For more than two decades, CyLab has helped educate the next generation of cybersecurity and privacy leaders by combining world-class research with hands-on learning opportunities. Through pioneering programs such as the CyLab Security Academy, interdisciplinary degree and certificate programs, undergraduate and graduate research experiences, world-class cybersecurity competition, and mentorship from internationally recognized faculty, we equip students and lifelong learners with the technical expertise and real-world perspective needed to address society's most pressing security and privacy challenges.
#1 in Undergraduate Cybersecurity Education Six Years Running
Carnegie Mellon University has been recognized as a national leader in cybersecurity education, earning the No. 1 ranking for undergraduate cybersecurity programs in the 2021 through 2026 U.S. News & World Report rankings and the No. 1 ranking for in-person cybersecurity master’s programs in Fortune Magazine’s 2025 rankings.
The recognitions highlight Carnegie Mellon’s long-standing strength in cybersecurity across multiple levels of study, from undergraduate education to advanced graduate training. Together, the rankings reflect the university’s emphasis on rigorous academics, interdisciplinary collaboration, and research that addresses real-world security and privacy challenges.
At the undergraduate level, the U.S. News & World Report ranking placed Carnegie Mellon at the top of the field nationwide for the sixth consecutive year. Undergraduate students interested in cybersecurity major in either computer science or in electrical and computer engineering and take additional courses that form a concentration in security and privacy. They engage with foundational computer science, engineering, and policy concepts while gaining exposure to the technical and societal dimensions of securing digital systems.
CMU also received top honors for its graduate offerings, with Fortune Magazine ranking the university’s cybersecurity in-person master’s programs No. 1. Our graduate programs are designed to prepare students for advanced technical and leadership roles in areas such as cybersecurity engineering, network security, privacy, and risk management.
Cybersecurity education and research at Carnegie Mellon are supported by faculty expertise across multiple schools and departments, as well as by university-wide initiatives focused on security, privacy, and emerging technologies. Students at both the undergraduate and graduate levels benefit from opportunities to engage in research, collaborate across disciplines, and work on problems relevant to industry, government, and society.
Project links:
CMU student Dani Wicklund joins the Leadership Development Institute & Counselors for Computing Program Workshop at the Pittsburgh Technology Council to lead an AI Security in Education session for 21 national trainer-educators.
Cybersecurity Training for Middle School and High School Students
The CyLab Security Academy serves more than one million registered users worldwide and hosts one of the largest cybersecurity competitions in the world. The annual online capture-the-flag (CTF) competition attracts participants ranging from middle and high school students to university students and working professionals, providing a unique longitudinal view into how competitive cybersecurity behavior evolves over time.
The CyLab Security Academy grew out of picoCTF, an interactive, gamified experience launched by CyLab faculty member David Brumley in 2013. Participants reverse-engineer programs, decrypt messages, exploit vulnerabilities, and think creatively to solve real-world inspired challenges, all in pursuit of digital “flags” that earn points on the global scoreboard.
The competition serves as both an entry point and a test bed. For beginners, it offers hands-on exposure to concepts like cryptography, web exploitation, forensics, binary exploitation, and reverse engineering. For more advanced players, it provides increasingly complex challenges that simulate the kinds of thinking required in real-world cybersecurity roles.
In addition to the annual competition, CyLab Security Academy offers learning guides and produces a monthly YouTube lecture series to help introduce cybersecurity principles, such as cryptography, web exploitation, forensics, binary exploitation, and reversing. The platform allows users to practice what they’ve learned, providing access to newly released challenges, as well as challenges from past competitions.
The Academy also offers programs and resources for teachers looking to incorporate cybersecurity education into their curriculum. Carnegie Mellon University students serve as Academy ambassadors in Pittsburgh and surrounding areas, visiting classrooms to help onboard students to the platform and review basic security engineering concepts, methods, and terminology.
Today, the CyLab Security Academy continues to expand its educational offerings across cybersecurity, AI security, and blockchain security, areas that reflect the evolving skills and knowledge required of future security practitioners.
