‘Hacker’s bent of mind’: IIT Kanpur, Madras B.Cybersecurity course to train ‘cyber warriors’, says in-charge

Sheena Sachdeva | September 29, 2026 | 01:46 PM IST | 12 mins read

From 2027, a JEE-like screening test to precede a hackathon, no formal cyber security training needed; three more IITs to join soon, says IIT Kanpur course in-charge

Somitra Sanadhya, professor at Wadhwani School of AI and Intelligent Systems and course incharge, IIT Kanpur

In June 2026, Indian Institute of Technology (IIT) Kanpur launched a bachelors in cybersecurity programme after a series of young students exposed the vulnerabilities in government-run platforms, including on-screen marking platform for Class 12 results this year. In the aftermath, the course has admitted 52 students at IIT Kanpur and Madras. Somitra Sanadhya , professor at Wadhwani School of AI and Intelligent Systems, IIT Kanpur, spoke with Careers360 on the new course admission, curriculum, IITs joining the bandwagon, internships and many others. Edited excerpts:

Q. How did IIT Kanpur and Madras admit students for its new B.Cybersecurity course ?

This year, we admitted students similar to what we do for the Joint Entrance Examination (JEE) exam. Students are selected through a common test, but once they are admitted to an institution, the responsibility of how the course will be run falls on the respective IITs.

We were the first to develop the curriculum and get it passed by our senate and the council. Immediately after that, IIT Madras joined us . So, there was no time this year to have a separate entrance test.

Three more IITs are likely to join in the next few months and we are planning to have a joint test, similar to JEE. The syllabus will be different since our aim is to select students who are at least inclined towards cybersecurity . The coursework will depend on the requirements of each IIT separately.

Also read Password in public? CBSE OSM portal under lens after 19-year-old hacker claims to bypass security measures

Q. Why has this course been launched now and not before? And what makes it different?

Courses are not launched all of a sudden. There was a consistent effort to design such a programme and get the requisite approvals from within the institute over the last one year.

Our senate looked at the initial proposal and gave feedback. We incorporated its inputs and made some changes. We then approached the Board of Governors, after which the proposal had to be passed through the IIT Council, which was done by our director.

So there was a lot of involvement from authorities within the institute, particularly members of the senate, our undergraduate committee chairman, the dean of the Wadhwani School of AI and Intelligent Systems and the director. All of them collaborated and extended support, and that is how we could launch this programme.

All the approvals took some time which left us with two choices. We could either run the programme immediately from this year or delay it by a year to decide on how the examination would be conducted and other aspects. But we decided to go ahead from this year itself.

I joined IIT Kanpur in July 2025 and started working on this immediately. The final approvals came around April-May, and we immediately started the admission test and selection process .

None of the IITs run a programme in cybersecurity at the bachelor's level. We were the first, and now IIT Madras is also onboard. Many institutions, including National Institute of Technology (NITs) and Indian Institutes of Information Technology (IIITs), run master's-level programmes.

We felt that there is a growing trend among youngsters who are motivated by what is romanticised as hacking. The idea was to tap this potential and train them right, rather than having them do something else for four years. In that sense, it was a novel programme at the bachelor's level.

Q. Please give the break-up of the new batch’s backgrounds.

The total number of applications we received was about 2,800. But we did not call most of the applicants for the hackathon. We called about 120 for the hackathon, out of whom we selected 52 – 32 joined IIT Kanpur and 20, IIT Madras.

They come from all backgrounds, including scheduled caste (SC), scheduled tribes (ST), other backward communities (OBC), economically weaker section (EWS) and women. I believe many of them are from North India. The reason is that when the programme was launched, only IIT Kanpur was available as a choice. IIT Madras joined later. Possibly, people who applied at the time were primarily interested in coming to Kanpur. However, there were a few students from the east, south and a few from the west.

