Here’s a quick (hopefully) helpful guide to Cybersecurity at UTD. I’ve compiled this guide from my own experiences as a current student with the advice of several other current and former UTD students. Hopefully this will give you a pretty good idea about what your experiences may be like here and what other students are doing to learn, practice, and excel in cybersecurity at UTD and beyond.
Why Cybersecurity
First off, what’s so great about going into cybersecurity, particularly at UTD?
Pros:
- Money. Any salary site will tell you cybersecurity is great financially.
- Jobs. Relative to software development or AI or a lot of other tech roles, cybersecurity is way less saturated (and there’s a reason for that)
- AI-resistant Career. So far, AI has had a pretty limited effect on cybersecurity careers. Certainly AI tools are being used and developed, but they aren’t really much different than what non-AI tools do. And bad guys are using AI to ramp up the volume of attacks, but that actually helps our careers. More people will be needed as AI allows unskilled hackers/”script kiddies” to perform more attacks that are better customized to their targets. Also there’s work securing AIs and their infrastructure from hacks. Most importantly, in the event of AI taking over the world, its well documented that hackers have the best chance of surviving.
- Community. The community is amazing too and there are a lot of open-source projects you can dive into. Also, you don’t have to know coding to start! It’s a great field to transition into no matter your background as there is something for everyone because the field is so diverse.
- Cool factor. Hacking and defending systems is a lot of fun for someone who likes tinkering with technology.
Neutrals:
- Continuous Learning. There’s an expectation that you keep up with cybersecurity trends and new technologies and there’s a whole market for cybersecurity credentials/certificates, conferences, professional development, etc. If you expect your studies to end after graduating, cybersecurity might not be for you.
- Depth and Breadth. Cybersecurity is a lot to learn. Its exciting, but also intimidating. Be prepared for a challenge and feeling like you don’t know that much for a long time. This also means there’s a little bit for everyone. No matter your background, there’s probably a way your experience helps you know something about cybersecurity.
- Maintenance. Cybersecurity is a continuous process. Its not something you do and then you’re done. If you do it right the first time and you setup systems to help you handle problems, your job is relatively easy, but often this is not the case. Typically you’re having to deal with problems left by your predecessors.
Cons:
- Barriers to Entry. Cybersecurity, with its breadth and depth, is an advanced domain. Its fundamentals (networking, operating systems, databases, etc.) are topics that typically don’t get covered until pretty late in your degree. Most people work in IT or engineering for a year or two before going into Cybersecurity. This is why the market is less saturated, its harder to get into. Many would say its “not an entry-level job”
- Certification Costs. Well-respected certs are typically expensive which is a problem for us broke college kids. Ideally, whoever you work for will support getting you certified and help cover some or all of the costs, but it can be hard to get these as an individual.
- Demographics. Although the backgrounds of cybersecurity professionals are diverse (I’ve met lawyers, rock stars, people with PhDs and people with no degrees, and more who are all working in cybersecurity) it is male-dominated like many other STEM-fields.
At UTD
Cybersecurity at UTD has always been strong. Although we just got a dedicated undergraduate cybersecurity degree program in 2025, we’ve had great graduate cybersecurity programs with excellent scholarships and our emphasis on Computer Science (about a quarter of campus is CS majors) and similar fields helps us attract top cybersecurity faculty. Clubs, events, and the environment in DFW has strengthened the community here at UTD.
Beyond this, UTD is designated as a Center of Academic Excellence in Cybersecurity by the NSA and DHS for Cyber Defense, Cyber Research, and Cyber Research (CAE Map). 484 institutions in the US hold one or more of these distinctions, but only 11 (!!!) have all three. When received the third designation for Cyber Operations in 2015, we were the only institution to have it in Texas. We received Cyber Research in 2008 and Cyber Defense in 2004 (renewed).
Also in 2004, we opened the Cyber Security Research and Education Institute (CSI) which has continued to produce research on anti-malware defense, data security and privacy, cloud security, cyber physical systems/IoT security, hardware security, security analytics and machine learning, network security, cryptography, and secure software engineering. These research papers consistently put us amongst the top 50 institutions worldwide by publications every year (rankings).
In addition our other centers like C-STAR (secure AI), GC-TIRI (Counterterrorism), and TraCR (Transportation) apply cybersecurity to other fields. And this is just the work from the CS department. Other departments and schools like JSOM and EPPS also contribute to risk management and policy related to cybersecurity.
If its not clear, UTD is kinda goated at Cybersecurity. One of the best institutions in the world.
