Cybersecurity in the Public Interest: Inside Stanford’s Real-World Lab for Students

Case Study

min read


Programs that allow students to participate in cybersecurity activities benefit the students academically and professionally, and they improve institutional defenses against cyberattacks.

Case Study
Credit: Muslianshah Masrie / Shutterstock.com © 2026

Institutional Profile

Stanford University is a private research university in Stanford, California. Founded in 1885, the university is organized into seven schools and has fifteen independent laboratories, centers, and institutes, along with more than 7,500 externally sponsored, award-funded research projects. In the 2025–26 academic year, Stanford enrolled 7,289 undergraduate students and 10,025 graduate students.

The Opportunity

In 2015, Alex Keller, senior systems security engineer at the Stanford University School of Engineering, was approached by a student who was worried that his Stanford account had been compromised. Keller had no idea it would spark a journey that would result in students actively participating in the institution’s cyber defenses.

The student had a part-time job with the government and was concerned that his compromised account might affect his eligibility for government employment. After Keller guided the student on securing the account and reporting it to his government supervisor immediately, the student came back to say he was interested in understanding cybersecurity better and asked if Keller would share his expertise. Although Stanford has a prominent reputation in engineering and computer science, at that time it did not offer many classes focused on cybersecurity. And, because Stanford is a research university, the classes it did offer were focused more on principles of computer science rather than operational security and hands-on projects.

Keller and that student began to meet informally to talk about topics including defensive security, which focuses on building and maintaining resilient systems, and offensive security, which replicates the tactics used by malicious actors to find vulnerabilities that need to be fixed. A second student joined them for these informal information-sharing sessions, and in the meantime Keller noticed a post on an internal mailing list by two other students planning to start a cybersecurity student group on campus. He invited these four students to join forces, and the Stanford Applied Cyber student group was born.

More students quickly joined that core group, excited for the opportunity to develop their skills on real-world cybersecurity problems. Eleven years later, Stanford Applied Cyber has more than 70 active members and participates in or leads a range of activities on and off campus, building skills that help them win intercollegiate cybersecurity competitions, test and improve Stanford’s own security, and offer pro bono reviews and consultations to startup companies emerging from the Stanford community. Along the way, many members of Stanford Applied Cyber have launched careers in cybersecurity leadership roles across government, industry, and nonprofit sectors.

“The students are getting incredible academic research opportunities, and we’re feeding that back into operational security at Stanford,” said Keller. “It’s been a dream to see that come to fruition.”

Fostering a Student-Led Initiative

Stanford Applied Cyber is largely made up of students from the School of Engineering, though the group includes students from cyber policy, international relations, physical sciences, and other disciplines. The club focuses on building practical knowledge and experience analyzing, testing, and defending computer systems, and it is open to any undergraduate or graduate student at Stanford.

Keller has been the group’s advisor since the beginning but stressed that the students have shaped the program. “My job is to ignite that passion and to provide the scaffolding to do it safely,” he said. “I am the security expert I am today largely [due to] my engagement with the tremendously talented students we have here.”

In the beginning, the group did not have its own lab environment and infrastructure to practice on, which today’s members do. Keller, though, had access to both physical equipment and virtual systems students could hack in a controlled environment. For example, Keller knew of a vulnerability in a particular brand of server that allowed someone to take full control of the system remotely. He happened to have one of these servers that was no longer being used, so he suggested using an Applied Cyber meeting to practice hacking into it. More than 15 students showed up to that early meeting of the group, he said. At other meetings, the club held workshops with refurbished election voting equipment and an ATM to demonstrate the insufficient security controls of these systems.

More recently, students are learning to exploit sophisticated software vulnerabilities and to hack agentic AI with prompt injections. These practice activities are complemented by building industry-level knowledge. For example, the group hosts community discussions with invited experts on topics such as supply-chain risk or the cybersecurity implications of the vibe-coding trend. The range of events organized by Stanford Applied Cyber draws a diversity of students, said Keller, “So you don’t have to be a super-technical expert to engage with this community and get something out of it.”

Creating a Productive Space for Exploration

Keller acknowledged that some of the students’ activities—which eventually included searching for actual vulnerabilities in Stanford’s live systems (so-called “white-hat hacking”)—can raise eyebrows among nontechnical colleagues and institutional leaders. He explained to the administration that the group’s goal of training students to become “better hackers than the hackers” was in service of discovering vulnerabilities so defenders could close them. “Of course, I’m using ‘hacking’ in the original sense of the word,” Keller explained, referring to actions taken by malicious actors. In contrast, the students were engaged in hacking to test systems to learn more about them. “We’re exploring that curiosity around technology and how it functions,” Keller noted.

