Competition wins and a new course put cyber skills to work

This Cybersecurity Awareness Month, the message from University of Maryland Global Campus (UMGC) is clear: Making life difficult for cybercriminals starts with awareness.

Cybercriminals may ultimately target businesses, the military, and other large organizations, but they often gain access through individual accounts and unsecured devices. That is why cybersecurity awareness matters to everyone, not just people who work in IT.

“One person can affect the security of a network based on their role. A single compromised device or employee account can expose much more than people realize. The way to get around this is education,” said Steve Epstein, PhD, portfolio director of cybersecurity technology at UMGC. “Cybersecurity awareness has more to do with training people who are not cyber savvy to try and give them enough education to become savvy.”

At UMGC, that emphasis on awareness extends to practical skills and real-world experience.

UMGC’s cyber competition team has earned 10 first-place finishes so far in 2026.

Cybersecurity beyond the classroom

UMGC offers online programs in cybersecurity operations, technology, and management, including bachelor’s degrees, master’s degrees, and certificates. These programs, including a new master’s in applied artificial intelligence, are designed to help learners build technical knowledge while applying what they learn in real-world settings.

A key example is UMGC’s award-winning cybersecurity competition team.

“Our cyber team is world-renowned. We’re world-ranked, continuously winning or placing in the top three of tournaments against larger universities,” said Helen Barker, DM, department chair of cybersecurity at UMGC.

So far in 2026, the team has earned 10 first-place finishes, two second-place finishes, and advanced to the Elite Eight in the Hack the Madness Capture the Flag (CTF) event. Coached by Jesse Varsalone, collegiate associate professor of cybersecurity technology, the team brings together UMGC learners, faculty, and alumni from around the world.

“Students gain tremendously from learning by doing,” said Varsalone. “In competitions, you encounter things you haven’t seen before, and that’s where you have to apply the skills and tools learned in the classroom. Our team also benefits from having members from all over the world. Many bring professional cybersecurity experience, and that diversity of experience makes the team stronger.”

The cybersecurity competition team was recognized as UMGC’s 2026 Student Organization of the Year in August. 

Related coverage of the UMGC cybersecurity competition team:

UMGC’s CyberTEACH program trains K-12 educators on cybersecurity and digital literacy education.

Learning by doing

At UMGC, experiential learning extends beyond competitions.

In January 2027, UMGC will launch the Forge CyberAI Clinic, a supervised consulting clinic where teams of learners will deliver cybersecurity and AI readiness assessments to organizations that might otherwise be unable to afford the service. The pilot clinic will launch through a new course, CYCL 586, with 10 learners from undergraduate and graduate cybersecurity and AI programs split into two five-person teams that will work with clients throughout the semester. The clinic is designed to mirror a professional consulting engagement, including client meetings, stakeholder interviews, and a formal report.

“The core idea is to close the gap between classroom learning and real consulting practice. Learners aren't doing simulated exercises, they're delivering actual assessments to a real client, using the same frameworks that working professionals use,” said Chad Whistle, PhD, who serves as the cybersecurity program’s assistant dean for portfolio lifecycle and student success and who oversees the pilot program.

“It also gives us a way to extend real cybersecurity and AI capacity to organizations that are often the most exposed and the least resourced to defend themselves,” he said.

Related coverage of cybersecurity education and UMGC alumni:

Helen Barker, DM, serves as department chair of cybersecurity at UMGC.

Everyday habits that reduce risk

UMGC faculty experts note that many cyber scams try to manipulate people into taking a specific action: clicking, approving, sharing, or paying. That pressure is often paired with confusion, or a sense of urgency. 

“One of the key factors [that something is suspicious] is when anybody asks for something immediately, any kind of urgency to their email or texts,” said Epstein.

By now, even people who do not work in IT or cybersecurity are familiar with common tactics of bad actors: phishing emails with suspicious links or attachments, bogus phone calls and text message scams, browser pop-ups, and risks associated with public Wi‑Fi networks. Knowing is one thing. Acting is another.

Barker and Epstein recommend building a few consistent habits:

  • Pause before you click: Unexpected urgency can be a red flag.
  • Use strong, unique passwords: Create a different password for each account. If you reuse a password, an attacker who steals it from one account may be able to access your other accounts. “Focus on making each password long and unique,” said Epstein. “A memorable passphrase made of several unrelated words can be easier to remember and harder to guess. Avoid common sayings, song lyrics, or personal details that someone could discover about you. A password manager can also create and store strong passwords for you.” 
  • Enable multifactor authentication (MFA): It adds another layer of protection that Epstein refers to as “a major but not unbreakable deterrent.”
  • Keep devices and software updated: Delayed updates can leave known vulnerabilities open longer than necessary. “The sooner you do the patch, the sooner your protection is as strong as it can be,” said Barker. 
  • Be aware of connected devices: Smart devices can create risks people do not always think about.

That last point matters more than many people realize. Internet-connected devices can remain connected even when people are not actively using a smartphone or computer, according to Barker.

“Anything that communicates—TVs, cameras, devices with a web component—can become an Internet of Things device where you might not even know you were hacked,” said Barker.

Internet of Things (IoT) devices rely on the internet to communicate and perform tasks. In addition to the electronics Barker named, IoT devices include smart thermostats, smartwatches, smart speakers, and even smart refrigerators. Like other connected technology, they can also create cybersecurity risks.

Artificial intelligence is only increasing the sophistication of cyber threats. AI tools can make sloppy phishing emails and fake landing pages easier to polish than ever. Cybercriminals also count on MFA fatigue, weak or reused passwords, and delays in installing critical updates.

The counter is consistently applying basic cybersecurity habits while continuing to learn. 

For Cybersecurity Awareness Month, the goal is to turn that awareness into everyday practice as threats evolve.

 

For those interested in building stronger digital safety habits, UMGC is hosting a series of Cybersecurity Awareness Month webinars and virtual events throughout October 2026. Topics include scams, social engineering, behavioral science, fraud prevention, and interactive cybersecurity trivia, offering practical ways for participants to strengthen their awareness and stay safer online. Learn more and register at www.umgc.edu/cyberaware.