Summary

  • Baldwin Wallace identifies Kenneth Atchinson as an associate professor, cybersecurity-program lead and coach whose CyberSec team reached the national CCDC in 2019.
  • The team's 2023 DOE CyberForce result shows how simulated energy-infrastructure operations can connect network administration, defensive work, service continuity and communication.

Kenneth Atchinson's public record is not primarily a story about a single research paper, product or company. It is a record of teaching systems work: networks that have to remain available, students who have to divide responsibilities, and simulated organizations that continue to demand service while defenders investigate and respond to attacks. Baldwin Wallace University identifies Atchinson as an associate professor, the lead of its cybersecurity analyst program and the coach of its CyberSec team.

University reports then show that team moving through two different national competition environments: the Collegiate Cyber Defense Competition and the U.S. Department of Energy's CyberForce program.

Those competitions matter because they make cybersecurity operational. A classroom can explain network architecture, operating systems, access controls, vulnerabilities and incident response. A timed exercise asks students to combine those subjects while users, judges, administrators and an adversarial team create competing demands. The objective is not simply to identify a flaw or capture a token. Students must preserve services, understand a changing environment, document decisions and communicate under pressure.

In the 2023 CyberForce scenario described by Baldwin Wallace, that environment represented a company coordinating distributed energy resources. The systems included industrial-control technology alongside Linux, Windows and Active Directory.

The scenario was simulated. The students were not operating a real power grid, defending actual customers or responding to a documented compromise. That boundary is essential. It prevents a workforce-development exercise from being mistaken for evidence of real infrastructure authority or security outcomes. At the same time, the simulation was designed around a genuine educational problem: people preparing to defend critical infrastructure need opportunities to practice how information technology, operational technology, service continuity and organizational communication interact.

Atchinson's significance in that record is therefore best understood through continuity. An institutional curriculum vitae traces his background from electrical engineering and computer science into software, Unix administration, network consulting and campus network management before and alongside academic work. Baldwin Wallace's later pages place him at the center of a cybersecurity program that combines technical foundations with internships, teamwork and network-security competitions. The competition reports show the program's ideas being exercised in public, scored settings.

Together, the sources describe an educator whose subject is not security in isolation, but security as part of running a system.

From Engineering and Networks to the Classroom

The institutional curriculum vitae published by Baldwin Wallace names him Kenneth Lee Atchinson and records two degrees that help explain the breadth of his later teaching: a bachelor's degree in electrical engineering from the Georgia Institute of Technology in 1987 and a master's degree in computer science from Kent State University in 1989. The document is a dated institutional record rather than a real-time employment database, so its open-ended dates do not independently verify every current role. Its chronology is still useful for understanding the technical path that preceded the competition work.

According to that CV, Atchinson worked in software development and Unix system administration at Harris Corporation's Space Systems Division from 1989 to 1992. It next lists Unix workstation administration at NASA Lewis Research Center through a contractor from 1992 to 1994, followed by Unix and network consulting at Realogic in 1994 and 1995. The document then records a Baldwin Wallace campus network-management role beginning in 1995 and academic work at the university beginning in 1999.

The sequence crosses several boundaries that later appear inside cyber-defense exercises. Electrical engineering supplies a way to think about physical systems, interfaces and constraints. Computer science brings software, architecture and abstraction. System administration focuses on the health and behavior of deployed machines. Network management deals with shared infrastructure, reachability and service dependencies. Consulting adds the need to interpret another organization's requirements. Teaching requires all of those ideas to become understandable, repeatable and assessable for students.

No public source proves that this sequence alone caused Atchinson to adopt competition-based teaching. The record does show why the approach fits his background. Cyber-defense competitions are difficult to coach from a purely theoretical perspective because their problems are operational. A defender may need to understand how a service is supposed to function before deciding whether unusual behavior is malicious, accidental or the consequence of a rushed configuration change. A team may need to patch one component without disrupting another. Technical correctness has to coexist with availability and documentation.

The current Baldwin Wallace faculty profile lists Atchinson's areas of interest as networks, web programming and architecture. Those subjects form a practical triangle. Networks carry the traffic. Applications create the services and exposure. Architecture determines how components relate and where boundaries can be enforced. A competition environment makes the triangle visible because a weakness or failure in one layer changes the work required in the others.

