Group Purchasing
Group Purchasing

ICS456: Essentials for NERC Critical Infrastructure Protection

ICS456Industrial Control Systems Security
  • 5 Days (Instructor-Led)
  • 31 Hours (Self-Paced)
Course authored by:
Tim ConwayTed GutierrezFelix Schallock
Tim Conway, Ted Gutierrez & Felix Schallock
Course authored by:
Tim ConwayTed GutierrezFelix Schallock
Tim Conway, Ted Gutierrez & Felix Schallock
  • GIAC Critical Infrastructure Protection (GCIP)
  • 31 CPEs

    Apply your credits to renew your certifications

  • In-Person, Virtual or Self-Paced

    Attend a live, instructor-led class at a location near you or remotely, or train on your time over 4 months

  • Essential Skill Level

    Course material is for individuals with an understanding of IT or cyber security concepts

  • 23 Hands-On Lab(s)

    Apply what you learn with hands-on exercises and labs

Close the gap between NERC CIP compliance and real-world security. Learn hands-on skills to protect the Bulk Electric System and strengthen your preparation for both audits and emerging threats.

Course Overview

ICS456: Essentials for NERC Critical Infrastructure Protection offers practical guidance that translates regulatory policy into action. The evolving landscape of cybersecurity threats and regulatory pressure has made compliance with the North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP) standards more than just a checkbox exercise—it is a complex, high-stakes challenge for organizations operating the Bulk Electric System. Designed to cut through the confusion for operations, IT/OT security, and compliance professionals alike, the course demystifies NERC CIP requirements, aligns them with real-world industrial control system (ICS) environments, and equips teams to better understand risks, support compliance efforts, and build a culture of cyber resilience. If supporting audit preparedness while defending critical infrastructure is your mission, ICS456 delivers the knowledge and tools to approach it with confidence.

NERC CIP Essentials: Power Grid Security Compliance

ICS456 goes beyond the basics of NERC CIP training by providing actionable strategies for compliance and security. You will gain a deep understanding of the role of the Federal Energy Regulatory Commission (FERC), North American Electric Reliability Corporation (NERC), and Regional Entities in enforcing reliability standards. The course teaches multiple approaches for identifying and categorizing Bulk Electric System (BES) Cyber Systems, ensuring that asset owners can accurately scope and apply requirements to their unique environments. More than just a compliance course, ICS456 bridges the gap between regulatory requirements and real-world security implementation. You will explore practical strategies for securing industrial control systems (ICS) and operational technology (OT), balancing cybersecurity best practices with the realities of compliance. This knowledge is valuable for professionals seeking a deeper understanding of critical infrastructure protection or preparing for the GCIP certification as part of their professional development.

Unlike other NERC CIP courses that focus only on the regulations, ICS456 immerses you in hands-on learning with 23 labs utilizing three dedicated virtual machines. These labs cover critical skills such as securing workstations, performing digital forensics, and even lock picking—because securing physical access is just as important as protecting digital assets. Our students consistently report that these interactive exercises reinforce learning and prepare them to apply their knowledge immediately on the job. By the end of this course, you will know not just what NERC CIP requires, but how to apply its safeguards in practice to support compliance efforts and strengthen the security posture of the grid.

Author Statement

"The SANS ICS456: NERC Critical Infrastructure Protection Essentials course was developed by SANS ICS team members with extensive electric industry experience, including former Registered Entity Primary Contacts, a former NERC officer, and a Co-Chair of the NERC CIP Interpretation Drafting Team. Together the authors bring real-world, practitioner experience gained from developing and maintaining NERC CIP and NERC 693 compliance programs and actively participating in the standards development process."

- Tim Conway and Ted Gutierrez

What You'll Learn

  • Understand the structure and authority of the NERC regulatory framework and how CIP standards align with broader BES reliability goals
  • Acquire accurate BES Cyber System identification, categorization, and impact rating strategies to better understand and manage compliance considerations.
  • Learn how to interpret nuanced NERC CIP terminology and apply standards appropriately in complex ICS and OT environments
  • Apply practical approaches to implementing effective cyber and physical access controls, monitoring, and logical protections
  • Master system and configuration management strategies, including timelines for patching, vulnerability assessments, and procedural controls
  • Gain techniques for maintaining a sustainable CIP program, including personnel training, risk assessments, and recurring task management
  • Practice proven methods to prepare audit-ready compliance evidence and effectively support audit engagements

Business Takeaways

  • Reduce compliance risk through better program management
  • Enhance security posture beyond minimum requirements
  • Improve audit readiness and defensible documentation
  • Better ROI on security technology investments
  • Streamline recurring compliance activities
  • Support proactive approaches to compliance.
  • Balance compliance and operational security needs

Course Syllabus

Explore the course syllabus below to view the full range of topics covered in ICS456: Essentials for NERC Critical Infrastructure Protection.