Cybersecurity Undergraduates
I’m graduated with a B.S. in Computer Science and a Minor in Business Intelligence and Analytics. My experiences are largely limited to those programs, but I’ve tried to solicit feedback from other students in different programs to make this as comprehensive as possible. I hope people will share their own experiences with the various programs in the comments to help new students still deciding what they want to study.
Cybersecurity Degrees
Note: Key Skills for each degree are the skills relevant to cybersecurity, taught by the default required courses. Electives could allow you to specialize further.
Cybersecurity-Focused Undergraduate Degrees
Computer Science (ECS)
As the broadest and most technical degree for cybersecurity, it will expose you to many aspects of the domain while preparing you for other career paths in technology. The key to getting the most out of this degree is taking relevant elective courses. In my opinion, a CS student can graduate and know a lot about technology in general, but very little about cybersecurity. Just getting a CS degree is insufficient to demonstrate knowledge of cybersecurity, so a lot must be learned through self-study, clubs, and extracurriculars.
- Key Skills: Linux/bash, C++, C, Assembly, Databases, Operating Systems, Statistics, Discrete Math & Linear Algebra (relevant for specializing in cryptography)
- Perk: By taking the right electives, every CS student can also earn the UG Certificate in Cyber Defense without adding to their overall hours.
- Challenge: CS students often neglect the business/communication aspects of cybersecurity. Being able to understand the business context of technology and communicate technical knowledge to non-technical people is a vital skill.
Computer Information Systems & Technology, formerly ITSS (JSOM)
CISTech is also a broad degree that maintains the option to focus on cybersecurity through the Concentration in Cybersecurity Management. The coursework is generally less rigorous compared to ECS equivalents, which allows motivated students additional time to pursue personal projects, certifications, or internships to deepen their technical expertise and stand out.
- Key Skills: Python, Databases, Network Security, IT Infrastructure, Statistics
- Challenge: As many ITSS courses aren’t really that technical and hands-on, a CISTech student needs to go deeper into technical concepts, beyond what the curriculum covers, and find ways to prove their technical knowledge through tinkering, projects, and extracurriculars to really distinguish themselves.
Cybersecurity and Risk Management (JSOM)
A relatively new degree offered for the first time in Fall 2025 but also narrow in scope. Students unsure about committing to cybersecurity long-term may find broader degrees like CS or CISTech more versatile as they study technology more holistically.
- (potential) Key Skills: Python, Operating Systems, Network Security, Digital Forensics & Incident Response (DFIR), Governance, Risk, & Compliance (GRC), Statistics
- Challenge: With this being a newer degree, its unknown how well this will prepare students for their careers. Undoubtable courses will be being tweaked and curriculum edited for years as UTD learns how to best to teach this. I’ve been paying close attention to this degree as it has been released and there are both some promising and concerning aspects to this degree that I’m anxious to see play out. To manage this risk, you certainly should not rely on the degree alone to teach you cybersecurity. Be curious, action-oriented, and find your own communities and sources of knowledge to explore cybersecurity beyond the classroom.
Cybersecurity-Relevant Undergraduate Degrees
While not centered on cybersecurity as a whole, these programs often intersect with specific cybersecurity domains, providing alternative and potentially valuable pathways into the field. Other degrees not listed may also intersect with cybersecurity in interesting ways; feel free to ask in the comments how your degree might be related.
Software Engineering (ECS)
- Relevant Domains: Secure Software Development, Application Security
- Key Skills: Linux/bash, C++, C, Assembly, Databases, Operating Systems, Software Testing, Technical Project Management, Statistics, Discrete Math & Linear Algebra
Computer Engineering or Electrical Engineering (ECS)
Note EE has a Concentration in Computing Systems.
- Relevant Domains: Hardware Security, Embedded Systems Security, IoT Security
- Key Skills: C++, C, Assembly, Networks, Operating Systems, Embedded Systems Statistics, Discrete Math & Linear Algebra
Data Science (ECS & NSM)
- Relevant Domains: AI for Cybersecurity, Cybersecurity for AI, Security Analytics, Anomaly Detection, Risk Modeling, Threat Intelligence
- Key Skills: Python, C++, Databases, Statistics, Discrete Math & Linear Algebra
Business Analytics and Artificial Intelligence (JSOM)
This assumes the IT Concentration to specialize more in cybersecurity.
- Relevant Domains: Security Analytics, Anomaly Detection, Risk Modeling, Threat Intelligence
- Key Skills: Python, Statistics, Databases, Network Security, IT Architecture, Cloud, GRC
Mathematics (NSM)
- Relevant Domains: Cryptography, Formal Verification
- Key Skills: Python, Statistics, Discrete Math, Linear Algebra, Abstract Algebra
Systems Engineering (ECS)
Note the secondary field requirement for the degree can be used to focus on computer science/cybersecurity.