Building an Experiential Cybersecurity Program

Baldwin Wallace's cybersecurity analyst major describes a curriculum that moves from computing foundations into network design, administration, scripting, security, ethics, teamwork and communication. The page presents experiential learning as a core part of the program rather than a decorative extra. It identifies internships, security conferences and network-security competitions as ways students apply classroom knowledge.

That institutional design matters because the competition team is not isolated from the curriculum around it. A student who enters a defense exercise needs more than a collection of security tools. The program outcomes published by Baldwin Wallace include the ability to design and build local-area networks, administer networks, understand security issues in network design and defend system integrity. They also include written and oral communication, organization and collaboration. Those are precisely the capabilities that become interdependent in an operations-style event.

Atchinson's role sits at the point where the curriculum and the competition meet. The faculty page calls him lead of the cybersecurity analyst program and coach of the CyberSec team. A 2020 Baldwin Wallace report also associated him with the program, mentoring and team coaching when the university announced that he had received an IT Educator of the Year award at a Greater Cleveland technology event. The award is an institutional claim reported by the university, not an independent ranking of every educator. It nevertheless records how Baldwin Wallace presented his contribution: teaching, program leadership and sustained student support.

Experiential learning can be described too casually. The phrase sometimes means only that students perform a lab whose answer is already known. A cyber-defense competition is different because the environment changes while the exercise runs. Teams receive requests. Services fail. Adversarial activity creates uncertainty. Judges score technical work and professional response. The students cannot solve each task in a clean sequence because the tasks compete for time and attention.

Atchinson's systems background is relevant because network and system administration are disciplines of tradeoffs. An administrator has to decide what to observe, what to change, what to leave stable and how to recover when a change has an unexpected effect. A coach preparing students for a competition has to create similar habits without pretending that a simulated environment is identical to production.

The program page also makes a useful distinction between technical and organizational preparation. It lists programming, network administration and security, but it also requires teamwork and communication. In a scored exercise, defenders may understand the correct technical action yet lose points or create confusion if they cannot explain it. They may protect one system while neglecting a business request. They may solve a problem individually but fail to share information with teammates. The educational value lies in making those dependencies hard to ignore.

The CyberSec Team and the 2009 Starting Point

Baldwin Wallace reported in 2019 that Atchinson started the university's CyberSec team in 2009 to give students experience beyond what a classroom alone could provide. The date establishes a long horizon. By the time the team reached the national Collegiate Cyber Defense Competition in 2019, the program had been developing through repeated seasons rather than appearing for a single event.

A competition team is not simply a class section with a scoreboard. Membership, preparation time and role assignment can differ from ordinary coursework. Students may return across multiple years and transfer knowledge to newer entities. Coaches can compare how different groups respond to similar pressure. Baldwin Wallace has not publicly documented the exact preparation schedule, internal lab design or selection process, leaving those details unknown. The decade between the reported start and the 2019 milestone does show sustained institutional commitment.

The name CyberSec also signals a team identity. That identity can help students treat preparation as a collective practice. In defensive work, shared habits matter: documenting changes, preserving evidence, confirming assumptions and communicating ownership of a task. A team that meets over time can rehearse those habits repeatedly. The value is not that a competition perfectly predicts workplace performance. It is that the exercise makes coordination observable.

Atchinson described the classroom as providing only part of what a student needs, according to the university's 2019 account. The report connected extracurricular events such as CCDC and the National Cyber League to challenges that augment course skills. Classroom teaching and competition do different work rather than substituting for one another. Courses can build structured knowledge and give students time to understand principles. Competitions force that knowledge into situations where timing, uncertainty and team behavior matter.

The distinction helps explain why the team remained relevant as the technology changed. A course may teach the architecture of operating systems or networks in a deliberate sequence. A competition can place familiar and unfamiliar components in one environment and require students to establish priorities. Even when specific products change, the operational questions remain: Which services are critical? What is normal? Which accounts and paths require attention? How can a change be tested? What evidence supports the team's conclusion?

By 2019, the CyberSec team had a result that made its development visible outside the program. It won the Midwest regional CCDC qualifier and reached the national event for the first time. That finish was a competition result, not a certification of a real network. Its educational value lies in what the team had to practice to earn it.

