Group Purchasing
Group Purchasing
AI SKILLSUPDATED

LDR516: Strategic Vulnerability and Threat Management

LDR516Cybersecurity Leadership, Artificial Intelligence
  • 5 Days (Instructor-Led)
  • 30 Hours (Self-Paced)
Course authored by:
Jonathan Risto
Jonathan Risto
LDR516: Building and Leading Vulnerability Management Programs
Course authored by:
Jonathan Risto
Jonathan Risto
  • 30 CPEs

    Apply your credits to renew your certifications

  • In-Person, Virtual or Self-Paced

    Attend a live, instructor-led class at a location near you or remotely, or train on your time over 4 months

  • Advanced Skill Level

    Course material is geared for cyber security professionals with hands-on experience

  • 19 Hands-On Lab(s)

    Apply what you learn with hands-on exercises and labs

Integrate strategic and tactical approaches to level up enterprise exposure management programs while addressing infrastructure and cloud environment challenges.

Course Overview

This course equips security leaders with the strategies, tools, and insights needed to build and mature vulnerability and exposure management (VM and EM) programs that reduce real-world risk. With a strong emphasis on business alignment, risk-based prioritization, and modern threat modeling, LDR516 teaches students how to build a program that evolves from reactive patching toward measurable exposure reduction.

Through 11 hands-on labs, 10 of them powered by artificial intelligence (AI), and the Cyber42 simulation game, you’ll gain the hands-on and strategic experience needed to make vulnerability management work—at scale, and with impact.

Strategic Vulnerability Management for Modern Enterprises

Whether you’re building a VM program from scratch or leading a large-scale modernization effort, this course will transform how you think about managing exposures across your enterprise. You’ll move beyond checklists and patch deadlines to tackle the real challenges: aligning with business priorities, managing risk acceptance responsibly, and driving remediation across siloed teams and complex infrastructure.

LDR516 blends tactical techniques and strategic leadership. You’ll explore how to prioritize beyond CVSS using exploit prediction (EPSS), real-time threat intelligence (CISA KEV, MITRE ATT&CK), and asset criticality. You’ll address challenges in cloud, container, and IoT environments—and learn to navigate resistance, resource constraints, and governance hurdles.

The course also dives into the principles of Continuous Threat Exposure Management (CTEM), breach and attack simulation (BAS), and VulnOps to help you plan for proactive, continuous improvement—but it does not require CTEM adoption. Instead, the focus is on building practical, scalable programs grounded in real-world constraints.

The course teaches two practical maturity frameworks, the Vulnerability Management Maturity Model (VMMM) v2 and the Continuous Threat Exposure Management Maturity Model (CTEMMM), to help leaders evaluate and evolve their programs.

Over five days, you’ll complete 11 labs set inside one fictional company, ArctiqNova Industries, where the decisions you make early in the week carry into later labs. In most labs, AI produces the generic answer and your job is to find where it fails ArctiqNova; in others, the model argues against your position or attacks your own decisions. The Cyber42 leadership simulation game weaves through each day, putting you in realistic scenarios in 5 strategic initiative rounds with 10 decision challenges that test your ability to lead under pressure.

If you’re ready to stop drowning in vulnerability data and start driving meaningful risk reduction, this course is your blueprint for building a future-ready VM program.

Hands-On Vulnerability Management Training

LDR516 uses the Cyber42 leadership simulation game, AI-driven scenario labs, and tool-based exercises to provide students with a dynamic, hands-on learning experience. These elements are woven throughout the course to reinforce core concepts, strengthen leadership and communication skills, and simulate the real-world decisions that vulnerability management professionals face. Students assume the role of a VM leader at the fictional ArctiqNova Industries, where they select strategic initiatives, respond to realistic operational challenges, and make prioritization and governance decisions that affect security outcomes and business risk. Decisions carry from section to section, in both the labs and Cyber42.

