REVIEW 4 major objections 5 minor 47 references
Cybersecurity Study Programs: What's in a Name?
T0 review · 4 major / 5 minor · reviewed 2026-08-12 · deepseek-v4-flash
Pith's one-line read Top-ranked universities have not widely adopted cybersecurity curricular guidelines, and most 'cyber'-named degree programs omit non-technical knowledge areas and mandatory internships.
desk verdict A useful, genuinely new global dataset on cybersecurity programs, but the Section 6 'all eight KAs' claim overstates what the coding actually measured. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The argument is carried by the CSEC2017 Knowledge Areas, used as the benchmark for what a complete cybersecurity curriculum should contain, and a strict counting rule that credits a program with covering a knowledge area only when its essential concepts appear as a substantial part of core or core-elective courses—not as one or two topics in a single introductory course. The authors apply this rule to publicly available program websites and course catalogs for 45 'cyber'-named programs, and separately check program requirements for internships and final projects or theses. The survey set itself is built from five university rankings to ensure global coverage.
What would settle it
Inspect the official curriculum records or accreditation self-studies of the same 45 'cyber' programs and count how many have required courses that substantially cover the human, organizational, and societal security knowledge areas of CSEC2017; if that count is substantially larger than five, the paper's central finding is an artifact of relying on public course descriptions.
Extended reading notes
Core claim
The paper's central discovery is that the existing cybersecurity curricular guidelines have not been broadly adopted by top-ranked universities. Among the 45 programs with 'cyber' in their name at 101 institutions in 24 countries, only five programs cover the human, organizational, and societal security knowledge areas defined by CSEC2017; the rest concentrate on the technical knowledge areas such as data, connection, and system security. Mandatory internships are required by only five programs, and only four programs are bachelor's degrees. The authors conclude that most of these 'cyber' programs lack essential non-technical content and experiential learning, and that graduates may therefore need additional training to meet employer expectations.
Load-bearing premise
The findings assume that what appears in publicly available program descriptions and course catalogs is an accurate reflection of what a program actually requires and teaches; if those descriptions are outdated or misleading, the reported coverage numbers would be wrong.
Editorial extensions
If this is right
- Students cannot rely on the word 'cyber' in a degree title to mean the program covers the full CSEC2017 curriculum, so they should check the required courses for law, policy, risk, and human factors.
- Employers hiring from these programs should expect to provide additional on-the-job training, because most of the surveyed programs do not require internships and therefore do not guarantee workplace experience.
- The scarcity of bachelor's programs (only four at top universities) means students seeking an early, deep specialization in cybersecurity have few options at leading institutions.
- Program directors can use the paper's 10-item checklist and the highlighted good-practice examples to add the missing non-technical and experiential components.
- The paper's dataset and Python notebook are publicly available, so prospective students and researchers could re-examine or extend the analysis.
Reading between the lines
- My reading: the strict counting rule (ignoring a knowledge area that appears as only one or two topics in an introductory course) is a design choice that may undercount borderline programs; a more lenient counting of any mention in a course description could push the number of 'covering' programs higher, so the exact percentages should be treated as lower bounds under the authors' own criterion.
- The paper assumes employers value the CSEC2017 non-technical areas because job-ad studies emphasize soft skills, but it does not directly link graduates of the five 'full coverage' programs to better employment outcomes; that link is a testable next step.
- By limiting the detailed analysis to programs with 'cyber' in the name, the paper leaves open the possibility that security tracks inside general computer science programs cover these areas; a broader scope might change the picture of global coverage.
- A natural extension is to map the job-market skill categories from the cited ad analyses onto the CSEC2017 knowledge areas and then check which programs' descriptions align with which job roles; that would turn the curriculum check into a workforce-readiness forecast.
Signed reviews
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. This paper surveys 133 study programs at 101 universities selected from five international rankings and focuses on the 45 programs whose names contain "cyber." Based on manual inspection of public program and course descriptions, the authors code whether programs cover the human, organizational, and societal security knowledge areas of CSEC2017 and whether they require internships or final projects/theses. They report that only five cyber-named programs cover the three non-technical knowledge areas, only five mandate internships, and only four require both an internship and a final project/thesis. The paper concludes that top-ranked universities have not widely adopted existing curricular guidelines and offers a ten-item checklist for program directors. A dataset and Python notebook are released as supplementary material.