The 2019 CCDC Milestone

The Baldwin Wallace report on the 2019 Midwest regional CCDC says the university finished first in the regional event and became one of ten teams advancing to the national competition. Seventy teams from two-year and four-year institutions competed in the Midwest qualification process, according to the university. Baldwin Wallace entered the regional field through a wildcard qualification and then won.

Atchinson attributed the result to a team that worked well across technical ability, communication and other professional skills. That explanation is more revealing than the rank alone. It presents cyber defense as a coordination problem. A team can contain strong individual technicians and still struggle if members duplicate work, fail to communicate risk or make changes without understanding dependencies.

The CCDC environment described by Baldwin Wallace represented a mock production business. Students defended and maintained its infrastructure while an adversarial team attempted to compromise systems. Judges also introduced operational requests and upgrade tasks. The defenders were therefore responsible for more than blocking attacks. They had to keep a fictional organization functioning and respond to its needs.

That model changes how security decisions are evaluated. Shutting down every service might reduce exposure, but it would also prevent the business from operating. Applying every update immediately might appear responsible, but an untested change can disrupt a dependency. Focusing only on an attacker may leave ordinary administration undone. The exercise rewards defenders who understand the system as a service environment rather than a collection of targets.

The current National Collegiate Cyber Defense Competition site continues to frame its live-fire challenges around teamwork, infrastructure hardening and incident response. Those objectives support a general analysis of the competition model. They do not add Kenneth-specific results beyond what Baldwin Wallace reported, and they do not prove how every CCDC season is configured. They show why the 2019 achievement fits the broader record: the team was being evaluated on operating and protecting infrastructure under coordinated pressure.

The national qualification was also a milestone in the team's own chronology. Baldwin Wallace called it the university's first appearance at the national event. A first qualification after years of participation can be meaningful to a program because it creates a reference point for later teams. It shows that the preparation process produced a result against a broad field. It does not establish that the same students, methods or technologies remained unchanged afterward.

The 2019 record also reveals the limits of rank as an educational measure. First place identifies competitive performance during the event. It does not show which lessons each student retained, how they later applied those lessons or whether the team would perform the same way in a different scenario. The achievement is clear, while the deeper educational value lies in the practice behind it: systems knowledge, role coordination and communication.

Operations Rather Than a Simple Capture-the-Flag Exercise

Many cybersecurity competitions emphasize finding vulnerabilities, solving puzzles or capturing digital flags. Those formats can test valuable skills, but an operations-style defense exercise asks a different question: Can a team keep an organization working while the environment is being contested?

CCDC makes that question concrete through business services and administrative demands. A fictional user or manager can ask for a change while defenders are investigating suspicious activity. Teams may need to preserve access for legitimate users, repair a configuration and explain what happened. The system's purpose remains relevant throughout the security response.

This model is especially useful for students because it exposes the cost of local optimization. A technically elegant response in one area may create a failure elsewhere. Tightening access controls without understanding application dependencies can break a service. Rebuilding a machine without preserving evidence can make incident analysis harder. Dividing the network into stronger boundaries can help defense, but doing so hastily can disrupt legitimate traffic.

No complete scoring record for Baldwin Wallace's 2019 run is available in the reviewed sources. The larger educational principle follows from the event description. Defenders were judged while operating, maintaining and securing a corporate-style network. That is a more integrated responsibility than demonstrating one exploit or answering a fixed quiz.

Atchinson's coaching role can be read through that principle. A coach cannot make decisions for students during every live event. Preparation has to establish ways of thinking that remain useful when the scenario changes. Students need to form a picture of the environment, choose priorities, test changes and share information. They also need to recognize when they lack evidence.

That final skill is important. Cybersecurity work is vulnerable to overconfidence because unusual behavior can have several causes. A service failure may be malicious, accidental or self-inflicted. A new account may be unauthorized or part of a legitimate request. Competition pressure encourages quick action, but sound operations require disciplined uncertainty. The exercise can make that tension visible in a way that a static lab often cannot.

Communication is not separate from the technical work. It determines whether the team's picture of the system is coherent. If one student finds a compromised account but does not tell the teammate managing authentication, the evidence remains isolated. If a team completes a change but cannot document it for judges or fictional management, the operational value is reduced. The 2019 account's emphasis on technical and communication performance therefore points to one educational system, not two unrelated skill lists.