The following is a breakdown of the Cyber42 simulation and AI labs by course section:

Section 1:

  • Cyber42: Round 1
    • Initiative selection
    • 2 challenges
  • AI Labs
    • Lab 1.1 – Making the Business Case for VM
    • Lab 1.2 – Communicating a Critical Flaw

Section 2:

  • Cyber42: Round 2
    • Initiative selection
    • 2 challenges
  • AI Labs
    • Lab 2.1 – Trusting Your Asset Picture
    • Lab 2.2 – Rank and Commit
    • Lab 2.3 - Rank and Commit, Part 2

Section 3:

  • Cyber42: Round 3
    • Initiative selection
    • 2 challenges
  • AI Labs
    • Lab 3.1 – Deciding Under Scarcity
    • Lab 3.2 – Stakeholder Negotiation

Section 4:

  • Cyber42: Round 4:
    • Initiative selection
    • 2 challenges
  • AI Labs
    • Lab 4.1 – Defend It and Measure It
    • Lab 4.2 – Policy That Governs

Section 5:

  • Cyber42: Round 5
    • Final initiative selection
    • 2 challenges
  • AI Labs
    • Lab 5.1 – Attack Path Analysis
    • Lab 5.2 - Red-Team Your Own Decisions

Syllabus Summary

  • Section 1: Course overview, leadership and business alignment, common challenges, attack surface, asset criticality, configuration management, asset management, and exposure debt.
  • Section 2: Contextual information, decision trees, weighted averages, vulnerability clustering, hardening, remediation, remediation challenges, and risk.
  • Section 3: Metrics that show value, program maturity measurement, reporting that gets attention, storytelling with data, stakeholder communication and negotiation, IR and VM integration, and post-breach reviews.
  • Section 4: Compliance and audit readiness, zero-day rapid response, emergency patch coordination, crisis communication, enforceable policies and procedures, governance and staffing, supply chain and third-party risk, cloud, containers, OT, and IoT.
  • Section 5: Attack-path analysis, breach and attack simulation, CTEM lifecycle, adapting VM to CTEM, AI-native exposures, VulnOps, and remediation without testing.

Author Statement

"Over the years, I’ve seen teams struggle not because they lacked tools, but because they lacked clarity on where to focus. The challenge today isn’t a lack of data. It’s the sheer volume of it. Teams face overwhelming scanner output, expanding cloud and hybrid attack surfaces, and growing expectations from leadership, regulators, and customers. The hard part isn’t finding vulnerabilities. It’s understanding which ones truly matter, communicating that risk clearly, and driving meaningful action across the organization.

This course is built around how real programs mature over time. Organizations don’t succeed because of a single tool or process. They succeed when leaders build structured, scalable programs that evolve from reactive patching toward measurable risk reduction.

The goal of LDR516 is to give students the tools, context, and confidence to lead vulnerability management efforts in the real world, not just technically, but strategically. We explore how to align VM with business priorities, gain stakeholder buy-in, and communicate risk in ways that influence budget decisions, remediation efforts, and leadership support.

AI is part of the solution. It helps analysts work faster and smarter, but it is not a replacement for human judgment. That’s why the labs and Cyber42 simulation focus on helping leaders think critically, prioritize effectively, and manage trade-offs across complex environments.

Vulnerability management is ultimately a risk reduction function, but one that must be grounded in business reality to succeed. Students leave this course understanding not just what to fix, but why it matters, and how to move their programs forward with clarity, consistency, and impact.”

- Jonathan Risto

What You'll Learn

  • Build and evolve vulnerability management programs across traditional, cloud, IoT, and hybrid environments
  • Prioritize vulnerabilities using business-aligned context and threat intelligence
  • Measure program maturity and risk reduction using metrics and maturity models such as VMMM and CTEMMM
  • Validate real exposure through attack-path analysis and breach and attack simulation, then drive remediation at scale through VulnOps
  • Use AI to accelerate analysis while applying the human judgment that tests and challenges its output
  • Communicate vulnerability risk effectively to executives, IT, and business units through tailored reporting
  • Align VM with regulatory frameworks (e.g., NIS2, NIST, HIPAA, GDPR, CRA) and board-level governance

Business Takeaways

  • Assess organizational strengths, weaknesses, and maturity in vulnerability management programs
  • Prepare for and respond to critical vulnerabilities and zero-day issues
  • Prioritize security investments using data-driven decision-making and contextual risk models
  • Translate technical VM findings into business impact to improve executive understanding and buy-in
  • Uncover hidden obstacles by grouping and analyzing vulnerabilities
  • Use program metrics and reporting to improve compliance posture and guide continuous improvement
  • Implement proactive remediation capabilities

Course Syllabus

Explore the course syllabus below to view the full range of topics covered in LDR516: Strategic Vulnerability and Threat Management.

Section 1Building the Blueprint for Vulnerability Management Success

Establish a strong foundation by understanding the VM lifecycle, aligning with business goals, and building the asset and discovery practices that power effective risk reduction.

Topics covered

  • Foundation of vulnerability management (VM)
  • Asset management and attack surface understanding
  • Business alignment
  • Asset classification
  • Configuration flaws

Labs

  • Making the Business Case for VM
  • Communicating a Critical Flaw
  • Cyber42 Game Round 1

Overview

Section 1 sets the stage for the week by emphasizing why vulnerability management is a critical business function, not just a technical task. It explores how the VM lifecycle differs across business areas and environments, and how leaders drive prioritization, buy-in, and accountability. You then dive into asset management, attack surface discovery, and asset classification, because accurate, enriched asset data is foundational to effective VM. The section covers scanning and manual testing, configuration flaws, and zero-days, then closes with business goals, exposure debt, and budgeting. This section also introduces the Cyber42 simulation game, where you begin shaping your strategic approach to program improvement.

Full Lab Details

  • Lab 1.1 Making the Business Case for VM: Have AI draft a generic business case, then rework it into a pitch the ArctiqNova CEO would fund
  • Lab 1.2 Communicating a Critical Flaw: Frame one critical vulnerability for three stakeholders at speed, keeping the core facts identical in every message
  • Cyber42 Game
    • Game introduction and ArctiqNova Industries overview
    • Round 1: Initiative selection
    • Two challenge events focused on foundational gaps and visibility

Full Topic Details

  • What Is Vulnerability Management (VM) and The VM Lifecycle
  • Leadership and Business Alignment
  • Common Challenges
  • Why Asset Management Matters
  • Attack Surface and Discovery
  • Asset Classification
  • Scanning, Manual Testing, Identification Challenges
  • Configuration Flaws: Understanding the Risks
  • Zero-Days and Emerging Threats
  • Business Goals
  • Risk, Compliance, and Exposure Debt
  • Communicating Value, Resources, and Budgeting

Section 2Mastering the Art of Prioritization and Remediation

Learn how to move beyond CVSS and prioritize vulnerabilities using context, threat intel, and business impact—while deploying smart, scalable remediation and risk acceptance strategies.

Topics covered

  • Prioritization strategies
  • Weighted Averages and Decision Trees
  • Remediation approaches
  • Measuring and tracking success
  • Risk management and documentation

Labs

  • Trusting Your Asset Picture
  • Rank and Commit
  • Rank and Commit, Part 2
  • Demo: MITRE ATT&CK Mapping
  • Cyber42 Game Round 2

Overview

Raw severity scores do not tell you what to fix first. This section builds prioritization on context: threat intelligence, asset criticality, CVSS v4, EPSS, CISA KEV, and MITRE ATT&CK. You compare decision trees, including CISA’s SSVC, with weighted scoring models, group findings into remediation campaigns that remove root causes, and weigh patching against compensating controls. The section closes with hardening, remediation automation, success metrics, risk acceptance, and FAIR-based quantification that puts a dollar range on an exposure.

Full Lab Details

  • Lab 2.1 Trusting Your Asset Picture: Reconcile several sources that disagree into one trustworthy asset picture, by hand
  • Lab 2.2 Rank and Commit: Rank a shortlist of competing findings from the evidence in front of you and commit to the call in writing
  • Lab 2.3 Rank and Commit, Part 2: Re-rank the same findings as new intelligence arrives and name the evidence that moved each one
  • Cyber42 Game
    • Round 2: Initiative selection
    • Two challenge events addressing cloud exposure and scanning blind spots

Full Topic Details

  • It's All About the Context
  • Decision Trees
  • Weighted Averaging
  • Vulnerability Clustering
  • Patch vs. Compensating Controls
  • Hardening
  • Remediation Automation
  • Measuring Remediation Success
  • Remediation Challenges
  • Risk Acceptance, FAIR, and Documentation
  • Stakeholders and Accountability

Section 3Communicating Risk and Driving Action In VM

Translate technical findings into business-relevant risk insights through metrics, reporting, storytelling, and executive communication that prompt real action.

Topics covered

  • Risk-based strategic and maturity metrics
  • Effective reporting and communication
  • Automation and efficiency
  • Driving culture change and executive engagement
  • Integration with incident response

Labs

  • Deciding Under Scarcity
  • Stakeholder Negotiation
  • Cyber42 Game Round 3

Overview

Numbers only matter when they drive decisions. This section builds metrics that prove program value, from crawl, walk, and run operational measures to risk-based and strategic metrics, and measures program maturity with the Vulnerability Management Maturity Model (VMMM) v2. You’ll design reports that get attention and action, automate reporting, and use storytelling with data to move executives. The section then turns to winning over stakeholders through disclosure, cultural change, executive communication, and negotiation. It closes by connecting VM to incident response through shared threat intelligence, post-breach reviews, and a joint SOC and VM operating model.

Full Lab Details

  • Lab 3.1 Deciding Under Scarcity: Have AI produce a generic severity ranking, then overturn it using reachability to ArctiqNova’s crown jewels and pick the six findings your team can fix this week
  • Lab 3.2 Stakeholder Negotiation: Defend a Lab 3.1 decision against an AI-played stakeholder and decide when to hold, trade, or escalate
  • Cyber42 Game
    • Round 3: Initiative selection
    • Two challenge events focused on prioritization failures and stakeholder miscommunication

Full Topic Details

  • Metrics That Prove Your Program’s Value
  • Key Risk-Based Metrics and Operational and Strategic Uses
  • Measuring Program Maturity
  • Reporting That Gets Attention and Action
  • Automation in Reporting
  • Storytelling with Data
  • Communicate Effectively: Winning Over Stakeholders
  • Vulnerability Disclosures and Effective Risk Communication
  • Cultural and Organizational Change
  • Executive Communication Strategies
  • VM in Incident Response, Vulnerability vs. Exploit Detection
  • Using Threat Intel for IR and VM Alignment
  • Post-Breach VM Actions, Bridging SOC and VM Teams

Section 4Navigating Compliance, Crisis, and Governance in VM

Balance regulatory obligations and risk-based strategies, build resilient VM programs with strong policies and governance, and respond effectively to zero-day events and audit demands.

Topics covered

  • Compliance and regulatory alignment
  • Preparedness and response
  • Post-incident and continuous improvement
  • Roles, responsibilities, and risk ownership
  • Evolving VM with technology

Labs

  • Defend It and Measure It
  • Policy That Governs
  • Cyber42 Game Round 4

Overview

Compliance sets the floor, and risk decides where to go beyond it. This section maps VM to major regulatory themes, including NIS2 and the Cyber Resilience Act, and shows how to balance compliance-driven and risk-based VM while producing audit-ready evidence. You’ll build zero-day rapid response capability from the Log4j, SolarWinds, and Fortinet lessons, coordinate emergency patching, and run crisis communication and post-incident reviews. The section closes with governance: clear roles, enforceable policy, staffing and budgeting, enterprise risk alignment, third-party and supply chain risk, cloud and containers, and OT and IoT.

Full Lab Details

  • Lab 4.1 Defend It and Measure It: Reconstruct a past deferral for an auditor using only what was known at the time, then build one honest board metric and name what it hides
  • Lab 4.2 Policy That Governs: Have AI generate a standard VM policy, then strip out unenforceable clauses and add what a generic policy misses for ArctiqNova’s OT, cloud, and unscanned assets
  • Cyber42 Game
    • Round 4: Initiative selection
    • Two challenge events on risk acceptance, resistance, and cloud remediation

Full Topic Details

  • Compliance, Regulations, and Critical Frameworks
  • Balancing Compliance and Risk-Based VM
  • Zero-Day Rapid Response Strategies and Real-World Lessons
  • Coordinating Emergency Patches
  • Crisis Communication and Response Coordination
  • Effective Post-Incident Reviews
  • Defining Roles: Security, IT Ops, DevOps
  • Writing and Enforcing Policies and Procedures
  • Engagement and Governance Practices
  • Staffing and Team Composition for Effective VM
  • Aligning VM with Enterprise Risk Strategy
  • Securing Supply Chains and Third Parties
  • VM Challenges: Cloud and Containers
  • Beyond IT: Securing OT and IoT

Section 5The Future of Vulnerability Management – Proactive Defense and Continuous Exposure Management

Explore forward-looking practices like CTEM, attack path modeling, breach and attack simulation, VulnOps, and AI as you evolve from reactive patching to continuous, business-aligned threat exposure management. Students explore how maturity-based exposure management approaches help organizations transition from reactive vulnerability practices toward continuous exposure reduction.

Topics covered

  • Attack path modeling and breach and attack simulation
  • CTEM (Continuous Threat Exposure Management)
  • Adoption challenges and solutions
  • AI-native exposures
  • VulnOps and remediation without testing

Labs

  • Attack Path Analysis
  • Red-Team Your Own Decisions
  • Cyber42 Game Final Round

Overview

Sustaining a modern VM program requires more than technical skill; it demands strategic leadership. This section moves from vulnerable to exploitable: you’ll model attack paths, validate exposures with breach and attack simulation (BAS), and stress-test your own decisions. You’ll then work through the CTEM lifecycle, adapt an existing VM program to CTEM, and measure the transition with the Continuous Threat Exposure Management Maturity Model (CTEMMM). The section closes with AI-native exposures, VulnOps as the execution engine of exposure management, and remediation without testing. The course concludes with the Cyber42 final round, initiative scoring, and a roadmap for moving forward.

Full Lab Details

  • Lab 5.1 Attack Path Analysis: Use AI to chain vulnerabilities across ArctiqNova’s network into realistic attack paths to business-critical systems, then brief executives on the choke points
  • Lab 5.2 Red-Team Your Own Decisions: Turn AI into an adversary against your own Lab 3.1 decision, then judge which attacks land and which are manufactured noise
  • Cyber42 Game
    • Final initiative selection
    • Final two challenge events and scoring

Full Topic Details

  • Attack Path Modeling
  • Breach and Attack Simulation
  • CTEM Lifecycle Overview
  • CTEM Lifecycle and Implementation
  • Adapting VM to CTEM
  • Overcoming CTEM Adoption Challenges
  • Identifying, Assessing, and Managing AI-Native Exposures
  • VulnOps
  • Taking the Leap: Remediation Without Testing

Things You Need To Know

Important! Bring your own system configured according to these instructions.

A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will not be able to fully participate in the exercises in your course. Therefore, please arrive with a system meeting all of the specified requirements.

Back up your system before class. Better yet, use a system without any sensitive/critical data. SANS is not responsible for your system or data.

Mandatory System Hardware Requirements

  • Wireless networking (802.11 standard) is required. There is no wired Internet access in the classroom.

Mandatory Host Configuration And Software Requirements

  • Your system must be able to open PDF, text, spreadsheet, and CSV files. Most standard office suites (Microsoft Office, LibreOffice, OpenOffice) will work. Note that you can get a Microsoft 365 Trial (free for 30 days).
  • You will access additional course materials through a dedicated Egnyte course drive provided to registered students. Ensure your system is not blocking access to Egnyte or file downloads from it.
  • Hands-on exercises use the Ranges.io platform. Access to this site is required to participate in the simulation exercises.
  • Labs use SANS-provided ChatGPT instance, accessed through a web browser. Ensure your system is not blocking access to ChatGPT web interfaces. Without this access you will be unable to complete the lab exercises.

If you have additional questions about the laptop specifications, please contact customer service.

LDR516 training is recommended for a diverse range of individuals, including:

  • Vulnerability program managers and analysts managing vulnerabilities in the enterprise or cloud
  • Information security managers, architects, analysts, officers, and directors
  • Aspiring information security leaders
  • Risk management, business continuity and disaster recovery professionals
  • IT operations managers and administrators
  • CISOs
  • Cloud service managers, administrators, integrators, developers, and brokers
  • Cloud service security and risk managers
  • Government IT professionals who manage vulnerabilities in the enterprise or cloud (FedRAMP, NIST CSF)

  • Student manuals containing the entire course content and lab introductions and debriefs
  • Access to lab materials and bonus content and videos on the class website
  • Access to the Cyber42 security leadership simulation game
  • MP3 audio files of the complete course lecture

A basic understanding of security operations—including concepts such as patching, vulnerability scanning, and configuration management—is recommended. While the course covers foundational material, it is designed for professionals seeking to advance their ability to lead or support enterprise vulnerability management and exposure reduction efforts.