Significance. If the descriptive claims hold, the paper provides a useful global snapshot of cybersecurity program design that complements prior US-centric work, and the released dataset is a reproducible community artifact. The study is anchored to external standards (CSEC2017 and CC2020) rather than to parameters fitted by the authors, so circularity is not a concern. The authors are also transparent about sampling limitations and about using publicly available descriptions. However, the paper's headline quantitative claim that only five programs cover all eight CSEC2017 knowledge areas is not supported by the measurements actually reported, which cover only three non-technical knowledge areas. The coding procedure is also under-specified, with no inter-rater reliability and no auditable concept-level coding decisions. These issues are fixable within the paper's scope, so the central descriptive message remains plausible after revision.
major comments (4)
- [Section 6 (Conclusion)] The statement that 'only five cover all eight knowledge areas defined by CSEC2017' is not supported by the methods described in Sections 3.2 and 4.3. The authors report coding only for the human, organizational, and societal security knowledge areas; they do not report any measurement of the five technical knowledge areas (for example, data security, software security, component security, connection security, and system security). A program could therefore be counted as 'not covering all eight' even if it covers the technical areas well, and no program is positively verified as covering all eight. Please reword the headline to 'only five cover the three non-technical knowledge areas' or collect and report evidence for all eight knowledge areas.
- [Section 4.3] The coding procedure is under-specified and not independently auditable. The authors do not report the list of CSEC2017 essential concepts used for each knowledge area, the operational definition of 'one or two topics out of ten or more in a single, typically introductory course,' or inter-rater reliability. The released dataset contains links to programs and a processing notebook, but not per-program coding decisions. Since the central percentages (for example, 5/45 and 12/45) are counts produced by this coding, a reasonable re-coding could shift the headline numbers. Please publish a concept-level coding sheet with evidence per program and report agreement statistics from at least two coders on a sample of programs.
- [Section 4.4 and Figure 3] The treatment of the 'N/A' category in Figure 3 is ambiguous and affects the reported counts. The figure distinguishes 'N/A' from 'Yes' and 'No,' but Section 4.4.1 states that mandatory internships are present in only five programs (11%), and Section 6 states that six programs require neither an internship nor a final project/thesis. If 'N/A' means the program descriptions do not state the requirement, then absence of stated information is not evidence of absence from the curriculum. Please state explicitly how 'N/A' observations were mapped into the yes/no totals, and report ranges or sensitivity analyses where the classification is uncertain.
- [Section 1.3 and Abstract] The claim that graduates 'may not meet employer expectations and may require additional training' goes beyond the data collected. The study measures presence or absence of certain course topics and experiential-learning components in public descriptions; it does not measure employer satisfaction, graduate outcomes, or the actual relationship between those curriculum features and job readiness. Please reframe this as an inference or hypothesis motivated by prior literature rather than a finding of the present survey, or add direct evidence linking the coded features to employment outcomes.
minor comments (5)
- [Section 4.3] The phrase 'the least represented (6×)' is informal; consider writing 'six programs' or 'six occurrences' for consistency with the other counts.
- [Figure 3] The bar labels in Figure 3 are dense and the exact per-category counts are not repeated in the prose, which makes the figure hard to verify; please restate the counts for each group in the text or in a table.
- [Section 4.2] The statement that 'only 6 out of 17 cyber programs offered in the USA have been validated by NSA' would benefit from a brief explanation of what 'validated' means in this context, since the cited CAE designation is a program-level designation rather than a simple binary check.
- [References] Reference [31] is cited as 'Cybersecurity Curricular Guideline' in the reference list but as 'CSEC2017' throughout the text; please standardize the title and ensure the URL is the version used for coding.
- [Throughout] There are minor spelling and formatting inconsistencies, such as 'post-graduate' versus 'postgraduate,' 'cyber crime' versus 'cybercrime,' and the phrase 'InProceedings' in reference [25]; these should be cleaned up in the camera-ready version.