The selection process was based on the students’ cybersecurity experience. Last year, we gave some weightage to their prior work in cybersecurity. Based on that, candidates were shortlisted and then we conducted a hackathon . Each student was given a computer and practical problems to solve. Those who could solve at least a few were selected.

Also read A decade on, Mahatma Gandhi Central University has 5 campuses, none permanent; CAG flags lapses

Q. Going forward, we heard that JEE Main will not be a primary criterion, rather a new examination will be conducted for this course. How are you planning this?

We realised that as the programme is gaining traction and more IITs are joining, there will be a lot of candidates, certainly much more than what we can cater to. So, there will have to be a two-stage selection process from this year onwards.

We are going to have a first-level test, the syllabus for which is under discussion right now. We are planning to have a theoretical test similar to JEE, but with a different paper. There may be some weightage on mathematics, some aptitude tests and some computer science concepts, including programming, on which we will have an objective-type test.

From this year, we are also planning for the hackathon to be conducted in a distributed manner. It will not be held only at IIT Kanpur. In the next few months, there will be an update about the IITs participating this year on their respective websites.

Q. You mentioned that there will be a two-pronged assessment, with a theoretical test followed by a hackathon. What does the institute want to assess through this process that conventional entrance exams may not be able to capture?

JEE Main and JEE Advanced test the fundamental understanding of physics, chemistry and mathematics, which is a good skill to have. That is how the IIT system has been successful.

But for cybersecurity, we want students with a different bent of mind – what we call a “hacker's bent of mind” – or one who thinks about how to break a system. This is usually not testable through the standard tests of physics, chemistry and mathematics. That is the reason we want at least a certain level of mathematical and logical ability. The test will therefore include some mental aptitude and mathematics.

Apart from that, we want them to be motivated towards computer science in particular and system security in general. For that, we want candidates to have some understanding of what IP packets are, how an operating system works, how programmes are written, how buffer overflows can be done, etc.

So, we will test students through this written test first. The real test will be the hackathon, where we expect them to demonstrate their skills. This skill testing is also because of the logistics involved. We cannot have, say, one lakh students coming for that kind of a test. So, the written test will help us filter students and reduce the numbers.

Also read Visva-Bharati: SC, ST, OBC forum seeks audit of VBU’s spending, recruitment; writes to education ministry

Q. Will prior cybersecurity exposure continue to be considered, and how will students without access to cybersecurity competitions or formal training be assessed?

For this year, we relied on certain criteria which included formal training, but it was the only criterion. There were people who did not have any prior certifications but who, for example, found vulnerabilities in a government website; and some government organisations thanked them for it. These kinds of commendation letters were also used.

If they had participated in a national-level competition and won a prize, that was also considered. All of this was done because we had very little time last year and could not have conducted the first-stage test. So, it was only a replacement for one year.

From this year onwards, there is no intention to have any formal education in cybersecurity as a requirement. But they will be given a live system on which they will be asked to solve certain puzzles, sometimes called capture the flag (CTF) and some competitions.

Q. How is the curriculum formulated, and what are the broad cybersecurity capabilities and skills that students are expected to develop through the four-year programme?

The way we have designed the programme, which differentiates us even from other existing master's-level programmes is that it is very hands-on. To defend a system, one has to first practise attacking the system and find loopholes. For this, we have created some vulnerable systems on which students can test their skills, understand how they can use the various tools available and, ultimately, learn to defend them.

Secondly, the programme is being launched from the Wadhwani School of AI and Intelligent Systems. So, we have a focus on AI. There has been a tremendous change in the field of cybersecurity due to the various new LLM models. We plan to incorporate many of these tools.

For the first two years, students will undergo regular courses at IIT Kanpur and correspondingly at IIT Madras. In the next two years, they are going to be in government organisations where they will be testing their skills on live systems.

Q. The course follows a 2+2 model, with the first two years focused on academic learning and the latter two years on internships. Why was this model chosen, and how will the two-year internship component work in practice?

