
8th Annual OCRI Symposium: Advancing Cybersecurity Together
Join us for the 8th Annual OCRI Symposium. The event is an opportunity to engage with Ohio's leaders in cybersecurity education, workforce development, and economic development from military, government, industry, academia, in public and private sectors. The event is in person at the University of Cincinnati Digital Futures and 1819 Innovation Hub buildings. The event is free and advanced registration is required. Register today to secure your spot as they fill up quickly!
Event Details:
-
Date: Wednesday, October 7, 2026
-
Time: 9AM-4PM
-
Location: Digital Futures, University of Cincinnati
-
Address: 3080 Exploration Ave, Cincinnati, OH 45206
Keynote Speaker

Dr. Emily O. Goldman, Cyber Strategist, Department of War. Dr. Goldman combines national security experience and policy scholarship, gained and applied at the National Security Council, the Department of State, US Cyber Command, the National Security Agency, and the University of California, Davis. She has published and spoken on strategy, technology diffusion, and cyber operations, and has implemented the resulting concepts for more than two decades. recent publications include Cyber Persistence Theory: Redefining National Security in Cyberspace (Oxford University Press 2022) with Michael P. Fischerkeller and Richard J. Harknett; and “Why Analytic Superiority Matters Most in the AI Race” (The National Interest, 6 July 2026) with Robert L. Grossman
Breakout Session 1 (10:15 - 11:15 AM)


Role of Lawyers in Incident Response and Resiliency
Presented by Albert W. Klein, Jr. PhD. LLM, MS. JD, Associate Professor-Educator, School of Public and International Affairs University of Cincinnati; Kevin Mamula, Associate Director of Cyber Exercises and Technology, Ohio Cyber Range Institute
Room: Digital Futures 262
We will explore the role of the Legal Advisor during an Incident Response event with emphasis on the phases of the incident event and how the Legal Advisor can be helpful.

GenAI Use Patterns in Cybersecurity Credential Education
Presented by Nadia Ibrahim-Taney, Associate Professor, UC
Room: Digital Futures 145
As generative artificial intelligence becomes increasingly integrated into cybersecurity workplaces, educators are being challenged to better understand how students are actually using these tools during workforce preparation experiences, e.g. cooperative education. This session presents findings from a semester-long survey study conducted with cybersecurity and IT students enrolled in an industry-recognized credential course designed as an alternative experiential learning pathway to traditional cooperative education.
Channeling Technical Curiosity for Good: Help Youth Choose the Right Path
Presented by Kirsten Minnie, Cyber Operations Officer, Homeland Security Investigations; Julia Armstrong, Institute for Cybersecurity and Digital Trust Director at the Ohio State University
Room: Digital Futures 625
Cybercrime in the US and abroad is increasing at an exponential rate, and youth, as young as in grade school, are often tempted, lured and exploited into committing serious cybercrime. Learn about global efforts by international law enforcement agencies to stop this and how educators are effective partners.



Security-First, AI-Assisted: Integrating SSDLC into Agile Development Courses
Presented by Phu Phung, PhD, Professor of Computer Science, University of Dayton; Marc Cahay, PhD, Professor and Electrical and Computer Engineering Department Head, and Ohio Cyber Range Institute Co-Director, University of Cincinnati
Room: Digital Futures 231C
As software systems grow more complex and AI-powered coding becomes standard industry practice, educators face a dual challenge: teaching students to build secure software and to use AI tools responsibly. This presentation introduces replicable pedagogical modules to integrate the Secure Software Development Lifecycle (SSDLC) and Generative AI into programming courses. Each developed module is self-contained and aligned with hands-on exercises and a teamwork project, making it adaptable to a range of programming and software engineering courses beyond its original course context. Security is treated as a cross-cutting concern embedded throughout the software process lifecycle — from system analysis and design, through threat modeling and security requirements, to implementation and cloud deployment with DevOps. GenAI tools are introduced deliberately after students have internalized secure coding practices, so they evaluate AI-generated code through a security lens rather than accepting it uncritically.

