In June 2026, IIT Kanpur launched India's first bachelor's degree program in cybersecurity, soon joined by IIT Madras. This new course aims to train students with a "hacker's bent of mind" to become cyber warriors capable of defending critical systems. The program admits students through a specialized test and hackathon, focusing on practical skills and real-world applications.
- The program admits students via a two-stage process: a theoretical test and a hackathon.
- The curriculum emphasizes hands-on learning, including malware analysis, digital forensics, and penetration testing.
- The course follows a 2+2 model: two years of academic study followed by two years of internships in government organizations.
- Admission considers prior cybersecurity experience but does not require formal training.
- Collaboration between IIT Kanpur and IIT Madras is ongoing, with plans to include more IITs.
How are students admitted to the new cybersecurity program?
Students are admitted through a two-stage selection process. First, they take a theoretical test covering mathematics, aptitude, and computer science concepts. Those who pass are invited to participate in a hackathon where they solve practical cybersecurity problems. This approach helps identify students with the right mindset and skills beyond traditional entrance exams like JEE.
Why was the cybersecurity bachelor's program launched now?
The program was developed over a year with approvals from IIT Kanpur’s senate and council. It responds to the growing need for cybersecurity professionals, especially after recent incidents exposing vulnerabilities in government platforms. Unlike existing master’s programs, this bachelor’s course taps into young students’ interest in hacking and trains them properly from the start.
What backgrounds do the admitted students have?
Out of around 2,800 applicants, 52 students were selected—32 at IIT Kanpur and 20 at IIT Madras. They come from diverse backgrounds, including various social categories and regions across India. Selection was based on prior cybersecurity experience, hackathon performance, and commendations for identifying security flaws.
How will the admission process evolve in the future?
With more IITs joining, a joint entrance test tailored to cybersecurity will be introduced. This test will assess mathematical ability, logical thinking, and computer science knowledge. The hackathon will be conducted at multiple locations to accommodate more candidates. Prior formal cybersecurity training will no longer be mandatory.
What skills and knowledge does the curriculum focus on?
The curriculum is highly practical, emphasizing attacking and defending systems. Students learn malware analysis, digital forensics, cryptography, vulnerability assessment, and penetration testing. The program integrates AI tools and adapts to emerging threats like deepfakes and AI-driven cyberattacks. The first two years cover academic courses, while the last two involve internships in government agencies.
Why does the program use a 2+2 model with internships?
Cybersecurity requires hands-on experience. The initial academic years build foundational knowledge and lab skills. The subsequent internships allow students to apply their learning on live government systems, gaining real-world exposure under expert supervision. This approach prepares them to defend critical infrastructure effectively.
How do IIT Kanpur and IIT Madras collaborate on this program?
Though each IIT runs its courses independently, IIT Kanpur and IIT Madras coordinate closely on curriculum design and program development. They hold regular meetings and share expertise, with plans to offer some courses jointly in the future. This collaboration ensures consistent quality and innovation.
What challenges were faced in creating the program?
Key challenges included a shortage of faculty with hands-on cybersecurity expertise and rapidly evolving threats driven by AI technologies. To address this, IITs leveraged external experts and Section 8 companies for tutorials and lectures. The curriculum remains flexible to incorporate new developments and tools quickly.
What are the prospects for placements after completing the program?
The program aims to prepare students for roles in government and industry cybersecurity teams. With four years of rigorous training and practical experience, graduates are expected to be highly employable. IITs plan to invite cybersecurity organizations for campus placements, confident in the students’ capabilities.
