Group Purchasing
Group Purchasing
AI SKILLS

LDR516: Strategic Vulnerability and Threat Management

LDR516Cybersecurity Leadership, Artificial Intelligence
  • 5 Days (Instructor-Led)
  • 30 Hours (Self-Paced)
Course authored by:
Jonathan Risto
Jonathan Risto
LDR516: Building and Leading Vulnerability Management Programs
Course authored by:
Jonathan Risto
Jonathan Risto
  • 30 CPEs

    Apply your credits to renew your certifications

  • In-Person, Virtual or Self-Paced

    Attend a live, instructor-led class at a location near you or remotely, or train on your time over 4 months

  • Advanced Skill Level

    Course material is geared for cyber security professionals with hands-on experience

  • 21 Hands-On Lab(s)

    Apply what you learn with hands-on exercises and labs

Integrate strategic and tactical approaches to level up enterprise vulnerability management programs while addressing infrastructure and cloud environment challenges.

Course Overview

This course equips security leaders with the strategies, tools, and insights needed to build and mature vulnerability management (VM) programs that reduce real-world risk. With a strong emphasis on business alignment, risk-based prioritization, and modern threat modeling, LDR516 teaches students how to build a program that evolves from reactive patching toward measurable exposure reduction.

Through 9 artificial intelligence (AI)-powered labs and the Cyber42 simulation game, you’ll gain the hands-on and strategic experience needed to make vulnerability management work—at scale, and with impact.

Strategic Vulnerability Management for Modern Enterprises

Whether you’re building a VM program from scratch or leading a large-scale modernization effort, this course will transform how you think about managing exposures across your enterprise. You’ll move beyond checklists and patch deadlines to tackle the real challenges: aligning with business priorities, managing risk acceptance responsibly, and driving remediation across siloed teams and complex infrastructure.

LDR516 blends tactical techniques and strategic leadership. You’ll explore how to prioritize beyond CVSS using exploit prediction (EPSS), real-time threat intelligence (CISA KEV, MITRE ATT&CK), and asset criticality. You’ll address challenges in cloud, container, and IoT environments—and learn to navigate resistance, resource constraints, and governance hurdles.

The course also dives into the principles of Continuous Threat Exposure Management (CTEM) to help you plan for proactive, continuous improvement—but it does not require CTEM adoption. Instead, the focus is on building practical, scalable programs grounded in real-world constraints.

The course introduces practical maturity frameworks, including concepts aligned with the Vulnerability Management Maturity Model (VMMM) and Continuous Threat Exposure Management maturity approaches, to help leaders evaluate and evolve their programs.

Over five days, you’ll complete 9 AI-enhanced labs that demonstrate how modern tooling, automation, and language models can accelerate decision-making, risk analysis, and reporting. The Cyber42 leadership simulation game weaves through each day, putting you in realistic scenarios in 5 strategic initiative rounds with 12 decision challenges that test your ability to lead under pressure.

If you’re ready to stop drowning in vulnerability data and start driving meaningful risk reduction, this course is your blueprint for building a future-ready VM program.

Hands-On Vulnerability Management Training

LDR516 uses the Cyber42 leadership simulation game, AI-driven scenario labs, and tool-based exercises to provide students with a dynamic, hands-on learning experience. These elements are woven throughout the course to reinforce core concepts, strengthen leadership and communication skills, and simulate the real-world decisions that vulnerability management professionals face. Students assume the role of a VM leader at the fictional “Everything Corporation” (E Corp), where they select strategic initiatives, respond to realistic operational challenges, and make prioritization and governance decisions that affect security outcomes and business risk.

The following is a breakdown of the Cyber42 simulation and AI labs by course section:

Section 1:

  • Cyber42: Round 1
    • Initiative selection
    • 2 challenges
  • AI Labs
    • Lab 1.1 – Explaining VM to Executives
    • Lab 1.2 – Communicating Critical Flaws

Section 2:

  • Cyber42: Round 2
    • Initiative selection
    • 3 challenges
  • AI Labs
    • Lab 2.1 – Patch Prioritization Stand-Off
    • Lab 2.2 – Compensating Controls

Section 3:

  • Cyber42: Round 3
    • Initiative selection
    • 3 challenges
  • AI Labs
    • Lab 3.1 – Audience Specific Report
    • Lab 3.2 – Board Risk Briefing

Section 4:

  • Cyber42: Round 4:
    • Initiative selection
    • 2 challenges
  • AI Labs
    • Lab 4.1 – Building a VM Policy that Works
    • Lab 4.2 – VM Process Modernization

Section 5:

  • Cyber42: Round 5
    • Final initiative selection
    • 2 challenges
  • AI Labs
    • Lab 5.1 – Attack Path Analysis

Syllabus Summary

  • Section 1: Course overview, policies and standards, cloud design considerations, and cyber asset attack surface management
  • Section 2: Identification challenges, processes, and technology across both infrastructure and applications
  • Section 3: Analysis, metrics, and communication techniques for effectively influencing action
  • Section 4: Common treatment or remediation processes and technologies
  • Section 5: Getting buy-in and advancing your program

Author Statement

"Over the years, I’ve seen teams struggle not because they lacked tools, but because they lacked clarity on where to focus. The challenge today isn’t a lack of data. It’s the sheer volume of it. Teams face overwhelming scanner output, expanding cloud and hybrid attack surfaces, and growing expectations from leadership, regulators, and customers. The hard part isn’t finding vulnerabilities. It’s understanding which ones truly matter, communicating that risk clearly, and driving meaningful action across the organization.

This course is built around how real programs mature over time. Organizations don’t succeed because of a single tool or process. They succeed when leaders build structured, scalable programs that evolve from reactive patching toward measurable risk reduction.

The goal of LDR516 is to give students the tools, context, and confidence to lead vulnerability management efforts in the real world, not just technically, but strategically. We explore how to align VM with business priorities, gain stakeholder buy-in, and communicate risk in ways that influence budget decisions, remediation efforts, and leadership support.

AI is part of the solution. It helps analysts work faster and smarter, but it is not a replacement for human judgment. That’s why the labs and Cyber42 simulation focus on helping leaders think critically, prioritize effectively, and manage trade-offs across complex environments.

Vulnerability management is ultimately a risk reduction function, but one that must be grounded in business reality to succeed. Students leave this course understanding not just what to fix, but why it matters, and how to move their programs forward with clarity, consistency, and impact.”

- Jonathan Risto

What You'll Learn

  • Build and evolve vulnerability management programs across traditional, cloud, IoT, and hybrid environments
  • Prioritize vulnerabilities using business-aligned context and threat intelligence
  • Develop and apply VM metrics to measure program maturity, demonstrate risk reduction, and drive stakeholder support
  • Design remediation strategies that include patching, compensating controls, and automated tools to minimize exposure
  • Evaluate and evolve VM programs using maturity-based models that align operational capability with business risk reduction goals
  • Communicate vulnerability risk effectively to executives, IT, and business units using tailored reporting and dashboards
  • Align VM with regulatory frameworks (e.g., NIS2, NIST, HIPAA, GDPR, CRA) and board-level governance for sustainable compliance

Business Takeaways

  • Assess organizational strengths, weaknesses, and maturity in vulnerability management programs
  • Prepare for and respond to critical vulnerabilities and zero-day issues
  • Prioritize security investments using data-driven decision-making and contextual risk models
  • Translate technical VM findings into business impact to improve executive understanding and buy-in
  • Uncover hidden obstacles by grouping and analyzing vulnerabilities
  • Use program metrics and reporting to improve compliance posture and guide continuous improvement
  • Implement proactive remediation capabilities

Course Syllabus

Explore the course syllabus below to view the full range of topics covered in LDR516: Strategic Vulnerability and Threat Management.

Section 1Building the Blueprint for Vulnerability Management Success

Establish a strong foundation by understanding the VM lifecycle, aligning with business goals, and building the asset and discovery practices that power effective risk reduction.

Topics covered

  • Foundation of vulnerability management (VM)
  • Asset management and attack surface understanding
  • Assessment techniques
  • Common challenges and pitfalls
  • Responding to evolving threats

Labs

  • Explaining VM to Executive
  • Communicating Critical Flaws
  • Cyber42 Game Round 1

Overview

Section 1 sets the stage for the week by emphasizing why vulnerability management is a critical business function, not just a technical task. It explores how cloud service models and deployment architectures affect discovery, visibility, and treatment. You then dive into asset management—discussing why accurate, enriched asset data is foundational to effective VM. This section also introduces the Cyber42 simulation game, where you begin shaping your strategic approach to program improvement.

Full Lab Details

  • Explaining VM to Executive: Use AI to describe the business value of VM to different audiences (security, IT, leadership)
  • Communicating Critical Flaws: Practice presenting a critical vulnerability to non-technical stakeholders using plain language and risk framing
  • VM Alignment: Analyze how VM activities support or hinder business objectives using AI-supported self-assessment
  • Cyber42 Game
    • Game introduction and E Corp overview
    • Round 1: Initiative selection
    • Two challenge events focused on foundational gaps and visibility

Full Topic Details

  • Vulnerability Management – More Than Patching
    • What is VM?
    • The VM Lifecycle
    • Leadership and Business Alignment
    • Common Challenges
  • Know Your Assets
    • Why Asset Management Matters
    • Attack Surface and Discovery
    • Asset Classification and Tools
  • Finding Vulnerabilities
    • Scanning vs. Manual Testing
    • Common Identification Challenges and Pitfalls
    • Configuration Flaws: Understanding the Risks
    • Zero-Days and Emerging Threats
  • Making Vulnerability Management Matter
    • Stakeholders and Business Goals
    • Risk, Compliance and Security Debt
    • Communicating Value, Resources and Budgeting

Section 2Mastering the Art of Prioritization & Remediation

Learn how to move beyond CVSS and prioritize vulnerabilities using context, threat intel, and business impact—while deploying smart, scalable remediation and risk acceptance strategies.

Topics covered

  • Prioritization strategies
  • Remediation approaches
  • Measuring and tracking success
  • Risk management and documentation
  • Governance and stakeholder engagement

Labs

  • Patch Prioritization Stand-Off
  • Compensating Controls
  • Demo: MITRE ATT&CK Mapping
  • Cyber42 Game Round 2

Overview

Vulnerability identification is foundational, but many programs struggle with coverage gaps, noisy results, and lack of cloud visibility. This section examines scanning strategies for different asset types and evaluates how discovery architecture and tool configuration affect visibility. It also explores how to safely authorize testing, validate questionable results, and improve identification across modern development pipelines.

Full Lab Details

  • Patch Prioritization Stand-Off: Evaluate competing vulnerabilities using business impact, exploitability, threat intelligence and operational constraints
  • Compensating Controls: Assess mitigation and risk acceptance strategies when patching isn’t feasible, ensuring defensible governance and documentation
  • MITRE ATT&CK Mapping Demo: Demonstration of mapping vulnerabilities and exposures to adversary techniques using MITR ATT&CK framework
  • Cyber42 Game
    • Round 2: Initiative selection
    • Three challenge events addressing cloud exposure and scanning blind spots

Full Topic Details

  • Beyond CVSS – Smarter Prioritization
    • Challenges in Prioritization
    • It’s All About the Context
    • Decision Trees & Weighted Averaging
  • Fixing the Right Things the Right Way
    • Patch vs. Mitigation Strategies
    • Hardening
    • Remediation Automation
    • Measuring Remediation Success
    • Remediation Challenges
  • Risk Acceptance – Knowing When Not to Fix
    • Justifying & Documenting Risk
    • Compensating Controls & Governance
    • Documenting Risk Acceptance
    • Risk & Stakeholders

Section 3Communicating Risk & Driving Action in VM

Translate technical findings into business-relevant risk insights through metrics, reporting, storytelling, and executive communication that prompt real action.

Topics covered

  • Risk-based and strategic metrics
  • Effective reporting and communication
  • Automation and efficiency
  • Driving culture change and executive engagement
  • Integration with incident response

Labs

  • Audience Specific Reporting
  • Board Risk Briefing
  • Cyber42 Game Round 3

Overview

Raw scan output is rarely useful on its own. This section teaches you how to analyze vulnerability data in context—combining threat intelligence, asset criticality, and business impact to prioritize what matters most. You’ll also develop meaningful metrics, executive-ready reports, and communication approaches that drive action, not just awareness. Meeting strategies and reporting workflows are emphasized to improve collaboration.