Moving From Corporate Networks to Energy-Sector Scenarios

The CyberForce program extended the operational model into a different context. The Department of Energy's CyberForce site describes the program as a cybersecurity workforce-development initiative. Its original competition, launched in 2016, uses a defend-and-attack cyber-physical scenario. The program also offers resources that connect cybersecurity, operational technology and the energy sector.

Cyber-physical scenarios introduce consequences and dependencies that differ from a conventional office network. Information systems still matter, but they exist alongside representations of physical processes and operational equipment. Availability, timing and safe state can become as important as confidentiality. A defender needs to understand not only whether a machine is compromised, but what function the machine supports.

This does not mean students are entrusted with real critical infrastructure. CyberForce uses a controlled scenario. The purpose is educational: to make the relationship between digital systems and physical operations concrete without placing real services at risk. Describing the environment as simulated is not a minor disclaimer. It is the difference between a training record and a claim of operational authority.

Baldwin Wallace reported that it began participating in CyberForce in 2018. The university listed an eighth-place national finish in 2019, an eleventh-place result in 2022 and sixth place in 2023. Those figures come from the university's own account. The DOE's official 2023 event page independently lists Baldwin Wallace among the competing schools and names the top three finishers, but it does not independently publish BW's sixth-place rank on the page reviewed here.

That evidence boundary is straightforward. Baldwin Wallace supports the detailed team result and Atchinson's role. DOE independently confirms the university's participation and the competition framework. Combining the sources is stronger than treating either as proof of everything. It also keeps the rank in proportion to the article. Sixth among a large field is a notable result, but the more important evidence is what the scenario required students to integrate.

CyberForce's energy focus gave the team a reason to think beyond enterprise information technology. An energy environment can include control systems, specialized protocols, field devices and operational objectives that do not map neatly onto office applications. Even when represented in a lab, those components force defenders to ask what a system does before deciding how to protect it.

This is where Atchinson's network and architecture interests become especially relevant. A cyber-physical environment is defined by connections among layers. Authentication, directory services and servers may sit beside industrial-control components. A network boundary may separate some functions but not others. Monitoring has to distinguish routine process behavior from malicious activity. The competition turns architecture into a lived problem for the team.

The 2023 Distributed-Energy Scenario

The Baldwin Wallace account of the 2023 CyberForce competition provides the most detailed public example of Atchinson's competition coaching. The university reported that the BW CyberSec team finished sixth among 95 teams from 75 colleges and universities. It identified Atchinson as professor and coach and described the November event in St. Charles, Illinois.

The fictional organization in the scenario managed communication between local solar-energy customers and an energy-generating plant, according to Atchinson's explanation in the university article. Students had to maintain service while defending and patching systems under attack from competition professionals. The environment included industrial-control systems, Linux, Windows and Active Directory, along with other technologies.

Each element adds a different form of operational responsibility. Linux and Windows systems can host services with different administration models and security controls. Active Directory can centralize identity and access, making it both operationally important and attractive to an adversary. Industrial-control components bring process-oriented behavior into the environment. The communications link between distributed resources and a generating plant makes network availability part of the simulated business purpose.

Baldwin Wallace did not publish the exact topology, products, vulnerabilities or attack paths, so those details cannot be reconstructed from the available record. The documented heterogeneity is enough to establish the instructional challenge. The students were not defending one operating system or one application. They were responsible for a connected environment whose technologies had to continue serving a fictional energy-management company.

Distributed energy resources are an effective teaching context because they decentralize the picture. Instead of one plant and one network, the scenario involved communication among local solar customers and generation. A distributed environment raises questions about identity, trust, connectivity and visibility across multiple endpoints. Those questions are relevant to real infrastructure, but the competition's answers remain part of a simulation.

The service-continuity requirement is equally important. Students were expected to patch and defend without abandoning operations. That creates the central tension of critical-infrastructure security education: protection is necessary, but the protected system exists to perform a function. A defense that destroys the function is not a complete success.

Atchinson's public explanation of the scenario focused on the work students performed rather than a vague claim that they "did cybersecurity." They maintained operations, patched systems and defended against attacks across several technology families. That level of detail makes the competition result useful as educational evidence. It shows the kinds of decisions the team had to practice, while stopping short of claiming that the students operated real energy assets.

