Key Takeaways
- Marshall University is building a new Institute for Cyber Security on 4th Avenue, with an anticipated opening in August 2027.
- The structure will contain multiple floors, each dedicated to a distinct defense‑focused function such as learning labs, private‑industry partnership spaces, and specialized research labs.
- Three Security Operations Centers (SOCs) will sit at the heart of the facility, serving as the first line of defense for monitoring, analyzing, and responding to cyber threats.
- Cybersecurity training and work are already underway across campus, highlighted by Intuit’s on‑campus SOC and student employees like Cole Perry.
- Institute Director Alexandria Donathan stresses the rapid pace of the field, the breadth of career opportunities, and a five‑year vision to expand the institute’s impact from a regional asset to a national one.
Overview of the New Institute for Cyber Security Facility
Marshall University is constructing a purpose‑built home for its Institute for Cyber Security along 4th Avenue, close to the main campus. The project is slated for completion and opening in August 2027, providing a modern hub where academic instruction, research, and industry collaboration can converge. University leaders emphasize that the building will not merely be a classroom space but a functional environment designed to mirror real‑world cyber defense operations. By situating the institute near the university’s core, officials hope to foster seamless interaction between students, faculty, and external partners, creating a pipeline of talent ready to meet the growing demands of the cybersecurity workforce.
Floor‑by‑Floor Design and Specialized Spaces
Each floor of the new building will be assigned a distinct, defense‑driven focus, allowing for specialized activities without overlap. The lower levels are expected to house learning labs where students can engage in hands‑on exercises, ranging from network configuration to malware analysis. Mid‑level floors will be dedicated to spaces for private industry partners, enabling companies to co‑develop solutions, sponsor projects, and provide mentorship directly within the institute’s ecosystem. Upper floors will contain specialized labs equipped for advanced research, such as threat intelligence, cryptography, and secure software development. This stratified approach ensures that learners can progress from foundational skills to cutting‑edge research while remaining immersed in a professional‑grade environment.
Current Progress and Campus‑Wide Cyber Activities
Although construction is still underway, Alexandria Donathan, the institute’s executive director, notes that cybersecurity defense work is already taking place at several locations across Marshall’s campus. She encourages anyone interested in the field to begin immediately, likening the discipline to a fast‑moving river where opportunities constantly flow. Donathan’s remarks underscore that the institute’s mission is not contingent on the building’s completion; rather, the university is leveraging existing resources to start training and operational work now. This proactive stance allows students to gain relevant experience while the physical infrastructure catches up, ensuring continuity of education and skill development.
Career Opportunities and the Fast‑Moving Nature of Cyber
Donathan highlights the broad spectrum of career paths available within cybersecurity, ranging from analyst and engineer roles to positions in policy, risk management, and incident response. She advises students to “just start,” emphasizing that the field evolves rapidly and that early engagement yields the greatest advantage. By exposing learners to real‑world scenarios and industry‑standard tools early in their academic journey, the institute aims to produce graduates who are not only knowledgeable but also immediately employable. This focus on immediacy aligns with the university’s broader goal of addressing the national shortage of qualified cybersecurity professionals.
Intuit’s On‑Campus Security Operations Center
In June, Intuit launched a Security Operations Center (SOC) directly on Marshall University’s campus, providing students with a tangible, hands‑on learning environment ahead of the new building’s opening. The SOC allows participants to monitor live network traffic, analyze alerts, and practice incident response under the guidance of industry professionals. This initiative bridges the gap between theoretical coursework and practical application, giving students a taste of the day‑to‑day responsibilities they will encounter in professional settings. The presence of a corporate SOC also reinforces the institute’s commitment to fostering strong partnerships with private‑sector leaders who can offer mentorship, internships, and potential employment pathways.
Student Employee Perspective: Cole Perry
Cole Perry, one of two full‑time employees already working at the Intuit SOC while still enrolled as a student, shares his experience as a testament to the institute’s forward‑looking approach. Perry explains that he had originally planned to secure a traditional internship after graduation, but the early opportunity to work in a live SOC has “jump-started” his professional development. By contributing to real‑time threat monitoring and response, he is acquiring skills and credentials that would typically take years to accumulate. His story illustrates how the institute’s emphasis on immediate, experiential learning can accelerate career readiness and provide a competitive edge in the job market.
The Role of the Three Security Operations Centers (SOCs)
At the core of the forthcoming building will be three Security Operations Centers, which Donathan describes as the first layer of defense for the institute’s cyber operations. Each SOC will serve as a central hub where all network data, logs, and traffic converge, enabling analysts to detect anomalies, identify potential incidents, and uncover vulnerabilities. By positioning the SOCs as the initial point of contact for information flowing through the institute’s networks, the design ensures that threats are spotted early, allowing for swift containment and mitigation. This layered defensive strategy mirrors industry best practices, where continuous monitoring and rapid response are critical to maintaining security posture.
Operational Workflow Within the SOCs
Inside each SOC, analysts will follow a structured workflow: ingesting data from various sources, correlating events to distinguish benign activity from genuine threats, and escalating confirmed incidents to appropriate response teams. The centers will be equipped with advanced SIEM (Security Information and Event Management) tools, threat intelligence feeds, and forensic capabilities, allowing staff to trace attack vectors, assess impact, and recommend remediation steps. Once an incident is validated, the SOC will coordinate with other units—such as the incident response team, legal counsel, and senior management—to execute a predefined response plan. This end‑to‑end process ensures that detection leads to actionable outcomes, minimizing potential damage and reinforcing the institute’s role as a trusted cyber defense hub.
Strategic Vision: From Regional to National Impact
Looking beyond the physical structure, Donathan outlines an ambitious five‑year plan that seeks to transform the institute from a regional asset into a national leader in cybersecurity education and innovation. She draws an analogy to the expansion of aviation programs across the state, envisioning a similar growth trajectory for cyber capabilities—expanding outreach, developing new curricula, and fostering collaborations with federal agencies, industry consortia, and academic partners. By scaling its influence, the institute aims to contribute to national cyber resilience, produce a steady pipeline of highly skilled professionals, and position West Virginia as a hub for cybersecurity excellence. This vision reflects both the urgency of the cyber threat landscape and the institute’s commitment to staying ahead of the curve through continuous growth and adaptation.

