the same as falling behind. He wears his paranoia openly and treats worst-case thinking as a duty rather than a defect, insisting the goal is never to survive the first breach but to make sure it never arrives. For Littrell, the work is quieter than a headline and more human than a firewall: a graduating senior who still has their credit, their name, and their future intact.

The conversation

In this conversation: Josh Rubin (Host, CTO Studio) and Brett Littrell (Chief Technology Officer, Alum Rock Union Elementary School District).

Recorded for the CTO Studio interview series. Interview recorded on 06/30/26.

Josh Rubin

working in cybersecurity in a school district is a very specific skill set and rule and kind of bad actors that you're working to keep at bay, I imagine, or unique. Tell me a little bit about that.

Brett Littrell

Yeah, so when I worked previously at Milpitas School District, which is more of a unified school district for me, it's K through 12, we actually had a lot of high school students. And so from a cybersecurity perspective, it's more like an insider threat, right? And so the kids are always trying to hack into, you know, the system and get into everything. And so it was always a battle, you know, who can have, you know, can you defend against the high school teenagers and so on. Fortunately, I've always been into cybersecurity as far as like always concerned about it. So from the very beginning of getting, you know, implementing the network, because I got to actually implement the greenfield, meaning that there was nothing there before. So I was actually able to stay ahead of the students. So that was fortunate for me for Milpitas. When I ended up going into the private sector, you know, it's a bit more interesting because you walk into companies that do networking or cybersecurity for their business. And they have not, you know, it's kind of crazy, that you think they would actually have something in place, but they actually don't. A lot of companies, even on the networking side, it's almost like the, it's just saying, the cobbler's kids have no shoes type thing. It's like, for some reason, they don't build it in themselves. And so I took a lot of experience from the school district where I actually did implement a lot of that security because we did have insider threats. We did have an outsider threats and actually implement them in the private sector. And so that was a big thing for me. So a lot of times I go into these companies and I have to remake the entire network, remake the entire security architecture and so on. And eventually I made it back to the school districts. And again, I thought, well, maybe school districts will be a little bit different. Now I get back there, you know, they're a little more security conscious, but I was disappointed again. So, you know, this last one, in the last five years, I've been building it back up, building up the architecture and so on. But there are real issues as far as like, people actually either trying to hack in or, you know, just people not even understanding the basics for cybersecurity or information in general, like, you know, people going out innocently, putting student information on the web, but not really knowing or securing it or anything like that. And so I think from a school district perspective, that's quite the more insidious, you know, side of things where that information leaks out, not because someone intentionally does it, but unintentionally do it. You have bad actors that actually grab it later.

Josh Rubin

I find it absolutely fascinating that a good training ground for cybersecurity, sure you can go the intelligence route and try to keep the Iranians and the Russians out of your system, or you could spend your time trying to prevent a bunch of high school teenagers from getting to the thing they absolutely want to get to. And that's probably pretty intense on occasion.

Brett Littrell

Yeah, no, it definitely can be. And it's funny you mentioned that because one of the companies I worked at, I actually targeted and found a nation state attack happening on the system, but mostly because of what I've learned from previously in the school district and how to actually look at stuff, what should be there, what shouldn't be there, and so on and so forth. So it actually served me quite well. In fact, at the time, my boss, who came from big companies like Oracle Sun, you know, he looked at the same thing I was looking at, he said, "Oh, no, it's fine, it's no problem." And I'm like, "No, yeah, that's not, something's going on here." And I actually dug a little deeper, and sure enough, we suspected it was the Chinese trying to break into the company, and we were able to stop it, fortunately, right away. But it's just one of those things, you know, you have to learn it if you want to defend against it.

Josh Rubin

I mean, look, on a day-to-day basis, I am more terrified of a 16-year-old than a Chinese spy, just in my daily life, but that's only as someone with a 14-year-old who terrifies me on the regular. Exactly, exactly. How has the proliferation of AI tools affected cybersecurity in kind of this school setting?

Brett Littrell

Yeah, and I think, I've been trying to think about this, and I kind of, I don't know if you recall, you probably recall, definitely, Donald Rumsfeld, when he did his saying, you know, there's things we have to watch out for that we know, the known-knowns and the unknowns

Josh Rubin

And you go to war with the army you had, not necessarily the one who won.

