Cybersecurity Guide

  • Bootcamps
  • Degrees
    • Associate in Cybersecurity
    • Bachelor’s in Cybersecurity
    • Master’s in Cybersecurity
    • Graduate Certificate
    • Computer science with cybersecurity emphasis
    • Cybersecurity Analytics Degree
    • MBA in cybersecurity
    • phd in cybersecurity
    • Cybersecurity law degree
    • AI and Cybersecurity Degree
  • Online
    • Online Certificate in Cybersecurity
    • online bachelor’s in cybersecurity
    • online IT degree
    • online master’s in cybersecurity
    • Online master’s in information security
    • online phd in cybersecurity
  • CERTIFICATIONS
    • Certified Information Systems Auditor (CISA)
    • Certified Ethical Hacker (CEH)
    • Certified Information Security Systems Professional (CISSP)
    • Certified Information Security Manager (CISM)
    • Digital Forensics Certifications
    • Security+
    • CompTIA Advanced Security Practitioner (CASP+)
    • Certified Network Defender (CND)
    • OSCP
    • CRISC
    • Pen Testing
    • CTIA
    • Cryptography
    • Malware Analyst
  • CAREER GUIDES
    • Security Engineer
    • Chief Information Security Officer
    • Security Analyst
    • Computer Forensics
    • Security Consultant
    • Digital Forensics
    • Cryptographer
    • Security Administrator
    • Penetration Tester
    • Security Software Developer
    • Security Specialist
    • Security Code Auditor
    • Security Architect
    • Malware Analyst
    • Data Protection Officer
    • Cybercrime Investigator
    • Cryptanalyst
    • Security Incident Responder
    • Chief Privacy Officer
    • Risk Manager
    • Network Administrator
    • Business InfoSec Officer
    • Information Security Manager
  • States
    • Alabama
    • Alaska
    • Arizona
    • Arkansas
    • California
    • Colorado
    • Connecticut
    • Delaware
    • Florida
    • Georgia
    • Hawaii
    • Idaho
    • Illinois
    • Indiana
    • Iowa
    • Kansas
    • Kentucky
    • Louisiana
    • Maine
    • Maryland
    • Massachusetts
    • Michigan
    • Minnesota
    • Mississippi
    • Missouri
    • Montana
    • Nebraska
    • Nevada
    • New Hampshire
    • New Jersey
    • New Mexico
    • New York
    • North Carolina
    • North Dakota
    • Ohio
    • Oklahoma
    • Oregon
    • Pennsylvania
    • Rhode Island
    • South Carolina
    • South Dakota
    • Tennessee
    • Texas
    • Utah
    • Vermont
    • Virginia
    • Washington
    • Washington, DC
    • Wisconsin
    • West Virginia
    • Wyoming
  • Podcast
  • Resource Center
    • Women in Cybersecurity Statistics
    • Centers for Academic Excellence
    • Job Guide
    • Veteran’s Guide
    • Women’s Guide
    • Internship Guide
    • Security Clearance Guide
    • Ethical Hacker Guide
    • Coding for Cybersecurity Guide
    • Cybersecurity 101
    • Student Guide to Internet Safety
    • Scholarship Guide
    • Cybersecurity Math Guide
    • Small Business Guide
    • Cybersecurity for K-12 students
    • Career Networking Guide
    • What is a Cyber Range?
    • Code Like a Hacker
    • Reacting to a Cyber Incident
    • Introduction to Cyber Defense
    • Cybersecurity Courses Online
    • Recommended Reading
    • Phishing Attacks
    • Cybersecurity Responsibility
    • How to Get Into Cybersecurity
    • Cyberwarfare
    • Cybersecurity Insurance
    • Job Interview Prep
    • Readiness Economy
    • Is Cyber a Good Career?
    • What is CyberCorps?
    • DEI in Cyber
    • NIST and Small Business
  • Research
    • AI and Cybersecurity
    • Holiday Hacks
    • Jobs Report
  • Industries
    • Financial Sector
    • Insurance Sector
    • Healthcare Sector
    • Environmental Sector
    • Energy Sector
    • Government Sector
    • Transportation Sector
    • Food and Ag Sector

An interview with David Maimon | Georgia State University

Last updated: July 20, 2026

Written by Steven Bowcut

With over 30 years of experience in the security industry, Steven Bowcut is a skilled editor, writer, and consultant.