- Relevant Domains: Risk Management, Secure System Architecture, Cyber-Physical Security
- Key Skills: Networks, Technical Project Management, Statistics, Discrete Math & Linear Algebra
Cognitive Science (BBS)
- Relevant Domains: Social Engineering
- Key Skills: C++, Statistics, Psychology, Discrete Math
Cybersecurity Minors and Certificates
Its very important to note that upper division (3000/4000) courses that you use to satisfy degree requirements for your major cannot count towards your minor. So if both your major and a minor require CS 4347, for example, you’ll only be able to count that towards your major and its unlikely you’ll be able to earn that minor.
This rule doesn’t apply to certificates. So if you can’t earn the minor that you want, see if there is an equivalent certificate.
Also note you must satisfy the prerequisites for any course you take. It will say it will take “X semester credit hours”, but this doesn’t take into account the prerequisites you might need so be sure to look at those when planning your degree.
ECS Minors and Certificates
Cyber Security, Computer Science, and even Software Engineering minors may help less technical cybersecurity students take more technical coursework.
The Certificate in Cyber Defense is a great alternative for CS students to demonstrate their focus on cybersecurity by taking a few security-oriented electives (which counts as major technical electives on their degree plans).
JSOM Minors and Certificates
Business Intelligence & Analytics or Information Technology and Systems can help both non-technical cybersecurity students get exposed to more technical course and technical students exposed to business and operations. Other JSOM minors or certificates may help in a similar way.
I am getting a Business Intelligence & Analytics minor with my CS degree because it pairs especially well together. I am also getting the Certificate in Cyber Defense, largely because I wanted to take those electives anyways.
EPPS Minors and Certificates
Criminology, Political Science, Public Affairs, Public Policy or Science, Technology, & Policy minors all would help a cybersecurity student understand privacy laws, GRC, cybercrime and other legal policies around cybersecurity. Some cybersecurity professionals go as far as to getting law degrees and many cybersecurity professionals end up getting security clearance in order to support the government’s cybersecurity initiatives through agencies or contractors.
Cybersecurity Courses
This is not necessarily an exhaustive list, but I tried to get as many as I could.
ECS
This largely is following the CS degree plan plus several electives you may find interesting.
CS 1436, CS 1337, CS 2336/2337 (“Programming courses”) While programming isn’t absolutely required for all jobs in cybersecurity, it always helps to be able to read code, script to automate processes, or even engineer security software and tools. Play close attention to these courses and always ask yourself about the vulnerabilities or potential vulnerabilities that come from the programming language.
If you want a Fun project: code a game in C++ or Java, then look into memory scans and tools like Cheat Engine and see if you can hack your own game to set the high score to whatever you want.
CS 2340 (Computer Architecture) Being able to read assembly is useful for reverse engineering binary files like executables. This class typically teaches MIPS assembly, rather than x86. But the skills carry over.
ECS 2390 (Professional and Technical Communications) If you work well on teams, have given presentations and done well in interviews and you have a solid resume, this class may not provide a lot of value. Communication skills in general are hard to learn in a classroom, but they are absolutely essential in cybersecurity. Communicating with non-technical people about technical problems, solutions and risk will be a lot of your job. Don’t slack on the people skills.
CS 3162 (Professional Responsibility) This course will likely go into topics like cybercrime and can help introduce you to the history of cybersecurity and hacking.
CS 3341 (Probability & Statistics in CS & SE) A fundamental understanding of statistics and how they’re calculated is useful for cybersecurity. You may not need to go super deep into this subject, but make sure you have strong analytical skills and its nice if you know how to setup visualizations.
CS 3377 (Systems Programming) One of the most important classes as it introduces you to Linux environments. This is a essential skill because, for a lot of cybersecurity careers, you will live in the command line. A fun way to learn this stuff is to pair it with doing CTF (capture-the-flag) challenges. You’ll also do some more programming in this course.
If you’re serious about cybersecurity, I wouldn’t wait to take this course to learn Linux. Set up a VM (Virtual Machine) or WSL (Windows Subsystem for Linux) or if you’re on Mac just open Terminal, and start getting comfortable with commands. I would recommend being able to navigate the CLI (command line interface) as easily as you can the GUI (graphical user interface).
CS 4337 (Programming Language Paradigms) I have described this class as the “waste paper bin of computer science”. Basically, it felt like they just dumped a ton of concepts that you should know all together in class, even though they didn’t necessarily relate to each other. Some of those concepts happen to be security-related like language-based security, control flow integrity, web scripting security, return oriented programming, fuzzing and others. And you will do some more programming in languages you probably haven’t learned, but are very secure.