Project links:
- White paper: “Skill or Shortcut? AI, Competitive Cybersecurity Learning, and the Growing Gap Between Performance and Expertise”
- Explore the platform
In 2026, Carnegie Mellon University students claimed first place in the MITRE Embedded Capture the Flag (eCTF) cybersecurity competition for the fifth consecutive year.
The World’s Top Collegiate Competitive Hacking Teams
For nearly two decades, Carnegie Mellon University has built one of the most dominant traditions in collegiate competitive hacking, producing teams that consistently outperform the world's best student and professional cybersecurity competitors.
Through its renowned Plaid Parliament of Pwning (PPP) team and a culture that emphasizes hands-on offensive and defensive security research, Carnegie Mellon students have transformed capture-the-flag (CTF) competitions into a proving ground for the next generation of cybersecurity leaders.
The university's greatest success has come at DEF CON's prestigious capture-the-flag competition, widely regarded as the "Olympics of hacking." Since first competing in 2010, Carnegie Mellon's PPP team has established itself as the most successful competitor in the event's history.
The team has captured nine of the past 13 DEF CON CTF championships, more than any other organization, and has won four consecutive titles in an unprecedented run that reflects years of sustained excellence in offensive cybersecurity, reverse engineering, vulnerability research, and systems defense. The competition pits the world's top qualifying teams against one another in a demanding attack-and-defense format that requires participants to simultaneously protect their own infrastructure while exploiting vulnerabilities in their opponents' systems.
Carnegie Mellon has demonstrated similar dominance in the MITRE Embedded Capture the Flag (eCTF) competition, which challenges teams to secure increasingly complex embedded systems that mirror real-world devices and critical infrastructure.
In 2026, CMU claimed its fifth consecutive eCTF championship, extending a record-setting streak in one of the nation's premier embedded cybersecurity competitions. Success at MITRE eCTF showcases the breadth of Carnegie Mellon's cybersecurity expertise, requiring students to integrate secure hardware design, software engineering, cryptography, systems architecture, and adversarial thinking into practical, deployable solutions.
These sustained victories highlight Carnegie Mellon's long-standing commitment to experiential cybersecurity education, interdisciplinary collaboration, and research-driven innovation. By consistently producing championship-caliber teams across multiple competition formats, the university has helped shape generations of cybersecurity professionals while reinforcing its reputation as one of the world's leading institutions for cybersecurity education and research.
Project links:
- News story: Carnegie Mellon extends historic run with its fifth straight MITRE eCTF title
- News story: Carnegie Mellon’s hacking team wins fourth straight, record ninth overall DEF CON Capture-the-Flag title
Defining and Institutionalizing Privacy Engineering and AI Governance Education
As governments and technology companies increasingly recognized that privacy in the 21st century could not be achieved through policy alone, Carnegie Mellon University pioneered a new approach: teaching engineers to build privacy directly into technology.
Drawing on decades of groundbreaking research, Norman Sadeh and Lorrie Cranor started Carnegie Mellon University's pioneering master’s program in privacy engineering in 2012, formally introducing the Master of Science in Information Technology-Privacy (MSIT-Privacy) as the first degree of its kind anywhere in the world.
Today, that program has been rebranded as the Privacy Engineering and AI Governance Program to better capture what it teaches in an era increasingly shaped by artificial intelligence. It also remains the first and foremost program in this area in the world.
The programs were co-founded and directed by CyLab faculty members Lorrie Cranor and Norman Sadeh, whose research helped define the principles of usable privacy, privacy by design, and responsible data governance. Rather than treating privacy as a legal or compliance issue addressed after products are built, Carnegie Mellon's curriculum teaches students to incorporate privacy protections throughout the software development lifecycle. Students combine advanced coursework in information security, privacy engineering, computer and AI law, responsible AI, privacy policy, and usable privacy with interdisciplinary capstone projects that solve real-world challenges for industry and government partners.
