DOCTORAL DEGREES

Doctor of Philosophy in Cybersecurity

Accredited by

  • Flexible for working professionals
  • AI and machine learning integrated
  • No GRE or residency required

100% Online

This program is designed to be completed within 44 months. However, students who pursue this program at an accelerated rate may be able to complete the program in as few as 33 months.

33 Months

60

$1,039

Why Get an Online Doctor of Philosophy in Cybersecurity?

Four Specializations

NSA-Designated

Expert Faculty Mentorship

Flexible Online Program

Getting Started

Earning Your Degree

Build expertise in the core concepts, theories, and practices of your field.

In this course, students are prepared for an understanding of networks and related theory to support computer science, cybersecurity, and technology management needs. Students will learn network concepts, as well as designing networks for reliability, availability, confidentiality, and network monitoring. Content will include high-level design of networks, evaluation of service providers, and strategies to prepare an organization for future communication needs (such as multi-cloud, satellite, 5G & 6G, and quantum data communications, plus related security techniques). Students will learn network design, planning, the role of network data communication devices, global access, and safe third-party data exchange.

This course will consolidate a foundation of concepts relating to security and cybersecurity, enabling the successful examination of greater detail and complexity in later courses. You will examine the full range from governance through compliance with laws, through people risks, to technology. Various mitigation options are considered to reduce vulnerabilities, counter threats, and to protect an organization’s data and system assets. You will study the need to protect organizations from future exposures and apply critical thinking and synthesis to motivate the resources needed to defend an organization.

Cybersecurity has the primary objective of averting losses and restoring proper operations should there be a loss. During this course you will study the foundations of risk and the opportunities to reduce cybersecurity losses for organizations. Risk assessment abilities and research options form the base of cyber defenses and determine the need for subsequent resources. The course continues with measuring risk and events leading to the identification of potential incidents and solutions. Learning about contingencies consider the needs of the organization, maintaining operations, and preparing for the best recovery should there be a loss.

Tracking and responding to cyber events requires massive databases integrating content from all devices at every location. Cyber threat analysis and response implies long term access and complex manipulation of event databases. In this course you will learn techniques to capture and display relevant data and leverage automation to reduce losses. Data manipulation, automated sense-making, appropriate fast reactions, machine learning, data analysis, and presentation are rapidly developing cybersecurity techniques. You will also leverage required capabilities for the defense of the organization, respond to enhanced threat complexity and capabilities, and address the need to counter data poisoning by threat actors.

Risk management is the foundation of defending organizations from information security, cyber threats, compliance, audit, and privacy exposures. To address risk and assurance, this course builds an integrated approach solution leading to the prioritization of resources for an organization. You will extend your knowledge and skills for global protection within and beyond the perimeter. This course positions the importance of risk management within a cybersecurity program and its role within Enterprise Risk Management (ERM). You will also assess theories and practices concerning risk management, compose a risk strategy, and leverage maturity models to improve the protection of organizations.

Risk management is the foundation of defending organizations from information security, cyber threats, compliance, audit, and privacy exposures. To address risk and assurance, this course builds an integrated approach solution leading to the prioritization of resources for an organization. You will extend your knowledge and skills for global protection within and beyond the perimeter. This course positions the importance of risk management within a cybersecurity program and its role within Enterprise Risk Management (ERM). You will also assess theories and practices concerning risk management, compose a risk strategy, and leverage maturity models to improve the protection of organizations.

This course serves as an extensive exploration of statistics for the technology leader. Included in the course, is an advanced examination of statistical analyses commonly used for information systems and technology research. During this course, you will use different statistical tools to enhance your advanced analytical skills. These statistical analysis skills are required to plan, conduct, and interpret quantitative data to inform enterprise decisions. You will also learn to illustrate and produce technical output reports.

This course serves as an extensive exploration of statistics for the technology leader. Included in the course, is an advanced examination of statistical analyses commonly used for information systems and technology research. During this course, you will use different statistical tools to enhance your advanced analytical skills. These statistical analysis skills are required to plan, conduct, and interpret quantitative data to inform enterprise decisions. You will also learn to illustrate and produce technical output reports.

