SANS Institute

Location
8120 Woodmont Ave, Bethesda, MD
Website
https://www.sans.org/
More Events

Upcoming SANS Institute Events

Closing the Gaps in Modern Data Protection

Sep 10, 2026

Virtual / Online

SANS Institute

Data flows continue to increase in complexity as enterprise architectures continue to change and mature. Data flows have expanded across cloud platforms, on-premises systems, collaboration tools, and increasingly, AI/ML pipelines. Yet the security controls designed to protect it haven’t evolved at the same pace—leading to fragmented data loss prevention (DLP) coverage, increased operational complexity, and growing risk.

Join us on September 10, 2026 at 10:30 AM EDT for a SANS Security Lab featuring Certified SANS Instructor Kevin Garvey and Broadcom’s Security Strategist, Alejandro Loza. Together, they will examine where traditional DLP approaches fall short and explore practical strategies for protecting data across today’s hybrid and AI-driven environments.

Through expert discussion and live demonstration, they’ll break down key challenges facing security teams, including data sprawl, tool fragmentation, and protecting sensitive information at the application layer and within emerging AI workflows.

Attendees will learn how to:

  • Evaluate modern approaches to DLP across distributed environments
  • Reduce operational overhead while improving visibility
  • Address evolving risks in SaaS applications and AI pipelines
  • Communicate data protection priorities effectively to stakeholders

The session will include brief; illustrative examples of how these concepts can be applied in practice.

Learn more

Sep 15, 2026

Virtual / Online

Sensitive data is already flowing into AI systems across your organization—often without security teams knowing what data is being shared, where it's going, or how it's being used.

Employees are adopting AI tools at an unprecedented pace, while AI copilots, embedded AI features, and autonomous systems are gaining access to business data in ways that traditional security controls were never designed to monitor. From intellectual property and source code to customer and regulated data, organizations are facing new challenges in maintaining visibility and control.

In this webinar, we'll explore where AI is creating new data exposure risks, how shadow AI is expanding the attack surface, and what security teams can do to identify, monitor, and reduce AI-related risk across the enterprise.

You'll gain practical guidance for improving visibility into AI-driven data activity, evaluating AI-enabled applications and vendors, and implementing controls that support AI adoption without sacrificing security.

What You'll Learn

  • Where AI tools, copilots, and agents are creating new security blind spots
  • How shadow AI is expanding the enterprise attack surface
  • Why visibility into AI-driven data access is becoming critical
  • How to reduce sensitive data exposure across AI systems and workflows
  • What security teams should evaluate in AI vendors, platforms, and embedded AI capabilities
  • Practical approaches for balancing AI innovation with security and governance requirements

Sep 16, 2026

Virtual / Online

Threat hunting is no longer just a niche skill—it’s a critical pillar of modern defense. Now in its second decade, the 2026 SANS Threat Hunting Survey delivers a comprehensive, vendor-neutral look at how organizations around the world are adapting their hunting strategies to match the speed, complexity, and stealth of today’s threats. This year’s report explores the maturation of threat hunting in the face of faster, stealthier adversaries. From credential abuse and malware-free intrusions to the hunt for lateral movement in cloud environments, defenders are evolving—and this survey shows how. Join us for an exclusive look at the key findings from the latest research, and discover how threat hunters are staying proactive, practical, and one step ahead.

What You’ll Learn

  • Top Threats: How teams are detecting malware-free intrusions, credential abuse, and lateral movement 
  • Cloud Hunting: Progress and pain points in multi-cloud environments 
  • AI in Hunting: Where AI helps, where it doesn’t, and what’s actually working 
  • Hunt Maturity: Benchmarks on tools, training, and metrics 
  • Lessons Learned: What works, what doesn’t, and how to stay ahead 

Why Register? By registering, you’ll gain:

  • Actionable benchmarks to measure your organization against industry peers. 
  • Practical strategies you can take back to your team immediately. 
  • 3 CPE credits for attending. 
  • Access to attend both live or the recorded session on your own time. 
  • Exclusive access to the full 2026 Threat Hunting Survey Insights report

Sep 21-26, 2026

Las Vegas, NV

Elevate your cybersecurity skillset at SANS Network Security 2026! Dive into an exhilarating week of intensive, top-tier training designed to sharpen your skills, whether you're just starting out or advancing your expertise. Engage directly with leading minds in the field through hands-on labs and real-world techniques, and gain insights that only face-to-face interactions can offer.

