![]()
SEI Defines Framework for National Security Cyber Research
PR Newswire
PITTSBURGH, Sept. 21, 2026
The framework identifies the 37 most impactful cybersecurity research opportunities across national security missions and systems.
PITTSBURGH, Sept. 21, 2026 /PRNewswire/ — Nation-state adversaries have gained digital footholds in critical infrastructure, and new artificial intelligence (AI) tools are accelerating software vulnerability discovery and exploitation. These cyber threats and others like them are evolving and expanding on many fronts. Those leading cyber research, operations and missions for national security must focus their efforts where they can best bolster our country’s safety. A new framework from the Software Engineering Institute (SEI) at Carnegie Mellon University defines the cybersecurity research areas and opportunities that hold the greatest potential benefit for national security.
Seven Enduring Cybersecurity Areas
Within the complex, rapidly changing landscape of cybersecurity there are enduring subjects where research and development (R&D) can drive significant operational improvements. Not all these topic areas fit the unique requirements and resources of cybersecurity for national defense.
“There is greater urgency than ever before to take considered action to improve the nation’s cybersecurity posture—and in a way that accelerates the delivery of capability to the mission,” said Bill Scherlis, the framework’s editor and a special advisor to the director of the SEI.
More than 25 SEI technical experts, led by Scherlis and Greg Touhill, director of the SEI’s CERT Division, developed Advancing Cybersecurity: A Framework of Cyber Research Priorities. They selected seven areas of cybersecurity R&D that have the greatest potential impact on cyber operations and envisioned cyber capabilities in the Department of War (DoW), the intelligence community, the Department of Homeland Security and other federal agencies:
- Analytic and Operational Tradecraft for Cybersecurity
- Securing AI-Based Systems and Workflows
- Cyber-Physical System Security
- Cybersecurity for Complex Integrated Systems
- Insider Threat and Human–Systems Interaction
- Secure Engineering and Mission Confidence
- Modeling and Simulation in Support of Security
The framework details each of these seven areas, presents the 37 highest priority opportunities for advancement across the areas and provides near- and long-term actions to get there.
To make the R&D strategies measurable, the framework recommends that organizations frame their cyber research efforts around the three elements of cyber risk: threat characteristics of potential attackers, consequence to mission and system vulnerability.
Focused on Mission
While broader cybersecurity research, such as recent reports from the National Academies of Sciences, Engineering and Medicine, informed the SEI’s work, the Framework of Cyber Research Priorities focuses on national security missions. SEI CERT Division experts, in collaboration with SEI software and AI researchers and government stakeholders, selected the seven topic areas because they arise in national security, are challenges for CERT Division mission partners and can guide future mission-focused R&D within the CERT Division and industry cyber research organizations.
The SEI brings leading-edge research in all seven topic areas to bear on the most pressing mission problems. “We benefit from an extraordinary range and depth of expertise and experience in our core areas of cybersecurity, software and AI,” said Scherlis.
“Our collective security depends on our ability to out-innovate and act with greater velocity and precision than those who seek to exploit our vulnerabilities,” said Touhill. “We call on leaders in the research, operations and product development communities to use this framework to set vision-driven cyber research agendas. In today’s rapidly evolving digital environment, we must work together to engineer the future of national security in the digital age.”
The cybersecurity community can suggest changes to the framework, share information and identify best practices by emailing info@sei.cmu.edu.
Download Advancing Cybersecurity: A Framework of Cyber Research Priorities from our Digital Library. Learn more about the SEI’s research and development work on our website.
About the Carnegie Mellon University Software Engineering Institute
The Software Engineering Institute (SEI) advances software as a strategic advantage for national security through research, development, and deployment of tools, technologies, and practices in software engineering, artificial intelligence (AI), cyber, and acquisition transformation. We serve the nation as a federally funded research and development center (FFRDC) sponsored by the U.S. Department of War (DoW). For more information, visit the SEI website at https://www.sei.cmu.edu.
View original content to download multimedia:https://www.prnewswire.com/news-releases/sei-defines-framework-for-national-security-cyber-research-302884970.html
SOURCE Carnegie Mellon University Software Engineering Institute
