Studying how hands-on environments actually teach people to defend systems.
My research focus is instructional design for cybersecurity: how labs, ranges, and courseware build defensive skill that holds up outside the exercise, and how to tell the difference between a learner who finished and a learner who learned.
How should a hands-on security environment be designed so that skill transfers out of it, and what evidence tells you whether the transfer happened?
Designing for Transfer
A lab that only works when the inputs are clean teaches the exercise rather than the skill. Current work looks at how authentic conditions, incomplete evidence, ambiguous scope, and systems that resist the obvious first move, change what a learner is able to do afterward in an environment they have never seen.
Scaffolding and Cognitive Load
Hands-on security asks a beginner to hold tooling, syntax, network context, and adversary reasoning at the same time. The question is which of those to carry for the learner early on, when to hand each one back, and where a removed scaffold quietly turns an exercise into guesswork instead of practice.
Evidence Beyond the Flag
A captured flag records an outcome, not a method, and two learners can reach the same string by very different paths. Work here looks at what a range can legitimately observe about process, and which of those signals actually support a claim that an environment taught something.
[~] Instrumenting ranges to find where learners actually stall
[ ] Empirical study and formal publication (planned)