 

Connect with SANS faculty, participate in workshops exclusively offered in-person, and join a community of peers who are just as passionate as you are. From networking events to community-building activities, you’ll enjoy all-access, in-person only benefits that foster memorable and lasting connections.

Sep 22, 2026

Virtual / Online

This talk begins with a brief examination of recent breach data and the growing ecosystem of attacker tooling available through Dark Web marketplaces and Telegram channels, highlighting where OSINT and cyber threat intelligence teams should focus their monitoring efforts. We will then explore why multi-factor authentication (MFA) bypass attacks continue to succeed despite widespread adoption, examining both the technical and operational factors that make these attacks so effective.

The majority of the presentation will focus on Artificial Intelligence (AI) and its rapidly expanding role in modern offensive security. We will analyze how attackers are leveraging AI to dramatically increase the speed, scale, and sophistication of attacks, while also examining AI systems themselves as an emerging attack surface.

The session will demonstrate how AI can be applied as both a SAST and DAST capability for discovering and exploiting zero-day vulnerabilities in web applications, as well as its growing role in binary exploitation. Offensive innovation has historically outpaced defensive adaptation, and the adoption of AI is accelerating this imbalance. This talk provides practical insight into how the threat landscape is evolving and what security professionals must understand to keep pace.

If your next step is capability-building, SEC543: AI-Assisted Source Code Analysis and Exploitation for Penetration Testers teaches you how to map codebases faster, find what scanners miss, and generate validated exploit tooling with AI assistance.

Sep 23, 2026

Virtual / Online

Threat hunting is no longer just a niche skill—it’s a critical pillar of modern defense. Now in its second decade, the 2026 SANS Threat Hunting Survey delivers a comprehensive, vendor-neutral look at how organizations around the world are adapting their hunting strategies to match the speed, complexity, and stealth of today’s threats. This year’s report explores the maturation of threat hunting in the face of faster, stealthier adversaries. From credential abuse and malware-free intrusions to the hunt for lateral movement in cloud environments, defenders are evolving—and this survey shows how. Join us for an exclusive look at the key findings from the latest research, and discover how threat hunters are staying proactive, practical, and one step ahead.

What You’ll Learn

  • Top Threats: How teams are detecting malware-free intrusions, credential abuse, and lateral movement
  • Cloud Hunting: Progress and pain points in multi-cloud environments
  • AI in Hunting: Where AI helps, where it doesn’t, and what’s actually working
  • Hunt Maturity: Benchmarks on tools, training, and metrics
  • Lessons Learned: What works, what doesn’t, and how to stay ahead

Why Register? By registering, you’ll gain:

  • Actionable benchmarks to measure your organization against industry peers.
  • Practical strategies you can take back to your team immediately.
  • 3 CPE credits for attending.
  • Access to attend both live or the recorded session on your own time.
  • Exclusive access to the full 2026 Threat Hunting Survey Insights report

Oct 6, 2026

Virtual / Online

AI transformed business and IT security. Now it's crossing into OT, bringing the same efficiency gains, the same defensive potential, and the same adversarial capabilities into environments that were never designed to absorb them.

On October 5, 2026 at 10:30AM ET, SANS Certified Instructor Michael Hoffman and OPSWAT's Director of Product Marketing Matt Wiseman will share new survey data on how industrial organizations are encountering and defending against AI-enabled threats in their ICS/OT environments, from adaptive malware built to evade OT-native detection to AI systems now connected to the control systems themselves.

The session and corresponding paper will cover:

  • Which AI-enabled attack vectors OT security teams are actually seeing, including AI-assisted lateral movement from IT into OT networks and automated scanning of internet-exposed OT devices
  • The risk exposure created by cloud-connected AI systems with write-back access to control systems
  • How confident practitioners are that their current OT security tools can detect and respond to AI-driven attacks
  • What role AI should play in ICS/OT cybersecurity today, from analyst decision support to automated detection and alerting
  • What's limiting broader AI adoption for ICS/OT defense, including data quality constraints and operational disruption risk

Register now to see how your organization's exposure to AI-enabled OT threats compares to peers across critical infrastructure sectors.

Oct 7, 2026

Virtual / Online

Cloud sprawl, misconfigurations, shadow IT, third-party risk, and identity-driven threats—exposure management is now a defining challenge in cybersecurity. As digital environments expand, so does the complexity of defending them.

The 2026 SANS Exposure Management Survey explores how organizations are tackling this challenge. Join us for a webcast unveiling key findings from this global survey of cybersecurity leaders and practitioners.

You’ll get data-driven insights into how teams discover, assess, and reduce exposures—plus what’s working, where the gaps are, and how maturity is being measured.

What You'll Learn

  • How organizations are gaining visibility across cloud, hybrid, and third-party ecosystems
  • Which tools and techniques are helping teams prioritize exposures here automation and AI are making the biggest impact
  • How maturity is measured and how exposure management aligns with business goals
  • Common pain points and blind spots in modern exposure management programs
  • Cultural and organizational factors that influence success

Why Register? By registering, you’ll gain:

  • Actionable benchmarks to measure your organization against industry peers.
  • Practical strategies you can take back to your team immediately.
  • 3 CPE credits for attending.
  • Access to attend both live or the recorded session on your own time.
  • Exclusive access to the full 2026 Exposure Management Survey Insights report

Oct 15-22, 2026

Arlington, VA

All of DFIR. One Event.

Digital Forensics | Incident Response | Ransomware | Threat Hunting

The SANS DFIR Summit & Training is back—in a new city, a new season, and with our most in-depth program yet.

This year, the Summit has expanded to tackle today’s most challenging DFIR topics—from core digital forensics and incident response to focused deep dives in threat hunting and ransomware—through expert-led talks, open-source tool sessions, and more hands-on opportunities than ever before.

If staying sharp on the latest research, tools, and investigative tradecraft matters to you, this is where you need to be.

Summit: Oct 15-16 | Training: Oct 17-22

Oct 15, 2026

Virtual / Online

SANS 2026 DFIR Summit Solutions Track delivers a deep technical exploration of the tools, methodologies, and operational models driving next-generation digital forensics and incident response. Sessions focus on advanced evidence acquisition, host and network artifact analysis, memory forensics, cloud-native IR workflows, and the application of machine learning to accelerate triage and attribution. 

 Attendees will learn how to operationalize automation, standardize investigative pipelines, and integrate DFIR technologies into high-scale, distributed environments to improve precision, reduce dwell time, and harden enterprise response capabilities.

 What to Expect

  • Technical walkthroughs of emerging DFIR tooling—including endpoint telemetry pipelines, memory forensics frameworks, malware analysis sandboxes, and automated evidence extraction workflows.
  • Deep-dive case studies detailing attacker tradecraft, artifact correlation strategies, cross-host timeline reconstruction, and cloud IR techniques across AWS, Azure, and GCP.
  • Practical guidance and reference architectures for building scalable DFIR environments with automated triage, standardized enrichment, and integrated SOAR/EDR workflows.

Who Should Attend

  • DFIR practitioners, digital forensic examiners, threat hunters, and reverse engineers seeking advanced, tool-focused investigative techniques.
  • Incident response leads and SOC engineers responsible for building automated triage pipelines, forensic readiness strategies, and high-throughput investigation environments.
  • Security architects and platform engineers integrating DFIR telemetry, EDR/XDR data, and cloud-native artifacts into centralized analysis and response systems.
  • Organizations evaluating next-gen DFIR platforms, scaling IR operations, or adopting automation and ML-driven investigative workflows.