Circularity Check
No significant circularity: the empirical claims are benchmarked against external CSEC2017/CC2020 standards, not against author-fitted inputs.
full rationale
The paper's claimed derivation is an empirical comparison, not a derivation from its own assumptions. The authors select universities using five external rankings (THE-WU, QS-WU, EDU, GCI, THE-EE), extract 133 programs from public catalogs, and then evaluate only the 45 'cyber'-named programs against external CSEC2017 essential concepts for human, organizational, and societal security, and against CC2020's experiential-learning recommendations. No parameter is fitted to the data and then renamed as a prediction; no equation is defined in terms of the result being explained. The coding rule in Section 4.3 ('searched for essential concepts' and not counting concepts appearing as 'one or two topics out of ten or more') is under-specified, and the Section 6 sentence 'only five cover all eight knowledge areas defined by CSEC2017' exceeds what was measured, since Section 4.3 only coded three non-technical KAs; these are validity and overreach concerns, not circularity. The paper's own Section 3.3 also acknowledges that outdated websites may limit the findings, which is a data-quality caveat rather than a circular step. The authors' self-citations ([4], [39], [40]) are not load-bearing: [39] is background literature, [4] supports an optional checklist suggestion, and [40] is the released dataset. The checklist in Section 5 is explicitly based on 'study findings and our experience' and is not presented as a prediction forced by the data. Therefore, no circular step is present; score 0.
Assumptions & free parameters
free parameters (2)
- Non-technical coverage counting threshold =
Concepts appearing as one or two topics out of ten or more in a single course are not counted
- University ranking cutoffs =
Top 50 THE, top 50 QS, top 50 EDU, top 31 GCI, top 15 THE-EE
assumptions (3)
- domain assumption CSEC2017 is the correct and complete normative standard for evaluating cybersecurity program content
- domain assumption Publicly available program websites and course catalogs accurately reflect actual program content and requirements
- domain assumption The five selected ranking lists identify the universities that matter for evaluating guideline adoption
Cite this review
Pith. "Pith review of Cybersecurity Study Programs: What's in a Name?." pith.science (2026). https://pith.science/paper/JBWDR7HL
@misc{pith2026241109240,
author = {Pith},
title = {Pith review of: Cybersecurity Study Programs: What's in a Name?},
year = {2026},
howpublished = {\url{https://pith.science/paper/JBWDR7HL}},
note = {Machine review of arXiv:2411.09240}
}
read the original abstract
Improving cybersecurity education has become a priority for many countries and organizations worldwide. Computing societies and professional associations have recognized cybersecurity as a distinctive computing discipline and created specialized cybersecurity curricular guidelines. Higher education institutions are introducing new cybersecurity programs, attracting students to this expanding field. In this paper, we examined 101 study programs across 24 countries. Based on their analysis, we argue that top-ranked universities have not yet fully implemented the guidelines and offer programs that have "cyber" in their name but lack some essential elements of a cybersecurity program. In particular, most programs do not sufficiently cover non-technical components, such as law, policies, or risk management. Also, most programs teach knowledge and skills but do not expose students to experiential learning outside the traditional classroom (such as internships) to develop their competencies. As a result, graduates of these programs may not meet employer expectations and may require additional training. To help program directors and educators improve their programs and courses, this paper offers examples of effective practices from cybersecurity programs around the world and our teaching practice.
