There is no standalone "Cybersecurity PhD" at most universities. What you're actually applying to, in nearly every case, is a Computer Science or Electrical/Computer Engineering PhD, within which you choose a security-focused advisor and research group — cryptography, systems security, network security, applied security, or security-adjacent areas like privacy and formal verification. A small number of specialized institutes (Royal Holloway's Information Security Group being the clearest example) run something closer to a dedicated security PhD, but even there the degree is usually still formally a PhD in the parent department. This guide covers where the strongest security research groups sit and how to evaluate them.
Universities With the Strongest Security Research Groups (QS / THE CS Rankings + Field Reputation)
A note before the table: for a PhD, overall university or even overall CS department rank matters far less than the strength and current activity of the specific security research group and potential advisors within it. QS and THE computer science subject rankings, alongside field-specific reputation (publication records at top security venues like IEEE S&P, USENIX Security, ACM CCS, and NDSS), broadly point to the same cluster of strong programmes — but treat this as a starting list to research further, not a final answer.
| University | Country | Notable For |
|---|---|---|
| Carnegie Mellon University | USA | CyLab; one of the largest, most active security faculty groups anywhere |
| Massachusetts Institute of Technology (MIT) | USA | Strong systems/crypto security research within CSAIL |
| Stanford University | USA | Strong applied security and systems research |
| University of California, Berkeley | USA | Strong systems security and crypto research |
| Georgia Institute of Technology | USA | Large, active security research group within CS |
| University of Maryland | USA | Maryland Cybersecurity Center; strong systems and network security research |
| Purdue University | USA | CERIAS; long-running, well-funded security research base |
| University of Illinois Urbana-Champaign | USA | Strong systems and network security research |
| Royal Holloway, University of London | UK | Information Security Group; one of the few genuinely dedicated security research units globally |
| University of Cambridge | UK | Strong security research within the Computer Laboratory |
| Imperial College London | UK | Strong systems/security research group |
| ETH Zurich | Switzerland | Strong applied cryptography and systems security research |
How to Choose: Advisor and Lab Fit Over Overall Rank
1. Find the Specific Research Group, Not Just the School
Security research spans cryptography, systems/OS security, network security, web/application security, hardware security, and increasingly AI/ML security and privacy. A department with strong overall CS rank but no active faculty currently publishing in your specific subarea is a weaker choice than a slightly lower-ranked department with two or three active researchers in exactly your area. Read recent papers (the last 2-3 years) from potential advisors at each school before applying, not just their faculty bio page.
2. Advisor Availability and Lab Culture
Reach out to potential advisors before applying where possible, and ask directly whether they're taking new PhD students in the coming cycle — a well-known professor who isn't currently taking students is not a viable reason to apply to a programme. Lab size, publication venues the group targets, and whether current students present at top security conferences (IEEE S&P, USENIX Security, ACM CCS, NDSS) are good signals of an active, well-resourced group.
3. Housed in CS vs. Engineering vs. a Dedicated Institute
| Structure | Example |
|---|---|
| Within Computer Science | CMU, MIT, Stanford, Berkeley, Georgia Tech, UIUC |
| Within Electrical/Computer Engineering | Some hardware-security-focused programmes |
| Dedicated security institute/department | Royal Holloway's Information Security Group |
Where a group sits administratively matters less than its research output — but it can affect funding sources, coursework requirements, and how much flexibility you have to work across departments.
Funding and the Research/Career Path
Funding is the norm, not the exception, for security PhDs — as with CS PhDs broadly, admission at a reputable programme typically comes with a full tuition waiver plus a living stipend, funded through a mix of research assistantships, teaching assistantships, and fellowships. In the US specifically, security research also benefits from dedicated government and industry funding sources worth knowing about: NSF grants, the DoD's CySP (Cyber Scholarship Program), and CyberCorps: Scholarship for Service (which funds students in exchange for post-degree government service) are common funding paths alongside standard departmental RA/TA support. If a programme in this field isn't offering funding, treat that as a strong signal to look elsewhere rather than a cost to absorb yourself.
Programme length is typically 5-6 years, similar to CS PhDs generally: 1-2 years of coursework plus qualifying exams, followed by independent dissertation research. Career outcomes split fairly evenly between academia, industry research labs (increasingly common given strong industry demand for security researchers), and government/national-lab positions — a security PhD has a notably strong industry-track option compared to some other CS subfields, given how much demand there is for deep security expertise outside academia.
Selectivity
| Programme | Approximate Acceptance Rate |
|---|---|
| CMU (CS PhD) | ~5-8% |
| MIT (CS PhD) | ~5-8% |
| Stanford (CS PhD) | ~5-8% |
| UC Berkeley (CS PhD) | ~5-8% |
| Georgia Tech (CS PhD) | ~10-15% |
| Royal Holloway (Information Security PhD) | ~20-30% |
CS and security PhD cohorts are small, and acceptance depends heavily on whether a specific advisor has funding and space for a new student in a given cycle — these figures are approximate departmental averages, not a guarantee for any specific research group. Confirm current figures and, more importantly, advisor availability directly with each programme.
Prepare for IELTS with Gabble — once you've shortlisted your target programmes, make sure your English test score isn't what holds your application back. AI-powered speaking and writing feedback helps you reach the score you need. Or prepare for TOEFL if your target schools lean TOEFL.