An open-source text collection for student consultants, practitioners, and clinical educators bridging cybersecurity, artificial intelligence, and public interest technology. Written for the course-based Cybersecurity Clinic at UNC Charlotte, but adaptable for almost anyone's program or curriculum.
By Dr. Cori Faklaris (with a lot of help from Gemini to summarize sources and format the text).
1. Interviewing for Impact: A Field Guide for Student Consultants
In a CyberAI Clinic, technical expertise is only half the equation. You can deploy the sharpest vulnerability scanners or evaluate the most sophisticated Large Language Model (LLM) architectures, but if you don't understand the human, organizational, and operational realities of your client, your technical recommendations will end up gathering dust on a shelf.
Interviewing for Impact is the practice of moving beyond rigid, checklist-driven audits to conduct empathetic, context-aware discovery sessions. It transforms client interviews from administrative interrogations into collaborative, trust-building strategic dialogues.
1.1 The Mindset Shift: Auditor vs. Impact Consultant
To conduct impactful interviews, you must pivot from an auditor mindset to a clinic consultant mindset.
Dimension
The Auditor Mindset
The Impact Consultant Mindset
Primary Goal
Finding compliance gaps and technical flaws.
Understanding workflow realities and organizational constraints.
Stance
Evaluative, top-down, and interrogative.
Curious, collaborative, and grounded in partnership.
Question Type
Closed ("Yes/No") checklist items.
Open-ended, scenario-based, and human-centered.
Focus
What software/security controls exist.
How people interact with tools, trade off risks, and adapt under pressure.
Client Reaction
Defensive, cautious, formal.
Transparent, engaged, candid.
💡 Core Clinic Insight: Organizations rarely fail to implement security or AI safety because they lack awareness—they fail because security controls conflict with their core mission, timeline pressure, or budget limits.
1.2 The 3-Phase Framework for Impactful Interviews
Figure 1.The 3-Phase Framework for Impactful Student-Client Engagements. A linear methodology guiding CyberAI student consultants through pre-interview contextual preparation, empathetic execution during discovery, and strategic post-interview synthesis.
1.3 Rewording Questions for Impact: A Cheat Sheet
When preparing your interview guide, use this reframing guide to convert closed technical questions into impact-driven prompts:
Cybersecurity:
❌ Auditor: "Do you enforce multi-factor authentication (MFA) across all staff accounts?"
✅ Impact Consultant: "Walk us through how your team logs into their daily software tools—where do friction points or login headaches usually happen?"
AI Governance:
❌ Auditor: "Does your organization use Generative AI tools?"
âś… Impact Consultant: "When workload is heavy, what informal AI assistants or online tools do team members turn to to draft documents or automate repetitive tasks?"
2. Qualitative Interview Moderating: A Field Guide for Student Consultants
📌 Credit & Attribution: This section is adapted for student consulting teams based on the foundational principles established in Meta Research's article, Qualitative Interview Moderating Phrase Toolkit.
As a student consultant, qualitative interviews—whether with executives, technical staff, or frontline end-users—are your primary channel for gathering authentic field data. However, conducting a discovery interview isn't just about reading questions off a script; it's about moderation.
Moderation is the art of steering the conversation, digging past surface-level assumptions, managing time, and remaining completely neutral—all while keeping your participant comfortable.
2.1 Setting the Stage: Building Rapport & Permission
When interviewing experienced industry professionals, you may encounter a perceived authority gap. Bridge this immediately by establishing clear roles: they are the subject-matter experts, and you are the neutral researchers.
To lower their guard:"There are no wrong answers today. We aren't testing you, and we don't work directly for internal management, so please feel free to be completely candid."
To establish the mindset:"We’re here to understand how things work in reality, not just how they’re supposed to work on paper."
To grant permission to pass:"If I ask a question that’s outside your scope or sensitive, just let me know and we’ll move right along."
2.2 Probing: Digging Past Surface Answers
Participants often default to buzzwords or high-level generalizations (e.g., "Communication is bad" or "The interface is confusing"). Your job is to extract concrete behavior without asking leading questions.
Participant Says...
Avoid Asking (Leading)
Use This Moderating Phrase
"The software is unusable."
"Did it crash a lot?"
"Can you walk me through the last time you tried to use it?"
"Our team lacks alignment."
"Is leadership bad at communicating?"
"What does 'alignment' look like when a project is going well vs. when it isn't?"
"The system is too slow."
"Did you have to wait minutes?"
"When you say 'slow,' what is happening on your screen during that time?"
The Replay Probe:"Take me back to yesterday morning when you ran into that roadblock—what was your very first step?"
The Contrast Probe:"How does completing [Task A] compare to how you handle [Task B]?"
The Emotion Anchor:"You mentioned that process felt frustrating—what specifically made it frustrating?"
2.3 Steering: Managing Time & Tangents
Consulting interviews run on strict schedules. When an executive goes on a long tangent, regain control politely without dismissing their input.
The Gentle Pivot:"That context around [Tangent Topic] is super helpful. I want to make sure we respect your calendar today—may I pause us here and loop back to [Original Topic]?"
The Parking Lot:"I want to explore that further, but I want to make sure we cover our core topic first. Let me write [Tangent Topic] down so we can revisit it at the end if time permits."
The Speed Check:"We have about 15 minutes left and three key areas I’d love your perspective on. I might nudge us along a bit faster for this next section."
2.4 Clarifying: Validating Without Influencing
Always avoid feeding your consulting hypotheses directly to the participant. Echo their points back to confirm accuracy without shaping their response.
Echo & Confirm:"I want to make sure I capture this accurately for our findings: You're saying that [Summary]—did I capture that correctly?"
Disentangling Acronyms:"You mentioned [Internal Term]—how would you explain what that means to someone joining the team on day one?"
Testing Extremes:"Is that something that happens on every project, or was that specific to this particular vendor?"
2.5 Navigating Silence & Awkward Moments
Silence feels uncomfortable, but in qualitative research, silence is often when the deepest reflection occurs.
Embrace the 5-Second Rule: After a participant finishes speaking, count silently to five before jumping in. They will frequently expand on their answer.
If They Get Stuck:"Take all the time you need—there's no rush on this one."
If They Give One-Word Answers:"Tell me a bit more about the thinking behind that."
If They Ask for Your Opinion:"As consultants, we’re keeping our perspective neutral for now so we don't bias the research, but I’d love to hear what you think first."
2.6 The Golden Wrap-Up Questions
Conclude every interview session with open-ended probes to unlock unscripted insights:
The Magic Wand Question:"If you had a magic wand and could change one single thing about this workflow tomorrow, what would it be?"
The Blindspot Check:"What is one question I didn't ask today that you think I should have asked?"
The Network Bridge:"Who else on your team has a unique or differing perspective on this that we should speak with?"
2.7 Quick Reference Moderator Cheat Sheet
=== STUDENT MODERATOR FIELD CHEAT SHEET ===
[01. DON'T LEAD] âž” "Tell me about..." NOT "Did you like..."
[02. BE SPECIFIC] âž” "Walk me through the last time..."
[03. USE SILENCE] âž” Count to 5 before asking the next question.
[04. PIVOT GENTLY] âž” "In the interest of time, let's look at..."
[05. BLINDSPOTS] âž” "What question should I have asked today?"
3. Demystifying Algorithmic Dependencies: A CyberAI Clinic Field Guide
When a client tells you, "We built an internal AI customer support tool," it is easy to imagine a single, self-contained box. The reality is almost always a complex web. Modern AI and cybersecurity tools depend on open-source libraries, cloud-hosted foundation models, vector databases, and third-party APIs.
3.1 The Anatomy of an Algorithmic Dependency
An algorithmic dependency exists whenever a client’s technology relies on an external algorithm, model, service, or dataset to make decisions, transform data, or execute security functions.
Figure 2.Anatomy of an Implicit Algorithmic Dependency Chain. Architectural breakdown demonstrating how client data moves from internal environments through middleware orchestration layers to third-party vendor APIs and foundation models.
3.2 Algorithmic and API Dependency Risk Framework
Risk Category
Key Vulnerability Question
Real-World Clinic Impact
Data Privacy & Terms
Do vendor Terms of Service (ToS) permit data retention or model training?
Sensitive customer PII sent to a third-party LLM endpoint becomes part of the vendor's training pipeline.
Authentication & Keys
Are API keys hardcoded in frontend code or stored securely in secret managers?
An attacker decompiles a web app, steals the client's API key, and runs up thousands of dollars in unauthorized usage.
Fallback & Redundancy
What happens if a third-party API goes offline or responds with invalid JSON?
A security dashboard silently stops ingesting threat alerts because an external API rate limit was hit.
Model Drift & Evasion
How does the system handle unexpected model behavior or prompt injection?
A client-facing customer service bot is manipulated via prompt injection to divulge internal system instructions.
Table 1. Algorithmic and API Dependency Risk Taxonomy.
4. Problem Diagnosis and Reframing: A Field Guide
When a client walks into a CyberAI Clinic project, they rarely hand you the real problem. Instead, they hand you either a symptom or a premature solution. Problem Diagnosis and Reframing is the art of looking past surface-level requests to uncover root technical and human vulnerabilities.