With artificial intelligence continuously transforming the technological landscape, Carnegie Mellon’s Privacy Engineering team has consistently evolved the program to meet emerging challenges. In 2026, the university expanded its flagship privacy engineering degree into the Master of Science in Privacy Engineering and AI Governance, while also introducing the Master of Science in Privacy Technology and AI Governance, which features a fully remote option for working professionals, as well as a five-weekend, fully remote Privacy Engineering and AI Governance Certificate. The updated curriculum reflects the growing demand for engineers who can not only design privacy-preserving systems, but also develop trustworthy AI technologies that satisfy evolving legal, ethical, and technical requirements.
The team also offers executive education in this area through its Certificate Program in Privacy Engineering and AI Governance, a condensed, fully remote weekend program tailored to the needs of working professionals and taught by the same faculty as the degree programs. The certificate is available for individual enrollment and can also be offered to cohorts from a single organization.
Carnegie Mellon's Privacy Engineering and AI Governance programs remain the global standard for graduate education in the field they helped create. Supported by the research ecosystem of CyLab and taught by faculty who have shaped international privacy policy and engineering practice, the programs have produced graduates who now lead privacy engineering, AI governance, and technical compliance efforts across industry, government, and academia.
The program’s continued leadership includes Hana Habib, who serves as associate director and contributes expertise in usable privacy, policy, and human behavior. Together with Sadeh and other faculty, Habib helps guide both curriculum development and the broader direction of the program as privacy concerns intersect with emerging technologies.
Project links:
picoCTF-Africa team training sessions
Innovating Security and Privacy in Africa
Since its founding in 2011, Carnegie Mellon University Africa (CMU-Africa) has emerged as a premier center for cybersecurity and privacy research.
CMU-Africa has helped strengthen digital security across Africa and prepared a new generation of cybersecurity leaders by combining graduate education with interdisciplinary research and close partnerships with governments, industry, and academic institutions. Its work has focused on addressing challenges unique to emerging economies, including securing digital financial systems, protecting user privacy, strengthening digital public infrastructure, and expanding access to trustworthy technologies.
A major milestone came in 2021 with the launch of CyLab-Africa. Initially established to improve the cybersecurity and resilience of Africa's rapidly growing financial technology ecosystem, the initiative has since expanded into a broad research program spanning cybersecurity, privacy, digital inclusion, and public outreach.
Researchers at CyLab-Africa have collaborated with researchers in Pittsburgh to examine the security of mobile financial applications used across Africa, develop tools to improve cybersecurity for fintech companies, create privacy recommendations for digital public goods, investigate mobile-money fraud and SMS phishing (“smishing”), and advance artificial intelligence and data-driven approaches to strengthen cyber resilience. CyLab-Africa has also become a hub for conferences, workshops and collaborations that connect researchers and policymakers working to build secure and equitable digital ecosystems throughout Africa.
CMU-Africa further expanded its impact through the Upanzi Network, launched in 2021 with support from the Gates Foundation to create an Africa-based network of engineering research laboratories focused on secure and resilient digital transformation. The network develops and evaluates digital public infrastructure and digital public goods in areas including digital identity, payments, cybersecurity, cloud computing, artificial intelligence, data governance and technology policy.
Since its inception, the Upanzi Network has grown beyond Rwanda by establishing research nodes in Morocco, Botswana, Senegal, and South Africa while building partnerships across the continent. Its researchers have assessed the security of more than 260 financial applications and 66,000 government e-services, developed an open portal containing more than 5,000 African datasets, established Africa's first Academic Security Operations Center, and organized hackathons and collaborative research initiatives to advance secure digital identity systems and public infrastructure.
Beyond research, CMU-Africa has made cybersecurity education and workforce development central to its mission. Through picoCTF-Africa, the university has introduced thousands of middle school, high school, and university students across the continent to cybersecurity. The Upanzi Network has helped educate more than 3,500 students through picoCTF-Africa while training dozens of early-career researchers through internships and research programs.
Together, CyLab-Africa and the Upanzi Network have established CMU-Africa as a leading catalyst for cybersecurity innovation, privacy research and digital public infrastructure, demonstrating how globally recognized research can be adapted to address the unique technological opportunities and challenges facing Africa.
Project links: