Most conversations about cybersecurity focus on adults — protecting bank accounts, corporate networks, or government systems. But a growing number of educators argue that the real front line is much younger: kids who are on gaming platforms and social media every day, often without realizing that some of the “friends” and strangers they interact with online may have less-than-friendly intentions. That’s the premise behind a new three-day Cybersecurity Camp at Northeastern State University (NSU) in Oklahoma, which kicked off on July 20 and ran from 9 a.m. to 2 p.m. each day, aimed at students in grades 5 through 8.

Who’s Running the Camp

The camp is led by three instructors: Charlie Niemi, Ethan Stubblefield, and Courtney Graham, who take turns engaging the kids on different aspects of how cybersecurity touches their everyday lives. Stubblefield serves as NSU’s cybersecurity clinic program coordinator, while Niemi and Graham work as cybersecurity instructors for the Oklahoma Cyber Innovation Institute — a partnership that reflects a broader, increasingly common model where universities team up with dedicated cyber-education organizations to bring specialized instruction directly to younger students.

What the Kids Are Actually Learning

According to Stubblefield, the goal of the camp is straightforward: introduce kids and young teens to core cybersecurity concepts — internet awareness, building secure passwords, staying safe online, and recognizing newer, evolving cyber threats, including those introduced by AI.

Some of the practical lessons covered include:

Password hygiene — instructors stressed that reusing the same password across multiple accounts makes it far easier for a single compromise to spread across a person’s entire digital footprint.
What to do if you’re hacked — Stubblefield explained that most modern phones’ factory security settings make full device access difficult even after a breach, meaning only highly skilled, advanced attackers typically target a device at that level. The key advice for kids: react quickly. As Stubblefield put it, resolving the issue and changing your password quickly helps prevent the compromise from spreading further.
Password managers — rather than expecting kids to memorize dozens of complex passwords, instructors introduced the idea of password managers, tools that can automatically generate and fill in strong, unique passwords for each account.
Making Cybersecurity Feel Like Summer Camp, Not a Lecture

One of the more telling details from the camp’s opening day is how it started: not with a slideshow, but with a game. The kids kicked things off with a rock-paper-scissors competition to break the ice — a small but deliberate choice that speaks to how the instructors approached the material. Nine-year-old Charlie Young admitted he couldn’t quite explain why he was at the camp, and fellow camper Cullen Bryant joked that he’d mainly come to sleep — before going on to win the warm-up competition anyway. That light, informal energy seems to be part of the design: meeting kids where they are, rather than trying to talk over their heads about technical security concepts.

Why Starting Young Matters

The reasoning behind camps like this one comes down to timing. Kids today are often online — gaming, messaging, browsing social platforms — well before they’ve developed the instincts to recognize manipulation, phishing attempts, or scams. Unlike adults, who may have already learned (sometimes the hard way) to be suspicious of unsolicited messages or too-good-to-be-true offers, kids are still building their sense of who to trust online. That makes them an attractive target for scammers, and it also makes early, age-appropriate education one of the most effective long-term defenses available.

This isn’t NSU’s first attempt at reaching this age group either. The university has previously run similar cybersecurity camps for middle-school-aged students, often offered free of charge through partnerships with the NSU Cyber Security Clinic and the Oklahoma Cyber Innovation Institute, reflecting a sustained institutional commitment rather than a one-off event.

The Bigger Trend: Cybersecurity Education Is Getting Younger

NSU’s camp is part of a wider national shift. Cybersecurity education, once reserved for high schoolers considering technical careers or college-level students, is increasingly being introduced to much younger age groups — in some cases even to fourth and fifth graders. Educators pushing this trend argue that foundational digital-safety habits, like recognizing suspicious links or understanding why password reuse is risky, are best formed early, before risky online habits set in. Some cybersecurity teachers running similar youth programs elsewhere in the country have been recognized nationally for this kind of early-intervention approach, underscoring that this isn’t a fringe idea — it’s becoming a recognized part of how the cybersecurity education pipeline is being built from the ground up.

Conclusion

At first glance, a three-day summer camp with rock-paper-scissors and a handful of middle schoolers might seem like a small story next to headlines about billion-dollar scam networks or nation-state cyberattacks. But programs like NSU’s Cybersecurity Camp represent something important: an investment in prevention, not just response. By teaching kids as young as grade 5 to recognize risky online behavior, use strong passwords, and know what to do if something goes wrong, camps like this one are trying to build a generation that’s harder to scam in the first place — one rock-paper-scissors match at a time.

Leave a Reply

Your email address will not be published. Required fields are marked *