Oct 21, 2026

Virtual / Online

Cloud security is no longer optional—it's a moving target. As organizations accelerate multi-cloud adoption, they face growing complexity, evolving threats, and rising expectations around compliance, visibility, and control.

The 2026 SANS Cloud Security Research Survey brings together insights from security leaders and practitioners worldwide. This year’s study examines the current state of cloud security, highlighting key challenges, top threats, and the tools organizations are using—or wish they had—to secure cloud environments at scale.

Join us for this exclusive webcast to explore the survey findings, gain practical insights, and benchmark your organization’s approach to cloud security.

What You’ll Learn

  • Top Cloud Threats in 2026: Credential theft, misconfigurations, ransomware, and more
  • Tool Adoption Trends: CNAPP, SSE, IAM—who's using what, and how well it's working
  • DevSecOps Integration: How teams are embedding security earlier in the cloud development cycle
  • Compliance & Governance: Strategies to keep up with expanding regulatory demands
  • AI in Cloud Security: Emerging use cases and buyer sentiment around AI-driven tools
  • Gaps & Opportunities: What the industry still lacks—and where investment is headed next

Why Register? By registering, you’ll gain:

  • Actionable benchmarks to measure your organization against industry peers.
  • Practical strategies you can take back to your team immediately.
  • 3 CPE credits for attending.
  • Access to attend both live or the recorded session on your own time.
  • Exclusive access to the full 2026 Cloud Survey Insights report

Nov 4, 2026

Virtual / Online

Automation promised to free security teams from the alert treadmill, but for many organizations, it created a new one. Join Dave Shackleford, SANS Instructor, on November 4, 2026 at 10:30 AM EST where he will share survey data from practitioners across industries on what the transition from automation to genuine agency actually looks like in 2026.

Specifically, he will speak to how agentic threats are landing on the radar, the barriers stalling SOC autonomy, and how teams are weighing the tradeoffs of letting AI act independently in production environments. Beyond the technology questions, the data also dives into how organizations plan to reshape their teams as AI absorbs some of the work that currently fills an analyst's day.

Nov 10, 2026

Virtual / Online

As industrial environments become more connected and threats more advanced, the challenge of securing ICS and OT systems grows more urgent. How are asset owners responding—and where are the biggest gaps?

Join us to discuss insights from SANS 9th annual State of ICS/OT Security Survey. This trusted industry research captures how organizations across sectors are evolving their industrial cybersecurity strategies in response to regulatory pressures, emerging threats, and operational demands.

Building on key findings from 2025—like improvements in incident response and IT-OT alignment—this year’s survey dives deeper into visibility across the ICS cyber kill chain, the growing role of cyber-informed engineering (CIE), and the need for resilience-focused security controls.

Whether you manage industrial assets, influence cyber strategy, or lead incident response, this session delivers the benchmarks and insights you need to make informed decisions in 2026 and beyond.

What You’ll Learn

  • How organizations are improving visibility across the ICS Cyber Kill Chain to detect and respond to threats earlier
  • What cyber-informed engineering (CIE) looks like in practice—and how it’s being used to bridge safety, reliability, and cybersecurity
  • Where key gaps and dependencies exist in OT-specific security controls and architectures
  • How to maximize the ROI of cybersecurity investments in industrial settings
  • Which areas saw progress in 2025, including response times, visibility, and IT-OT collaboration—and where critical misalignments remain how standards, regulations, and threat intelligence are shaping ICS/OT cyber programs moving forward
  • Real-world safety and reliability impacts of modern ICS threats—and what your peers are doing to mitigate them

Why Register? By registering, you’ll gain:

