SANS Institute - Experts & Thought Leaders

Latest SANS Institute news & announcements

Infosecurity Europe 2025 masterclasses by SANS

Infosecurity Europe, the most influential information security event, which runs from 3-5 June 2025, has announced the launch of ‘Infosecurity Europe Masterclasses, powered by SANS Institute,’ an exclusive new training initiative designed to equip cybersecurity professionals with hands-on, practical skills.  Developed for Infosecurity Europe 2025, the Masterclasses will offer three deep-dive sessions covering Digital Forensics, Cloud Security, and Security Culture. Digital Forensics and Cloud Security Digital Forensics and Cloud Security Masterclasses will be held on 3rd June, with the Security Masterclass Each masterclass will be delivered by a SANS-certified instructor and will take place in the South Gallery Rooms at ExCeL London during the event. The Digital Forensics and Cloud Security Masterclasses will be held on Tuesday, 3rd June, with the Security Culture Masterclass on Wednesday, 4th June.  Partnership with SANS Institute Introducing these masterclasses highlights the growing demand for specialised training as organisations contend with an increasingly complex threat landscape. Infosecurity Europe has long been a hub for industry pioneers to share knowledge, explore innovative solutions, and foster collaboration. The partnership with SANS Institute builds on this and enhances the event's educational offering.  Cybersecurity professionals with the practical skills "Partnering with Infosecurity Europe and bringing hands-on masterclasses to this year’s event is a pivotal moment to elevate security readiness across the UK and Europe. This collaboration will support cybersecurity professionals with the practical skills they need to stay ahead of emerging threats." "Continuous learning is essential in an industry that evolves at such a rapid pace, and by providing hands-on, immersive experiences, we are ensuring that security practitioners can apply cutting-edge techniques in real-world scenarios to make an immediate impact within their organisations," said John Davis, UK Director, SANS Institute. Infosecurity Europe’s 2025 Cybersecurity Trends Report Digital Forensics Masterclass will be led by SANS Certified Instructor Kathryn Hedley on Tuesday, 3rd June The masterclasses are designed to deliver practical, actionable insights and are tailored to help cybersecurity professionals tackle modern challenges head-on. The Digital Forensics Masterclass will be led by SANS Certified Instructor Kathryn Hedley on Tuesday, 3rd June, and will provide practical experience in decoding file signatures, data recovery techniques, and forensic disk image exploration. Attendees will learn how to extract and interpret critical digital evidence across platforms, equipping them with the skills to handle complex forensic investigations. This session aligns closely with industry demand, as over 50 per cent of organisations plan to increase investment in incident response and forensics according to Infosecurity Europe’s 2025 Cybersecurity Trends Report. Cloud security investment With 65 percent of cybersecurity pioneers also planning an increase in cloud security investment, the Cloud Security Masterclass on Tuesday, 3rd June, is key to guiding participants through advanced cloud security practices. Hosted by SANS Certified Instructor Simon Vernon, topics will include securing logging setups in Azure and preventing remote code execution. Infosecurity Europe’s report   Infosecurity Europe’s report shows respondents citing a lack of accountability and identifying communication gaps On day two, Wednesday 4th June, the Security Culture Masterclass will be fronted by SANS Certified Instructor John Scott and directly addresses key challenges faced by organisations. Infosecurity Europe’s report shows respondents citing a lack of accountability and identifying communication gaps between departments as major obstacles to building a strong cybersecurity culture. This interactive session will address these challenges and more with a focus on embedding a resilient security culture within organisations.  New Infosecurity Europe Masterclasses Participants will engage in the Cyber42 Game Day simulation, where they will navigate real-world decision-making scenarios to strengthen their leadership and cultural impact.  Brad Maule-ffinch, Event Director at Infosecurity Europe, commented: "We are thrilled to be partnering with SANS Institute on our new Infosecurity Europe Masterclasses. Delivering high-quality, relevant content that meets the evolving needs of cybersecurity professionals is a core commitment for us, and SANS Institute is the ideal partner to help achieve this." "Their dedication to providing practical, actionable insights that attendees can immediately apply to their roles aligns perfectly with our vision for the Masterclasses, making this collaboration a perfect fit." Challenges in cybersecurity Infosecurity Europe 2025 will celebrate its 30th anniversary by bringing together industry experts, practitioners, and innovators to discuss and address the most pressing challenges in cybersecurity. Alongside the masterclasses, attendees will have access to a comprehensive programme of keynotes, panel discussions, and interactive workshops. Spaces for the masterclasses are limited, and early booking is recommended to secure a place and are priced at £299 + VAT, with lunch provided.