Global integration and broad alliances between criminal elements and nation-states frequently lead to rapidly changing and significant threats to all nations, organizations, and citizens. During this course, you will study current and predictable threats, target critical infrastructure, and determine risks implied in new technology. You will also learn to recognize the risks originating from cybercriminals, terrorism, hacktivism, and nation-state, and other significant threat actors. You will devise and work to get funding for viable strategies to defend critical infrastructures, organizations, and the citizens of the nation.

This course provides a survey of the different methods used to conduct technology-based research. During this course, you will learn about the research principles and methodologies that guide scientific inquiry in order to develop an understanding of the effects of research on individuals and organizations. Specifically, you will study the scientific research lifecycle, data collection methods, and research design methodology. You will finish the course by selecting a research design methodology to support your research interests through the remainder of your program.

The results of technical research are frequently used to support informed management decisions. This course provides technology leaders and professionals with the skills needed to design and conduct quantitative research studies to support specific types of data. During this advanced course in research, you will explore and apply different types of quantitative research methods and statistical techniques. You will also explore instrumentation, data collection, and data analysis tools and techniques to create aligned, ethical, and substantive research designs.

A quantitative research design includes objective analysis using experimental, quasi-experimental, and related techniques. Technical quantitative research involves statistical analysis of data collected from a larger number of participants to determine an outcome that can be applied to a general population. During this course, you will work through the scientific research process and apply your knowledge of quantitative research design to develop a technical research proposal in which you can use to support your research interests through the remainder of your program.

The results of qualitative research are frequently used to support informed management decisions. This course provides technology leaders with an in-depth introduction to qualitative methods for studying human behavior, including grounded theory, narrative analysis, and case studies. During this advanced course in research, you will apply qualitative research methods to an information technology-based study. You will also deepen your research knowledge and skills by conducting interviews, collecting and coding data, producing ethical data conclusions, and creating objective research reports.

A qualitative approach to research of a technical nature integrates theoretical, conceptual, and empirical constructs with common practices and experience to gain an understanding of performance and functionality, develop an applied and testable model for improvement, or provide insights into problems to develop new ideas. During this course, you will work through the scientific research process and apply your knowledge of qualitative research design to develop a technical research proposal to support your research interests through the remainder of your program.

The results of technical research are frequently used to develop new products and services. This course provides technology leaders and professionals with the skills needed to design and conduct constructive research studies based on theory. During this advanced course in research, you will examine the methods and measurements used to design constructive research studies to develop sound technical solutions or prototypes. You will also explore software and security testing tools and user acceptance testing methods in order to create aligned, ethical, and substantive research designs.

Technical constructive research focuses on models, frameworks, tools, and software used by industry to improve value creation. A constructive approach to research of a technical nature integrates theoretical and empirical constructs with common practices and experience to develop an applied and testable model to improve the fields of computer science and information technology. During this course, you will work through the scientific research process and apply your knowledge of constructive research design to develop a technical research proposal in which you can use to support your research interests through the remainder of your program.

The Pre-Candidacy Prospectus course is intended to ensure students have mastered knowledge of their discipline within cybersecurity prior to doctoral candidacy status and are able to demonstrate the ability to design empirical research as an investigator before moving on to the dissertation research coursework. During this course, you will demonstrate the ability to synthesize empirical, peer-reviewed research to prepare for the dissertation sequence of courses. This course should be completed only after the completion of all foundation, specialization, and research courses.

In this course, students will complete Chapters 1 and 2 of their Dissertation Proposal. Chapter 1 includes a brief review of the literature with substantiating evidence of the problem, the research purpose and questions, the intended methodological design and approach, and the significance of the study, while Chapter 2 consists of the literature review, including the theoretical/conceptual framework. Completed and committee-approved (against the minimum rubric standards) Chapter 1 and Chapter 2 are required to pass this course successfully.

In this course, students will complete Chapter 3 and their Dissertation Proposal (DP). Chapter 3 includes the research methodology and design, population, sample, measurement instruments, data collection and analysis, limitations, and ethical considerations. Students will then assemble their Dissertation Proposal including all appendices necessary. A completed, committee-approved Chapter 3 and a final approved Dissertation Proposal (against the minimum rubric standards) are required by the end of the course.