Brett Littrell

Exactly, and I kind of tried to equate that into cybersecurity, and so, like, the known-knowns are like things like viruses, you know, you know what they are, you know what they look like, you know what they do, you know how to block it. You got the known-knowns, which are like, you know, maybe viruses or polymorphic viruses that behave a certain way, so you don't know what they are, but you know what they do, you know how to find them and stop them, that could also be logging as well as, you know, seeing stuff going on. But what are the unknown-unknowns? How do you defend against those? Those are things like zero days that you don't even know to look out for, and, you know, that's what I kind of view AI is right now, and the only answer I have is building good security architecture, not just kind of like throwing in like an EDR solution because it blocks this stuff, but really thinking about when you build your network and your security architecture, what is this defending against? What is this defending against? Do we have enough compensating controls that they get through this and this and this and this, that we're gonna detect them before they get to the good stuff, right? And I think that's really lost on a lot of companies, a lot of organizations in general, schools, companies, what have you, is to actually look at that, and I think one of the things, at least for me, you know, one of the hurdles I run into is trying to convince people that this isn't just me being, you know, pessimistic or, what is it, just scared in general. These are real things that protect you, and if you don't think of them, and you don't think the how, why, and what it's for, then you're always gonna have these little holes, I mean, that pop up, and that's the only thing that I can think of that protects you from this AI cyber security threat, because now, they can utilize zero days, but they can do it at a programming level, in a sense that, you know, they can hit you and get through everything if you don't have that faster than you can actually even get notified that there's an issue in the first place.

Josh Rubin

You bring up a good point about pessimism, specifically, and how important it actually is in threat detection and cyber security, because I think there is a bias, and I've read this a number of times, against pessimism. Oh, it's the worst case scenario, we don't need to, it could, yes, it could go super bad, but it's not going to, nothing ever is worst case scenario. Sometimes it is. And you don't do yourself any favors by ignoring the worst case scenario. And ultimately, for somebody who's operating in cyber security in a school district, it must be exhausting for you, but we want you thinking about, what is the worst that could happen? I need to be thinking about that.

Brett Littrell

Yeah, and probably the most cringe-worthy line I get to hear is from people that's, well, has this ever happened before? That can justify why you don't do it. The only answer I really have is, well, you know, but that's the whole point. We don't want it to happen the first time, and that's why we put this in place. But for the longest time, I didn't really know how to answer that. Well, is this an issue? Did we ever have this before? It's like, how do you answer that? Well, no, maybe we got lucky, maybe we did a good job with security, maybe not, but yeah.

Josh Rubin

The answer that I give to that is essentially, well, it wasn't a war crime the first time it was that. Everything begins somewhere.

Brett Littrell

Yeah, that's right.

Josh Rubin

Are you using AI in your technology role, in your practices, specifically because it seems like AI is the only solution for problems that AI creates. All aphorism, the only thing that can protect you from a bad guy with a gun is a good guy with a gun?

Brett Littrell

Yeah.

Josh Rubin

AI seems to be in the same situation. Yeah, or a fire with fire or something.

Brett Littrell

So again, if we come back to this, good security architecture, it's not really using AI in that sense, although part of that architecture is using AI. But building it in general isn't actually an AI function. It's someone actually taking a thoughtful look at the architecture in general and saying, "Okay, how are we going to limit this, protect that," and so on and so forth. So you have to really think of the who, what, why, when, type of thing, what you're dealing with, building that architecture. Now, inside that architecture, it could be everything from static things like access control lists to more automated things like rules based off of identity and so on and so forth. But then nowadays, they're also adding in a lot of AI. So like in the firewalls and the antivirus or the endpoint detection response, the endpoint management detection response, those things are using a lot of AI to actually respond to direct threats coming from AI. So no matter what you're doing, it doesn't matter really what endpoint detection response, what firewall, pretty much all of them are now integrating AI into it. But I think from an overall architecture perspective, AI is not gonna build you a resilient, secure architecture. You have to do that. You have to understand the company and you have to understand cybersecurity in general to be able to do that. Maybe someday AI will get to that point, but I don't even know how you would ask AI a question if you don't know the question to ask in the first place. And that's really kind of what it comes back to is AI is as good as the question, but if you don't really know cybersecurity, you don't know information technology, you don't know technology in general, how do you know what to even ask for to help secure that and that becomes an issue?