Varieties of International Cyber Strategies (VoICS) Dataset and its Importance to Understanding Cyber Persistence Engagement (CPE)
Presented by Ivan Dinev Ivanov, School of Public and International Affairs; Co-Presenter: Shifan Rashid, UC
Room: Digital Futures 150
We introduce an expanded version of the Varieties of International Cyber Strategies (VoICS) dataset that includes all states on the world stage. Additionally, the latest version of the VoICS dataset expands cybersecurity documents’ scope to include not only national cybersecurity strategies but also sectoral strategic documents, such as cyber defense strategies and international cyber engagement strategies. The expanded dataset enables a reassessment of whether states are converging towards the logic of cyber persistent engagement (CPE) while exploring important sources of variation in the diffusion of this strategic concept. Specifically, the presentation examines four questions. First, are national cybersecurity strategies of states across the globe increasingly aligned with CPE’s strategic ideas? Second, do more specialized sectoral cyber strategies adopt CPE earlier and more extensively than national cybersecurity strategies adopted by the national governments? Third, does early adoption of CPE in sectoral documents facilitate or predict subsequent incorporation of CPE into broader national strategies? Finally, our presentation investigates whether institutional design influences strategic adaptation. It discusses whether CPE is being adopted faster and earlier by states whose competent national cybersecurity authority is an independent government agency.

Student Workforce Development in Local Governments
Panel Discussion: Moderated by Cassie Barlow, PhD, SOCHE
Room: 1819 Building, Room 230
This panel will focus on student and Local Government Entity experiences while participating in the Ohio Persistent Cybersecurity Clinic Internship Program. Students will talk about how they became involved in the PCCIP and what sparked their interest in the program. In addition students will discuss their lessons learned throughout the program to include what they learned from the OCRI training as well as through their interactions with the Local Governments. The students will also discuss what they learned about Local Governments and their requirements to meet specific Cybersecurity standards. In addition, students will discuss the employability skills that they learned throughout this internship. Local Governments will discuss the benefits derived from working with College students while they built their cybersecurity programming. Audience members will have the opportunity to ask questions of the students and Local Governments .
Breakout Session 2 (12:30 - 1:30 PM)

Crash Dummies For Cyberspace: Agentic Simulation To Generate Checklists Before Real Attackers
Presented by Amir Asadi, PhD Candidate, University of Cincinnati
Room: Digital Futures 625
How do you test a system against unpredictable human behaviors without hiring thousands of human testers? This presentation introduces a behavioral testbed utilizing large language models as interactive crash dummies for personified privacy and security testing. By drawing from 128 distinct personas, including regular users, threat actors, and security practitioners, our platform creates a digital twin that brings opportunities for proactive vulnerability identification. We simulate human behavioral patterns, rigorously testing against complex social dynamics, trust relationships, and adversarial manipulation tactics. This strategy helps uncover flaws in system interaction flows before real attackers can successfully exploit them. This extensive automated scale enables continuous testing across a remarkably broad spectrum of user behaviors. Ultimately, the system generates highly actionable scenario checklists and comprehensive analysis reports detailing specific ratings of vulnerabilities. Join us today to learn exactly how deploying these simulated personas can directly inform your security audits and significantly elevate enterprise defenses against threats.
Cybersecurity Education in the Age of AI
Presented by Seth Hammond, PhD, Director, Center for the Advancement of Cybersecurity, Professor of Cyber Operations and Computer Science
Room: Digital Futures 231C
This session will rely heavily on audience participation as we discuss together the challenges and opportunities of teaching cybersecurity in the age of AI. We will discuss the benefits of traditional education as well as ideas for incorporating AI into cyber curriculum. We will also look at some of the freely available resources for teaching cybersecurity from OCRI and CLARK.

Threat Models For Embedded Devices with MITRE EMB3D
Presented by Adam Hahn, Principal Engineer, MITRE Corporation
Room: Digital Futures 145
As embedded devices evolve, product developers must continuously account for emerging threats and identify effective mitigations throughout the device lifecycle. They must also communicate clearly to asset owners and operators whether products incorporate the security capabilities needed to address those threats. This talk introduces MITRE EMB3D™, a threat model and mitigation framework developed specifically for embedded devices. EMB3D provides a common foundation for device vendors, asset owners and operators, test organizations, and security researchers to identify relevant threats, evaluate mitigations, and improve communication about embedded device security capabilities.

The Abysmal State of Software Security - And What to Do About It.
Presented by Dave Hatter, Consultant, Intrust IT
Room: Digital Futures 150
From the SolarWinds breach to hospitals and automotive giants shutdown, software supply chain attacks are causing billions in damage and increasingly threatening our national security. Meanwhile, the software we depend on is increasingly assembled from “vibe coding” and/or third-party and open-source components that organizations often can't even inventory, much less secure. Some would argue that most software is now garbage, focused on speed to market, data collection, market share, ease of use, and profit rather than security, resilience, and privacy.
But this isn't all a doom-and-gloom talk we'll demystify Software Bills of Materials (SBOMs). What they are, why Executive Order 14028 now requires them for government software vendors, and how they serve as a foundation for vulnerability management, license compliance, and zero-trust architecture. Attendees will learn the about SBOMs, explore Software Composition Analysis (SCA) tools, and understand how Vulnerability Exploitability eXchange (VEX) helps separate real risk from noise. The session closes with a call to action around CISA's Secure by Design principles and practical steps every organization can take today.

CyberOhio: Advancing a Whole of State Cybersecurity Model
Presented by Lexie Meade, CyberOhio Administrator
Room: Digital Futures 262
CyberOhio leads Ohio’s unified cybersecurity strategy by coordinating state agencies, local governments, critical infrastructure, and education partners under a whole‑of‑state model. This presentation outlines how Ohio built a scalable, collaborative cybersecurity ecosystem rooted in shared priorities and statewide operational support.
Central to this approach is the State of Ohio Comprehensive Cybersecurity Plan, which sets strategic goals for risk management, capability maturity, information sharing, and incident response. CyberOhio advances these goals through cross‑agency alignment and programs supporting organizations of all sizes.
A core element is the Ohio Persistent Cyber Improvement (O‑PCI) program, offering free assessments, training, and exercises for local governments, along with grant funding for MFA, secure email, endpoint protection, and .gov adoption. The presentation also covers the role of the Ohio Cyber Integration Center (OCIC) in threat intelligence and incident coordination, and the work of the volunteer Ohio Cyber Reserve. Attendees will learn practical lessons from Ohio’s collaborative model to strengthen statewide readiness and resilience.

Talent Development in the Age of AI
Panel Discussion: Moderators: Ravi Katyal, Manager, Emerging Tech and Dionte Grinstead, Security Analyst, Cintas Corporation, and Director of Student Engagement, Greater Cincinnati ISSA.
Room: Digital Futures 140
This panel explores how talent development is being redefined in the age of AI with a focus on cybersecurity & AI. The conversation brings together leaders and practitioners from industry and academia around a shared reality. We are preparing people for roles that are no longer centered on doing work but on thinking through it. As AI takes on more execution, the human role is shifting toward judgment, evaluation, and end to end ownership. Yet most training models still emphasize tools and tasks instead of decision making and context awareness. This creates a growing gap between how talent is developed and how work is actually evolving.
The panel will examine where current approaches are falling short. These include siloed training, lack of exposure across domains, limited focus on reviewing AI generated output, and the absence of safe environments where people can experiment and learn. In cybersecurity, where risk and trust are critical, these gaps become even more visible.
The discussion will also explore how organizations are thinking about workforce readiness across two tracks. One focused on productivity and efficiency. Another focused-on product thinking, governance, and responsible use. Both require different mindsets and development approaches.
An interactive segment will present real world cyber scenarios involving AI assisted decision making. Participants will reflect on not just what they would do, but how they would think, evaluate, and respond under uncertainty.
The goal is to move beyond technical skills and focus on developing professionals who can navigate complexity, risk, and responsibility in an AI driven environment.
Table Top Exercise Plus (TTX+) for Ohio Persistent Cyber Improvement Project
Presented by: Megan Hopperton, Assistant Director Cyber Exercise, Ohio Cyber Range Institute, Unversity of Cincinnati.
Room: 1819 Building Room 230
As a part of the OCRI's Ohio Persistent Cyber Improvement project, the OCRI develops and conducts a whole of organization TTX+. The plus is the inclusion of simulated network and systems in the Ohio Cyber Range to compliment the real world scenario in the tabletop exercise. This session will give an overview of this process and working with local governments to train them not only in the exercise, but to run future exercises to keep improving their cyber posture.
Breakout Session 3 (2:00 - 3:00 PM)
Trustworthy and Certifiable AI for Explainable Detection and Safe Automation at Airports
Presented by Kelly Cohen, Ph.D. Brian H. Rowe Endowed Chair in Aerospace Engineering, University of Cincinnati; Director, AI Bio Lab, UC Digital Futures; Past President, North American Fuzzy Information Processing Society (NAFIPS)
Room: Digital Futures 150
Airports are prime targets for cyberattacks, and a single missed intrusion can cascade into operational disruption or safety compromise. Yet most AI-based detection tools are black boxes by being powerful but impossible to audit, certify, or fully trust in safety-critical environments.
In this session, Dr. Kelly Cohen presents a breakthrough approach: a fuzzy logic-based AI system that achieves near-perfect anomaly detection which includes zero false negatives on realistic kernel-level attack data, while remaining fully interpretable and verifiable. Attendees will learn why explainability is a structural requirement for aviation cybersecurity, how formal verification enables a genuine path to certification, and why human trust is the last mile of AI deployment in Security Operations Centers.
Drawing on three decades of trustworthy AI research and ongoing collaboration with airport operations, this talk offers a practical roadmap for deploying AI that security teams can understand, verify, and rely on.

Artificial Intelligence: Organizing AI Knowledge for Cybersecurity Education
Presented by Daniel Schaupner, Associate Director for Cyber Library;
Dr. Gloria Yeomans-Maldonado, Assistant Director for Cyber Library
Room: Digital Futures 231C
Artificial intelligence presents a useful case study in cybersecurity knowledge organization. AI terminology continues to evolve across academic institutions, government organizations, industry leaders, and specialized vendors. Terms such as Large Language Models (LLMs), Reasoning Models, Agents, Agentic Workflows, Copilots, Large Multimodal Models (LMMs), and Autonomous Agents often vary in definition and scope.


Cybersecurity for All: Layering Cybersecurity Learning Across the University
Presented by Julia Armstrong, Executive Director, Institute for Cybersecurity and Digital Trust, The Ohio State University
Room: Digital Futures 145
As cybersecurity becomes foundational across all sectors, institutions must move beyond discipline-specific training to reach the full student population. This session presents three complementary, scalable approaches developed at The Ohio State University that expand cybersecurity education from broad access to more targeted integration beyond the cyber-focused students to impart education and importance of cybersecurity in all careers.
The presentation highlights: (1) a General Education cybersecurity course designed for students of any major, building foundational cyber literacy while counting toward graduation requirements and offering potential for dual-enrollment programs; (2) a large-scale National Security Simulation that engages students from law, journalism, policy, and other non-technical fields in complex, cyber-enabled crisis scenarios; and (3) the integration of Cyber-Informed Engineering (CIE) concepts —developed by Idaho National Laboratory—into engineering and system design education.
Together, these efforts represent a layered strategy: reaching all students at a broad level, engaging diverse disciplines through experiential learning, and embedding cybersecurity deeply within technical design contexts. This approach helps institutions prepare a more cyber-aware and resilient workforce without requiring all students to become technical specialists. Attendees will gain adaptable ideas for expanding cybersecurity education across their own campuses. A portion of the session will be reserved for audience to share additional ideas and discussing future possibilities.

Cultivating Inquiry in the Age of AI
Panel Discussion: Moderator: John Wiseman, Ohio Department of Education and Workforce
Room: Digital Futures 140
As AI continues to shape a new era of teaching and learning, fostering a culture of inquiry is more essential than ever. This session explores how educators can integrate AI to enhance reading, writing, thinking, and speaking skills while also strengthening awareness of cyber security in an increasingly digital world. Participants will examine strategies to deepen disciplinary and information literacy competencies, empowering students to ask critical questions, analyze data and sources, evaluate digital safety considerations, and develop evidence-based conclusions.
Through real world examples, the session will highlight how AI can enhance civic engagement, promote responsible and secure technology use, and deepen understanding across disciplines. Educators will also consider how digital hygiene, privacy conscious practices, and cyber aware decision-making can support safe and effective classroom AI integration. Discover how thoughtful integration of AI and attention to cyber security can elevate inquiry-driven learning and prepare students for a rapidly evolving world.
Cyber Resilience for Ohio Water Infrastructure
Presented by Taiwo Akinremi, School of Information Technology, University of Cincinnati
Room: Digital Futures 262
Water and wastewater systems are among the most critical components of Ohio's infrastructure, yet many existing cybersecurity assessments focus primarily on known attack scenarios and component-level vulnerabilities. This presentation introduces a framework for evaluating cyber resilience in water and wastewater treatment systems by identifying structural weaknesses that may enable operational disruption, service degradation, or unsafe system states.
Using representative water infrastructure architectures, this breakout session will facilitate discussion on how cyber compromises can propagate through interconnected operational systems. Participants will explore approaches for identifying structural vulnerabilities, assessing resilience, and implementing proactive cybersecurity measures. The session will highlight how utilities, local governments, and critical infrastructure operators can prioritize resilience investments, improve monitoring capabilities, and strengthen operational safeguards before incidents occur.
This session directly supports Ohio's Comprehensive Cybersecurity Plan by presenting a scalable methodology for assessing and enhancing the resilience of critical infrastructure. The approach provides practical guidance for local governments, water utilities, cybersecurity professionals, and policymakers seeking cost-effective strategies to strengthen cyber defenses, improve operational continuity, and support statewide efforts to protect essential public services.
When Consent Fails: Privacy Nudges as Security Risk
Presented by Lily Botsyoe, PhD Candidate, School of Information Technology, University of Cincinnati
Co-Presenters: Joshua Berkoh, PhD Candidate, University of Cincinnati,
Jess Kropcznski, PhD, Professor, School of Information Technology, University of Cincinnati
Thomas Synaepa-Addisson, PhD Candidate, University of Cincinnati
Renkai Ma, PhD, Assistant Professor, School of Information Technology, University of Cincinnati
Room: Digital Futures 625
When users don't understand what they're consenting to, they become easier targets — for social engineering, data harvesting, and downstream exploitation that starts with information they never meant to share. Privacy nudges (consent banners, settings toggles, permission prompts) are the front line of this risk, yet most platforms get them only partly right. This session introduces the Privacy Nudge Evaluation Framework (PNEF), an eight-criterion instrument grounded in situational awareness theory and built from GDPR/CCPA requirements, persuasive design principles, and usability heuristics — giving security professionals a concrete way to assess whether an interface actually equips users to make safe decisions, or just checks a compliance box.
Drawing on a benchmarking study of 14 major platforms, the session reveals a consistent failure pattern: interfaces are good at confirming user actions and using clear language, but weak at helping users grasp the long-term consequences of their choices and at being transparent about what's actually happening with their data. These are exactly the gaps that quiet, low-friction social engineering and data exploitation exploit — users who don't understand consequences make decisions attackers can leverage later.
Attendees will leave with a practical lens they can apply immediately: a working knowledge of the eight PNEF criteria, hands-on practice scoring real consent interfaces in small groups, and a discussion of where their own organization's products, vendor tools, or training materials might be creating this kind of user-side risk exposure. The session is designed for cybersecurity professionals, risk and compliance teams, security educators, and policy-minded technologists who want a concrete, teachable framework for treating informed consent as a security competency, not just a legal one.
Poster Session (Digital Futures Lobby - 9am-4pm)
-
AI-Augmented Ethical Hacking and Penetration Testing Course, Author: M. Ajmal Khan, Ohio Northern University
-
From Blind Spots to Board Insight: The Johari Window for Enterprise Cybersecurity, Author: Michael Gomez, Sinumbra.org
-
AI-Driven Cybersecurity Education: A Multi-Agent Red-Team/Blue-Team Cyber Range with Judge-Agent Evaluation, Author: Weibing Zheng, School of Information Technology. Co-Author: Shane Halse, PhD, Associate Professor, School of Information Technology, University of Cincinnati.
Past Events
.png)
Symposiums
Symposiums
-
Inaugural Cybersecurity Education Symposium
-
Second Annual Cybersecurity Education Symposium
-
Third Annual Cybersecurity Education Symposium
-
Fourth Annual Cybersecurity Education Symposium
-
Fifth Annual Cybersecurity Education Symposium
-
Sixth Annual Cybersecurity Education Symposium
-
Seventh Annual Cybersecurity Education Symposium
.png)
Workshops
Workshops
-
Ohio Persistent Cyber Improvement (O-PCI) Webinar
-
Ohio CyberEd Workshop - March 2023 at Cedarville University
.png)
Bootcamps/
Cyber
Exercises
Bootcamps/Cyber Exercises
-
Workforce development bootcamp courses
-
Workforce development cyber exercises