In this course, students will prepare, submit, and obtain approval of their IRB application. After obtaining IRB approval, students will collect data and submit a data collection verification form when data collection is complete. Students will begin synthesizing collected data and analyzing results. IRB study approval and a completed data collection verification form are required by the end of the course.

In this course, students will complete Chapters 4 and 5, followed by their Dissertation Manuscript. Chapter 4 includes presenting study results aligned to the research design and research questions and/or hypotheses. Chapter 5 includes study implications, recommendations, and conclusions. Students will then compile and present findings in the completed Dissertation Manuscript and in an Oral Defense. A completed, committee-approved Chapter 5, Dissertation Manuscript, and successful Oral Defense (against the minimum rubric standards) are required to complete the course and graduate.

In this course, you will be introduced to the field of advanced cyber forensics. You will review various tools, techniques, and steps needed for a successful forensic investigation. In addition, you will examine various legal regulations that impact the collection of data, the importance of federal rules of evidence, and the critical requirement of evidence admissibility in a court of law.

Information technology systems require formal review to ensure not only that they function correctly, but also that they are secure. In this course you will learn the issues and lack of proper defenses for internal and commercial off-the-shelf (COTS) systems and solutions. In addition, you will investigate the benefits and implications of cloud computing and proper processes to leverage innovative solutions to decrease risk, such as FedRAMP. With the redefinition of the “perimeter” that must be defended and new threat vectors, you will explore and research novel approaches to safe computing and cybersecurity monitoring.

Knowledge of security principles and practices in software engineering is vital to provide quality software solutions. This course is an application-based examination of software engineering for the security professional. During this course, you will explore the foundations that support secure software development and analyze different secure software design and development practices. You will also select and defend a secure software architecture and technology approach and then design a secure software deployment and maintenance solution strategy.

This course provides the source, role, and implementation of governance within the cybersecurity arena and the entire organization, including related policy. The execution considers the breadth of state and federal laws plus regulations to establish a further domain for cyber objectives. Important global laws and regulations round out the foundation, leading to effective compliance. Learning includes a focus on specific industries and agencies, including banks, hospitals, government, etc. During this course you will prepare to enable governance, compliance, privacy, and related solutions for medium to very large organizations, including the ability to support the significant changes anticipated in laws.

This advanced course integrates all cyber content learning across the degree and specialization, combining theory and practice for the holistic cybersecurity strategy. During this final content course, you will construct a response addressing cyber governance, policy, risk, compliance, and assurance. You will contribute technical leadership by addressing architecture and operational needs to reduce both treats and vulnerabilities from internal and external sources. The evaluation of tools, data, and processes must facilitate resilience and support the protection of critical information from current and future losses.

This course addresses cybersecurity complexity implied by global influences in terms of laws, locations, facilities, and operations. During this course you will combine cyber global governance, audit, privacy, and compliance to support a comprehensive cyber response. Your foundation would enable the organization’s integrated abilities to defend the technical systems that facilitate its global operations for both global and local needs across all locations. You will address the diversity of laws and audit practices, different views of privacy, and multiple compliance implications that require a carefully balanced practical solutions that harnessing theory.

Organizations with a global footprint need to balance a single approach for cybersecurity with a range of diverse influences from people, governments, and organizations. In this course, you will explore cybersecurity challenges relating to communication systems, various local support capabilities, and supply chain challenges. Further learning considers the variety of contracts available in different countries, available service levels, and approaches to management, maintenance, and controls. Within diversity and continuous change, the course adds theoretical and practical approaches to constant revision, thereby facilitating viable solutions for local and global needs.

Global organizations need to balance a wide range of influences that compromise options to achieve required outcomes from multiple external and internal demands. Global laws adjust to local expectations in each individual country, implying diverse needs that need to be matched with carefully devised controls. You will learn about diverse cultures across nations, regions, and within organizations implying careful and pragmatic approaches to integrate diversity. You will also discover diverse views and approaches to ethics that will require careful responses and protection of all stakeholders.deployment and maintenance solution strategy.

This course combines all the previous cybersecurity insights and extends the learning to include policy and operations to reduce risk. You will learn about policy in commercial organizations that need to balance costs with safety to serve all their stakeholders. Policy supplies the expectations and sanctions to all persons that use the information systems and is authorized by the Board. You will also learn government views that complement laws and standards. The operational functions and implied architecture of the organization adds practical insights, all aligned to reduce risk within the organization and all its stakeholders.

