icon-carat-right menu search cmu-wordmark
Our Research

Cybersecurity Engineering

The Software Engineering Institute (SEI) stands on the front lines of defense against cyber adversaries. Our cybersecurity engineering (CSE) research protects and defends national security systems, software components, and data from unauthorized access, cyberattacks, and other malicious activities.

With new vulnerabilities emerging daily, staying ahead of threats in today’s fast-paced cybersecurity landscape is a race against time. At the SEI, our mission-driven focus is to strengthen our nation's cybersecurity infrastructure by securing the country's most critical systems and protecting agencies and systems from a loss of confidentiality, integrity, or availability (CIA) due to cyber threats.

It's vital to balance opportunities, such as shared resources and capabilities, third-party tools, and cloud capacity, with the increased cybersecurity risk that these opportunities introduce to the defense industrial base (DIB). To reduce risk, it's imperative to implement effective and repeatable practices that can respond to changing technology needs, discover vulnerabilities before attackers do, manage the growing threats against software products that support critical infrastructure, enable warfighters, monitor and manage money, and control physical resources, buildings, and transportation.

The SEI’s CSE researchers aim to ensure that the acquisition and development process is secure from the start. Our mission success is dependent on making sure that stakeholders make choices that protect them against legacy or weak supply chain management (SCRM), software acquisition, or development practices and strengthen cybersecurity resilience. With a deep, scalable understanding of how to detect and defend against security weaknesses and exploitation, our cybersecurity professionals are driven to harden the nation’s vulnerability surface and protect national security interests.

Advance Cybersecurity Resilience

The goal of CSE is to ensure that the software the Department of Defense (DoD) and federal agencies develop or acquire delivers the expected functionality and blocks actions that might introduce risk. To achieve this goal, the SEI helps prepare managers, engineers, developers, testers, and other groups involved in lifecycle tasks, to build and field effective cybersecurity in current and future software acquisition and development, validate and sustain cybersecurity in systems and software, and deliver the mission impact your organization expects of its software.

Build Security into Application Lifecycles

The SEI’s CSE team leverages expertise in system and software engineering, risk management, program management, measurement, and cybersecurity to create methods and solutions that you can integrate into your existing acquisition and development lifecycle practices. To this end, the SEI offers many tools and approaches to help engineering, development, acquisition, and sustainment groups that work in or with your organization.

The SEI continues to expand CSE research through engagements with the DoD and other federal agencies to address real-world challenges. Over the years, we have shared our findings in many notable publications, including a book on cybersecurity, a paper on assessing DoD risk in acquisition, and a program manager’s guidebook for software assurance.

What We Offer

The Latest from the SEI Blog

Cyber-Informed Machine Learning

Blog Page
and

This blog post proposes cyber-informed machine learning as a conceptual framework for emphasizing three types of explainability when ML is used for cybersecurity.

READ

13 Cybersecurity Predictions for 2025

Blog Page

It’s that time of year when we reflect on the past year and eagerly look forward. This post presents 13 cyber predictions for 2025.

READ

Latest from the Digital Library

DeepSeek V3 and R1: An Overview of Technology Innovations and Implications for United States National Security

White Paper
, , , , and

In this paper, SEI researchers perform an initial analysis of three questions regarding impacts of the DeepSeek V3 and R1 model releases.

Read

AI Hygiene Starts with Models and Data Loaders

White Paper
, , , and

This paper places a call to action for traditional cybersecurity tools and techniques to be applied to artificial intelligence (AI) for improving the cybersecurity of AI systems.

Read

Explore Our Cybersecurity Engineering Projects

Cybersecurity Engineering Topic Page Looking Ahead

Our Vision for the Future of Cybersecurity Engineering

The SEI’s cybersecurity professionals are working to expand available CSE options to bolster national security. We are currently developing and tailoring archetypes to support agencies in identifying cybersecurity risks improving evaluation of mission impact.

To collaborate on these new projects in the field of cybersecurity engineering, contact us.