CS 4347 (Database Systems) Databases are a key target for hackers, so learn as much as you can about them. Some professors take the time to also teach a hacking technique called SQL Injection in this course. I would recommend taking them and learning more about it on your own time. This course may also be your first introduction to web development, which is a great skill to have. You can develop a personal website for building your cybersecurity reputation, but also understand how web applications work and how they can be exploited.
CS 4348 (Operating Systems) Operating systems are incredibly important to cybersecurity. This course is purely theoretical, so be sure to get hands-on experience with things like containers and VMs.
CS 4371 (Big Data) Like databases, but bigger. This course goes into web and big data security.
CS 4389 (Data & App Security) Now we’re getting into the pure cybersecurity courses. Everything so far has been Computer Science courses that may touch on security topics, but Data & App Sec is a broad introduction to Cybersecurity. Just be sure to get hands on with any of the topics you learn: whether that’s a quick programming project, a CTF, deploying infrastructure, whatever.
CS 4390 (Computer Networks) Networking is arguably the most important topic in cybersecurity. I would take this course as soon as you can as it is a prerequisite to many other security-oriented courses.
CS 4393 (Computer and Network Security) Now you have learned networking, start figuring out how to break it and how to secure it.
CS 4396 (Networking Laboratory) Takes the networking concepts you learned and makes them hands-on and practical.
Note: If you haven’t realized, hands-on and practical are the magic words to supercharging your cybersecurity learning. Don’t just think about this stuff, do it. Break it. That’s how the best have learned. That’s how the bad guys have learned.
CS 4398 (Digital Forensics) Understand how security events are recorded.
CS 4459 (Cyber Attack and Defense Laboratory) No exams, no homeworks. Just 8 CTF-style challenges. Your grade is wholly dependent on your ability to hack these challenges and retrieve the flags. I have heard it typically takes 20-30 hours per week on these challenges so this is an incredibly challenging and time consuming course, but goes deep into what it actually takes to be a hacker. Make sure you know x86 Assembly if you’re going to take this course.
JSOM
JSOM is introducing the fleet of CYBR courses to support the new degree. No one has taken these (unless they were equivalent courses from other programs) so my feedback won’t be able to go beyond the catalog so I’ll just give you that:
https://catalog.utdallas.edu/2025/undergraduate/courses/CYBR
ITSS 3300 (IT for business) A high level introduction to security topics and how tech fits into the enterprise as a whole.
ITSS 3311, 3312 (“programming courses”) Similar to the CS versions, programming isn’t absolutely required for all jobs in cybersecurity, but it always helps to be able to read code, script to automate processes, or even engineer security software and tools. Unlike CS, you learn Python, the language of choice for many cybersecurity professionals.
ITSS 3320 (Operating Systems and Networking) OS and Networks are two of the biggest concepts in cybersecurity. You should really build a strong base in these topics.
ITSS 3390 (Web Design and Development for Business Applications) Web security is key domain in cybersecurity as often web apps can be serious targets for hackers. Understand how to build and break web apps is a great skill to further your career.
ITSS 4300, 4301 (Databases) This covers more content that CS 4347, but at a higher level. This means you might actually get to more security topics. Just be sure to get hands on with databases, SQL Injection, and data security. I would recommend doing a project like building a CRUD website connected to a database. ITSS 4300 seems more security-oriented than ITSS 4301.
I don’t have much feedback for the remaining courses, but I’ll list them just so you know what’s out there. Maybe some people who have taken these course can give their thoughts on these in the comments. My general advice remains the same: no matter what the course requires, get hands-on, practical experience with every topic or technology discussed if you can. ITSS 4355 (Data Governance) ITSS 4357 (Digital Forensics and Incident Management) ITSS 4358 (Applied Cybersecurity Analytics and AI) ITSS 4359 (Preparing for Cybersecurity Threats) ITSS 4360 (Network and Information Security) ITSS 4361 (Information Technology Cybersecurity) ITSS 4362 (Cybersecurity Governance) ITSS 4370 (Information Technology Infrastructure) ITSS 4371 (Cloud Computing with AWS) ITSS 4380 (Advanced Database Management)
Other
Again not much experience here, but some courses oriented towards cyber policy. Cybersecurity has close ties to law and politics because they intersect around topics like cybercrime, compliance, and privacy.