  • Actionable benchmarks to measure your organization against industry peers.
  • Practical strategies you can take back to your team immediately.
  • 3 CPE credits for attending.
  • Access to attend both live or the recorded session on your own time.
  • Exclusive first access to the full 2026 ICS/OT Survey Insights report

Nov 17, 2026

Virtual / Online

SANS Fall Cyber Solutions Fest 2026: Emerging Technologies Track explores the cutting edge of security innovation as organizations race to secure increasingly complex digital ecosystems. This track highlights breakthrough capabilities in AI-driven defense, autonomous security operations, quantum-resilient architectures, next-gen cloud and CNAPP frameworks, and advanced identity protection. Attendees will gain deep insights into how emerging tools, platforms, and methodologies are reshaping modern security strategies and accelerating detection, response, and resilience.

Designed for practitioners, leaders, and technology evaluators, this track delivers practical, vendor-agnostic guidance from top SANS experts and real-world case studies from the front lines. Sessions will showcase how emerging technologies can be operationalized at scale, reduce analyst workload, improve visibility across hybrid environments, and help organizations prepare for the next wave of threats. Join us to understand what’s coming, what matters, and how to build a future-ready security posture.

Why Register

  • See what’s next first—gain early insight into the technologies shaping security in 2026 and beyond.
  • Hear from top SANS and industry experts delivering practical, unbiased guidance you can apply immediately.
  • Evaluate emerging solutions with real-world case studies that separate hype from reality.
  • Strengthen your strategy with actionable frameworks for adopting AI, autonomous security, quantum-resilient design, and more.

Nov 18, 2026

Virtual / Online

The SANS Fall Cyber Solutions Fest 2026: Identity Security and Zero Trust Track delivers a deep technical examination of identity as the modern attack surface. As adversaries exploit misconfigured IdPs, weak federation trust, poisoned authentication flows, and over-permissioned service principals, this track analyzes the mechanics of identity compromise across multiple attack surfaces, and hybrid environments. Sessions will dissect novel identity threat vectors, including token replay and manipulation, MFA fatigue attacks, conditional access bypass techniques, and identity infrastructure persistence. Practitioners will gain prescriptive guidance on securing authentication pipelines, hardening federation architectures, and monitoring high-risk identity events with advanced telemetry.

Anchored in Zero Trust architecture, the track focuses on continuous policy enforcement, adaptive authentication, micro-segmentation, and automated privilege reduction across distributed systems. Experts will present reference architectures and implementation patterns for identity-centric Zero Trust deployments, covering identity threat detection and response (ITDR), identity-driven segmentation, policy decision point/orchestration design, and integration of identity context into SIEM, XDR, and SOAR workflows. Attendees will leave with actionable techniques for securing machine identities, enforcing least privilege at scale, validating trust signals in real time, and operationalizing Zero Trust across multi-cloud and SaaS ecosystems.

View all

Events We Are Sponsoring

Sep 22-24, 2026

Huntsville, AL

National Cyber Summit is the nation’s most innovative cyber security-technology event, offering unique educational, collaborative and workforce development opportunities for industry visionaries and rising leaders. NCS offers more value than similar cyber conferences with diverse focus-areas, premier speakers, and unmatched accessibility. Our core focus is on three things: education, collaboration and innovation.

Oct 8, 2026

Tysons, VA

Uniting Women in Cyber (UWIC), hosted by The Cyber Guild, brings together women cybersecurity professionals, technology leaders, government officials, and industry experts to build connections, share expertise, and advance women’s leadership in the cybersecurity field. The event focuses on the evolving cyber threat landscape, leadership development, professional growth, and creating stronger networks across the cybersecurity community.
View all

Events Where We Are Exhibiting

Sep 22-24, 2026

Huntsville, AL

National Cyber Summit is the nation’s most innovative cyber security-technology event, offering unique educational, collaborative and workforce development opportunities for industry visionaries and rising leaders. NCS offers more value than similar cyber conferences with diverse focus-areas, premier speakers, and unmatched accessibility. Our core focus is on three things: education, collaboration and innovation.
View all