Figures
Reference graph
Works this paper leans on
-
[1]
Saleh AlDaajeh, Heba Saleous, Saed Alrabaee, Ezedin Barka, Frank Breitinger, and Kim-Kwang Raymond Choo. 2022. The role of national cybersecurity strategies on the improvement of cybersecurity education. Computers & Security 119 (2022), 102754. https://doi.org/10.1016/j.cose.2022.102754
arXiv 2022
-
[2]
Muhammad Rizwan Asghar and Andrew Luxton-Reilly. 2020. A Case Study of a Cybersecurity Programme: Curriculum Design, Resource Management, and Reflections. In Proceedings of the 51st ACM Technical Symposium on Computer Science Education (Portland, OR, USA) (SIGCSE ’20). ACM, New York, NY, USA, 16–22. https://doi.org/10.1145/3328778.3366918
arXiv 2020
-
[3]
William F. Atchison, Samuel D. Conte, John W. Hamblen, Thomas E. Hull, Thomas A. Keenan, William B. Kehl, Edward J. McCluskey, Silvio O. Navarro, Werner C. Rheinboldt, Earl J. Schweppe, William Viavant, and David M. Young
-
[4]
Razvan Beuran, Jan Vykopal, Daniela Belajová, Pavel Čeleda, Yasuo Tan, and Yoichi Shinoda. 2023. Capability Assessment Methodology and Comparative Analysis of Cybersecurity Training Platforms. Computers & Security 128 (2023), 103120. https://doi.org/10.1016/j.cose.2023.103120
arXiv 2023
-
[5]
Raymond W. Blaine, Jean R. S. Blair, Christa M. Chewar, Rob Harrison, James J. Raftery, and Edward Sobiesk. 2021. Creating a Multifarious Cyber Science Major. In Proceedings of the 52nd ACM Technical Symposium on Computer Science Edu- cation (Virtual Event, USA) (SIGCSE ’21). ACM, New York, NY, USA, 1205–1211. https://doi.org/10.1145/3408877.3432462
arXiv 2021
-
[6]
Borka Jerman Blažič. 2022. Changing the landscape of cybersecurity education in the EU: Will the new approach produce the required cybersecurity skills? Education and information technologies 27, 3 (2022), 3011–3036. https://doi.org/ 10.1007/s10639-021-10704-y
-
[7]
CAE in Cybersecurity Community. 2024. CAE Institution Map. Online, accessed July 8, 2024, map last updated July 1, 2024. https://www.caecommunity.org/cae- map
work page 2024
-
[8]
CC2020 Task Force. 2020. Computing Curricula 2020: Paradigms for Global Com- puting Education. ACM, New York, NY, USA. https://doi.org/10.1145/3467967
doi:10.1145/3467967 2020
Show all 47 references
-
[9]
Shuai Chen, Mengmeng Hao, Fangyu Ding, Dong Jiang, Jiping Dong, Shize Zhang, Qiquan Guo, and Chundong Gao. 2023. Exploring the global geography of cybercrime and its driving forces.Humanities and Social Sciences Communications 10, 1 (23 Feb 2023), 71. https://doi.org/10.1057/s...
2023 doi
-
[10]
Arthur Conklin, Raymond E
Wm. Arthur Conklin, Raymond E. Cline, and Tiffany Roosa. 2014. Re-engineering Cybersecurity Education in the US: An Analysis of the Critical Factors. In 2014 47th Hawaii International Conference on System Sciences . IEEE, New York, NY, USA, 2006–2014. https://doi.org/10.1109/H...
2014 doi
-
[11]
James Crabb, Christopher Hundhausen, and Assefaw Gebremedhin. 2024. A Critical Review of Cybersecurity Education in the United States. InProceedings of the 55th ACM Technical Symposium on Computer Science Education (SIGCSE 2024) . ACM, New York, NY, USA, 241–247. https://doi.o...
2024
-
[12]
Cybersecurity Guide Contributors. 2024. Cybersecurity Guide. https:// cybersecurityguide.org/programs/cybersecurity-bachelors-degree/#Schools On- line, last updated: May 10, 2024
2024
-
[13]
Cybersecurity Library. 2024. CLARK. Online, accessed July 15, 2024. https: //clark.center/home
2024
-
[14]
Adéle da Veiga, Elisha Ochola, Mathias Mujinga, Keshnee Padayachee, Emilia Mwim, Elmarie Kritzinger, Marianne Loock, and Peeha Machaka. 2021. A Reference Point for Designing a Cybersecurity Curriculum for Universities. In Human Aspects of Information Security and Assurance , S...