Dr. David Maimon is a professor of criminal justice and criminology at Georgia State University and director of its Evidence-Based Cybersecurity Research Group. His research explores cybercrime, online fraud, offender behavior, threat intelligence, and evidence-based approaches to cybersecurity policy and prevention.

Summary of the episode

Dr. David Maimon discusses his transition from traditional criminology research to evidence-based cybersecurity, focusing on cybercrime prevention, offender behavior, fraud ecosystems, and the effectiveness of security policies and interventions.

He also highlights Georgia State University’s interdisciplinary cybersecurity pathways and advises students to develop curiosity, critical thinking, AI literacy, and skills spanning technology, data analysis, policy, and human behavior.

Listen to the episode

Read a full transcript of the episode

Steven Bowcut:

Welcome to the Cybersecurity Guide Podcast, designed to help students and early to mid-career professionals discover their best options for cybersecurity education. My name is Steven Bowcut, and today my guest is Dr. David Maimon from Georgia State University.

Dr. Maimon is a professor in the Department of Criminal Justice and Criminology at Georgia State University’s Andrew Young School of Policy Studies, where he also directs the evidence-based cybersecurity research group. He also serves as the head of fraud insight at Centrelink.

His work focuses on cyber enabled and cyber-dependent crime experimental research methods, cybercrime prevention, online offender behavior, darknet and fraud ecosystems, and the use of empirical evidence to inform cybersecurity policy and practice. That makes Dr. Maimon an especially interesting guest for students who are exploring cybersecurity career paths.

Cybersecurity is often presented as a purely technical field centered along coding networks, cloud systems, and defensive tools. Those areas are certainly important, but the field also needs people who understand criminal behavior, online fraud, victimization, threat intelligence, law enforcement, policy, and the human side of cyber risk.

Georgia State University offers students several ways to approach cybersecurity, including pathways through computer science, information systems, business, FinTech, law, criminal justice, and interdisciplinary research.

In this episode, we talk with Dr. Maimon about those opportunities, but we will also spend time on the work that he is directly involved in, evidence-based cybersecurity research, cybercrime ecosystems, and the growing need for students who can connect technical understanding with behavioral and policy insight. With that, Dr. Maimon, welcome to the show and thank you for joining me.

David Maimon:

Thank you so much for having me, Steven.

Steven Bowcut:

All right, this is going to be fascinating. I’m looking forward to it. So as we like to do on the show, let’s start with a little bit more about you.

So if you could tell us a little bit about your academic and professional journey, including how your work in criminology and criminal justice led you to study cybercrime and cybersecurity.

David Maimon:

Yeah, I’m glad to do that. I started my academic career actually interested in neighborhood research. When I pursued my PhD in Ohio State University, my area of research focused on neighborhoods and juvenile delinquencies.

So I tried to figure out how the neighborhood within you live in impact or affect your delinquent outcomes as a juvenile and then later on as an adult. So I was doing this for four years in the Ohio State University that I got my first academic position with the University of Miami, continued to do that over there.

Then a couple of months after I joined the University of Miami, there was an opening at the University of Maryland and they were looking for someone who will do neighborhood research. I applied, got the position. At the time, the University of Maryland, their department of criminology was one of the best in the world.

I think they’re still highly ranked, but at the time all the major figures were there. I moved there and then I started to get bored conducting neighborhood research because it was very difficult for me to simply sit next to a computer and crank numbers trying to answer a question using other people databases.

At the time I was also talking to my department chair and her name is Sally Simpson and she had a huge impact on my career. And during the conversation I had with her trying to figure out what I need to do in order to make tenure, she told me I wanted to come up with a science piece, which is very rare if you’re with criminology.

And so I freaked out, I tried to figure out how will I be able to do that with my neighborhood research focus. And then another colleague from the department, Professor Gary LaFree, reached out and told me that he was looking for someone to put together a paper around cyber terrorism.

I’m this assistant professor, I need everyone votes to go up for tenure. And I said, sure, I’ll take it. I started digging in and I realized that at the time there weren’t really too many people doing rigorous work around the issue of both cyber terrorism and cybercrime.

And so that’s how I essentially started diving deeper and deeper into cybercrime world. We started doing some really cool research in the context of hacking in the context of darknet environments and of course online fraud. And this is essentially why I’m doing what I’m doing right now.

Steven Bowcut:

Okay, awesome. Thank you for sharing that. So you’ve built a career around understanding cyber-enabled and cyber-dependent crime through empirical research. So what drew you to that evidence-based approach? And maybe just as interesting is how has your view of cybercrime changed as the threat landscape has evolved?

David Maimon:

Yeah, so as I mentioned, before engaging in cybercrime research and also my first steps in this ecosystem, I was really trying to figure out relationships between at the time the neighborhood you live in and deviant outcomes. So at the time of delinquency, we actually worked on suicide and suicide attempts among adolescents and youth.

But all of those studies I’ve put together earlier in my career, I felt like they were extremely interesting. The relationships between personality traits and neighborhood sort of characteristics and then those deviant outcomes were fascinating to understand them.

But in terms of policy, in terms of actual impact and ability to change, I couldn’t really find a whole lot over there. So you can’t really do much knowing that if you have a kid with low level of self-control, there will be more likely to engage in crime. I mean that’s extremely interesting, but okay, what are you going to do with it?

Steven Bowcut:

Go back to the parents.

David Maimon:

So when I shifted gears to do some work on cybercrime, I wanted the work to be relevant to policy. I wanted the work to be relevant to law enforcement. I wanted the work to be relevant for cybersecurity professionals. So it had to be applied. It had to have some kind of applicability to the research.

If you spend all this time studying something and the government pay for it, or a funder like another sponsor like a bank or another funder to pay for this, it needs to have in my mind, some practicality to it. So I started to think about ways where we can design studies based on that. And that essentially what led me to the evidence-based approach.

Evidence-based is essentially a very popular aproach nowadays in science, which essentially suggests that we embrace policies based on scientific evidence with respect to what works and what doesn’t.

We don’t want to spend money over aproaches, policies, tools, which at the end of the day will not deliver on their promises. So that was really appealing to me. And that’s why I decided to embrace this evidence-based aproach, which was very popular in the medicine still is very popular. Dical field, criminological field.

A lot of scholars out there talk about evidence-based policing, like what can you do in order to make sure that what we do in the context of policing actually reduce crime or prevent crime?

I thought that was a really appealing approach to try and understand cyber crime and how to prevent and mitigate different types of cyber crimes out there. So I think that was essentially what drew me to the evidence-based approach.

And again, the fact that you can conduct scientific research and at the end of the day, tell the world we found something that at the end of the day you guys can use when you’re trying to prevent hacking, where you’re trying to prevent victims or targets probability of clicking links which would make them targets of cybercrime.

That to me was extremely powerful. So that is essentially what got me to this.

Steven Bowcut:

Yeah, excellent. I love that. I love that concept of evidence-based research because theories are great and theoretical research is wonderful and we need it, but that’s how we prove it is with evidence-based or empirical research.

Does it really prove? Does it work out the way we though it was going to work out?

David Maimon:

100%. And again, the theories are amazing. I love the theories. I love testing theories, but I think that given the state of academia right now where resources are not available like they used to be in the past, we need to be more conscious about the type of research that we conduct.

And I think that if we want to serve humanity, so to speaking, we need to engage in research which will have some kind of benefits to it to society. And that research in my mind is evidence-based, obviously.

Steven Bowcut:

Absolutely. All right, fascinating. So let’s focus on Georgia State University a little bit. In the opening there, we talked about some of the pathways. To offer pathways to cybersecurity through several areas, including computer science, information systems, business, criminal justice, law.

So for students who are just beginning to explore the field of cybersecurity, how would you describe the cybersecurity education ecosystem at Georgia State?

David Maimon:

The great question. Georgia State offers different paths to understand cybersecurity, and cybersecurity is a very interdisciplinary field, so you can attack it from different angles. So you can definitely attack it from a more technical perspective.

Try to understand some of the tools, try to build some of the tools which then will be used to prevent cyber attacks, prevent hacking, contain hackers when they’re on the system and deflect them from the holy grail, so to speak. And those are extremely important skills to have, technical skills to have.

So the computer science department will offer teaching those skills obviously. But in addition to understanding the technical skills or acquiring the technical skills, there are other skills which in my mind are very important in the context of the cybersecurity ecosystem.

For example, data science. At the end of the day, when we try to understand cyber attacks, oftentimes we’ll be looking at huge event logs which we will need to analyze in order to try and understand and find trends in those databases.

So data science is very important in the context of the cybersecurity ecosystem. The business school offer teaching those skills. In addition to technical skills as well as data science skills, there’s a lot that we can say about policies.

At this point, we know that the ecosystem constantly embrace new policies with respect to how to address different types of crimes out there, how to nudge victims or targets away from specific cyber crime campaigns that organized crime groups and nation states essentially lounge on a periodic every now and then.

So policies, understanding what policies work. Should we really change passwords every three months or so? Is it really effective to change password every three months or so? Should we actually try and arrest hackers out there who engage in cyber crime?

How should we doing that? All these policies are extremely important for us to understand, test and see whether we should pursue them in the future or simply drop them and try to think about different policies to imply the context of cybersecurity.

So policies and understanding policies, understanding how to address policies, how to implement policies, test policies another very important feature in the context of the cybersecurity field. And then you have the human component, the human component of cybercrime, which is essentially what I’m doing for a living.

I’m trying to understand the human and how they engage in cybersecurity or cyber crime sort of operations. It’s extremely interesting, extremely important to understand the human in the loop as well because at the end of the day, the tools are just tools.

Someone needs to operate those tools. Someone needs to make a decision with respect to how the tools work, how an attack would look like. Should an attack be lounged or not against who? Why specific attacks and so on.

And so the humans in the loops are extremely important as well, understanding their psychology, understanding the situation under which they will be more likely to engage in different types of cybercrime.

Why this cyber crime and another type of cyber crime. Pathways into cybercrime, pathway outside of cybercrime.

These are all extremely interesting topics that I think are very relevant in the conduct of cybersecurity and are very relevant for cybersecurity officials out there and practitioners out there simply because once you understand the human in the loop, you will be able to perform your work better.

So Georgia State allows you concentration in each of those paths. And I think pursuing the four of them simultaneously will of course give you a lot of benefits in the job markets once you graduate.

Steven Bowcut:

Absolutely. Well, that is so fascinating to me. And so for a couple of reasons actually.

So first of all, I like the idea that many students begin their academic career maybe thinking that cybersecurity is all about coding and networks and technical defense, and maybe that’s not something that really appeals to them.

And I think as an industry, we’ve probably suffered for the last couple of decades because people who were more interested in human behavior may not have been attracted to what seemed to them to be a very technical field.

And now we’re finding all the things that you just described, why the attackers do what they do and what leads them into it and how can they get out of it and all of those things. And then there’s the other side of that, there’s the defender and/or the victim. Those are humans as well.

So does the research that you do, does it include looking at why do we give our passwords away? Why are we so easily tricked? Why does social engineering work? Or why do defenders just stop looking at logs after a while? Does it look at that as well?

David Maimon:

That’s exactly what we do. I pride myself in the fact that I try to immerse my teams in the cybercrime ecosystem. And when I’m thinking about the cyber crime ecosystem, I’m thinking about four actors who constantly meet each other on darknet places, clearnet, text message applications and their interaction, the junctions.

And the interaction essentially create junctions for us to essentially deploy our tools and collect information. And by four players, I’m talking about the targets/victims. I’m talking about offenders who constantly try to target the targets and the victim and make them victims.

I’m talking about law enforcement. Law enforcement, or we call them guardians because it’s not only law enforcement, it’s also cybersecurity professional cybersecurity practitioners who try to protect the victims. And then of course, enablers, individual who support the criminals operations.

The interaction between each of those actors online allows us with a unique opportunity to collect data and then try and test different hypothesis we have in respect to what should we do in order to deflect the offenders away from the target.

For example, we have this really cool project with my colleague, Professor Eden Kamar. And what she does is essentially deploy honeypots in check rooms which are being used by adolescents and youth. Our honeypots pretend to be adolescents and youth, like 13 years old male and female.

And the whole point of those honeypots is to deflect the pedophiles away from the real kids. Again, it’s just an example of how you can deploy a tool in the ecosystem, collect data, and then try to figure out a way to deflect or nudge either the offender or the victims away from each other.

Just one example. So that’s essentially what we do. We try to be out there in the ecosystem, collect data, run experiments in order to really try and answer what works and what doesn’t in the context of online crime prevention.

Steven Bowcut:

Yeah, interesting. I can see how that could get very complicated and maybe even kind of dangerous. But before I ask you about that, so the evidence-based cybersecurity research group at Georgia State, and maybe there’s a mission statement, but if there’s not a mission statement, if you had to condense what it is you do into a statement, what is the mission of that group and what kinds of questions are you and your students trying to answer, in addition to what we’ve talked about? I know you’ve talked about it already

David Maimon:

Yeah. So our mission is to really try and understand what works and what doesn’t in the context of online crime prevention and mitigation. We are trying to do three things. We are trying to understand which policies and tools actually work. We essentially try to test the effectiveness of policies and tools.

And just an example for that will be in 2022, we tried to figure out the effectiveness of implementation of two-factor authentication in reducing the volume of compromised bank accounts we’re able to find in darknet markets out there. 2FA, everybody is familiar with 2FA.

I mean you’re trying to log into your bank account after you fit in your password and username, you’re going to get the text message to your phone. Just you need to verify that you are who you say you are.

In 2022, several banks in Canada implemented this approach. At the same time, we spent a lot of time on darknet finding a lot of compromised bank accounts of those Canadian banks. We simply try to figure out what will happen once those bank implemented those 2FA within their customers.

And what we found was that once the banks implemented 2FA, the bank who enforced 2FA and obligated all their consumers to implement the 2FA, we find a significant reduction in the volume of compromised bank accounts that they were able to find coming from those specific banks.

So this is just an example of how we test policies. At the same time, we tried to figure out emerging trends, like what is it that the criminals are working on, like the models operandi of their operation?

In this sense, one example will be us trying to figure out the origin and the model operandi of check theft and check fraud here in the United States 2021. I mean, we were always there in the darknet and Telegram always finding checks that criminals have offered for sale.

But then in June of 2021, we started to see a dramatic increase in the volume of stolen checks. We started investigating and we realized that the checks essentially come from USPS collection boxes because essentially what the criminals were doing was just targeting the mailboxes, looking for the checks, washing the checks, and then offering the checks for sale.

That essentially is what causing and what caused this dramatic increase in check fraud here in the United States, which we are still seeing in 2026. So again, trying to figure out emerging trends and of course interventions. We’re trying to figure out the effectiveness of interventions out there.

Law enforcement is trying to take down specific darknet markets or specific text message applications. Will it really work in the context of reducing crime in that sense?

And so one of the findings we have focusing on dark-knit markets which offered for sale stolen identities was that when law enforcement takes down a market, it doesn’t necessarily disrupt the ecosystem.

Essentially what happened is that criminals simply move to another market, they become tighter over there. So in terms of the effectiveness of law enforcement operation there, the effectiveness of the intervention there, we find that it’s less effective, so to speak.

So that’s essentially what the evidence-based cybersecurity research group is all about. We try to understand the effectiveness of different interventions, different policies in reducing and mitigating cyber crime out there.

Steven Bowcut:

That is so fascinating to me. That just raises more questions in my mind. So when you’re doing this, so two questions I guess, and maybe I can combine them into and articulate a reasonable question here.

So first of all, how do you do this when you’re browling, if I can use that term around the dark net markets and the chat rooms and those kinds of things. So how do students in research study those spaces responsibly and safely?

And then it just raises the question in my mind, as you’re doing that, do you run across law enforcement and other researchers? Are you guys bumping into each other out there in all of these places?

And how do you deal with that when you think that’s going on?

David Maimon:

It’s a great question. As you know, as academics, we need to have IRB approvals for everything we do. The ethic committee review need to aprove all the studies we launch, and we definitely have approval for all the studies I mentioned earlier.

In terms of the infrastructure we have in Georgia State, Georgia State allows the group to have its own network, its own internet network, which then allows us to engage in this type of research that I just told you about.

Universities and companies don’t necessarily like you as a scholar or a researcher using their network in order to dive the dot. Yeah, I would think that.

Yeah. They don’t really like the fact that you use their network to deploy honeypots, attract hackers, and then allow the hackers to do what they want with the computers. But what’s so unique in Georgia State University is the fact that they allowed me to have my own standalone network.

