Security starts with
how the system is designed.

Students learn to see assets, identities, trust boundaries and attack paths, then engineer and verify the controls that meaningfully reduce risk.

TRUST OPERATIONSCY / LIVEATTACK PATH / CASE 014See the system through an adversary.PUBLIC APPIDENTITYPRIVILEGEDATAPATH OBSERVEDRISK REDUCTION72 → 18CONTROL VALIDATIONMFA boundaryPROVEDToken lifetimePROVEDAlert coverageREVIEW
CY

OUR POINT OF VIEW

Security education should produce judgment, not a catalog of tools and exploits.

THE FIELD IS MOVING

What students must learn to see differently.

The durable skill is not familiarity with today’s tool. It is the ability to reason about the system, its constraints, and the evidence behind a decision.

THE UNIT OF WORK
FROM

An isolated vulnerability

→
TOA system with assets, actors, and trust boundaries
THE CORE QUESTION
FROM

Can it be attacked?

→
TOHow should risk be reduced and verified?
THE ENGINEERING BAR
FROM

Tool output

→
TOEvidence, prioritization, controls, and response

INDUSTRY-VETTED COURSE PORTFOLIO

A pathway from foundations to consequential work.

Representative courses can be configured as electives, honors pathways, minors, faculty-development modules, or an integrated specialization.

CY-3014 credits · controlled security lab

Breaking and Defending Web Systems

Find, explain and fix application weaknesses inside a legal and instrumented environment.

01
CY-3154 credits · blue team studio

Detection Engineering

Turn telemetry and attacker behavior into useful detections, investigations and response actions.

02
CY-4024 credits · cloud defense lab

Cloud Identity and Zero Trust

Protect identities, workloads, data and infrastructure across realistic cloud systems.

03
CY-4104 credits · architecture practicum

Threat Modeling Real Products

Translate product context into trust boundaries, attack paths and prioritized security decisions.

04
CY-4254 credits · scenario based studio

Incident Response Lab

Triage, contain and investigate realistic incidents, then explain what must change.

05
CY-4904 credits · reviewed capstone

Digital Trust Studio

Assess a scoped system and prove that the highest priority risks were meaningfully reduced.

06

HOW WE TEACH THE DOMAIN

Practice that creates professional judgment.

Each learning experience is structured around how credible work is actually reviewed: assumptions are explicit, evidence is inspectable, and important tradeoffs must be defended.

01

Legal and ethical boundaries

Every exercise is scoped, authorized, isolated, and connected to responsible professional conduct.

02

Threat informed engineering

Students begin with assets, adversaries, attack paths and impact, not a favorite tool.

03

Blue-team evidence

Detection logic, telemetry, timelines, control validation, and incident artifacts make learning inspectable.

04

Security in the build loop

Secure design, code review, dependency risk, cloud policy, and testing enter before release.

APPLIED WORK

The kind of problems students can learn to own.

These briefs illustrate the project scope and engineering judgment we bring into programs, labs, and industry-supported capstones.

BRIEF / 01

Cloud breach simulation range

Instrumented environment for identity compromise, detection, and response.

CloudSecIRDetection
BRIEF / 02

Secure payment service review

Threat model, code analysis, controls, and verification plan.

AppSecThreat modelTrust
BRIEF / 03

Campus security operations lab

Telemetry pipeline and investigation playbooks for realistic scenarios.

SOCSIEMForensics

CENTER OF EXCELLENCE BLUEPRINT

A Cybersecurity & Digital Trust Center of Excellence

A controlled campus environment for secure engineering, defensive operations, applied research, and institution-wide security capability.

01

FOUNDATIONSSystems, networks, applications, identity, cryptography, risk

02

RANGEIsolated targets, telemetry, cloud labs, source code, scenarios

03

DEFENDThreat modeling, hardening, detection, response, secure design

04

PROVEAssessments, detections, incident reports, control validation

CAPABILITYEVIDENCE

WHAT ACADEMIC LEADERS CAN INSPECT

Proof beyond completion.

Every program is designed to leave behind concrete evidence of what students can do and how well they can reason.

Threat models and attack-path mapsDetection rules with validation dataSecurity architecture decisionsIncident timelines and after-action reviews

CY / START A CONVERSATION

What could Cybersecurity look like at your institution?

We’ll help you choose the right academic format, faculty enablement model, infrastructure, and first set of student outcomes.

Discuss a Partnership