LDR516 is part of the SANS Cybersecurity Leadership Curriculum and a core component of the Operational Cybersecurity Executive Triad alongside LDR551: Building and Leading Security Operations Centers and SEC566: Implementing and Auditing CIS Controls. This course focuses on vulnerability and exposure management leadership—equipping students to design scalable programs, enable risk-informed decisions, and strengthen communication with IT, cloud, compliance, and executive stakeholders. It builds strategic and operational excellence for those ready to advance into senior roles.

Vulnerability Management (VM) is a risk reduction discipline that identifies, evaluates, prioritizes, treats, and monitors security weaknesses across infrastructure, applications, and cloud environments. It combines technology, process, and governance to minimize the attack surface and improve organizational resilience.

Modern VM goes beyond just scanning and patching—it requires context-aware prioritization, business alignment, cross-functional coordination, and clear communication. A mature VM program enables organizations to stay ahead of threats, align with compliance mandates, and make informed decisions about where to invest remediation efforts.

LDR516 helps you become a more effective and strategic security leader. You’ll develop the skills to lead vulnerability management efforts, drive remediation decisions based on real-world risk, and communicate findings in ways that influence stakeholders. Through AI-powered labs and Cyber42 simulation challenges, you’ll gain practical experience in decision-making, prioritization, reporting, and stakeholder engagement—making you better prepared to lead, influence, and advance in your career.

Relevant Job Roles

Operational Cybersecurity Executive

Cybersecurity Leadership

Lead operational teams from the point of view of an adversary in order to protect your most sensitive assets.

Explore learning path

Security Manager Training, Salary, and Career Path

Cybersecurity Leadership

Daily focus is on the leadership of technical teams. Includes titles such as Manager, Information Security Specialist, and Program/Project Leader.

Explore learning path

Vulnerability Analysis (OPM 541)

NICE: Protection and Defense

Responsible for assessing systems and networks to identify deviations from acceptable configurations, enclave policy, or local policy. Measure effectiveness of defense-in-depth architecture against known vulnerabilities.

Explore learning path

Cybersecurity Researcher

European Cybersecurity Skills Framework

Research the cybersecurity domain and incorporate results in cybersecurity solutions.

Explore learning path

Chief Information Security Officers Training, Salary, and Career Path

European Cybersecurity Skills Framework

Chief Information Security Officers lead cybersecurity initiatives, aligning strategic vision with operational execution, fostering a resilient security culture, and proactively managing risks to safeguard organisational assets and reputation.

Explore learning path

Course Schedule and Pricing

Have Questions?Contact Us
  • Location & instructor

    Virtual (OnDemand)

    Instructed by
    Date & Time
    OnDemand (Anytime)Self-Paced, 4 months access
    Course price
    $8,260 USD*Prices exclude applicable local taxesBuy now for access on Nov 5. Use code Presale10 for 10% off course price!
    Registration Options
  • Location & instructor

    SANS London October 2026

    London, GB & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    £6,715 GBP*Prices exclude applicable taxes | EUR price available during checkout
    Registration Options
  • Location & instructor

    SANS Cyber Safari 2026

    Riyadh, SA & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    $8,375 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Dallas 2026

    Dallas, TX, US & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    $8,260 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Nashville 2027

    Nashville, TN, US & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    $8,260 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS 2027

    Orlando, FL, US & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    $8,260 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Live Online Europe April 2027

    Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    €7,715 EUR*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANSFIRE 2027

    Washington, DC, US & Virtual (live)

    Date & Time
    Fetching schedule..
    Course price
    $8,260 USD*Prices exclude applicable local taxes
    Registration Options
Showing 8 of 8

Benefits of Learning with SANS

Bryan Simon: Teacher Standing Next to Smartboard and Explaining Concept

Get feedback from the world’s best cybersecurity experts and instructors

OnDemand Mobile App

Choose how you want to learn - online, on demand, or at our live in-person training events

Close Up of Woman Holding a Pen and Documents

Get access to our range of industry-leading courses and resources