AI risks in security: Insights from HackerOne survey

HackerOne, the pioneer in human-powered security, revealed data that found 48% of security professionals believe AI is the most significant security risk to their organisation. Ahead of the launch of its annual Hacker-Powered Security Report, HackerOne revealed early findings, which include data from a survey of 500 security professionals. Review of AI implementations AI red teaming offers this type of external review through the global security researcher community When it comes to AI, respondents were most concerned with the leaking of training data (35%), unauthorised usage of AI within their organisations (33%), and the hacking of AI models by outsiders (32%).  When asked about handling the challenges that AI safety and security issues present, 68% said that an external and unbiased review of AI implementations is the most effective way to identify AI safety and security issues. AI red teaming offers this type of external review through the global security researcher community, who help to safeguard AI models from risks, biases, malicious exploits, and harmful outputs. AI security and safety best practices “While we’re still reaching industry consensus around AI security and safety best practices, there are some clear tactics where organisations have found success,” said Michiel Prins, co-founder at HackerOne. “Anthropic, Adobe, Snap, and other pioneering organisations all trust the global security researcher community to give expert third-party perspective on their AI deployments.” Impact of AI on cybersecurity Further research from a HackerOne-sponsored SANS Institute report studied the impact of AI Further research from a HackerOne-sponsored SANS Institute report explored the impact of AI on cybersecurity and found that over half (58%) of respondents predict AI may contribute to an “arms race” between the tactics and techniques used by security teams and cyber criminals.  The research also found optimism around the use of AI for security team productivity, with 71% reporting satisfaction from implementing AI to automate tedious tasks. However, respondents believed AI productivity gains have benefitted adversaries and were most concerned with AI-powered phishing campaigns (79%) and automated vulnerability exploitation (74%). Best applications for AI “Security teams must find the best applications for AI to keep up with adversaries while also considering its existing limitations — or risk creating more work for themselves,” said Matt Bromiley, Analyst at The SANS Institute. “Our research suggests AI should be viewed as an enabler, rather than a threat to jobs. Automating routine tasks empowers security teams to focus on more strategic activities.” Deeper vulnerability insights HackerOne’s AI-powered co-pilot Hai continues to free up time for security teams by automating tasks HackerOne’s AI-powered co-pilot Hai continues to free up time for security teams by automating tasks and offering deeper vulnerability insights. These benefits drive Hai’s adoption, which has grown 150% since launch and saves security teams an average of five hours of work per week. AI-focused products also continue to drive HackerOne’s business, with AI Red Teaming growing 200% quarter over quarter in Q2 and a 171% increase in security programs adding AI assets into scope. Survey of security professionals Test the AI risk readiness with this interactive quiz and read the full SANS AI 2024 Survey and methodology. The full Hacker-Powered Security Report will be released this fall. The survey of security professionals was conducted by Opinion Matters and surveyed 500 security professionals across the US and Europe. The survey was conducted between July 31, 2024, and August 6th, 2024.

NCSC and SANS Institute launch fourth annual CyberThreat Summit in London

The National Cyber Security Centre (NCSC) and The SANS Institute have announced details of the fourth edition of CyberThreat, a technical and interactive Summit which will be hosted in-person at the Novotel London West, Hammersmith, London, and available virtually on Monday 20th and Tuesday 21st November 2023.  CyberThreat 2023 One of the largest cyber security conferences in the UK, CyberThreat 2023 will bring together the global cybersecurity community for exclusive keynotes and talks from pioneering industry experts, challenges to test and hone skills including a Capture the Flag (CTF) and hackathons, and opportunities for knowledge and experience sharing with industry peers. The event is a vital chance for participants to collaborate and network with some of the best minds in cyber security. CyberThreat 2022 CyberThreat has also been host to presentations by Google Cloud, Bank of England, PwC, MITRE, and Microsoft The previous CyberThreat conference featured industry-pioneering keynote speakers, which included Yevheniia Volivnyk and Yevhen Bryksin, Chief and Deputy Chief respectively of the Computer Emergency Response Team of Ukraine (CERT-UA), Viktor Zhora, Deputy Chairman and Chief Digital Transformation Officer for The State Service of Special Communication and Information Protection of Ukraine, and Gordon Corera, Security Correspondent, BBC News. CyberThreat has also been host to presentations by many major organisations including Google Cloud, Bank of England, PwC, MITRE, and Microsoft. Event registration Through the partnership with NCSC, several delegate places will be made available to public sector employees free of charge. The conference is also an opportunity for UK schools to attend and experience what CyberThreat has to offer. Sign up for the event on the SANS website. Complimentary and discounted tickets are also up for grabs for the winners of unique pre-registration online challenges and, at the event, there will be further opportunities to win, including a free SANS course for the CTF winners.  Cyber security event By sharing cutting-edge techniques and new solutions to ongoing problems, we will be best equipped" James Lyne, CTO at SANS, said, "CyberThreat is the pioneering UK cyber security event for both public and private worlds, providing a unique opportunity for professionals and practitioners to share their experiences, acquire new technical skills and learn from world-class experts."   “As technology advances and becomes even more embedded into our lives, the threat landscape scales to the same degree. Cybercriminals are employing novel and intuitive techniques, often creating truly sophisticated and impressive schemes. By sharing cutting-edge techniques and new solutions to ongoing problems, we will be best equipped to tackle these threats together as a community."  Discuss, debate, and demonstrate innovation Paul Chichester, Director of Operations, NCSC said, “This year’s CyberThreat promises to be a great occasion which will see global pioneers in cyber security come together to discuss, debate, and demonstrate innovative solutions to overcome challenges facing the online world." “We’re looking forward to partnering with SANS to build on the successes of previous summits to ensure that the UK remains a world leader in cyber security innovation.”

Quick poll
Which trend do you think will define physical security in the next 5 years?