This advanced course integrates all cyber content learning across the degree and specialization, combining theory and practice for the holistic cybersecurity strategy. During this final content course, you will construct a response addressing cyber governance, policy, risk, compliance, and assurance. You will contribute technical leadership by addressing architecture and operational needs to reduce both treats and vulnerabilities from internal and external sources. The evaluation of tools, data, and processes must facilitate resilience and support the protection of critical information from current and future losses.

This course addresses a broad background of current laws, governmental oversight from a variety of agencies, and industry regulations. The focus is the broad requirements across industries, organizations, and consumers. It excludes a focus on specific industries and agencies, such as banks, dams, or defense. During this course you will prepare to defend organizations and enable generic compliance, reduce privacy risks, and prepare to follow proposed laws and regulations. The scope includes all active laws and prepare for new requirements. You will also learn about demands from foreign powers and other states that apply to a broad range of organizations.

This course reviews a range of frameworks, models, standards, and controls to address a wide variety of needs. You will learn about broad and specific solutions responding to industries or laws. Depending on the specific expectations of the industry, the type of organization, and its location, you will consider appropriate solutions. In practice, one would need to find a way of combining diverse needs into a reasonable approach to establish controls without hampering effective value delivery within the organization. Most frameworks, models, standards, and controls change frequently, implying the need for continuous improvement and strategic planning.

This course focuses on United States law, regulations, and compliance that targets specific industries at both federal and state levels. Your learning in this course focuses on additional depth for the 16 critical infrastructures and attaining compliance across multiple requirements. In addition, regulations relating to centralized controls and related bodies frequently specify techniques and approaches. In developing areas of the law and regulations, the migration from federal to state and state to federal implies regular change and complexity for compliance. Your learning includes anticipation of changes and multi-period adjustments across internal and external stakeholders.

Cybersecurity policy provides guidance to all stakeholders and supports the governance that must be applied throughout the organization. The deployment of policy and leadership of cyber operations provides the execution channel for policy. In this course, you will learn about the structures that support policy and governance. You will review needs and devise solutions to enable sound cybersecurity responses, including both the creation of policy and its implementation. In addition, consideration is given to the needs of distributed organizations, outsourcing, and the implications of links to external parties.

This advanced course integrates all cyber content learning across the degree and specialization, combining theory and practice for the holistic cybersecurity strategy. During this final content course, you will construct a response addressing cyber governance, policy, risk, compliance, and assurance. You will contribute technical leadership by addressing architecture and operational needs to reduce both treats and vulnerabilities from internal and external sources. The evaluation of tools, data, and processes must facilitate resilience and support the protection of critical information from current and future losses.

Information technology systems require formal review to ensure not only that they function correctly, but also that they are secure. In this course you will learn the issues and lack of proper defenses for internal and commercial off-the-shelf (COTS) systems and solutions. In addition, you will investigate the benefits and implications of cloud computing and proper processes to leverage innovative solutions to decrease risk, such as FedRAMP. With the redefinition of the “perimeter” that must be defended and new threat vectors, you will explore and research novel approaches to safe computing and cybersecurity monitoring.

Cloud computing provides benefits and new challenges for cybersecurity. Unknown entities can review or divert communications and any person can try to authenticate or intercept access. This course provides insights regarding cybersecurity exposures relating to networking to remote sites and managing identities and access. Your aim is to enable the security of data assets where there is no perimeter defense. You will learn about improved networking options for confidentiality, integrity, and availability. Identity options include active directory options, extensions, controls, and alternatives. Other options consider virtual perimeters, other forms of trust, protocols, and anticipating the evolution of issues, including quantum computing.

The evolution of modern secure cloud computing will require a variety of vendors for solutions to organizations. Combining internal information systems with multiple cloud and solution suppliers requires careful cybersecurity integration and negotiation. You will learn about combining solutions, system changes, upgrades, changes to security, and multiple laws. Options to adjust architecture, orchestrate multiple adjustments, and selecting business optimization will introduce you to innovative approaches and risk mitigation. You will need to enable third parties and outsource arrangements to broker solutions. Global needs will expose you to different laws about security, data residency, regulations, audit, and diverse suppliers.

