EMPLOYER GUIDE

Scope a cybersecurity student project safely

A student security project needs a narrower brief than a slogan such as “find vulnerabilities”. Define the authority, targets, methods, evidence, and escalation route before the work begins.

Write the authorisation down

Name the system owner, the target, the time window, the allowed methods, and the actions that require a separate decision. Treat credentials, data, and third-party systems as explicit scope questions.

\n

If the project changes, update the authorisation before the student proceeds. A supervisor should be reachable while the work is active.

\n
  • Owner and accountable supervisor.
  • In-scope hosts, applications, accounts, and environments.
  • Out-of-scope systems, data, and techniques.
  • Stop conditions and an escalation contact.

Plan evidence and disclosure

Agree what evidence is necessary to demonstrate the finding and how it will be stored. Prefer the minimum evidence needed, protect personal or confidential data, and define who receives the report.

\n

Do not ask a student to publish a finding or share it outside the agreed route. Review the project with the school when assessment requirements affect the handling plan.

\n
  • Use test data and least-privilege access where possible.
  • Set a reporting format and response owner.
  • Close access and archive or delete project data when agreed.

NEXT STEP

Keep moving with DIVD.Works.

Submit or discuss a project

This guide is general information, not a promise of eligibility, placement, employment, or a specific outcome. Confirm the details for your programme, organisation, and opportunity directly.