The History of the School of Cybersecurity and Privacy
The School of Cybersecurity and Privacy (SCP) at Georgia Tech became the first academic unit in the world dedicated to studying cybersecurity as a societal problem when it launched in November 2020.
The school’s creation was the result of more than two decades of cybersecurity research and education at Georgia Tech. From a 1998 call for greater collaboration on information security to the creation of academic programs, interdisciplinary research institutes, and ultimately a dedicated school, Georgia Tech has continued to evolve its approach to cybersecurity as the field itself has changed.
1998: The Nunn Forum
Many consider the 1998 Sam Nunn Bank of America Policy Forum, known as the Nunn Forum, the natural starting point for information security research at Georgia Tech.
During the forum, Georgia Sen. Sam Nunn called for closer collaboration among government agencies, academic institutions, and business leaders to tackle cybersecurity challenges. Nunn and Peter Freeman, founding dean of the Georgia Tech College of Computing, urged attendees to prioritize cybersecurity policies, develop new information security techniques, and keep pace with evolving infrastructure technology.
But Georgia Tech’s interest in cybersecurity began before the forum.
Richard DeMillo, professor and former dean of the College of Computing and former director of the Georgia Tech Information Security Center, remembers that there was already interest in computer security, crime, and cryptography when he joined the faculty in the 1980s.
“Then in early 90’s, predating the Nunn Forum, there was gathering momentum in cybersecurity. It was just unorganized,” DeMillo said.
The Nunn Forum helped bring greater attention to the need for cybersecurity research and collaboration at Georgia Tech and beyond.
2002: Building a Cybersecurity Workforce
In the years following the Nunn Forum, Georgia Tech continued investing in cybersecurity faculty and education.
According to Professor Mustaque Ahamad, the Institute recognized the need to continue investing in new technologies. In the early 2000s, Georgia Tech began taking steps to expand the educational side of computer security.
“We launched the Master of Science in Information Security after talking to industry friends and listening to their anticipated workforce needs,” Ahamad said. “We had a critical mass of faculty at the time to develop and teach courses for this new degree because we laid the groundwork early on.”
In February 2002, the University System of Georgia Board of Regents approved Georgia Tech President Emeritus G. Wayne Clough’s request to establish the program in the College of Computing in cooperation with the Sam Nunn School of International Affairs and the Scheller College of Business. Georgia State University’s Management Information Systems program was also an early partner.
The new Master of Science in Information Security was expected to enroll about 25 students in its inaugural cohort. The program, later renamed the Master of Science in Cybersecurity, focused on protecting information technology systems supporting industry, government, and national defense.
The program also began building a community of cybersecurity professionals who would go on to become leaders in the field.
“We are still in touch with the graduates from that first cohort, including Dmitri Alperovitch, co-founder of CrowdStrike,” Ahamad said. “Many of our graduates go on to become leaders in the field and stay involved with our program by giving us regular feedback.”
2008–2015: Cybersecurity Becomes Interdisciplinary
As Georgia Tech’s cybersecurity research grew, faculty began recognizing that security problems could no longer be solved by computer scientists alone.
The annual Georgia Tech Cyber Security Summit in 2008 included presentations on cyber warfare and its potential effects on international confrontations. It was another indication that cybersecurity was becoming a multidisciplinary problem.
In the 2010s, the first steps toward a broader interdisciplinary program began taking shape.
Professor Wenke Lee recalls bumping into former Provost Steve McLaughlin, who was chair of the School of Electrical and Computer Engineering at the time. The two began talking and later met informally at a coffee shop, where they developed the blueprint for a cybersecurity research center open to Georgia Tech faculty from every discipline.
“Multidisciplinary was always the goal,” Lee said. “But the question was how to do it.”
Lee and McLaughlin began meeting with research scientists from the Georgia Tech Research Institute and faculty from schools and colleges across campus to build support for an expanded cybersecurity research center.
In August 2015, the Georgia Tech Information Security Center was elevated to a campuswide independent research institute and renamed the Institute for Information Security and Privacy, or IISP.
“IISP provided a lot of infrastructure support and thought leadership at Georgia Tech,” Lee said. “You cannot do great things alone and the whole point of IISP was, ‘let’s not do this alone anymore.’”
By 2017, nearly 500 researchers across nine academic units were affiliated with IISP.
2017–2019: Expanding Cybersecurity Education
While cybersecurity research expanded across Georgia Tech, the Institute also continued to grow its academic programs.
The success of the 2002 Master of Science in Information Security led to an expansion in 2017. The program was renamed the Master of Science in Cybersecurity and expanded to include specializations from the School of Computer Science, the School of Electrical and Computer Engineering, and the School of Public Policy.
In 2019, the program was further modified to offer the degree online with support from Georgia Tech Professional Education.
These changes expanded Georgia Tech’s ability to educate cybersecurity professionals and helped establish the interdisciplinary foundation that would eventually support the School of Cybersecurity and Privacy.
