Security governance & risk
Set security priorities and clarify who makes risk decisions. Connect oversight with the systems and information the organization needs to protect.
Ph.D. / DTech · Online
Develop the expertise to lead cybersecurity programs. Use advanced research to evaluate defenses and make informed decisions about risk.
For security professionals preparing for greater responsibility and managers who oversee cyber risk.
Leading an effective defense
Security leaders must decide which risks need attention and whether existing defenses are adequate. Those decisions require technical understanding and evidence about how safeguards perform.
NMU’s Cybersecurity program connects that work with doctoral research training. Develop the ability to evaluate security practices and guide improvements across an organization.
Set security priorities and clarify who makes risk decisions. Connect oversight with the systems and information the organization needs to protect.
Evaluate how safeguards work together to protect systems. Assess whether control choices address the threats and vulnerabilities that matter.
Assess the information used to identify suspicious activity. Judge which signals warrant investigation and how they inform a response.
Examine how teams coordinate during an incident. Establish clear responsibilities and use incident findings to improve future response.
Assess readiness to restore essential services after disruption. Evaluate recovery plans against the organization’s operating needs.
Professional relevance
Information security analysts protect computer systems and networks. BLS reports the following pay and employment projections for this occupation.
BLS · Information security analysts ↗
These figures describe information security analysts, not executive salaries or NMU graduate outcomes. Typical entry requires a bachelor’s degree and related work experience.
Lead a security function and set priorities for reducing risk. Explain the evidence supporting security decisions to organizational leaders.
Guide the design of defenses and assess whether controls meet the organization’s security needs.
Coordinate response teams and help the organization learn from incidents. Strengthen preparation for future disruption.
Evaluate security practices against organizational requirements. Communicate gaps and guide corrective action.
Career progression depends on experience, demonstrated performance, and employer requirements.
Advanced research in practice
Both pathways include 15 credits in research methods and an 18-credit dissertation. Build the skills to evaluate security evidence and justify improvements to your organization’s defenses.
Judge the methods behind product claims and security assessments. Determine how well the findings apply to your environment and threats.
Use quantitative and qualitative methods to examine security incidents. Assess possible causes and explain where the available evidence is incomplete.
Evaluate findings from security exercises and recovery reviews. Use that evidence to identify weaknesses and justify changes to response plans.
NIST’s Cybersecurity Framework 2.0 identifies evaluations and security testing as sources of improvement. Research skills help you judge those findings and make informed changes to security controls. NIST · Improving cybersecurity practice ↗
Ph.D. pathway
Conduct original research that contributes to understanding cybersecurity and the practices used to manage it.
DTech pathway
Apply research to cybersecurity problems within a professional or organizational setting.
Foundational coursework differs by pathway and develops the scholarly writing and ethical judgment needed for doctoral research.
Complete TCH720 and TCH721, Current Issues in Technology Research I and II, for the Ph.D.; or TCH722 and TCH723, Current Issues in Technology Practice I and II, for the DTech. These courses total six credits. Select another 12 elective credits with faculty and advisors.
Work with your committee to develop and defend a proposal. Complete the study and present your findings in a written dissertation and final oral defense.
Research involving human participants requires Institutional Review Board (IRB) approval before data collection. Organizational research also requires appropriate data access and protection of confidential business and personal information.
From coursework to defense
Coursework is online and asynchronous, with four instructional weeks in each monthly term. Students normally take one course per term.
An advisor helps you plan your studies from admission. Writing support and faculty office hours are available throughout your coursework.
After coursework, complete the candidacy examination and defend a proposal developed with your committee.
Obtain required ethics approval, carry out your research, and defend the completed dissertation before your committee.
Tuition
Per three-credit course for eligible geographic pricing zones. Additional fees apply.
Spread the cost of your doctorate across your studies. Pay for each course as you enroll, making tuition easier to manage.
The catalog lists a $20 application fee, $50 registration fee, and $200 graduation fee. Ask admissions for an itemized breakdown before enrolling.
Eligible first-time students receive a 50% tuition reduction on their first course, subject to catalog terms.
Rates are in USD. Source: NMU 2026–2027 catalog.
Your starting point
NMU reviews your academic preparation and readiness for doctoral study. Discuss how your security or technology background fits the program and which pathway supports your goals.
Before you decide
Cybersecurity focuses on protecting systems and managing cyber risk. IT Management addresses the broader oversight of enterprise technology. Both offer Ph.D. and DTech pathways in the School of Technology.
Doctoral study adds advanced research methods and a dissertation to your graduate preparation. Learn to evaluate cybersecurity evidence and conduct research that informs security knowledge or practice.
The Ph.D. emphasizes original research that contributes to technology scholarship. The DTech emphasizes applied research addressing technology problems in practice. Discuss your goals with admissions to choose the appropriate pathway.
The catalog allows up to six transfer credits, limited to approved electives. Courses are evaluated individually for equivalence. A prior master’s degree does not automatically shorten the program.
Asynchronous coursework lets you plan study around work, within published deadlines. Proposal and final oral defenses require scheduled participation. Completion depends on your progress through coursework and dissertation milestones; the catalog allows up to seven years from first enrollment.
The university catalog explains NMU’s status. NMU does not hold accreditation recognized by the U.S. Department of Education or CHEA. Check with an employer or receiving institution about acceptance for your intended use.
Cybersecurity · Ph.D. / DTech
Speak with admissions about your qualifications and whether the program fits your goals.