4.1 The Iceberg Model of Problem Diagnosis
Stated Request (Above Water): "Build an AI Security Chatbot" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Underlying Root Causes (Below Water): Unstructured Data & Noise • Fragile Access Controls • Workflow Bottlenecks • Governance Gaps
4.2 Diagnostic Matrix for Student Teams
Client's Stated Request
Diagnosed Root Cause
Reframed Project Scope
"We need a penetration test on our internal web app."
The app was built by volunteers on outdated open-source libraries with zero patch management.
Dependency & Vulnerability Audit: Audit open-source libraries, establish an automated patching workflow, and train staff.
"We want to train an internal LLM on our past client intake files."
Unstructured intake data contains unencrypted PII, and the team lacks cloud infrastructure to host local models.
Data Governance & Privacy Scoping: Build a PII masking pipeline, evaluate vendor API privacy terms, and establish safe data-handling standards.
Before an organization can assess risks, enforce security policies, or ensure regulatory compliance, it must answer a foundational question: What assets do we actually own and run?
5.1 Categorizing Cybersecurity vs. AI Assets
Asset Domain
Asset Category
Examples
Traditional Cybersecurity
Hardware & Endpoints
Laptops, servers, mobile devices, IoT devices, routers.
Raw training data, evaluation benchmarks, vector embeddings, synthetic datasets.
Model Assets & Dependencies
Model weights, checkpoint files, fine-tuned LLMs, third-party APIs (OpenAI, Anthropic).
5.2 Real-World Standards & Frameworks
NIST Cybersecurity Framework 2.0: A foundational guidance framework providing standards, guidelines, and best practices to manage and reduce cybersecurity risks across all types of organizations.
NIST AI RMF 1.0: A voluntary risk management framework designed to help organizations map, measure, manage, and govern risks associated with artificial intelligence systems throughout their lifecycle.
ISO/IEC 27001: An international standard specifying the requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS).
ISO/IEC 42001: An international standard for establishing, implementing, and maintaining an AI governance structure, including AI asset management protocols.
SOC 2: An auditing framework developed by the AICPA that assesses a service provider's internal controls based on five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy.
STRIDE: A threat modeling framework used to systematically identify potential security vulnerabilities across six threat categories: Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege.
MITRE ATT&CK: A globally accessible, open-source knowledge base detailing real-world cyber adversary tactics, techniques, and procedures (TTPs) to help teams model threats and test security controls.
MIT AI Risk Taxonomy: A comprehensive classification system and repository that categorizes potential AI-related harms, failure modes, and societal risks by domain, intent, and timing.
CIS Controls: A prioritized set of 18 actionable, high-impact cybersecurity safeguards published by the Center for Internet Security to help organizations defend against common cyber threats.
Traditional threat modeling answers a critical question: "How could a malicious actor break our system?" In a CyberAI Clinic environment, algorithms interact with human workflows, organizational incentives, and historical biases. Socio-technical risk identification expands traditional threat modeling to bridge software security with human impact.
6.1 The Integrated 4-Step Threat Modeling Workflow
Figure 3.The Integrated 4-Step Socio-Technical Threat Modeling Workflow. A comprehensive assessment lifecycle bridging traditional software threat modeling (STRIDE) with human-centric risk identification.
6.2 STRIDE Meets Socio-Technical Risk
STRIDE Category
Socio-Technical Expansion
Combined CyberAI Risk Example
Spoofing
Trust & Authority Exploitation
Users over-relying on an automated AI advisor, treating output as authoritative truth without validation.
Tampering
Data Pollution & Bias Amplification
Training data skewed by historical operational bias, causing systemic discrimination against marginalized clients.
Repudiation
Governance & Accountability Vacuum
Unclear human ownership when an automated triage system mistakenly denies services to an applicant.
Information Disclosure
Privacy Breaches & Consent Violations
Sensitive user data processed by third-party APIs in violation of client privacy policies or community trust.
Denial of Service
Operational Friction & Burnout
Overly complex MFA or AI guardrails that cause staff to bypass security controls entirely to meet job deadlines.
Elevation of Privilege
Power Asymmetry & Disempowerment
System design that deprives frontline workers or end-users of a mechanism to appeal automated decisions.
7. Hands-On Supplemental Toolkit: AI Security & Governance Tools
While theoretical risk frameworks provide strategic direction, student consultants benefit from hands-on exposure to specialized tools used to audit, red-team, and govern AI systems. Below is a curated selection of open-source security scanners, enterprise governance platforms, and technical guardrail frameworks for optional reading, video demonstrations, and practical exploration.