Communication as Defensive Infrastructure

Technical profiles often treat communication as a soft addition to "real" engineering. Atchinson's competition record suggests the opposite. Communication is part of the defensive infrastructure because it determines whether observations become coordinated action.

In a mixed environment, no individual can see everything at once. One student may notice an authentication anomaly. Another may be tracing network traffic. A third may be responding to a fictional business request. A fourth may be documenting an incident. The team succeeds only if those partial views become a shared operational picture.

Documentation also serves more than the score. It forces a defender to distinguish observation from inference. A clear record can state what changed, when it changed, what evidence supported the action and what remained uncertain. That discipline reduces the risk that the team acts on assumptions or repeats an unsuccessful step.

The 2019 Baldwin Wallace report connected the regional win to technical skill, communication and team cohesion. The program page separately lists written and oral communication among its learning outcomes. These two sources reinforce each other without proving a direct causal formula. The curriculum values communication, and the coach publicly associated it with competitive performance.

Business injects and judge requests add another layer. Defenders must translate technical conditions into explanations that a non-specialist can use. They may need to say why a service is unavailable, what risk a request creates or when a change can be completed. A technically correct answer delivered too late or without context may not support the fictional organization.

Critical-infrastructure scenarios make this translation especially important. Operational staff, engineers, managers and security teams may use different vocabulary and prioritize different risks. A student competition cannot reproduce every real organizational relationship, but it can demonstrate that security decisions are made among stakeholders rather than inside a technical vacuum.

This point helps explain why coaching is substantive. Coaching is not limited to teaching more commands or security products. It includes helping students form a team that can reason together. Atchinson's exact coaching methods are not public, but team performance and communication were central to how he described success.

Keeping the Curriculum Current

When Baldwin Wallace announced Atchinson's 2020 educator award, it reported his observation that information technology changes quickly and that keeping instruction relevant requires sustained work. The remark fits the competition record because each event can introduce unfamiliar systems, attack patterns or operational demands.

Relevance does not mean chasing every new product. A durable cybersecurity curriculum has to balance changing tools with stable concepts. Operating systems evolve, but identity, privilege, process and configuration remain important. Network technologies change, but addressing, segmentation, reachability and trust remain central. Attack techniques shift, but defenders still need evidence, prioritization and recovery.

Competition scenarios can help test that balance. Students use specific technologies, yet they cannot prepare only by memorizing one environment. They need models that transfer: understand the service, map dependencies, establish a baseline, inspect changes and communicate risk. The 2023 CyberForce environment's mix of industrial control, Linux, Windows and directory services rewarded breadth without making any one product the whole subject.

The Baldwin Wallace program page describes a foundation in computing, mathematics, architecture, programming and telecommunications alongside practical network and security skills. This structure supports adaptation. Students need enough theory to recognize patterns when a tool or interface changes. They also need enough practice to act when the situation is incomplete.

Atchinson's own CV illustrates the same kind of transition. It connects electrical engineering, software development, Unix administration, consulting, network management and academic work. The document does not establish that he remains active in every field it lists. It does show a career that crossed multiple generations of systems before the CyberForce result.

The 2020 award is one institutional marker in a longer education story, not proof that every program outcome belongs to one individual. Cybersecurity education is collective work involving colleagues, students, facilities and partner institutions. Atchinson's public role is visible because the university identifies him as program lead and coach. The program's development cannot fairly be reduced to him alone.

That boundary strengthens the profile. It places leadership where the evidence supports it: guiding a program, mentoring students and coaching competition teams. It avoids unsupported claims about sole authorship of curriculum, individual responsibility for every result or causation of graduates' careers.

What Competition Results Measure

Rankings provide clear numbers, but their meaning is narrower than it first appears. Baldwin Wallace's first-place Midwest regional result in 2019 and reported sixth-place CyberForce result in 2023 show that the teams performed well under the rules and conditions of those events. They do not certify real-world infrastructure, prove that every entity reached the same level or establish long-term security outcomes.

A competition is a bounded environment. Organizers select systems, adversarial actions, scoring methods and time limits. Real organizations have longer histories, incomplete inventories, legal obligations, procurement constraints and people who cannot be represented fully in a simulation. The exercise can approximate operational pressure without duplicating production.

