GenAI misuse. Vibe coding. Agentic AI. Employees are exploring new ways to use AI faster than many security programs can set clear guidlines. The 2026 SANS Security Awareness & Culture Report examines that gap and what the most prepared organizations are doing to address it. Get your copy: https://go.sans.org/K5EJ1N #SecurityAwareness #HumanRisk
SANS Security Leadership
Computer and Network Security
North Bethesda, Maryland 8,211 followers
Developing World-Class Cybersecurity Leaders
About us
Cyber security leaders need both technical knowledge and management skills to gain the respect of technical team members, understand what technical staff are actually doing, and appropriately plan and manage security projects and initiatives. This is a big and important job that requires an understanding of a wide array of security topics. The SANS Cybersecurity Leadership Curriculum, through world-class training and GIAC Certifications, develops cyber leaders who have the practical skills to build and lead security teams, communicate with technical and business leaders alike, and develop capabilities that build your organization's success. We teach how to lead security initiatives to manage information risk while aligning security with overall business strategy. We help you align communications and actions from the technical team up to the Board, while managing human risk across the entire organization. Decrease your technical spend while increasing your overall security posture by leading and managing your vulnerability management program, security operations centers, and human beings. GIAC's Leadership certifications confirm the practical skills to build and lead security teams, communicate with both technical teams and business leaders, and develop capabilities that strengthen your organization's security posture. "This is a fantastic introduction to all the areas a CISO is responsible for in modern organizations. Excellent instruction, very engaging course structure, and a ton of valuable information." - Michael C., ABS Global Training Ltd. Learn more about our courses at https://www.sans.org/u/1hFG
- Website
-
https://www.sans.org/u/1hFG
External link for SANS Security Leadership
- Industry
- Computer and Network Security
- Company size
- 201-500 employees
- Headquarters
- North Bethesda, Maryland
- Founded
- 1982
- Specialties
- Cybersecurity Leadership Essentials, Security Strategic Planning, Security Policy, Leading Vulnerability Management Programs, Leading Cloud Security, Leading Security Culture, Leading Project Management & Communication, Building and Leading SOC, Cyber Incident Management, CISSP Training, Managing Human Risk, and Auditing Systems, Applications, and Cloud
Updates
-
Training budgets are easiest to defend when you know exactly what they're fixing. ASAP's report shows precisely where a person's skills are strong and where they're not, mapped to the SANS courses that close the gap. That's what training investment looks like with data behind it. https://go.sans.org/Ayo6zK
-
-
AI is changing more than GRC tooling. It is changing the decisions leaders have to make. Kevin Garvey will lead interactive scenarios around governance, administrative controls, automation, and AI-driven change, with each exercise centered on the choices GRC leaders face in practice. 📅 Oct 20 | 12:00 PM ET 🔗 https://go.sans.org/iAutNh #GRC #AI #CyberLeadership #Governance
-
-
Adopting new AI tools is easy; preparing your workforce for them is another story. This session will take a look at the skills practitioners need to develop, how leaders should approach upskilling, and what HR and hiring managers need to reconsider as workforce requirements change due to AI. 📅 Oct 22 | 1:00 PM ET 🔗 https://go.sans.org/qw93re #CyberSkills #CyberWorkforce #AI #CyberLeadership
-
-
The gap between "trained" and "secure" is where most breaches live. Hannah Hardee, Cybersecurity Analyst in Training, Education and Awareness at Southwest Airlines, joins Rachael Saffer live in 1 hour to unpack what closes that gap. Find out what closes it → https://go.sans.org/rACNGW #SecurityAwareness #HumanRisk
-
Top tip for getting more out of the Security Awareness & Culture Report: don't just read it — use it as a checklist. That's what Don Devenney, who runs the security awareness program at Royal Roads University and sits on the Advisory Board for SANS's report, does. He checks the report against his own program to confirm what's working and spot where it needs more attention. His go-to section for this: the five open-ended questions, which he uses to spark ideas to scale his program. Try it yourself: read the open-ended questions section against your own program, and pull out what's missing from your plan. Download the report: https://go.sans.org/K5EJ1N #SecurityAwareness
-
As AI agents take on more responsibility, accountability can’t be an afterthought. At SANS AI Cybersecurity Summit Fall, Vinh Nguyen will explore what organizations need in place as frontier AI agents gain access to sensitive information and begin acting on people’s behalf. His framework centers on three interconnected foundations: - Observability to trace agent actions and catch failures - Accountability to connect actions back to those responsible - Confidentiality to govern how sensitive information moves Vinh will connect these foundations directly to the C-suite and Board conversations shaping how organizations deploy AI securely and responsibly at scale. 🗓️ Summit: Nov. 2–3 📍 Arlington, VA | All-Access + Workshops 🌐 Live Online | Summit Talks ➡️ Explore the Agenda & Save Your Spot: https://go.sans.org/USUvPm #AISummit #AISecurity #CyberLeadership
-
-
Most security awareness programs are still measured by completion rates, but pracitioners are questioning if that's the metric organizations should really be looking out for. As Cybersecurity Analyst in Training, Education and Awareness at Southwest Airlines, Hannah Hardee has watched her own role shift — from delivering training to practicing something closer to change management. Understanding why people behave the way they do, and using that insight to shift it. That's the conversation she's having with Rachael Saffer: what building real security culture looks like at enterprise scale, and where the profession is actually headed. 📅 Tue, Oct 6 | 11:00 AM–12:00 PM EDT Hear how Hannah is redefining the role → https://go.sans.org/rACNGW #SecurityAwareness #HumanRisk
-
The headlines will keep changing. The responsibility for securing AI won’t. You don’t need another reminder that AI is moving fast. You need to know what security teams are doing now. Join us in Arlington this November at the SANS AI Cybersecurity Summit Fall 2026 for keynotes, lightning talks, hands-on workshops, and real-world insights from practitioners building, securing, evaluating, and governing AI today. 🗓️ Nov. 2–3 📍 Arlington, VA | All-Access + Workshops 🌐 Live Online | Summit Talks See what’s working, where the hard problems remain, and what teams are learning along the way. Save Your Spot: https://go.sans.org/USUvPm #AISummit #AISecurity #CyberSecurity
-