2020: The School of Cybersecurity and Privacy
As cybersecurity research and education expanded across the Institute, it became clear that Georgia Tech needed its own cybersecurity school.
According to Steve McLaughlin, who was dean of the College of Engineering at the time, the effort to establish the School of Cybersecurity and Privacy received significant support from faculty as well as the deans of the College of Computing and the Ivan Allen College of Liberal Arts.
“We wanted to be recognized as the first mover in this space and decided it was the perfect time to create the school,” McLaughlin said.
For Charles Isbell, former dean of the College of Computing, cybersecurity education needed to look beyond information technology. Law, business processes, and cultural considerations were also important parts of preparing the cybersecurity workforce.
“Georgia Tech has been a leader in cybersecurity research for a very long time,” Isbell said. “But creating a new school elevates the importance of responsible interdisciplinary computing and expands our impact in teaching and research.”
Kaye Husbands Fealing, former dean and Ivan Allen Jr. Chair of the Ivan Allen College of Liberal Arts, also emphasized the interdisciplinary foundation behind the school.
The partnerships among Public Policy, Cybersecurity and Privacy, Electrical and Computer Engineering, and the Nunn School of International Affairs helped prepare students for the complex policy and technical challenges they would face in their careers.
In November 2020, 22 years after the Nunn Forum, the School of Cybersecurity and Privacy launched amid the COVID-19 pandemic, with Richard DeMillo serving as interim chair.
2020–2021: From an Idea to a School
Launching a new school during a global pandemic presented an unusual challenge.
“Founding a school virtually in the pandemic was surreal,” DeMillo said. “We went from PowerPoint slides to a functioning school while no one was watching.”
In a matter of months, a school that existed largely on paper began to take shape.
Faculty governance was established through work led by Ahamad. Professor Peter Swire developed policies and procedures, while Regents Professor Seymour Goodman worked to create and improve cybersecurity and privacy curriculum. Meanwhile, faculty hired by DeMillo began making their way to Atlanta.
The process of building the school virtually also came with an unexpected benefit. With Georgia Tech and universities around the world adjusting to remote work, the new school was able to establish its foundation without many of the traditional pressures associated with launching a new academic unit.
2021–Present: Growing the School
The launch of SCP marked a new chapter in Georgia Tech’s long history of cybersecurity research and education. Since 2021, the school has continued to expand its faculty, academic programs, research, and impact.
In 2021, graduate students enrolled in the 19-year-old MS Cybersecurity program had their own home unit for the first time. What began as a small academic unit has continued to grow into a multidisciplinary school bringing together researchers from computing, engineering, social science, business, and other fields.
The school has also expanded its academic offerings. In 2024, Georgia Tech introduced a Cybersecurity and Privacy thread in the Bachelor of Science in Computer Science program, extending cybersecurity education to undergraduate students. The first student to complete the new thread graduated in 2025.
SCP’s faculty has continued to grow as well, bringing new expertise to areas such as artificial intelligence security, cryptography, usable security, network security, cybersecurity forensics, and software supply chain security. The school has also recognized the accomplishments of its faculty.
The school’s research has also gained national and international attention.
In 2025, Team Atlanta, a group of Georgia Tech students, faculty, and alumni, won the Defense Advanced Research Projects Agency’s (DARPA) Artificial Intelligence Cyber Challenge (AIxCC) and its $4 million grand prize. The team developed Atlantis, an artificial intelligence-enabled cyber reasoning system designed to find and patch software vulnerabilities.
The AIxCC victory also opened the door to new work beyond the competition. In 2026, Georgia Tech researchers began working with the Linux Foundation and the Open Source Security Foundation to develop OSS-CRS, an open-source framework designed to help bring cyber reasoning systems into real-world open-source software development. The team also adapted Atlantis for the framework.
SCP faculty and students have continued to earn recognition for their research and contributions to the field. In 2026, seven members of the SCP community received College of Computing awards, including four faculty members recognized for teaching and research. Taesoo Kim received the Outstanding Senior Faculty Research Award for his leadership of Team Atlanta, while Frank Li, Brendan Saltaformaggio, and Teodora Baluta were recognized for their research and teaching.
Leadership within the school has evolved as well. In 2025, Mustaque Ahamad became interim chair of SCP, succeeding Michael Bailey, the school’s inaugural chair. Ahamad had been involved in Georgia Tech’s cybersecurity efforts since the early development of the MS Cybersecurity program and helped establish the educational and research foundation that preceded SCP.
Together, these developments reflect the continued evolution of the school’s mission: bringing together expertise from across disciplines to address cybersecurity and privacy challenges as they emerge.
From its beginnings as a small academic unit to its growth into a multidisciplinary school with global research impact, SCP continues to build on the foundation established by generations of Georgia Tech cybersecurity researchers, educators, and students.