2021 doi
-
[15]
P. J. Denning, D. E. Comer, D. Gries, M. C. Mulder, A. Tucker, A. J. Turner, and P. R. Young. 1989. Computing as a discipline. Computer 22, 2 (1989), 63–70. https://doi.org/10.1109/2.19833
1989 doi
-
[16]
EduRank.org. 2024. Best Universities for Cyber Security in the World [updated February 29, 2024]. Online, accessed June 18, 2024. https://edurank.org/cs/ cybersecurity/
2024
-
[17]
Matt Graham and Yonggang Lu
C. Matt Graham and Yonggang Lu. 2023. Skills Expectations in Cybersecurity: Se- mantic Network Analysis of Job Advertisements.Journal of Computer Information Systems 63, 4 (2023), 937–949. https://doi.org/10.1080/08874417.2022.2115954
2023
-
[18]
Mark Guzdial. 2018. What We Care about Now, What We’ll Care about in the Future. ACM Inroads 9, 4 (Nov. 2018), 63–64. https://doi.org/10.1145/3276304
2018 doi
-
[19]
Jones, Akbar Siami Namin, and Miriam E
Keith S. Jones, Akbar Siami Namin, and Miriam E. Armstrong. 2018. The Core Cyber-Defense Knowledge, Skills, and Abilities That Cybersecurity Students Should Learn in School: Results from Interviews with Cybersecurity Professionals. ACM Trans. Comput. Educ. 18, 3 (2018), 12 pag...
2018 doi
-
[20]
Djedjiga Mouheb, Sohail Abbas, and Madjid Merabti. 2019. Cybersecurity Cur- riculum Design: A Survey. In Transactions on Edutainment XV . Springer, Berlin, Heidelberg, 93–107. https://doi.org/10.1007/978-3-662-59351-6_9
2019 doi
-
[21]
New York University, Tandon School of Engineering. 2024. Cybersecurity (MS). Online, accessed July 11, 2024. https://bulletins.nyu.edu/graduate/engineering/ programs/cybersecurity-ms/
2024
-
[22]
Marc Ohm, Christian Bungartz, Felix Boes, and Michael Meier. 2024. Assessing the Impact of Large Language Models on Cybersecurity Education: A Study of ChatGPT’s Influence on Student Performance. In Proceedings of the 19th Interna- tional Conference on A vailability, Reliabili...
2024
-
[23]
Raj, Henrique Santos, Muham- mad Rizwan Asghar, Audun Jøsang, Teresa Pereira, and Eliana Stavrou
Allen Parrish, John Impagliazzo, Rajendra K. Raj, Henrique Santos, Muham- mad Rizwan Asghar, Audun Jøsang, Teresa Pereira, and Eliana Stavrou. 2018. Global Perspectives on Cybersecurity Education for 2030: A Case for a Meta- discipline. In Proceedings Companion of the 23rd Ann...
2018
-
[24]
Pennsylvania State University. 2024. Cybersecurity Analytics and Operations, B.S. Online, accessed July 11, 2024. https://bulletins.psu.edu/undergraduate/colleges/ information-sciences-technology/cybersecurity-analytics-operations-bs/
2024
-
[25]
Mike Perkins, Jasper Roe, Darius Postma, James McGaughran, and Don Hickerson
-
[26]
Quacquarelli Symonds. 2024. QS World University Rankings by Subject: Computer Science and Information Systems 2024. Online, accessed June 18, 2024. https://www.qschina.cn/en/university-rankings/university-subject- rankings/2024/computer-science-and-information-systems
2024
-
[27]
Ying Sui. 2024. The Investigation of Cybersecurity Education Among College Students: Aiming to Address the Scarcity of Skilled Professionals.The Educational Review, USA 8, 6 (2024), 801–807. https://www.proquest.com/scholarly-journals/ investigation-cybersecurity-education-amo...