PPOL 4303 (The Internet and Public Policy) PPOL 4325 (Digital Economics and the Law) PPOL 4326 (Cyber Security Policy) PPOL 4327 (Violence in Cyber Space) PPOL 4328 (Governance and Auditing for Cyber Security) PPOL 4329 (Cybersecurity Law and Ethics) PPOL 4330 (Open-Source Intelligence for Cyber Security)
Takeaways
Cybersecurity is so broad and so deep, you won’t learn it all in 4 years. In my opinion, I don’t think cybersecurity is a field that we have figured out how to teach in the classroom. That means there is incredible opportunity for us because society has not yet found an efficient way to produce cybersecurity professionals, but also means you have a lot of work to do. I’ve seen some good things with the new cybersecurity degree (not a home run in my book, but leaning in the right direction), but I wouldn’t rely on any degree to prove I can do a cybersecurity job. You have to build that proof beyond the classroom: CTF writeups and competitions, cyber defense competitions, club participation & leadership, bug bounties, research/research papers, white papers, content creation, programming projects like open-source security tools or deploying infrastructure, certifications, hosting or attending events, etc.
Get involved. Break stuff. Learn.
Cybersecurity Extracurriculars
Cyber Defense and Response Unit (CDRU). CDRU does hands-on workshops every Thursday at 7 PM on Digital Forensics, Incident Response, Threat Hunting and similar. We focus on defending systems, rather than attacking, and the club was founded by a CrowdStrike employee/UTD masters student to bridge the gap between classroom learning and careers. I was an officer for this club because this is one of the most welcoming and interactive clubs I’ve encountered. Hands-on learning, but beginner friendly.
National Collegiate Cyber Defense Competition Team (CCDC). CDRU host’s UTD’s competitive cyber defense team, which made it to the Southwest Regional Competition last year. A cyber defense competition involves the team being handed IT infrastructure that they have to get up and running to score points, while a team of professional penetration testers (hackers) have been hired to break in and take them down. Which… is crazy freaking cool.
Computer Security Group (CSG). The oldest and largest cybersecurity club on campus. They do presentations (from students, industry professionals, or other speakers) every Wednesday at 7. Free pizza. They also hold capture-the-flag (CTF) competitions and organize cybersecurity conferences and other events.
Competitive CTF Team (UTDCSG). CSG hosts UTD’s official competitive CTF team, currently a top-ranked team in the US. A CTF competition involves using hacking techniques to break into systems setup as targets and score points by retrieving a flag (a secret piece of text). These are great for getting hands-on practice, and joining the competitive team represents join an incredibly elite group of hackers. I competed on this team.
Women in Cybersecurity (WiCyS). A women-focused cybersecurity club that does everything from workshops, community social events, and industry networking events to bridge the diversity gap in the cybersecurity field. They are a subchapter of a national organization that provides an inclusive environment and amazing resources to help build your cybersecurity career and completely beginner friendly.
UTD Student Subchapter of the North Texas Chapter of the Information Systems Security Association (UTD NTX ISSA). is a mouthful. ISSA in an international non-profit organization of security professionals and UTD has its very own subchapter which hosts educational events and offers discounted ISSA membership. They’re backed by the resources and community of ISSA which allows them to host talks from industry professionals. Although they cover all of InfoSec, they often are the experts on cyber policy, compliance, and governance.
Cybersecurity Club (CSC). JSOM’s organization focusing on professional/career development and networking (the people networking, not computer networking). Historically, they’ve invited industry contacts to give presentations about their work.
Takeaways
I would recommend you get as involved with as many as you can. If you want to become an elite hacker and you don’t have any real interest in the defensive side of cybersecurity, you definitely want to be in CSG and try to get on the CTF team, but you probably also should attend CDRU. The attackers need to understand how systems are defended (probably better than the defenders) in order to exploit them. And the same works in reverse. Defenders need to understand attacks. Studying both sides will help you learn faster and see the whole picture.
Also you never know how the people you meet will impact your career (and your life in general). I’ve personally benefited from friends who liked me enough or though i was good enough to recommend for internships and jobs. Or are just people that I can work with on projects or compete with (outside of the official teams). Clubs are a great way to start building that network while simultaneously building your skills. This is especially true for clubs like WiCyS or our chapters/subchapters because those can connect you to much much larger organization and its members.
And often the clubs have food. For those who are new to college, it is a vital skill to identify sources of free food.
If I had to choose only one club to attend, I would have to go with CDRU or CSG because those competitive teams will allow you to do a lot of cool stuff, meet a lot of cool people, teach you a lot of cool things, and add something really really cool (prestigious even) to your resume. Attending their events is a great way to start working your way onto the teams and understanding what skills you’ll need. All the clubs are really committed to growing and improving cybersecurity at UTD so attending any of them is a good idea, attending all that you can, if nothing else just to try it out, is a great idea.