Stanford’s chief information security officer (CISO) at the time, Michael Tran Duff, was supportive of the idea that students could be doing operational security for the benefit of the university. “He saw that we were the good guys who could be leveraged by university administration, not seen as a potential threat,” Keller said. “We have built on that relationship ever since and take pride in those partnerships for our common cause.”

Cyber Competitions

One common activity of the student group has been participating in cybersecurity competitions, which test students’ skills in both defensive and offensive scenarios. A number of industry organizations host these at the collegiate level, and Stanford Applied Cyber participates in the National Collegiate Cyber Defense Competition, which tests students’ abilities to assume administrative and protective duties for a network during a simulated attack, and the Global Collegiate Penetration Testing Competition, which asks students to go on the offensive to hack into a simulated business infrastructure. For the past decade they’ve competed in both events every year and have won podium spots multiple times and four national or global championships.

Bug Bounties

In the early years of the group, a student named Jack Cable joined the Applied Cyber group. Cable was already prominent from a young age in the offensive security world, having won several national bug-bounty competitions, including the U.S. Department of Defense “Hack the Air Force” challenge in 2017. With the strong support of the Information Security Office, Cable successfully campaigned to implement a bug-bounty program at Stanford. The program, which was one of the first at a U.S. institution, allowed students who discovered and responsibly reported vulnerabilities in production systems that benefitted the university to receive modest monetary rewards. “That was unheard of at the time,” said Keller.

Authorized Penetration Tests

As the skills of members of Stanford Applied Cyber grew through the competitions and bug-bounty program, Keller partnered with colleagues and administrators about opportunities to conduct authorized penetration tests at the university. The students selected for these tasks found undocumented vulnerabilities in important systems, which they then helped to close or report to the third-party vendors who could mitigate them. “The administration was supportive, but presumably they didn’t think we’d find anything critical,” Keller said. “When we discovered some profoundly impactful security issues, that was a real eye-opener.”

Stanford Security Clinic

In 2023, student group members Aditya Saligrama and Miles McCain founded the Stanford Security Clinic, a service offering the group’s expertise more broadly in the form of free security reviews for the Stanford community. As Keller explained, many Stanford students and faculty are also founders of startup companies, and the Security Clinic allows them to get free security evaluations as they are about to launch. “This is the time that could make or break them,” he said. Security Clinic sessions are two-hour engagements in which students perform lightweight penetration tests and evaluate security models, data models, and other fundamentals. The team has worked with dozens of startups and expanded to serve other university clients.

Building a Hacking Agent

The expertise students develop in the student club sometimes influences their coursework and research. For example, four members of Stanford Applied Cyber were technical leads on a research project in the computer science department on a new open-source offensive AI model named ARTEMIS. The autonomous agent conducts penetration tests with no human intervention, and in a comparative test it beat all but one of the human professionals. These students (Donovan Jasper, Ethan Ho, Anna Wu, and Arnold Yang) were also co-authors on the resulting research paper.Footnote1

Lessons Learned

Many of the students who have been most active in Stanford Applied Cyber have gone on to prominent jobs in government and Fortune 500 companies or have started their own companies. Some are in specific cybersecurity roles, some in broader engineering roles, and some in cyber policy roles. The experience they gained through the student club has been key, Keller said: “These incredibly talented young professionals go on to do amazing things. We will be working side-by-side with them for years to come.”

Stanford Applied Cyber students are sometimes invited to present their work to cabinet-level university executives. Keller noted that this good rapport, built over time, means the administration is better prepared to navigate thorny questions raised by crowdsourced cybersecurity, such as the responsible disclosure of vulnerabilities and handling sensitive information.

When Keller speaks with student groups at other institutions, however, he often hears they lack the same institutional support. On many campuses, as soon as the administration learns students want to practice real-world cybersecurity skills, they erect barriers. They won’t provide network connections, servers, or the access students need to train for cybersecurity projects or prepare for competitions.

“People say things like, ‘You’re teaching kids how to hack!’,” said Keller. “First, I’m not teaching them. They are, in many cases, teaching me. My value is helping students navigate the sensitive aspects in a way that’s constructive. Second, they’re not kids, they’re young adults, and when we treat them as professionals, they rise to the occasion.”

Keller said it’s understandable to be risk-averse about cybersecurity, but institutions can miss out on opportunities not just to improve their security through testing but to further their mission. “We need to create conditions that enable those who come after us to tackle the world’s most intractable problems,” he said. “That’s what higher education is about.”

Note

  1. Justin W. Lin et al., “Comparing AI Agents to Cybersecurity Professionals in Real-World Penetration Testing,” arXiv (March 3, 2026). Jump back to footnote 1 in the text.

Jessie Kwak is a writer with McGuire Editorial & Consulting.

© 2026 EDUCAUSE. The content of this work is licensed under a Creative Commons BY-NC-ND 4.0 International License.