It’s like a cold computer that they allow me to have and that allows me to engage in this research. So all the research I’m conducting on the darknet comes from that specific network, which is not sponsored by GSU. I mean, sponsored by sponsors out there who help us maintain the network.

We have standalone computers, which their own goal is to essentially perform those tasks I just mentioned, be on the darknet text message application, deploy honeypots, collect data from all those environments, allow hackers on the computers, allow them some leverage with the computers in order for them to perform whatever that they think they want to do, and then we essentially study them.

So in that sense, Georgia State really provided me with the infrastructure to engage in this research. Now with respect to student engagements, that’s a great questions because we have different types of students. We have undergraduate students and we have graduate students.

We also have folks who engage in their atempts to get some certificate program with us. And based on each of those students’ titles, we allow different types of freedoms on our network.

So undergraduate students will not be able to be on our network and simply monitor what happens on darknet. Not because I don’t trust them, it’s essentially a liability issue. Graduate students on the other hand are allowed to be on our computer, monitor the darknet, collect data from the darknet and text message application for us, of course, analyze it.

They’re not allowed to engage with people on those ecosystem. All professors are allowed to engage with individuals over those platforms. And so in that sense, we’re trying to contain the risk as low as we can. And so this is essentially the way we do things in Georgia State University and allow students with opportunities to be hands-on, so of speaking.

Steven Bowcut:

Yeah. Okay, excellent. All right, so let’s talk about some of the programs at Georgia State and maybe you could respond, but the different programs you have. Well, let’s list some of them here.

So you have a cybersecurity certificate, computer information systems, cybersecurity concentration, graduate security and privacy pathways. We’ve listed them a couple of times now, FinTech-related cybersecurity training.

So how do these academic options help prepare the students for different kinds of cybersecurity careers? Or what kind of careers are these different pathways built to provide? What kind of employment can someone expect to get from these various pathways?

David Maimon:

It really depends. It really depends on what students have in mind in terms of what they want to do in the context of their future academic career.

So if they want to build tools, if they want to be able to code and come up with new hardware, new software, which will allow defenders to do their work better, then computer science is definitely the school that they will need to go to because they will be able to acquire all the computer language, all the computer skills, which will allow them to put together those technologies.

If folks are more interested in understanding paths and trends and analyze cybersecurity relevant topics, then the school of business, the business school will be the right pick for them, the right choice for them because the data science programming in that school is top-notch.

Folks will be able to work with big databases, analyze them and acquire the skills which will allow them to then look at huge databases, try to come up with interesting trends that they’re seeing coming from attackers and then guide computer scientists with respect to how to build better tools, more effective solutions to defend against those attacks.

If folks are interested in policies and laws, the law school offer some interesting programs there as well, understanding the new laws, legislation around cybersecurity, the development of policies, the enforcement of policies both on the private sector as well as the government sector. companies,So that is another really interesting angle that you can take when you engage in cybersecurity studies.

And then of course you have what we do in the Department of Criminal Justice and Criminology at Georgia State University, which is more hands-on with respect to the human, with respect to some of the forensic tools that you’ll be able to gather use and guide your operation with, with respect to some of the threatened intelligence skills that you will be able to acquire.

We will equip students with those skills. We’ll try to make sure that they have hands-on experience with the ecosystem out there. So we’ll allow them to use real data.

We’ll ask them to collect real intelligence. We will ask them to use some of our sandboxes to experiment with some of the malicious software that we’re seeing out there.

But at the same time, we will ask them to try and test the effectiveness of some of the policies, some of the interventions that law enforcement as well as companies will engage in order to try and prevent and mitigate cyber crime.

So these are all paths that are available at Georgia State University, but depending on what you have in mind for your future, you will have to pick one and simply pursue it.

Steven Bowcut:

Interesting. And so just to make sure that I understand, so let’s take the law scenario. So it’s hard for me, and maybe I’m wrong here, but it’s hard for me to imagine a young student starting college and them coming up with the idea that they want to study cybersecurity, but specific to law.

It seems more likely that they want to study law and so when they get there to law school or their pre-law education, then they would know that there’s this concentration or a certificate that they can get, something like that.

So their primary path is law, but cybersecurity is kind of secondary to that. Is that the way it’s designed for some of these paths?

David Maimon:

It’s one way to go. I mean, it’s definitely one path. The other path will be someone who starts studying criminal justice and criminology.