7.1 AI Red Teaming & Vulnerability Assessment
Tool Name
Primary Focus & Description
Learning Resources & External Links
Microsoft Counterfit
An open-source command-line framework designed to automate penetration testing and security auditing for machine learning models across text, image, and tabular datasets.
The Python Risk Identification Tool for Generative AI. An open-source automation framework built for security professionals to proactively identify safety, security, and operational risks in LLM architectures.
Known as the "Nmap for LLMs"—an open-source vulnerability scanner that probes language models for prompt injection, jailbreaks, data leakage, toxicity, and hallucinations.
A comprehensive Python library providing attack simulation algorithms and defense mechanisms to evaluate model resilience against data poisoning, extraction, and evasion attacks.
An enterprise AI governance platform that automates risk tracking, policy mapping, and clinical audit reporting aligned with regulatory standards such as the NIST AI RMF and EU AI Act.
An interactive companion guide from NIST offering actionable, function-by-function suggestions for mapping, measuring, managing, and governing AI risks in real-world organizations.
An open-source toolkit used to program safety boundaries, topic restrictions, and security filters around LLM applications before inputs hit the model or outputs reach users.
A fine-tuned open-weights safeguard model designed to classify human prompts and model responses for safety violations and policy compliance in application middleware.
đź’ˇ Clinical Practice Tip: When evaluating a client's AI system, start by testing model safety using lightweight CLI tools like Garak or PyRIT in a sandboxed environment before reviewing governance processes using Credo AI or the NIST AI RMF Playbook.
Mock clinical intake interviews simulate real client discovery sessions, allowing student teams to practice active listening, qualitative moderation, and risk diagnosis in a safe, peer-driven setting. The primary goal during intake is not just cataloging software, but identifying an organization's "red lines"—non-negotiable boundaries where automated data processing or AI deployment introduces unacceptable legal, ethical, operational, or safety risks.
8.1 Running a Mock Intake Session
Pair up with a teammate—one acting as the student consultant and the other roleplaying an organizational stakeholder (e.g., non-profit director, small business owner, or IT administrator).
Establish Neutral Governance: Frame the session as a collaborative discovery partnership to help stakeholders disclose actual daily workarounds rather than idealized policies.
Uncover Hidden Dependencies: Probe for shadow AI usage, third-party API integrations, and manual data export routines across teams.
Listen for Operational Friction: Pay attention to bottlenecks where staff feel pressured to bypass security controls or safety guardrails to meet deadlines.
8.2 Defining Risk Tiers with Industry Frameworks
An organizational "red line" marks data processing practices that must be restricted, gated, or halted immediately. Standard industry frameworks provide clear benchmarks for categorizing these risk levels:
Unacceptable Risk (Hard STOP): Passing sensitive personal data (PII/PHI) through unvetted third-party public LLMs, or executing fully automated decisions in high-stakes domains (e.g., hiring, access to benefits or services) without human oversight (EU AI Act / NIST AI RMF Govern 1.2).
High Risk (Strict Controls & Human-in-the-Loop): Ingesting proprietary client records into third-party vector databases or relying on automated security triage. Requires data masking, encryption, and mandatory human validation (ISO/IEC 42001 A.8 / NIST AI RMF Measure 2.3).
Limited Risk (Transparency & Logging): Public-facing chatbots or internal drafting tools. Requires clear disclosure to end-users and strict API access logging (CIS Control 3 / NIST AI RMF Manage 1.3).
8.3 Diagnostic Red Line Matrix
Client Practice Discovered
Risk Level
Applicable Framework
Recommended Action / Red Line
Staff pastes confidential client case notes into public AI models for drafting summaries.
Unacceptable
NIST AI RMF (Measure 2.1)
Red Line: Halt public LLM input immediately; deploy enterprise zero-retention endpoints or local PII masking pipelines.
Automated system screens job candidates or loan applicants without manual review or appeal mechanisms.
Unacceptable
EU AI Act (High-Risk Category)
Red Line: Institute mandatory human-in-the-loop review and bias auditing before automated decisions take effect.
Third-party vendor API retains query logs for model re-training without explicit user consent.
High Risk
ISO/IEC 42001 (A.6.2)
Red Line: Renegotiate API Terms of Service to opt out of data training or migrate to a compliant privacy-first vendor.
đź’ˇ Probing Strategy for Mock Intakes: Always dig past high-level answers by asking: "Where does that data go next?" and "Who reviews this automated output before it directly impacts a human being?"
