While many academics are still locked in debate about whether to allow artificial intelligence in the classroom — fearing academic dishonesty, over-reliance, or loss of rigor — I made a deliberate choice to do the opposite. I brought AI in, put it at the center of the assessment, and asked my students to challenge it.
That decision was not taken lightly. The dilemma is real: AI tools can write essays, solve problems, and generate code with startling fluency. For many educators, this feels like a threat to the integrity of learning. But in a cybersecurity classroom, I saw a different possibility. What if AI were not the shortcut we feared, but the instrument through which students developed sharper, more critical thinking?
At Majan University College, I ventured where many colleagues hesitated — and the results reshaped how I teach cyber threats entirely.
The Dilemma Most Academics Face
The debate around AI in higher education is genuine and ongoing. Concerns about academic integrity are legitimate. When a student can paste an assignment question into ChatGPT and receive a polished response in seconds, the traditional essay or report begins to feel obsolete as an assessment instrument. Many institutions have responded with blanket bans or AI-detection policies.
But in a field like cybersecurity — where AI tools are already embedded in professional practice — banning them from the classroom risks producing graduates who are technically unprepared for the workplace. The question I kept returning to was not whether to allow AI, but how to design learning around it so that critical thinking remained non-negotiable.
“The question was not whether to allow AI, but how to design learning around it so that critical thinking remained non-negotiable.”
The Problem with Traditional Cybersecurity Instruction
Cybersecurity changes faster than most curricula can keep up with. Threat actors adapt weekly, new vulnerabilities emerge daily, and students are expected to master concepts ranging from network intrusion to social engineering — often in a single module. Lecture-based instruction struggles to keep pace.
In my own classroom, I noticed a recurring pattern: students could recite definitions of common vulnerabilities but froze when asked to identify them in a live network scenario. The knowledge was there — the application was not. I needed a method that built not just understanding, but instinct.
Step 1: Real Tools, Real Vulnerabilities
The first shift was putting industry-grade tools directly in students’ hands. Through a free licence from Tenable, students registered for and used Nessus Essentials — the same vulnerability scanner used by professional penetration testers — to scan their own lab environments and identify real weaknesses.
This was not a simulation. Students discovered actual vulnerabilities in their own machines: open ports, misconfigured services, outdated software with known exploits. The moment a student sees Nessus flag a critical-severity bind shell backdoor on their own system, the abstract becomes concrete. Cybersecurity stops being a theory module and starts feeling like a professional responsibility.
Figure 1 — Topic 7: Network Traffic Monitoring on MOVE (Majan E-Learning), showing Nessus Essentials registration, microlearning certificate upload, and the AI tools forum activity.
Step 2: Compare Three AI Tools, Then Decide
Once students identified a vulnerability, the next task was not to fix it immediately. Instead, they were asked to consult three AI tools of their choice — such as ChatGPT, Google Gemini, and Claude AI — and compare the remediation approaches each one suggested. They then had to evaluate which solution was most technically sound, justify their choice, and document their reasoning in a forum post.
This comparative exercise produced some of the richest academic discussion I have seen in a computing module. Students quickly discovered that different AI tools gave meaningfully different answers — not just in wording, but in technical depth, persistence, and correctness. One student’s analysis of a critical bind shell backdoor (CVE-linked, severity 10.0) illustrated this perfectly.
Figure 2 — A student’s submitted report comparing Claude, ChatGPT, and Gemini remediation approaches for a critical bind shell backdoor vulnerability discovered using Nessus Essentials.
As the student’s report showed, Claude’s approach — disabling the ingreslock entry in /etc/inetd.conf and de-registering the xinetd super-server — permanently removed the vulnerability at its source and survived reboots. ChatGPT’s suggestion to kill the process was effective in the moment but non-persistent. Gemini’s firewall rule blocked external access but left the backdoor process running locally. The student chose Claude’s method because it satisfied NIST SP 800-53 SI-2 requirements.
This kind of critical AI literacy — knowing not just how to use AI tools but how to evaluate and challenge their outputs — is precisely what the cybersecurity industry needs from the next generation of practitioners.
“Students discovered that different AI tools gave meaningfully different answers — not just in wording, but in technical depth, persistence, and correctness.”
Step 3: Microlearning Before Every Lab
Supporting both the Nessus work and the AI comparison tasks was a restructured content delivery model. Rather than front-loading a two-hour lecture, I broke module content into focused microlearning units of five to ten minutes each — delivered on MOVE, Majan’s e-learning platform, before each lab session.
Each unit was deliberately brief and focused, ensuring students arrived at labs already familiar with the core concept — meaning lab time could be spent entirely on application rather than explanation. A microlearning certificate upload task on MOVE reinforced completion and accountability without adding administrative burden.
At Majan University College, where many students balance studies with work and family responsibilities, the flexibility of microlearning also reduced cognitive overload. Bite-sized content reviewable on a phone during a commute proved far more accessible than dense lecture recordings.
What the Results Showed
After one full semester using this combined approach, the outcomes were encouraging. Student performance on practical assessments — particularly those requiring live vulnerability identification and remediation — improved noticeably compared to previous cohorts. Student feedback consistently highlighted increased confidence in applying tools independently, and the forum posts demonstrated a level of critical analytical writing that prior cohorts had rarely produced.
Several students who had previously struggled with abstract networking concepts were among the most engaged contributors to the AI comparison discussions. The practical, tool-driven format appeared to level the playing field in ways that traditional assessment had not.
Three Takeaways for Fellow Educators
1. Start with Nessus Essentials. Tenable offers free licences for students and educators. Having students scan their own machines creates an immediate, personal connection to the vulnerability concepts you are teaching.
2. Make AI comparison the assessment, not AI use. Asking students to compare three AI tools’ outputs builds critical thinking and AI literacy simultaneously — far more valuable than letting them use a single tool uncritically.
3. Keep microlearning units under ten minutes and single-topic. Pair each unit with a concrete lab task so the knowledge is applied within the same session it is introduced.
Cybersecurity education is no longer just about teaching student’s what threats exist. It is about equipping them to think like defenders in a world where the threats change faster than the textbooks — and where AI tools are both an asset and a variable that must itself be critically evaluated. What began as an experiment at Majan University College has become the foundation of how I approach every cybersecurity module I teach.
This is an abridged version of the full peer-reviewed article: A Pedagogical Framework for Embedding Microlearning, Gamification, and Industry Credentials in Undergraduate Cybersecurity Education — Ramalingam Dharmalingam, Majan University College, Muscat, Sultanate of Oman.
Dr. Ramalingam Dharmalingam is an Assistant Professor in Faculty of IT at Majan University College, Muscat, Oman. His research and teaching interests span cybersecurity education, AI-assisted learning, and innovative pedagogical frameworks for technology modules. He is a Senior Fellow of the Advance HE, UK and Senior member of IEEE. https://www.linkedin.com/in/rama1972