And then we’ve seen a lot of that happen as well. So someone starting working with our group and they’re very much interested in understanding criminal’s behavior online. They spend a year or two working with a group and then they figure out that policies is what interests them.

And so then for their MA or the MS, they vert to the law school and they sort of focus on cybersecurity law on that. Same thing goes to individuals who are interested in computer science and data science coming from the computer science department or the business school.

When you’re an undergrad, you’re just exposed to all those ideas. The advantage of working with us is that you get exposure to all these databases and all those really interesting ideas that both we as well as other comes up with. And when you graduate, you can

Pick your path with respect to what it is that you want to do. Do you want to go and work for the industry? Do you want to go and work for the government? Do you want to pursue an academic career? And if you want to do all that, I mean, what will be that preferred route?

Do you want to do it as a technical person? Do you want to do it as a data scientist? Do you want to do it as a law professional? Paths are open all over simply because the opportunities are there in my mind.

Steven Bowcut:

Exactly. Okay. So it looks like we’ve got time for maybe a couple more questions and we always like to get some advice in here for the students if we can. And I’m really attracted to this idea of this interdisciplinary, how interdisciplinary cybersecurity is and how you’re addressing that head-on at Georgia State.

So what advice would you give students who want to build the skillset necessary for this interdisciplinary work? What do they need to be? If they’re just coming out of high school or they’re just in their first year or two of their undergraduate work, what do they need to be focused on to be prepared for that?

David Maimon:

Well, they need to be curious. That’s the most important thing. I think curiosity is key for a successful career in the context of cybersecurity in the cybersecurity field. You need to think outside of the box.

That’s another very important advice that I will give students, prospective students, potential graduate students, and professionals in our ecosystem. Think outside of the box because cyber criminals may be hackers, fraudsters, any cyber criminal out there, they constantly think outside of the box.

And if you want to be able to do good work in both prevention and mitigation, you need to think like them. And then critical thinking. I think folks needs to constantly think critically about whatever type of information they’re seeing.

I know that we’re in this day and age of us constantly consuming social media and maybe I hope that there’s some suspicion respect to the content that we’re seeing out there.

Critical thinking is extremely important in the context of cybersecurity because the anomalies that we think that should be obvious are not necessarily that obvious.

So we constantly need to challenge our thinking, constantly need to think about what we’re seeing with different lens. And for new folks who get into the cybersecurity ecosystem, I think they should definitely embrace that. So think outside of the box, critical thinking and be curious. These are the big threes for me.

Steven Bowcut:

I love that. Thank you. All right, one final question here. Oftentimes I know students, one of the things that they really want to give some weight to when they’re deciding which direction they want to go in their academic career is what is the need going to be on the other end?

So where do you see, I mean you’re in a unique position, so you can see a very broad picture across cybersecurity. So where do you see the greatest need for new cybersecurity talent? If everything else is equal, I love law, I love criminal justice, I love policy. Of all those things, all the pathways that they have to choose from are fairly equal. Do you see one where there’s a bigger need?

David Maimon:

I think with AI and the fact that we are seeing the implementation of AI in the context of cybersecurity field, there’s a need for folks who have skills in all four disciplines. I think that’s extremely important.

We know that writing code is becoming less and less necessary for companies out there because the AI tools quite quickly. I think in terms of gathering intelligence, the AI tools are less effective in that sense.

And so definitely focus on fraud intelligence, definitely focus on cybersecurity intelligence, be aware of policies. The evidence-based cybersecurity aproach is extremely important in that sense because that’s how you prove ROI.

And so someone who has all those skills in all those disciplines will be extremely attractive to the cybersecurity ecosystem. And the other important thing that I will add to that is someone who knows how to handle AI.

As we just mentioned, there’s a lot of push for using AI in the context of a cybersecurity ecosystem. You need to constantly experiment with the AI tools both as a defender as well as in the context of your operation as a red teamer.

Experiment with the AI tools, get as much exposure as possible to policies, to intervention, to tools. That is in my mind, what will make you extremely attractive to the industry once you graduate.

Steven Bowcut:

Great advice. Okay, thank you so much. Thank you for joining me today, Dr. Maimon. I really appreciate you giving our audience some of your time today.