Section 1Asset Identification and Governance

Develop understanding of electric sector regulatory structure and how Critical Infrastructure Protection (CIP) standards fit into the reliability framework. Explore Bulk Electric System (BES) Cyber Asset identification approaches and the importance of governance controls.

Topics covered

  • Regulatory History and NERC Model
  • NERC Reliability Standards
  • Key Terms and Definitions
  • BES Cyber System Categorization
  • Security Management Controls

Labs

  • Virtual Machine Setup
  • Protocol Analysis with Wireshark
  • Facility Environment Assessment
  • CSET Facility Evaluation

Overview

A transition is underway from NERC CIP programs that are well-defined and understood to a new CIP paradigm that expands its scope into additional environments and adds significantly more complexity. On day 1, students will develop an understanding of the electric sector’s regulatory structure and history as well as an appreciation for how the CIP Standards fit into the overall framework of the reliability standards. Key NERC terms and definitions related to NERC CIP are reviewed using realistic concepts and examples that prepare students to better understand their meaning. We will explore multiple approaches to BES Cyber Asset identification and learn the critical role of strong management and governance controls. We will also examine a series of architectures, strategies, and difficult compliance questions in a way that highlights the reliability and the cybersecurity strengths of particular approaches.

Full Lab Details

  • Virtual Machine Setup: Windows, Kali Linux, and Security Onion VM will be utilized throughout the five-day course
  • Checkpoint exercise: Ensure familiarity with the NERC website for locating standards, and cover entity registrations, the Functional Model, and a glossary of terms
  • Protocol Primer: Use Wireshark to analyze packet captures
  • Analysis of Facility Environments: Walk through assets owned by a fictitious company to determine in-scope assets and approaches to generation segmentation
  • CSET Facility Assessment: Utilize the ICS-CERT's Cybersecurity Evaluation Tool (CSET) to perform a self-assessment on a model network compared to industry standards, including NERC CIP

Full Topic Details

  • Regulatory History and Overview
  • NERC Functional Model
  • NERC Reliability Standards
  • CIP History
  • Terms and Definitions
  • CIP-002: BES Cyber System Categorization
  • CIP-003: Security Management Controls

Section 2Access Control and Monitoring

Gain proficiency in the physical and cyber access controls that form the foundation of effective security programs. Learn practical implementations of firewalls, proxies, gateways, and IDS. Understand strengths and weaknesses of physical security controls through hands-on exercises.

Topics covered

  • Electronic Security Perimeter(s)
  • Interactive Remote Access
  • External Routable Communication
  • Physical Security Planning
  • Visitor Control Programs

Labs

  • Network Analysis and Visualization
  • Firewall Rule Development
  • ICS Signatures and Alerting
  • Physical Control Breach Techniques
  • Security Review and Response

Overview

Strong physical and cyber access controls are at the heart of any good cybersecurity program. On day 2 we move beyond the what of CIP compliance to understanding the why and the how. Firewalls, proxies, gateways, IDS, and more - you'll learn where and when they help as well as practical implementations to consider and designs to avoid. Physical protection includes more than fences, and you'll learn about the strengths and weaknesses of common physical controls and monitoring schemes. Labs will re-inforce the learnings throughout the day and will introduce architecture review and analysis, firewall rules, IDS rules, compliance evidence demonstration, and physical security control reviews.