This limitation is not a reason to dismiss the result. Bounded environments make some forms of assessment possible. Teams can be compared under shared conditions. Instructors can observe how students respond to incidents and requests. Entities can encounter consequences for poor coordination. The event creates evidence about performance in the scenario.

The evidence supports a specific conclusion. Atchinson coached Baldwin Wallace teams that achieved documented competition milestones. The events required operational defense, teamwork and communication. The 2023 scenario connected those skills to a simulated distributed-energy company and mixed IT/OT environment. These facts establish a record of scenario-based cybersecurity education.

The record does not support claims that Atchinson or his students secured a real utility, prevented a real attack, operated customer infrastructure or guaranteed employment. It does not provide comparative data showing that competition entities outperform all other students. It does not disclose employer outcomes caused by the team.

Keeping those limits visible protects both the subjects and the reader. It prevents a university result from becoming an infrastructure claim. It also allows the genuine educational achievement to remain clear. Students prepared for and navigated complex scenarios, and their teams performed strongly against broad fields of institutions.

A Workforce-Development Record, Not an Infrastructure Claim

DOE describes CyberForce as a workforce-development program. Baldwin Wallace describes its cybersecurity major as preparation for network and security roles and requires experiential learning, including an internship. The two institutions therefore meet around education, but they do not make identical claims.

The university is responsible for a degree program with broad learning outcomes. CyberForce supplies a national scenario in which entities practice selected operational skills. Atchinson connects them as an educator and coach. The competition cannot replace a degree, and a degree does not guarantee a competition result. Together they create a richer preparation environment.

Critical-infrastructure cybersecurity needs that combination because the work is interdisciplinary. Defenders must understand computing systems and networks, but they also need context about operations, safety, regulation and organizational responsibility. A university program can provide foundations and time for reflection. A competition can expose the friction that appears when those foundations have to support a live objective.

The 2023 distributed-energy scenario illustrates the point. Students were not merely told that energy infrastructure is important. They were placed inside a fictional organization whose service depended on communications among distributed resources and generation. They had to maintain that service while defending systems. The scenario translated a policy concern into operational decisions.

Atchinson's record is meaningful because it shows sustained engagement with this method. The CyberSec team reportedly began in 2009. It reached the national CCDC in 2019. Baldwin Wallace's CyberForce participation began in 2018 and produced the documented 2023 result. The chronology spans different competition models and technology contexts.

Longevity is not proof that every season improved or that every method remained the same. It shows that experiential cyber defense became an enduring part of the program's public identity. Atchinson appears repeatedly as coach, professor and program leader across the institutional sources.

Kenneth Atchinson's Place in Cybersecurity Education

Kenneth Atchinson's public record shows how a technical career can become an educational method. Engineering and computer-science training led into software, systems and network work in the institutional chronology. Baldwin Wallace later placed him at the head of a cybersecurity analyst program and the coach of a team created to extend learning beyond the classroom.

The 2019 CCDC milestone demonstrated one form of that method. Students defended a mock business network while responding to attacks and operational demands. The team advanced from the Midwest regional field to the national event for the first time. Atchinson emphasized that technical ability had to work with communication and team cohesion.

The 2023 CyberForce result demonstrated another form. The scenario represented a distributed-energy company and combined industrial-control systems with Linux, Windows and Active Directory. Students were asked to maintain operations while defending and patching the environment. Baldwin Wallace reported a sixth-place finish among 95 teams, while DOE independently lists the university among the competitors.

The two events are separated by technology, scenario and sponsor, but they share an educational core. Defenders have to understand why a system exists, not only how it can be attacked. They have to protect services without losing sight of users and operations. They have to coordinate evidence and decisions across a team.

That is the most defensible account of Atchinson's contribution. It does not make him the sole author of the program or the operator of real critical infrastructure. It identifies a sustained role in building and coaching environments where students practice the combined responsibilities of administration, defense and communication.

Cybersecurity education often faces a gap between knowing a principle and applying it when several things are going wrong at once. Atchinson's competition record is a public example of how a university can narrow that gap. The exercises remain simulations, the rankings remain bounded, and the employment outcomes remain unproved. Within those boundaries, the record is substantial: more than a decade of team development, national competition milestones and a visible connection between classroom foundations and operational cyber defense.

Sources