Cybersecurity is a very practical and dynamic subject. It is not a subject where you simply study a lot of theory and then need a huge amount of machinery to implement the ideas. It is best to learn through practice and trial.

For that reason, our curriculum was designed with courses such as malware analysis, digital forensics, applied cryptography, vulnerability analysis and penetration testing. Multiple courses that will impart practical skills to students in a lab environment were incorporated.

The government organisations will supervise these students in their practical work, which could, for example, involve defending a particular server from attacks. Some of these agencies would not like to engage private partners as their systems may not be allowed to be open to the public. At the same time, because these students will be in-house, it is easier to give them access.

As our director puts it, we aim to create cyber warriors for the country through this programme.

Q. How is IIT Kanpur and IIT Madras collaborating for the course?

Every course at every IIT is run differently. So, theoretically, IITs themselves do not collaborate after the admissions. But because this is a new programme, we are collaborating heavily.

We have regular meetings with the team from IIT Madras, which is led by Chester Rebeiro from the computer science department. We had discussions when they were designing their curriculum. Even while running these courses, we are in constant touch. We hope that at some point there might be some courses which are taught in a shared manner across multiple IITs.

That has not happened yet because the programme started only a few months ago and not even a semester has been completed. But in the long term, we expect that at least some of the courses will be taught commonly across these IITs.

In the initial days, the courses themselves are fluid. We have approval for each of the courses from our Senate, so the course content and how they are going to be run are, in some sense, properly defined. But when a course is being run for the first time for a specialised programme such as this, there might be some teething problems. The departmental committee will look after these issues.

Also read ‘Not individual failure’: IIT Bombay students protest suicide, want director to quit, action against professor

Q. What were the key challenges in designing and implementing the programme, particularly in terms of developing the curriculum, faculty, cybersecurity infrastructure and internship ecosystem?

The IITs do not teach such courses, so we do not have enough faculty members who can be hands-on with some of these courses. That was a big challenge while designing the programme.

Thankfully, we have some organisations within the IITs, including Section 8 companies, and others who help with tutorials, expert lectures and so on. With this help, we have been able to design some of these lab courses. Hopefully, in a few years, we will have regular faculty in these domains as well.

Second, with the advent of AI, the number of cybercrimes is increasing tremendously. There are deepfakes where people will not even recognise whether they are talking to an actual person or watching a video-generated image and audio.

But every challenge also brings opportunities. There are also methods by which one can recognise whether the audio or video feed being received is actually fake. There are automated detection tools and development of such tools is also important.

Then there are all kinds of attacks happening through these specialised LLMs. This will also bring a requirement to incorporate such techniques into the courses, and how to prevent them. Many of these techniques have evolved in the last six months to one year.

IITs are dynamic systems and we keep changing our curriculum at a very fast pace. Typically, courses are changed every few years and, in almost a decade, the entire curriculum of an IIT is reviewed. Therefore, we hope that these new technologies will also be incorporated into our courses very soon.

We will also be hiring more people and hopefully have specialised courses of this kind added as electives. In addition, we also have a plan for the internships – that means two years of coursework and at least six months of internship, so about two-and-a-half years.

Also read IIT Ropar: Faculty ‘harassment’, forced resignation, a self-argued case – how a scholar won her PhD seat back

We also intend to have a review of the programme that has already been approved by our Senate. By that time, we will understand what was good and what was not good in the coursework and what the feedback was from the government agencies. We will therefore have feedback from both places and then try to review the curriculum at that point.

Q. How do you foresee the placements after two years of training and two years of coursework while also taking feedback from the industry consistently?

We intend to call organisations working in the field of cybersecurity for placement. If students spend four years very seriously, I do not see a reason why they would not be selected.

MakeCAREERS360
My Trusted Source
Add as a preferred source on google

Follow us for the latest education news on colleges and universities, admission, courses, exams, research, education policies, study abroad and more..

To get in touch, write to us at news@careers360.com.