Full Lab Details

  • Wireshark Analysis and Network Visualization: Utilize Wireshark to analyze real packet captures from an ICS/OT environment and introduce the Dragos Security CyberLens tool, which can be used to passively discover ICS/OT assets and visualize their network placement and communications
  • Firewall Rule Development and Analysis: Utilize the Common Open Research Emulator (CORE) to emulate a live network and to understand the effect of firewall rules on the network communications
  • ICS Signatures and Alerting: Utilize the Squil (pronounced squeal) network security monitoring tool to create event driven IDS alerts when replaying pcap packet captures from an ICS/OT environment
  • Breach of Physical Controls: Learn the basics of lock picking with your very own clear padlock and pick tool set
  • Physical Security Review and Response Exercise: Analyze physical security camera images and perimeter access logs to identify potential security and compliance problems

Full Topic Details

  • CIP-005: Electronic Security Perimeter(s)
  • Interactive Remote Access
  • External Routable Communication and Electronic Access Points
  • CIP-006: Physical Security of BES Cyber Systems
  • Physical Security Plan
  • Visitor Control Programs
  • PACS Maintenance and Testing
  • CIP-014: Physical Security

Section 3System Management

Address compliance challenges with CIP-007 and CIP-010 through system design and architecture approaches. Explore system security management requirements and configuration change management techniques through labs focused on implementation and testing.

Topics covered

  • Physical and Logical Ports
  • Patch Management
  • Malicious Code Prevention
  • Account Management
  • Configuration Change Management

Labs

  • Windows System Assessment
  • Validating Findings & Impact
  • System Hardening Techniques
  • System Log Management
  • Vulnerability Assessment Tools

Overview

CIP-007 has consistently been one of the most violated standards going back to CIP version 1. With the CIP Standards moving to a systematic approach with varying requirement applicability based on a system impact rating, the industry now has new ways to design and architect system management approaches. Throughout day 3, students will dive into CIP-007. We'll examine various Systems Security Management requirements with a focus on implementation examples and the associated compliance challenges. We'll also cover the CIP-010 requirements for configuration change management and vulnerability assessments that ensure systems are in a known state and under effective change control. We'll move through a series of labs that reinforce the topics covered from the perspective of the CIP practitioner responsible for implementation and testing.

Full Lab Details

  • Windows System Assessment: Utilize tools including Windows Baseline Security Analyzer, NetStat, and Windows Firewall Configurator to analyze the security posture of a provided Windows VM
  • Validating Findings and Demonstrating Impact: Utilize the provided Kali Linux VM and favorite red-team tools such as Cain & Able, remote desktop, and Metasploit Framework to gain unauthorized access to the Windows VM, demonstrating the risks of insecure configuration
  • System Hardening: Learn from the red team's action and use a number of native Windows tools to harden the Windows VM and prevent future exploitation
  • System Log Management: Use Splunk Enterprise to analyze a Windows event log to identify events of interest
  • Basic Change Management from the Command Line: Use hashing techniques and Tripwire to identify system file and configuration changes
  • Vulnerability Assessment Tool Capability: Gain familiarity with Nmap, SNMP, and the OpenVAS vulnerability scanning framework

Full Topic Details

  • CIP-007: System Management
  • Physical and Logical Ports
  • Patch Management
  • Malicious Code Prevention
  • Account Management
  • CIP-010: Configuration Change Management and Vulnerability Assessments
  • Change Management Program
  • Baseline Configuration Methodology
  • Change Management Alerting/Prevention

Section 4Information Protection and Response

Learn to build effective awareness programs that reinforce information protection and cybersecurity training. Understand incident response roles and disaster recovery requirements while mastering communication protocols and data preservation techniques.

Topics covered

  • Security Awareness Programs
  • Personnel Risk Assessment
  • Information Protection
  • Incident Response Planning
  • Recovery Plan Development

Labs

  • Information Leakage Awareness
  • Steganography Detection
  • Incident Response Tabletop Exercise
  • Forensic Data Preservation
  • Yara Introduction

Overview

Education is key to every organization's success with NERC CIP, and ICS456 graduates will be knowledgeable advocates for CIP when they return to their place of work. Regardless of their role, students can be a valued resource to their organization's CIP-004 training program and the CIP-011 information protection program. Students will be ready with resources for building and running strong awareness programs that reinforce the need for information protection and cybersecurity training. On day 4, we'll examine CIP-008 and CIP-009, covering identification, classification communication of incidents, and the various roles and responsibilities needed in an incident response or a disaster recovery event. Labs will introduce tools to ensure file integrity and the sanitization of files to be distributed, how to best utilize and communicate with the E-ISAC, and how to preserve incident data for future analysis.

Full Lab Details

  • Information Leakage Awareness: Walk through creating a Shodan account and using it to discover all sorts of interesting Internet-connected devices
  • Steganography Lab: Use the S-Tools application to conceal and identify data hidden in plain sight in order to understand the risk of data exfiltration in your environment
  • Yara Introduction: Learn the basics of Yara, the "Pattern Matching Swiss Knife for Malware," utilizing indicators of compromise (IOC's) to detect malware in memory images
  • Incident Response TTX: Walk through a tabletop exercise that you can take back to your organization and play with your larger team to test incident response capability and security policy/plan effectiveness
  • Forensic Data Preservation: Use FireEye's free Redline tool to learn how to collect and analyze forensic data and the FTL Imager tool to create a system image for data preservation

Full Topic Details

  • CIP-004: Personnel and Training
  • Security Awareness Program
  • CIP Training Program
  • PRA Evaluation Process
  • CIP-011: Information Protection
  • Information Protection Program
  • Data Sanitization
  • CIP-008: Incident Reporting and Response Planning
  • Incident Response Plan/Testing
  • Reporting Requirements
  • CIP-009: Recovery Plans for BES Cyber Systems
  • Recovery Plans
  • System Backup

Section 5The CIP Process

Master key components of an effective CIP compliance program including standards development, violation penalties, and RAI processes. Learn to prepare for audits through gap analysis, culture building, and self-reporting strategies.

Topics covered

  • Compliance Process Maintenance
  • Audit Preparation Techniques
  • Standards Development Process
  • Future CIP Directions
  • Violation Case Studies

Labs

  • Auditor Tools & NP-View Analysis
  • PowerShell Automation
  • Audit Simulation Exercise
  • DOE C2M2 Assessment
  • Blue Team-Red Team Approaches

Overview

On the final course day students will learn the key components for running an effective CIP compliance program. We will review the NERC processes for standards development, violation penalty determination, Requests for Interpretation, and recent changes stemming from the Reliability Assurance Initiative. Additionally, we'll identify recurring and audit-related processes that keep a CIP compliance program on track: culture of compliance, annual assessments, gap analysis, TFE's, and self-reporting. We'll also look at the challenge of preparing for NERC audits and provide tips to be prepared to demonstrate the awesome work your team is doing. Finally, we'll look at some real-life CIP violations and discuss what happened and the lessons we can take away. At the end of day 5, students will have a strong call to action to participate in the on-going development of CIP within their organization and in the industry overall as well as a sense that CIP is do-able! Labs on day 5 will cover DOE C2M2, audit tools, and an audit-focused take on a "blue team - red team" exercise.

Full Lab Details

  • Auditor Tools: NERC CIP auditors use NP-View to analyze their environment, and you should too! In this lab you will analyze firewall configurations for an example electric entity to determine and visualize network communications
  • Power Shell: Learn the basics and get an appreciation for the power of PowerShell for task automation and configuration management
  • Auditor/Defender: Whether you play the role of auditor or audited entity, this exercise will challenge your NERC CIP knowledge and ability to present material to tell a compelling story of compliance

Full Topic Details

  • CIP Processes for Maintaining Compliance
  • Preparing for an Audit
  • Audit Follow-Up
  • CIP Industry Activities
  • Standards Process
  • CIP of the Future

Things You Need To Know

Important! Bring your own system configured according to these instructions.

A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will not be able to fully participate in hands-on exercises in your course. Therefore, please arrive with a system that meets all of the specified requirements.

Back up your system before class. Better yet, use a system without any sensitive/critical data. SANS is not responsible for your system or data.

Mandatory System Hardware Requirements

  • CPU: 64-bit Intel i5/i7 (8th generation or newer), or AMD equivalent. A x64 bit, 2.0+ GHz or newer processor is mandatory for this class.
  • CRITICAL: Apple Silicon devices cannot perform the necessary virtualization and therefore cannot in any way be used for this course.
  • BIOS settings must be set to enable virtualization technology, such as "Intel-VTx" or "AMD-V" extensions. Be absolutely certain you can access your BIOS if it is password protected, in case changes are necessary.
  • 8GB of RAM or more is required.
  • 100GB of free local hard drive storage space or more is required. It is not recommended to rely on external storage or synced storage like one drive.
  • At least one available USB 3.0 Type-A port. A Type-C to Type-A adapter may be necessary for newer laptops. Some endpoint protection software prevents the use of USB devices, so test your system with a USB drive before class.
  • Wireless networking (802.11 standard) is required. There is no wired Internet access in the classroom.
  • SANS has begun providing printed materials in PDF and Web format (electronic workbook). In this new environment, a second monitor and a tablet device can be helpful by keeping the class materials visible while the instructor is presenting or while you are working on lab exercises.

Mandatory Host Configuration and Software Requirements

  • Your host operating system must be the latest version of Windows 10, Windows 11.
  • Fully update your host operating system and hardware drivers prior to the class to ensure you have the right drivers and patches installed.
  • Linux hosts are not supported in the classroom due to their numerous variations. If you choose to use Linux as your host, you are solely responsible for configuring it to work with the course materials and/or VMs.
  • Local Administrator Access is required. (Yes, this is absolutely required. Don't let your IT team tell you otherwise.) If your company will not permit this access for the duration of the course, then you should make arrangements to bring a different laptop.
  • You should ensure that antivirus or endpoint protection software is disabled, fully removed, or that you have the administrative privileges to do so. Many of our courses require full administrative access to the operating system and these products can prevent you from accomplishing the labs.
  • Any filtering of egress traffic may prevent accomplishing the labs in your course. Firewalls should be disabled or you must have the administrative privileges to disable it.
  • Download and install VMware Workstation Pro 16.2.X+ (for Windows 10 hosts), VMware Workstation Pro 17.0.0+ (for Windows 11 hosts) prior to class beginning. 
  • On Windows hosts, VMware products might not coexist with the Hyper-V hypervisor. For the best experience, ensure VMware can boot a virtual machine. This may require disabling Hyper-V. Instructions for disabling Hyper-V, Device Guard, and Credential Guard are contained in the setup documentation that accompanies your course materials.
  • Download and install 7-Zip (for Windows Hosts) or Keka (for macOS hosts). These tools are also included in your downloaded course materials.

Your course media is delivered via download. The media files for class can be large. Many are in the 40-50GB range, with some over 100GB. You need to allow plenty of time for the download to complete. Internet connections and speed vary greatly and are dependent on many different factors. Therefore, it is not possible to give an estimate of the length of time it will take to download your materials. Please start your course media downloads as soon as you get the link. You will need your course media immediately on the first day of class. Do not wait until the night before class to start downloading these files.

Your course materials include a "Setup Instructions" document that details important steps you must take before you travel to a live class event or start an online class. It may take 30 minutes or more to complete these instructions.

If you have questions about the laptop specifications, please contact customer service.

ICS456 training is recommended for a diverse range of individuals, including:

Individuals in the following roles with CIP responsibilities:

  • IT and OT (ICS) cybersecurity
  • Field support personnel
  • Security operations
  • Incident response
  • Compliance staff
  • Team leaders
  • Governance
  • Vendors / Integrators
  • Auditors

The GIAC Critical Infrastructure Protection (GCIP) certification validates that professionals who access, support and maintain critical systems have an understanding of the regulatory requirements of NERC CIP as well as practical implementation strategies.

  • BES cyber system identification and strategies for lowering their impact rating
  • Nuances of NERC defined terms and CIP standards applicability
  • Strategic implementation approaches for supporting technologies
  • Recurring tasks and strategies for CIP program maintenance

More Certification Details

  • Electronic Download package containing useful and otherwise hard to find NERC, regional entity, and various CIPC reference documents; SANS posters and brochures; and multiple documents created by SANS to help structure and guide your compliance program
  • Three virtual machines including a Windows 10, Kali Linux, and a Security Onion Linux VM which will be utilized during course labs to demonstrate and highlight security controls consistent with NERC CIP requirements
  • MP3 files of the course author/instructor to help recall course content and examples
  • A clear acrylic padlock and lockpicking tools
  • Incident response and security exercises designed for students to continue to utilize in their organizations
  • On-going access to course authors and instructors via a private NERC CIP focused community forum group

With your purchase of this ICS Security course, you will receive complimentary OnDemand access to ICS310: ICS Cybersecurity Foundations — an added benefit, not a prerequisite or requirement. This course is a great way to reinforce key concepts or fill gaps in your ICS/OT security knowledge, whether you complete it in full or focus on what is most relevant to you. Within 14 business days, you will receive a non-transferable access code via your SANS account email.

