Alumni News

The SIPA Alumni Reshaping US Cyber Strategy

By Jen Kirby
Posted Sep 14 2026
The SIPA Alumni Reshaping US Cyber Strategy


Each year, in SIPA’s Cybersecurity: Technology, Policy, and Law course, students must scrutinize a particular cybersecurity challenge and present policy recommendations. Last year, the cohort tackled the question of how non-state actors and private entities might be enlisted to disrupt potential hacking threats. The students turned in their reports in December.

This August, the White House issued a presidential memorandum, authorizing certain vetted private firms to conduct surveillance and offensive cyber operations against transnational criminal entities. It looked and sounded a lot like the blueprint that the SIPA students had debated and presented just a few months before. 

“Our students were right there at the front of it, having come up with that,” says Jason Healey, SIPA senior research scholar and adjunct professor, who specializes in cyber risk and conflict and teaches the popular course, along with Evan Wolff and Charles Carmakal, two outside experts in law and tech, respectively.

This wasn’t just a coincidence. Healey and his fellow SIPA faculty are designing a program that equips students to tackle realistic and urgent cyber and national security challenges. That happens in the classroom, with a curriculum that teaches students to problem-solve and think creatively. And it happens outside the classroom, by building strong connections to cyber practitioners in the public and private sectors, who bring the expertise and experience that connects SIPA coursework to current policy debates and developments. 

“[SIPA has] practitioners who have been policymakers. They’ve worked with policymakers. They’ve worked in ops. They’ve been there,” says Thomas Lind MIA ’17, who previously served in the White House Office of the National Cyber Director, one of the top senior officials shaping the administration’s AI and cyber policy. “It’s really useful to disillusion you a little bit as a grad student because you come in really wide-eyed and full of dreams. And it’s really good for them to be very clear about things like, ’Hey, there’s a hell of a lot of really pragmatic, department- and agency-relevant, hands-on knowledge that you need to have to navigate a really challenging policy landscape.’”

That strategy has worked. Former students, researchers, and faculty credit SIPA with preparing graduates to be adaptable – in cyber, the technology will change, and the threats will change with it. But despite that ever-shifting landscape, in the decade since Healey initiated SIPA’s cyber program, its graduates continue to work for federal agencies and the White House, as well as state and local governments. They’ve led cyber risk and resiliency at major corporations and tech firms. Some are shaping policy as researchers and analysts. Some are doing all of the above. 

“This is going to sound very cliche, but the only constant in cybersecurity is that everything’s changing, every single day,” says Sherman Chu MIA ’17, who most recently worked as cyberthreat intelligence lead at the investment firm BlackRock.

“But the fundamentals still remain the same,” he adds. “SIPA prepared me to be a person that can dynamically face these cyber threats.”

A focus on problem-solving

This year, students in Cybersecurity: Technology, Policy, and Law will tackle AI and cybersecurity. The timing is also pretty spot on: in July 2026, OpenAI confirmed that one of its models had gone rogue and hacked into the open-source AI platform Hugging Face. It was an unprecedented breach, and emphasized how AI is transforming cyber defensive and offensive capabilities. What, exactly, that transformation will look like is still unpredictable – but SIPA is leaning into that uncertainty in tech and national security policy to prepare students to be, well, prepared for anything. 

“Cyber is a place where students are challenged to think independently and creatively and come to a problem set where the answers are not obvious from a book they’ve read,” says Lind. “There’s no primer you can study and be really great at this. You have to be good at problem-solving.”

Lind had zero interest in pursuing cybersecurity when he arrived at SIPA. It seemed pretty niche and technical, far from his interests in intelligence and US strategic competition with China. But Healey recruited Lind to join the Cyber 9/12 Strategy Challenge, a SIPA-hosted global competition where students team up and compete to solve a hypothetical and evolving cyber catastrophe, role-playing as national security advisers to the US president. 

Someone had dropped out, and a team was short a player, so Lind ended up filling in. He came away from the competition recognizing, as he put it, “that every lever of power is cyber-enabled.” Intelligence, influence, military action – all of it reliant on cyber tools. “It just really opened my eyes: ’Oh, this is the most important thing,’” Lind says. "And if I can get into this when everybody else is still 10 years behind, then I’ll be ahead of the game.”

Other alumni echoed Lind, saying they hadn’t necessarily planned to pursue cybersecurity in their studies or future careers until they saw how it intersected with their policy interests. Others also changed their minds after opportunities like the Cyber 9/12 Strategy Challenge or classes like Cybersecurity: Technology, Policy, and Law, which emphasized critical thinking and collaboration over the kind of hacker, “Mr. Robot vibe,” as Danielle Errant MIA ’22 put it. 

That was how Errant, now a senior associate for JPMorgan, focusing on technology and cybersecurity policy and partnerships, saw cyber until she joined the Cybersecurity: Technology, Policy, and Law course, which brought together engineering, law, and SIPA students, where each week they analyzed different cyberattacks.

“A different CSO [chief security officer] or CEO would come to the class. We would present the case study, almost acting like role-playing consultants. But every student group was made up of students from all three of those schools, and I just loved it,” Errant says. 

“I loved the collaboration. I loved the fact that you could approach cyber – which is a very dense topic – from so many different perspectives,” she adds. 