Josh Rubin

Well, that speaks to, I think, a unique perspective you have in this, working in our school district especially. Media literacy is a thing, like we're talking about some new things here and cyber security literacy and AI literacy are probably going to become intrinsic parts of what we need to know. Are we going to be able to impart that knowledge? Are people talking about or thinking about this? How vulnerable are we?

Brett Littrell

If I were to go back five years and seeing the stuff I saw in the private sector, I would say we're in big trouble because people just, fully understand the side of IT and cyber security. They go to a class and they teach them, this is best practice. What they don't teach them is what is reality? And so, best practice is to have separation of duties. Security guys don't have access to the IT stuff and the IT stuff doesn't necessarily have access to security stuff. The problem is, more often than not, the reality is IT has access to everything regardless of the cyber security side. Really has access to just their cyber security stuff and they have no influence on getting IT to do anything. And so, the separation of duties in a very structured industry or in very structured organization, like something huge like the DOD or something like a huge health provider, it works because they have hundreds of millions and not billions of dollars to put toward it. Most companies don't wanna pay IT for anything and much less cyber security. So, they don't have that ability to build that structure. And so, what you end up doing, these best practices that sound great on paper, don't really hit it when it hits reality. So, what I've found is for me, the best practice for 95%, maybe 99% of the companies out there, is to train up your IT folks, so they're both cyber security and IT folks, and then you build redundancy across that board. And that's the only way you're going to actually build that good security architecture that hits on all levels, not just on the ones that the cyber security folks see or not just the ones that IT wants to enforce. IT is now an integral part of all that. Because they have access, they have the keys to the kingdom, they can actually make sure that that actually happens. But unfortunately, we do have a lot of folks out there that are both in IT as well as cyber security, that they don't wanna change their job. They don't wanna learn this extra stuff. They're comfortable with how they do stuff. But if you're stagnant in IT, and you're stagnant in cyber security, then you're falling behind, you always have to be moving forward. And that's what I try to teach everybody that works for me or I talk to. You always have to be pushing that forefront. You don't have to implement everything that a salesperson tells you, but you have to at least understand what's coming down the road, and understand is this going to be effective for us? You know, is it gonna help us moving forward? So I think that's what's missing. A lot of companies, a lot of organizations in general. They're comfortable. Exactly, yeah. And unfortunately, you know.

Josh Rubin

This is not a time to be comfortable.

Brett Littrell

That's right.

Josh Rubin

So there's a proper level of paranoia and anxiety that you really want in your IT professional right now.

Brett Littrell

Yeah, and it's funny you mentioned that because the way I got to this point was, when I first started at a school district, I was paranoid about people breaking, and this is mind you like 1999, you know, 2000. I was paranoid about someone breaking in, stealing a high schooler's personal information and using it to get credit cards and ruin this person's credit. And they graduate from high school, and they have, you know, they find out they have no credit, they can't even get a credit card or whatever, maybe because someone stole it from the school that I was managing. And so I was always paranoid, you know, like how do we make this better? How do we make this better? And to be honest, I had thought at the time that I was just keeping up with industry, you know. I'm like, you know, we gotta keep going, we gotta keep going. That drive, you know, stuck with me because I was at the school district for 15 years, struck, stuck with me throughout the rest of my life. And so when I left, I was, you know, dumbfounded to find out that people hadn't moved in the last 15 years. I mean, they're pretty much back to where they were at the very beginning. And I'm like, you know, when IT was really becoming a thing, like 2000, I'm like, wow, you guys really haven't done anything. And that disturbs me. And that makes me a little more pessimistic about, you know, where we are now. Because I'm afraid that organizations are still there and maybe they finally got the idea that they need to start moving forward, you know, but they still have a lot of road to catch up on and help defend against that kind of stuff.

GET INVOLVED

Be part of the
conversation.

Whether you're a CTO who wants to be featured, a company looking to sponsor, or an engineering leader wanting a seat in the room — there's a place for you here.