2024
-
[28]
Tallinn University of Technology. 2024. Cyber Security Engineering. Online, accessed July 12, 2024. https://ois2.taltech.ee/uusois/programme/IVSB17/23
2024
-
[29]
Tallinn University of Technology. 2024. Cybersecurity. Online, accessed July 12,
2024
-
[30]
The ACM Committee for Computing Education in Community Colleges (CCECC)
-
[31]
The ACM Joint Task Force (JTF) on Cybersecurity Education. 2017. Cybersecurity Curricular Guideline. Online, accessed May 27, 2024. http://cybered.acm.org
2017
-
[32]
https://ois2.taltech.ee/uusois/programme/IVCM09/24
-
[33]
The National Cyber Security Centre (NCSC). 2021. The Cyber Security Body Of Knowledge (CyBOK) v. 1.1. Online, accessed May 27, 2024. https://www.cybok. org/
2021
-
[34]
The National Institute of Standards and Technology (NIST). 2020. National Initia- tive for Cybersecurity Education (NICE). Online, accessed May 27, 2024. https:// www.nist.gov/itl/applied-cybersecurity/nice/nice-framework-resource-center
2020
-
[35]
Times Higher Education. 2021. Emerging Economies University Rankings 2022. Online, accessed June 18, 2024. https://www.timeshighereducation.com/world- university-rankings/2022/emerging-economies-university-rankings
2021
-
[36]
The European Union Agency for Cybersecurity (ENISA). 2022. European Cyber- security Skills Framework (ECSF). Online, accessed May 27, 2024. https://www. enisa.europa.eu/topics/education/european-cybersecurity-skills-framework
2022
-
[37]
International Telecommunication Union. 2020. Global Cybersecurity Index. Online, accessed June 18, 2024. https://www.itu.int/en/ITU-D/Cybersecurity/ Pages/global-cybersecurity-index.aspx
2020
-
[38]
Valdemar Švábenský. 2022. Automated Feedback for Cybersecurity Training . Doc- toral thesis. Masaryk University. https://is.muni.cz/th/dg3b4/?lang=en
2022
-
[39]
Valdemar Švábenský, Jan Vykopal, and Pavel Čeleda. 2020. What Are Cyber- security Education Papers About? A Systematic Literature Review of SIGCSE and ITiCSE Conferences. In Proceedings of the 51st ACM Technical Symposium on Computer Science Education (Portland, OR, USA) (SIGC...
2020
-
[40]
Times Higher Education. 2023. World University Rankings 2024 by subject: com- puter science. Online, accessed June 18, 2024. https://www.timeshighereducation. com/world-university-rankings/2024/subject-ranking/computer-science
2023
-
[41]
Richard Weiss, Jens Mache, Elizabeth Hawthorne, Ambareen Siraj, Blair Taylor, Siddharth Kaza, and Ankur Chattopadhyay. 2021. Integrating Hands-on Cyber- security Exercises into the Curriculum in 2021. In Proceedings of the 52nd ACM Technical Symposium on Computer Science Educa...
2021
-
[42]
Sherri Weitl-Harms, Adam Spanier, John Hastings, and Matthew Rokusek. 2023. A Systematic Mapping Study on Gamification Applications for Undergraduate Cy- bersecurity Education. Journal of Cybersecurity Education, Research and Practice 2023, 1 (2023), 9. https://doi.org/10.3272...
2023 doi
-
[43]
Özcan Özyurt and Ahmet Ayaz. 2024. Identifying cyber security competencies and skills from online job advertisements through topic modeling. Security Journal – (2024), 21 pages. https://doi.org/10.1057/s41284-024-00420-w
2024 doi
-
[44]
Lopez II, and Pavel Čeleda
Jan Vykopal, Valdemar Švábenský, Michael T. Lopez II, and Pavel Čeleda. 2024. Dataset: Cybersecurity Study Programs. Online, accessed November 8, 2024. https://gitlab.fi.muni.cz/cybersec/papers/2025-sigcse-cybersecurity-programs
2024
-
[1968]
ACM 11, 3 (March 1968), 151–197
Curriculum 68: Recommendations for Academic Programs in Computer Science: A Report of the ACM Curriculum Committee on Computer Science.Com- mun. ACM 11, 3 (March 1968), 151–197. https://doi.org/10.1145/362929.362976
1968
-
[2020]
Online, accessed May 27, 2024
Cybersecurity Curricular Guidance for Associate-Degree Programs. Online, accessed May 27, 2024. https://ccecc.acm.org/guidance/cybersecurity
2024
-
[2024]
https://doi.org/10.1007/s10805-023- 09492-6
Detection of GPT-4 Generated Text in Higher Education: Combining Academic Judgement and Software to Identify Generative AI Tool Misuse.Journal of Academic Ethics 22, 1 (2024), 89–113. https://doi.org/10.1007/s10805-023- 09492-6
2024 doi
Reviewed August 12, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.