ICS456 is one of six courses in the SANS Industrial Control Systems group. For learners seeking leadership roles in this space find SANS ICS418: ICS Security Essentials for Leaders course a solid fit. Experts in this field go on to gain roles as NERC Compliance Analysts, System Operators, and Reliability Engineers. Students in the ICS456 course also receive complimentary OnDemand access to ICS310: ICS Cybersecurity Foundations.

The North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP) standards are mandatory cybersecurity regulations for organizations that support the North American bulk electric system. These standards establish requirements for identifying and protecting critical cyber assets, implementing security management controls, and ensuring reliable operation of the power grid against cyber and physical threats.

This course provides the technical skills and regulatory knowledge needed to implement, maintain, and defend a NERC CIP compliance program. Participants gain hands-on experience with essential security controls and compliance documentation, making each learner a valuable asset to organizations in the electric sector. The associated GIAC Critical Infrastructure Protection (GCIP) certification demonstrates specialized expertise to employers and auditors.

Relevant Job Roles

ICS Security Leader

Industrial Control Systems

Builds and maintains business relationships with engineering staff and C-suite stakeholders by communicating and managing cyber-to- physical risks while reducing security risk to engineering operations and simultaneously prioritising safety.

Explore learning path

ICS Security Architect

Industrial Control Systems

Ensures control system network security compliance and best practices for control networks.

Explore learning path

Operational Technology (OT) Cybersecurity Engineering (OPM 652)

NICE: Design and Development

Responsible for working within the engineering department to design and create systems, processes, and procedures that maintain the safety, reliability, controllability, and security of industrial systems in the face of intentional and incidental cyber-related events. Interfaces with Chief Information Security Officer, plant managers, and industrial cybersecurity technicians.

Explore learning path

Industrial Control Systems and Operational Technologies

SCyWF: Industrial Control Systems And Operational Technologies

This role conducts cybersecurity tasks for Industrial Control Systems and Operational Technologies (ICS/OT). Find the SANS courses that map to the Industrial Control Systems and Operational Technologies SCyWF Work Role.

Explore learning path

Cybersecurity Analyst/Engineer

Cyber Defense

As this is one of the highest-paid jobs in the field, the skills required to master the responsibilities involved are advanced. You must be highly competent in threat detection, threat analysis, and threat protection. This is a vital role in preserving the security and integrity of an organization’s data.

Explore learning path

Privacy Compliance (OPM 732)

NICE: Oversight and Governance

Responsible for developing and overseeing an organization’s privacy compliance program and staff, including establishing and managing privacy-related governance, policy, and incident response needs.

Explore learning path

ICS Security Incident Responder

Industrial Control Systems

Executes specific industrial incident response for incidents that threaten or impact control system networks and assets, while maintaining the safety and reliability of operations.

Explore learning path

Infrastructure Operations (ITOP)

Skills Framework for the Information Age

Management of daily IT operations, including system monitoring, availability, maintenance, and response to incidents. Roles ensure service continuity and operational stability.

Explore learning path

Course Schedule and Pricing

Have Questions?Contact Us
  • Location & instructor

    Virtual (OnDemand)

    Instructed by
    Date & Time
    OnDemand (Anytime)Self-Paced, 4 months access
    Course price
    $7,650 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS DC Metro September 2026

    Bethesda, MD, US & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    $7,650 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Miami 2026

    Coral Gables, FL, US & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    $7,650 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Rockville 2027

    Virtual (live)

    Date & Time
    Fetching schedule..
    Course price
    $7,650 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS ICS Security Summit & Training 2027

    Orlando, FL, US & Virtual (live)

    Date & Time
    Fetching schedule..
    Course price
    $7,650 USD*Prices exclude applicable local taxes
    Registration Options
Showing 5 of 5

Benefits of Learning with SANS

Bryan Simon: Teacher Standing Next to Smartboard and Explaining Concept

Get feedback from the world’s best cybersecurity experts and instructors

OnDemand Mobile App

Choose how you want to learn - online, on demand, or at our live in-person training events

Close Up of Woman Holding a Pen and Documents

Get access to our range of industry-leading courses and resources