9. Shared Responsibility Across the AI Value Chain & Bystander Perspectives
Determining accountability in modern AI deployments is rarely simple. Responsibility is distributed across an intricate supply chain rather than resting solely on a single software creator, business operator, or end-user. For student consultants, evaluating AI risk requires tracing accountability through each tier of the technology stack while ensuring impacted communities are included in risk assessments.
9.1 The Shared Responsibility Model in the AI Tech Stack
In traditional software, security and operational liability are typically defined by contracts and end-user licenses. In AI applications, responsibility shifts depending on how models are trained, integrated, and deployed in real-world contexts.
Adhering to organizational policies, validating AI outputs for hallucinations, and exercising final human judgment.
Over-relying on automated outputs (automation bias) or attempting to bypass internal guardrails to meet job deadlines.
9.2 Incorporating Bystander, End-User, and Community Perspectives
The individuals most directly impacted by an AI system—such as job applicants scored by automated screeners or community members affected by algorithmic resource allocation—are often absent from software development and risk reviews.
The Bystander Gap: Traditional IT security audits focus almost exclusively on technical uptime and legal compliance, treating end-users and bystanders as passive recipients rather than key stakeholders.
Participatory Risk Assessment: Modern frameworks (such as the NIST AI RMF and EU AI Act) encourage moving beyond technical testing to conduct qualitative interviews, community red-teaming, and socio-technical impact assessments.
Actionable Recourse & Transparency: True accountability requires deployers to establish clear channels for affected individuals to appeal automated decisions, report algorithmic bias, and request human intervention.
đź’ˇ Consulting Discovery Checklist: When auditing a client's AI system, ask: "If this model makes an incorrect or biased decision today, who is legally and operationally accountable, and how does an impacted person appeal that result?"
10. Student Self-Assessment & Critical Reflection
As you transition from course material to real-world clinical engagements, synthesizing your learning is essential. This chapter serves as a structured self-assessment to help you evaluate your progress, measure your growing agency as an AI risk consultant, and identify areas where you need to build deeper technical or governance confidence before advising clients.
10.1 Synthesis Reflection Prompts
Review your work across Chapters 1 through 9 and respond to the following core reflection prompts in 350–400 words:
Mindset & Agency Shift (Chapters 1–2): Which specific communication concept (such as active listening, qualitative probing, or the 5-second rule) boosted your confidence the most when talking to non-technical stakeholders, and why?
Systems Thinking & Dependency Mapping (Chapters 3–4): Give an example of how you would look past a simple client request (like "We need an AI chatbot") to uncover and evaluate the real human and technical problems beneath it.
Navigating Red Lines (Chapters 5–8): How do you plan to handle it when a client wants to break a major security rule or cross an ethical boundary just to meet a tight operational deadline?
Value Chain Accountability (Chapter 9): How will you explain shared responsibility across the tech stack to a client who assumes their third-party AI vendor takes full legal and technical liability for mistakes?
Self-Assessment of Growth: Where do you feel your AI risk assessment knowledge is strongest today, and what is one technical or governance domain where you still need to build deeper confidence?
10.2 Capability Self-Assessment Matrix
Use this rubric to rate your current readiness before entering client discovery sessions:
Core Field Guide Capability
Developing Readiness
Client-Ready Mastery
Qualitative Moderation
Relies heavily on scripted checklist questions; occasionally asks leading "yes/no" questions.
Uses open-ended probes, embraces silence, and extracts real-world operational workflows without biasing answers.
Dependency Mapping
Treats AI applications as standalone software packages; focuses only on user-facing controls.
Traces data flows through middleware, APIs, vector databases, and third-party vendor training/retention terms.
Problem Reframing
Accepts the client's initial solution request at face value without exploring root causes.
Looks beneath surface requests to identify underlying data debt, governance vacuums, or process bottlenecks.
Red Line Identification
Struggles to distinguish between minor usability friction and severe compliance violations.
Uses frameworks (NIST AI RMF, EU AI Act, ISO 42001) to categorize risk tiers and enforce clear boundaries.
đź’ˇ Reflection Tip: Use your answers from this self-assessment to form learning goals with your team lead before launching your clinic client discovery phase.
Course Acknowledgments & Credits
This course has been designed based on materials made available through:
For Fall 2026, modifications include the Consortium of Cybersecurity Clinics’ AI Risk Management (AIRM) Pilot materials and Faklaris and Ramesh’s 2026–28 Participatory AI Risk Assessment course curriculum project.
We acknowledge and are grateful for the generous support of the Mozilla Foundation, the Mellon Foundation, the Consortium of Cybersecurity Clinics and its member sites, and Bank of America.