David Maimon:

Thank you so much for having me, Steph. All

Steven Bowcut:

Right. And I appreciate you helping our listeners understand both the cybersecurity opportunities available at Georgia State University and this broader role of cybercrime research, evidence-based policy, all the things that we’ve talked about. This is wonderful.

For students listening, one of the important takeaways from today’s conversation is that cybersecurity is not a single narrow career path. It doesn’t need to be. And some students may be drawn to computer science or secure systems or network defense. Others may be more interested in information systems, business risk, FinTech, all the other things that we’ve talked about today.

And I really like the fact that Georgia State is a useful example of how all of those things can connect. And if you’re considering a future in cybersecurity, please take time to explore the different academic pathways available to you. Look at the degree programs, certificates, research groups, internships, faculty and expertise that align with your interests.

And remember that the field needs people who can think technically, analytically, ethically and creatively, think outside the box, be curious, and thank you for listening to the Cybersecurity Guide podcast. And we hope this episode will help you explore your education and career options in cybersecurity.

Primary Sidebar

Why readers trust Cybersecurity Guide

Community icon

500,000+ annual visitors rely on Cybersecurity Guide

Accountability icon

750+ cybersecurity degree programs reviewed

Communication icon

80+ expert contributors across academia and industry

Career icon

50+ free career, education, and planning guides

  • Online Programs
    • Master’s
    • Bachelor’s
    • Bootcamps & Certificates
Sponsored Ad
cybersecurityguide.org is an advertising-supported site. Clicking in this box will show you programs related to your search from schools that compensate us. This compensation does not influence our school rankings, resource guides, or other information published on this site.
  • CERTIFICATIONS
    • Azure
    • CASP+
    • CCNA
    • CEH
    • CISA
    • CISM
    • CISSP
    • CRISC
    • Cryptography
    • CTIA
    • CND
    • Forensics
    • Malware Analyst
    • OSCP
    • Pen Testing
    • Security+
  • CAREERS
    • Security Engineer
    • Chief Information Security Officer
    • Security Analyst
    • Computer Forensics
    • Security Consultant
    • Digital Forensics
    • Cryptographer
    • Security Administrator
    • Penetration Tester
    • Security Software Developer
    • Security Specialist
    • Security Code Auditor
    • Security Architect
    • Malware Analyst
    • Data Protection Officer
    • Cybercrime Investigator
    • Cryptanalyst
    • Security Incident Responder
    • Chief Privacy Officer
    • Risk Manager
    • Network Administrator
    • Business InfoSec Officer
    • Information Security Manager
    • Cyber Operations Specialist
  • RESOURCE CENTER
    • Women in Workforce Statistics
    • Centers for Academic Excellence
    • Job Guide
    • Veteran’s Guide
    • Women’s Guide
    • Internship Guide
    • Security Clearance Guide
    • Ethical Hacker Guide
    • Coding for Cybersecurity Guide
    • Cybersecurity 101
    • Student Guide to Internet Safety
    • Scholarship Guide
    • Cybersecurity Math Guide
    • Small Business Guide
    • Cybersecurity for K-12 Students
    • Career Networking Guide
    • What is a Cyber Range?
    • Code Like a Hacker
    • Reacting to a Cyber Incident
    • Introduction to Cyber Defense
    • Cybersecurity Courses Online
    • Recommended Reading
    • Phishing Attacks
    • Cybersecurity Responsibility
    • How to Get Into Cybersecurity
    • Cyberwarfare
    • Cybersecurity Insurance
    • Job Interview Prep
    • Readiness Economy
    • Is Cyber a Good Career?
    • What is CyberCorps?
    • DEI in Cyber
    • NIST and Small Business
    • Cybersecurity Without a Degree
    • Cybersecurity Skills Gap in AI
  • RESEARCH
    • AI and Cybersecurity
    • Holiday Hacks
    • Jobs Report
  • INDUSTRIES
    • Financial Sector
    • Insurance Sector
    • Healthcare Sector
    • Environmental Sector
    • Energy Sector
    • Government Sector
    • Transportation Sector
    • Food and Agriculture Sector
Cybersecurity Guide
  • Home
  • Campus Programs
  • About Us
  • Popular Careers
  • Online Programs
  • Terms of Use
  • Resources
  • Programs By State
  • Privacy Policy

Copyright © 2026 · Cybersecurity Guide · All Rights Reserved