Global connections, in a global city

Healey says he knew from the start that he wanted to link SIPA students with cyber practitioners. Some of this is accomplished in a formal setting, as with SIPA’s Capstone workshops, which pair small groups of graduate students with a faculty adviser. Healey says he approached his former colleagues in the cyber field and asked them for advice on which courses would be most beneficial for students – and he roped many into being capstone advisers, too. 

“The program was great because it allowed us to bring in talent that we then bring onto the main faculty, and it allowed us to more easily diversify the faculty, bringing in folks that cared about students and worked hard with them,” Healey says. 

Erica Lonergan, an assistant professor at SIPA, who has helped shape the SIPA’s cyber program, emphasized the strength of the faculty and curriculum. “We bring a blend of full time and adjunct faculty with deep and diverse experience across a range of cyber issues, from the private sector and government to academic and NGOs, coupled with a capstone program that provides students with hands-on experience to grapple with real policy and management challenges for a broad set of clients.”

Emily Ellison MIA ’26 said the capstone program offered her an opportunity to work alongside and learn from industry professionals. Ellison, who works in cyber risk and analysis at Capital One Bank, spent her capstone project with consulting firm McKinsey, building agentic risk taxonomies – basically, a framework for how to evaluate AI capable of pursuing a multi-step goal with a degree of autonomy – and to come up with a code of conduct for how firms might deploy agentic AI safely. Ellison says the capstone exposed her to leaders in the field, and she saw it as a way to “translate a lot of the things we were learning in the classroom to how we can apply that within a professional context.” 

Alumni also say the SIPA cyber program encouraged networking outside the classroom, and that helped students make connections and find mentors who could help them start to navigate their own careers. Chu and Natasha Eastman MIA ’17, who currently works as the head of threat intelligence at CoreWeave, an AI firm, joined with other classmates to start a Digital and Cyber Group. The DCG, as it’s called, linked students with practitioners through lectures and other events, including helping to facilitate SIPA’s participation in the Cyber 9/12 Strategy Competition. From there, Healey and students started scheduling Uptown Socials, twice-a-semester networking events that connected cybersecurity professionals across New York City with students and other alumni. 

Lonergan described DCG as a "lynchpin” in connecting SIPA students with professional and networking opportunities. The campus being in New York City makes this a bit in connecting SIPA students with each other and with professional and networking opportunities.” She adds that SIPA benefits from being in a global hub like New York, something echoed by other alumni who felt they benefited from learning and networking on a campus at the center of local, national and international policy debates.

Ten years later, the DCG is still going strong – with some of its founding members, like Eastman, returning to speak to a new crop of graduate students. “I can read the same books, I can read the same articles, I can write papers,” says Eastman. “But the people – both the professors and the other students – are really what makes the program worth it, and having that time to learn from each other, to experience the world through other people’s eyes.”

Cyber pupils to practitioners

“Cyber is the mustard that goes on every sandwich,” Healey says. The field overlaps with so many challenges in national security, tech, and business. There’s something for every student in SIPA’s cyber offerings, no matter their concentration – human rights or development or international finance. 

But for those who pursue a more intensive program, that all-encompassing nature of cyber gives them an edge in both the public and private sectors. 

“There’s so much to be done that you can start having that impact really early, and unlike a lot of those other areas of national security, there’s this really rich private sector side of it as well that makes it, I think, really dynamic and exciting,” says Healey. 

That dynamism is also a challenge, as the field is constantly changing, as is the technology that underpins it. “SIPA is fundamentally a policy institution, so it’s going to teach you at the strategic and the operational levels,” says James Paisley MIA ’21, who previously worked as an international cyber policy analyst at the Department for Homeland Security before joining cybersecurity consulting firm The Soter Group, where he supports the US government on critical infrastructure resilience in the cyber mission space.

For Paisley, the technical aspects involved some on-the-job training, something other alumni also noted. But they felt SIPA gave them the tools to work through those challenges. “What you need is a willingness to learn, a willingness to be humble, and a willingness to engage on the issues,” Paisley says. 

For Chu, what helped him was deep study of historical cases, and understanding how the field has evolved. Virpratap Vikram Singh MIA ’20, a Singapore-based research fellow in the Cyber Power and Future Conflict Program at the International Institute for Strategic Studies (IISS), says he saw his SIPA education as giving him the ability to understand the nuances of cyber – how to speak about the different actors, incidents, and operators. “That’s the important information that’s going to separate you from someone who’s just, you know, an armchair reader of cyber,” he says. “Considering [SIPA is] a policy school, they definitely geared us up to bridge those gaps.” 

Clayton “CJ” Dixon MIA ’19 recently took over as the chief of New York City’s Cyber Command, responsible for the cybersecurity of all city agencies and all their services – from transportation to trash removal to traffic lights. He’s the first alum to become a chief security officer, in this case for New York City. Dixon says his job is to ensure that everything keeps running smoothly, so New Yorkers don’t have to think about it. “We help them protect themselves from some bad person with a grudge and a computer connection somewhere else. That is what we do.” To do that, Dixon and his team have to triage billions of alerts, sorting out what might be a real threat that requires a response. 

“It is an intimidating job, just by virtue of the scope of the mission,” Dixon says. “But someone has to do it, so why not you?” He says that’s the question he would pose to anyone taking on a big challenge or problem. “When I got the call, it was 100 percent intimidating,” he added. “But also, why go to SIPA if you’re not interested in tackling big, meaty problems?”