Secure cloud operations rely on equipment, processes, and personnel from providers, client organizations, and the networks linking all parties. Each are subject to the laws, regulations, and threats. In this course you will learn the theory and practice relating to delivering reliable and secure cloud services while coping with ongoing change. Concurrently, new uses for cloud computing and core technology evolution add further complexity. While operations might be tactical, the complexity and need to integrate diverse influences, calls for negotiation, resilience, strategy, and use of maturity models. One must attain and maintain acceptable delivery capabilities within local and global change.

This advanced course integrates all cyber content learning across the degree and specialization, combining theory and practice for the holistic cybersecurity strategy. During this final content course, you will construct a response addressing cyber governance, policy, risk, compliance, and assurance. You will contribute technical leadership by addressing architecture and operational needs to reduce both treats and vulnerabilities from internal and external sources. The evaluation of tools, data, and processes must facilitate resilience and support the protection of critical information from current and future losses.

Career Impact

At NU, we believe education should open doors to new opportunities. Explore career paths, salary insights, and workforce demand related to this degree, and discover how your education can support your professional goals.

*Data Source: The career outcomes data presented is sourced from Lightcast, which provides insights based on real-time job postings, public datasets, and analytics. Lightcast derives its data from sources such as the Bureau of Labor Statistics (BLS), the Quarterly Census of Employment and Wages (QCEW), and the Occupational Employment Statistics (OES). While accurate and reliable, this data reflects general labor market trends and may not represent individual outcomes or specific local conditions. For more details on Lightcast’s methodology, visit their Data Overview.

Professional Pathways

      *Data Source: The career outcomes data presented is sourced from Lightcast, which provides insights based on real-time job postings, public datasets, and analytics. Lightcast derives its data from sources such as the Bureau of Labor Statistics (BLS), the Quarterly Census of Employment and Wages (QCEW), and the Occupational Employment Statistics (OES). While accurate and reliable, this data reflects general labor market trends and may not represent individual outcomes or specific local conditions. For more details on Lightcast’s methodology, visit their Data Overview.

      ABD Students Welcome

      Finish your Dissertation With Us

      NU’s Dissertation Boot Camp is a multi-day, immersive experience focused on helping you make real progress.

      • Dedicated DCP advisors and faculty who understand your journey and desire to finish your doctorate
      • DCP Bridge courses, virtual sessions, and Dissertation Boot Camps to assist students from day one

      Upcoming Dissertation Boot Camps

      Upcoming Dissertation Boot Camps

      National University is redefining doctoral education for career-driven learners.

      Program Disclosure

      Successful completion and attainment of National University degrees do not lead to automatic or immediate licensure, employment, or certification in any state/country. The University cannot guarantee that any professional organization or business will accept a graduate’s application to sit for any certification, licensure, or related exam for the purpose of professional certification.

      Program availability varies by state. Many disciplines, professions, and jobs require disclosure of an individual’s criminal history, and a variety of states require background checks to apply to, or be eligible for, certain certificates, registrations, and licenses. Existence of a criminal history may also subject an individual to denial of an initial application for a certificate, registration, or license and/or result in the revocation or suspension of an existing certificate, registration, or license. Requirements can vary by state, occupation, and/or licensing authority.

      NU graduates will be subject to additional requirements on a program, certification/licensure, employment, and state-by-state basis that can include one or more of the following items: internships, practicum experience, additional coursework, exams, tests, drug testing, earning an additional degree, and/or other training/education requirements.

      All prospective students are advised to review employment, certification, and/or licensure requirements in their state, and to contact the certification/licensing body of the state and/or country where they intend to obtain certification/licensure to verify that these courses/programs qualify in that state/country, prior to enrolling. Prospective students are also advised to regularly review the state’s/country’s policies and procedures relating to certification/licensure, as those policies are subject to change.

      National University degrees do not guarantee employment or salary of any kind. Prospective students are strongly encouraged to review desired job positions to review degrees, education, and/or training required to apply for desired positions. Prospective students should monitor these positions as requirements, salary, and other relevant factors can change over time.