SANS Institute’s cover photo
SANS Institute

SANS Institute

Computer and Network Security

Rockville, Maryland 378,360 followers

SANS is the most trusted resource for information security training, cyber security certifications and research.

About us

SANS is the most trusted and by far the largest source for information and cybersecurity training and certification in the world. It also develops, maintains, and makes available at no cost, the largest collection of research documents about various aspects of information security, and it operates the Internet's early warning system - Internet Storm Center.

Website
http://www.sans.org/
Industry
Computer and Network Security
Company size
201-500 employees
Headquarters
Rockville, Maryland
Type
Privately Held
Founded
1989
Specialties
Information Security Training, Digital Forensics Courses, Cyber Security Training, Security Awareness Training, Penetration Testing Courses, Application Security Courses, Security Leadership Courses, Industrial Control Systems Security Courses, cloud security courses, blue team operations courses, cyber security certifications, security awareness training, cyber security white papers, cyber security webcasts, and cyber security policies

Locations

  • Primary

    11200 Rockville Pike

    Suite 200

    Rockville, Maryland 20852, US

    Get directions

Employees at SANS Institute

Updates

  • SANS Institute reposted this

    Finished SANS Institute SEC573: AI-Powered Security Automation this week in Bethesda, Maryland. It was a genuinely great course - a lot of useful Python, security automation, tool building, and ideas that I’m looking forward to putting into practice. I also managed to finish first on the SEC573 PyWars leaderboard and earn the challenge coin. A big thank you to Mark Baggett for the course. His depth of experience in both Python and information security added a lot beyond the course material itself. I’m also very glad I chose to attend in person. Meeting and working with people from different parts of the security industry made the whole experience considerably better. Great week, great people, and plenty to bring back home.

    • No alternative text description for this image
  • View organization page for SANS Institute

    378,360 followers

    Since June's SANS ICS Security Summit, attackers have hit 100+ US water systems and exposed PLCs across industrial sectors. SANS Fellow Tim Conway says two Summit talks predicted this. Brian Harrell's keynote discussed how nation-state actors build access before any visible disruption. Mark Bristow's tabletop exercise across five cities and five critical sectors showed mutual aid and communications breaking down faster than the attack itself. Conway's new blog post challenges two assumptions leaders often make: that their organization is too small to be a target, and that the worst case is just an outage. Read it here: https://go.sans.org/CTCPHH #CriticalInfrastructure #ICSSummit

    • No alternative text description for this image
  • SANS Institute reposted this

    Two weeks ago I was in Las Vegas to teach my first ever SANS class! It was a new course, SEC559: Identity Security for Cloud and Hybrid, which Maxim Deweerdt created with help from me and Christos Gourzoulidis. I have always enjoyed helping people learn new concepts. From being a TA at Penn State talking about network security, to an instructor at National Intelligence University talking about everything cyber, and now with SANS focused on identity security. It is a great feeling to see the light bulb go off (or just a head nodding). Our class was full of great students, including Richard Nelson who was an intern at CISA when I was there, but is now a SEC559 capstone champ. I still remember drawing on the wall in the office to explain how our NIDS/netflow logs were structured and generated. Now they all understand OAuth tokens, SAML, Entra device objects, guest users, authorization policies, Entra sign-in log structures, managed identities, access packages, and of course Kerberos (but not too much Kerberos). 🤓 I was also happy that people enjoyed the KQL queries and capstone exercise on Day 5. One student even asked for more KQL! If you're interested in taking the course, the next session is in Dallas, TX (December 7-11): https://lnkd.in/gCwXSTgG

    • No alternative text description for this image
    • No alternative text description for this image
    • No alternative text description for this image
  • View organization page for SANS Institute

    378,360 followers

    AI can clone a voice from just a few seconds of audio. The FBI's 2025 Internet Crime Report gave AI fraud its own section for the first time in the report's 25-year history, and voice-clone scams alone topped $5 million. This is the scam SANS digital forensics expert Heather Barnhart hears about most from families: a call comes in that sounds exactly like a kid or grandkid, scared, asking for money. The voice was cloned from a public video, no hacking required. What Heather tells every family: "What's the word?" Pick one word, agreed on in person, never posted or texted. Anyone calling for money, gift cards, or bail has to know it. No word, no money, no exceptions. Pair it with the callback: hang up and call the person back on a number you already have. Scams run on panic and speed; a callback removes both. 🔒 Don't make it easy for them. → https://go.sans.org/LExDoT #SecureTheFamily #SecureTheFamily #CybersecurityAwarenessMonth #AIScams #AIFamilyCyberSafety

  • If you're a hands-on practitioner rather than a spectator, CyberThreat 2026 was built with you in mind. James Lyne, CEO of SANS Institute, describes it as the technical get-together for "people sat at keyboards doing real work to make cyber criminals miserable." Now in partnership with the UK's National Cyber Security Centre, the two-day event returns to The Roundhouse in London on 16 and 17 November. Expect deep technical talks, hackable badges, and a new CTF challenge, alongside the space to practise, learn, and compare notes with people doing the same job as you. James says the part that matters most isn't the keynotes. It's what happens between sessions, when practitioners swap tools and tactics they haven't tried anywhere else. Last year threw up plenty of those conversations. This year's set to be bigger. If cybersecurity is your world, not just your job title, this is the event to attend. 👉 Register → https://go.sans.org/rfeBZa #CyberThreat2026 #Cybersecurity | UK's National Cyber Security Centre

  • Tech CEOs including OpenAI, Anthropic, Google, Meta and Nvidia signed an AI Accord at the White House last week, agreeing to a voluntary four step safety process for AI development: internal controls, internal oversight, and independent external review reporting to the board. Rob T. Lee, SANS Chief AI Officer, told Information Security Media Group (ISMG): "Regulation has to come from Congress, and that debate takes time regardless of the election calendar. A voluntary framework gets industry moving while that process plays out." With lawmakers campaigning ahead of the midterms, Lee called the voluntary route "the right move, at least right now," pointing to how "reasonable cybersecurity" became an enforceable standard after data breaches, even without a law defining it first. Voluntary commitments can work the same way, setting a baseline before formal regulation follows. https://lnkd.in/e2PvjcEm

  • Dont miss these upcoming SANS webcasts: 1️⃣ Unpack findings from this years global survey on how organizations discover, prioritize, and reduce exposures, and where automation and AI are moving the needle. October 7 | Jonathan Risto P. Eng Register: https://go.sans.org/gyTbOk 2️⃣ Walk through this years global survey results on top cloud threats, tool adoption (CNAPP, SSE, IAM), DevSecOps integration, and where AI is showing up in cloud defense. October 21 | Serge Borso Register: https://go.sans.org/0DVA2s 3️⃣ Examine new survey data on how security teams are responding to agentic threats like prompt injection and non-human identity compromise to the barriers still stalling SOC autonomy. November 5 | Dave Shackleford & Jane Goh Register: https://go.sans.org/7O3D3O 4️⃣ Jason Christopher covers visibility across the ICS cyber kill chain, cyber-informed engineering in practice, and where OT-specific controls still fall short. November 10 | Jason Christopher Register: https://go.sans.org/LwZrRT

  • We cannot secure what we cannot see, attribute, and contain. Join us at SANS AI Cybersecurity Summit Fall when Vinh Nguyen digs into what organizations need in place as frontier AI agents gain access to sensitive information and begin acting on people's behalf. His framework centers on three interconnected foundations: - Observability to trace agent actions and catch failures - Accountability to connect actions back to those responsible - Confidentiality to govern how sensitive information moves Vinh will also connect these technical foundations to the C-suite and Board conversations shaping how organizations deploy AI at scale. 🗓️ Summit: Nov. 2–3 📍 Arlington, VA | All-Access + Workshops 🌐 Live Online | Summit Talks ➡️ Explore the Agenda & Save Your Spot: https://go.sans.org/USUvPm #AISummit #AISecurity #CyberSecurity

    • No alternative text description for this image

Affiliated pages

Similar pages

Browse jobs