Renting Brains, Owning the Mistakes: LLMs in Cybersecurity Education

Students already use LLMs for almost everything: explaining concepts, writing reports, debugging their labs, and sometimes skipping the hard part of learning altogether. And they will not stop when they graduate: the habits formed in a lecture hall follow them into the SOC and the codebase, which makes how we teach with these tools a security problem, not just an academic one.
This talk briefly sets out why we care about LLMs, the economics, the energy, and the jobs behind the hype, then draws on hands-on experience teaching cybersecurity at the University of Turku. I'll share where LLMs genuinely help students and where they quietly erode the skills the field depends on.


Total length : 45-50 min + 10-15 min Q&A
Part 0 · Who, and why listen

whoami: PhD researcher, occasional lecturer, TurkuSec chair; teaching cybersecurity at the University of Turku.
Brief mention UTU / TurkuSec context for credibility.
Core idea is that an LLM is neither enemy nor friend a tool with a user, and the user owns the mistakes.


Part 1 · Why we care

Evangelist people think LLMs are good, and get only better, and it is impossible to get harm from it, and while they measure who burnt more tokens within 24h frames, people pay for it, and sometimes they pay too much.

"It's cheap" → economics. Uber burned its planned 2026 AI-coding budget in four months; engineers at $500–$2,000/mo; OpenClaw chewing $1–5k/day on a $200 plan; GitHub freezing Copilot sign-ups. At today's subsidized pricing the unit economics are propped up, not "it will collapse," but someone else is absorbing the bill.

"It's eco-friendly" → energy & where it lands. Tiny per prompt (0.24 Wh) vs vast in aggregate (~945 TWh by 2030); Jevons paradox; Google's own emissions up despite efficiency gains → then the local cost: Vantage VA, xAI Memphis, and externalities on bills, rent, land, sleep. LLM data centers cause severe pollution and harm people.

"It's a revolution, not a bubble" → jobs & failures. Layoffs framed as AI efficiency (Oracle, Meta, Microsoft, Amazon); real-world breakage (AWS/Kiro outage, the wiped DataTalks database, the Fastly senior-vs-junior split).
These claims are backed by independent papers and expert review of the waste and pollution LLMs produce.
Other claims supporting the point are interviews of local people complaining about noise, pollution and general detrimental impact of LLMs.
Students use these tools constantly and won't stop at graduation. The habits formed in the lecture hall walk into the SOC. So this is an education problem — which is where the rest of the talk lives.


Part 2 · The new learning reality
Taking Part 1 into account, why don't we want students to abuse LLMs? What they do at University becomes a habit once they start working.

Students already use LLMs for everything (to explain, to summarize, to write, to code, to debug, to exam-prep, and sometimes to skip the learning entirely).
UTU permits responsible use; the question is no longer whether but how.
Google-fu is dying from "find and think" to "ask and accept" (StackOverflow decline; same effect we observe at university, students do not google basic problems, and when LLM troubleshooting fails they immediately email us, and we reply with the first link on google).
The real problem: usage without structure, without knowing what these tools are good at, bad at, and where they quietly fail.


Part 3 · Where it quietly erodes — the bad

Faster learning, weaker thinking: outsourcing the struggle ≠ growth; a correct output doesn't prove understanding.
Most students don't verify; fluency is mistaken for correctness; beginners are most exposed to smooth nonsense.
Since most of the students LACK the experience (especially relevant for bachelor students), they immediately believe LLM, even when the facts are wrong.
Hands-on skills vs AI assistance: learn the underlying skill before automating it. Some students lack basic IT skills, and LLM is making it worse.
The purpose of homework is to solidify the knowledge on the matter, not to feed it to LLM for training the model and getting your answers.
Sharing a couple of negative examples from teaching time at UTU (no text on slide, but rather storytelling, 3 mins)
Sharing students' feedback on LLM incorporation to the course (This is being collected currently, ready in August)


Part 4 · The flip: where it genuinely helps — the good

The pivot: same tool, different user. The fluent output that fools a beginner teaches a careful student what good looks like.
Personal tutor: patient, available at 2am, removes the social cost of asking — especially for shy, Finnish, and non-native students.
From theory to "it works": environment-specific debugging companionship; the moment students used to quit becomes the moment they get unstuck.
It generates a lot of research avenues → master's/bachelor's theses, PhD dissertations, research assistants.
Force multiplier for instructors: faster lab design, exam variants, tighter feedback loops.
Self-study that finally works; serious entry points beyond the syllabus.
Language equity: non-native speakers judged on their security thinking, not their prepositions.
Sharing a couple of positive examples from teaching time at UTU (no text on slide, but rather storytelling, 5-6 mins)
Sharing the students' feedback on LLM incorporation to the course (This is being collected currently, ready in August)


Part 5 · Why verification is the whole game — capstone risk

The hardest risk we are afraid of at UTU isn't hallucination, it's bias you can't see.
Historical analogues: Sugar Research Foundation / Harvard (1967); Coca-Cola's GEBN; Merck/Vioxx ghostwriting (~55k deaths, Graham's FDA testimony).
Those manipulations had to clear high bars and fool trained audiences. The audience for LLMs is everyone — including future doctors and regulators, while they're still students.
The 2+2=5 problem: we learned to question the press and social media; we haven't learned to question the model. The presentation is the persuasion.
What if tomorrow an LLM starts telling students that telnet is a good idea or introduces some subtler bias? Because students trust the model, they won't double-check the claim; they'll simply believe it.


Part 6 · Takeaways & close

Neither enemy nor friend; a tool with a user, but the current approach is alarming
Verification is the new baseline literacy.
Compress work, don't replace judgment.
Cybersecurity education is uniquely positioned to lead.
The students who benefit most are the ones we were quietly losing.