
The Cyber Devils – Duke’s student team of Adrian Schmeichler T’28, Eli Coustan T’29, Phineas Quigley T’29 and Marilyn Zhao T’29 – won first place in the Atlantic Council’s Cyber Statecraft Initiative 2026 Cyber 9/12 Strategy Challenge. Held March 7-8 in Washington, D.C., the competition challenged students to respond to a realistic, evolving scenario of international cyber crisis by analyzing the threat it posed to national, international and private-sector interests, and presenting recommendations on the best course of action to mitigate the crisis. In the reflections below, two team members share their experiences.
Crisis, Adaptation & a Cyber 9/12 Victory
By Adrian Schmeichler T’28
Representing Duke University in the Atlantic Council's flagship Cyber 9/12 Strategy Challenge was one of the highlights of my semester. When the Duke Cyber Club assembled our team, none of us had prior competition experience. I was hoping to learn more about cyber policy by applying it in a simulated crisis and to meet others interested in the field. Just one month later, we would be walking onstage as the first-place team.

For weeks leading up to the competition, we spent hours working with our coaches, Kim Kotlar and Jim Hargrove, to refine a policy memo in response to a Democratic People's Republic of Korea attack on World Cup infrastructure, debating solutions and which U.S. agencies should get involved. Every word mattered: the page limit and the short speaking window forced us to defend each recommendation we would make to the mock National Security Council. By the time we arrived in Washington, D.C., we had developed a strong product and a tight team. I played the role of situation analyst, briefing the team on the attack, attribution, and risk level to set up the policy solutions my teammates would discuss.
The competition itself was a fast-paced simulation of a real-world cyber crisis, where new developments forced us to constantly adapt our strategy. We were surprised by how positively the judges responded in the first round, giving us high praise along with helpful feedback. While waiting for the results, we had time to meet teams and judges from around the world – one of my favorite parts of the event. I was deep in conversation with a professor from Johns Hopkins University on cyber defense in developing countries when one of our coaches had to drag me away for a team meeting to prepare for the next round.
We were among the 50% of teams that advanced to the second round. Our reward was a 40-page brief released at 7 p.m, describing a U.S. cyber-offense contractor who had gone rogue, and our response was due the next morning. We worked deep into the night, breaking when policy debates ran hot. Stress levels got high as the hours sped by. We woke early to write and practice the presentation.
After another round of strong feedback from the judges, we faced long odds for the finals: 20 teams cut to three. I was already proud to have made it past round one, but we reviewed the suggested improvements just in case we advanced – and were glad we did when we were named finalists alongside the UK team we'd met earlier that day.
Being sequestered and split from our coaches for the final round was when all the work and repetition paid off. Given only 15 minutes to adapt to a new brief, our specializations were essential. I trusted each teammate to nail their roles as foreign, domestic, and cyber strategy experts as we sped through the new scenario: attacks on several foreign banks.
Presenting our recommendations to senior leaders, including the Acting Director of the Cybersecurity and Infrastructure Security Agency (CISA), was both intimidating and rewarding, as their feedback showed how deeply they knew these issues. Winning Cyber 9/12 would mean that our work had held up under their intense scrutiny. We were lucky to have the support of our coaches in the audience, along with other teams and judges we'd met during the competition. My anticipation turned to elation as the Duke Cyber Devils team was called up for first place, bringing our month-long journey to a memorable close.
Cyber 9/12 was a chance to apply classroom concepts to a realistic, high-stakes scenario, to receive feedback from practitioners, and to better understand how policy decisions are made in practice. What stood out most during the competition was the community. From conversations with other teams to time spent with judges, coaches, and organizers, we got a firsthand look at the collaboration inherent to cyber policy. Winning was a bonus on top of the connections and skills that will last well beyond that jam-packed weekend in March.

From Cameron Crazie to Cyber Devil
While most of my friends were cheering on the Blue Devils in Cameron Indoor Stadium, I was sitting in Washington, D.C., researching the U.S. government’s policies for offensive cyberattacks. I had hoped to take a break to watch the Duke vs. UNC basketball game, but there was no time to waste.

My teammates and I were in D.C. representing Duke Cyber, Duke’s student-led cybersecurity policy club, in the Atlantic Council’s Cyber 9/12 Strategy Challenge. In this competition, teams of four present recommendations to a mock National Security Council on how the federal government should respond to a hypothetical cyberattack.
When I joined Duke Cyber, I was interested in learning more about cybersecurity and how the government responds to cyberattacks. Competing in Cyber 9/12 certainly deepened that knowledge, but the much more meaningful lessons came from interactions with my teammates, coaches, and judges.
Before Cyber 9/12, I had thought of cyber policy as a field that heavily prioritized technical know-how, but this competition helped me realize that developing effective cyber policy requires deep collaboration across disciplines. My teammates and I approached the scenario from different perspectives and often disagreed on what mattered and what responses we should recommend. Bridging these gaps required us to think through tradeoffs, challenge each other’s assumptions, and, at times, compromise. In the end, the final product we developed drew from each of our unique strengths and was much stronger than what any of us could have developed alone.
That collaborative process also helped me realize how my teammates and I were drawing on content and skills from our Sanford classes. In Professor David Hoffman’s Intro to Cyber Policy class, which several of my teammates and I took, we discussed and debated the role of various government agencies in offensive and defensive cyber responses. These discussions gave us the perspective needed to make appropriate recommendations and helped us think through potential objections. Furthermore, the class’s focus on presenting technical policy recommendations through concise, clear memos and oral presentations directly translated to our competition preparation.
Beyond the competition itself, talking to the judges and other schools’ coaches and students broadened my understanding of cybersecurity careers. Many had moved between roles in academia, government, and the private sector, but all were focused on addressing real-world threats. These interactions helped me see cyber policy not as one path but as a field with a multitude of opportunities to further explore.
While the Situation Room is no replacement for Cameron Indoor Stadium, being a Cyber Devil gave me a different kind of Duke memory. In D.C., I got to apply lessons from my Sanford classes while learning from incredible teammates, coaches, and judges. The experience left me with a clearer understanding of why cyber policy matters and a stronger sense of where I might fit within it.

With a focus in emerging tech policy, Adrian Schmeichler is majoring in public policy with minors in computer science and economics. The rising junior is currently working as a research assistant at Duke Sanford, studying data center community impacts. He is also involved in the Duke Cyber Club and Duke Puppy Kindergarten. This coming semester, he will head to Venice, Italy, to explore global governance, health policy, and architecture.
Eli Coustan is a rising sophomore majoring in public policy and computer science. At Duke Sanford, he conducts tech policy research with Professor Ken Rogerson. He is the incoming co-policy director of the Duke Cyber Club and one of the incoming co-treasurers of the Duke Debating Society. In his free time, Eli enjoys running and cooking.
About Duke Cyber
The Duke Cyber Club is a student-led organization that offers undergraduate and graduate students opportunities to engage with cybersecurity practitioners in the government and private sector, hone their policy and technical skills in practice sessions, and participate in competitions hosted by Duke and nationally-recognized organizations. Over the past six years, it has grown campus-wide to include students from all disciplines and interests. This work is made possible by support from campus partners, including the Duke Program in American Grand Strategy, the Duke Master of Engineering in Cybersecurity program, the Pratt Engineering Alumni Council, and Student Organization Finance Committee.