Full Lab Details

  • Translate for Your Audience: Leverage AI to craft tailored risk communications for executives, compliance, and technical teams
  • Board Risk Briefing: Use AI to create a high-level VM update suitable for a board or risk committee
  • Cyber42 Game
    • Round 3: Initiative selection
    • Three challenge events focused on prioritization failures and stakeholder miscommunication

Full Topic Details

  • Metrics That Prove Your Program’s Value
    • Key Risk-Based Metrics
    • Operational vs. Strategic Metrics
    • Measuring Program Maturity
  • Reporting That Gets Attention & Action
    • Audience-Specific Reporting & Dashboards
    • Compliance-Driven Reporting
    • Automation in Reporting
    • Storytelling with Data
  • Communicate Effectively - Winning Over Stakeholders
    • Security Awareness & Buy-In
    • Handling Vulnerability Disclosures & Communicating Risk Effectively
    • Cultural and Organizational Change
    • Executive Communication Strategies
  • Connecting VM to Incident Response – Bridging the Gap
    • VM’s Role in Incident Response, Vulnerability vs. Exploit Detection
    • Using Threat Intel for IR & VM Alignment
    • Post-Breach VM Actions, Bridging SOC & VM Teams

Section 4Navigating Compliance, Crisis, and Governance in VM

Balance regulatory obligations and risk-based strategies, build resilient VM programs with strong policies and governance, and respond effectively to zero-day events and audit demands.

Topics covered

  • Compliance and regulatory alignment
  • Preparedness and response
  • Post-incident and continuous improvement
  • Roles, responsibilities, and risk ownership
  • Evolving VM with technology

Labs

  • Building a VM Policy that Works
  • VM Process Modernization
  • Cyber42 Game Round 4

Overview

Remediation is more than applying patches. This section helps you understand when to patch, when to mitigate, and when to isolate--especially in legacy or fragile environments. It explores the role of automation, secure image pipelines, and stakeholder coordination in reducing time to fix. Organizational resistance, cultural inertia, and risk acceptance are also addressed as real barriers to success.

Full Lab Details

  • Building a VM Policy that Works: Develop a vulnerability management policy aligned to regulatory requirements, risk tolerance, accountability, and governance oversight
  • VM Process Modernization: Design VM workflows to strengthen governance, compliance reporting, stakeholder coordination, and sustainable risk reduction
  • Cyber42 Game
    • Round 4: Initiative selection
    • Two challenge events on risk acceptance, resistance, and cloud remediation

Full Topic Details

  • Mastering the Game: Compliance & Regulations
    • Critical Frameworks: GDPR, HIPAA, PCI DSS, SOX, NIST 800-53
    • Balancing Compliance and Risk-Based VM
    • Audit Readiness & Global Compliance
  • Zero-Day Panic Mode: Rapid Response Strategies
    • Real-world Lessons from the Zero-Days
    • Coordinating Emergency Patches
    • Rapid Response Playbooks
    • Crisis Communication
    • Effective Post-Incident Reviews
  • People, Policy & Governance: Building Sustainable VM
    • Defining Roles: Security, IT Ops, DevOps
    • Writing and Enforcing Policies and Procedures
    • Engagement and Governance Practices
    • Budgeting, Staffing, Team Resilience
    • Aligning VM with Enterprise Risk Strategy
  • Future-Proofing VM: Emerging Threats & Tech
    • Securing Supply Chains & Third Parties
    • VM Challenges: Cloud & Containers
    • Beyond IT: Securing OT & IoT
    • Leveraging AI and Machine Learning to Improve VM Programs

Section 5The Future of Vulnerability Management – Proactive Defense and Continuous Exposure Management

Explore forward-looking practices like CTEM, attack path modeling, automation, and AI as you evolve from reactive patching to continuous, business-aligned threat exposure management. Students explore how maturity-based exposure management approaches help organizations transition from reactive vulnerability practices toward continuous exposure reduction.

Topics covered

  • Proactive VM
  • CTEM (Continuous Threat Exposure Management)
  • Adoption challenges and solutions
  • Emerging risks and technology
  • Future-ready governance

Labs

  • Attack Path Analysis
  • Cyber42 Game Final Round

Overview

Sustaining a modern VM program requires more than technical skill-it demands strategic leadership. This section brings together what you have learned and equips them to build mature, scalable, and proactive programs. Topics include communicating with boards, engaging difficult stakeholders, modeling exposure risk, and designing CTEM-aligned future plans. The course concludes with Cyber42 wrap-up, initiative scoring, and a roadmap for moving forward.

Full Lab Details

  • Attack Path Analysis: Use AI to model threat actor movement and highlight vulnerable choke points for prioritization
  • Cyber42 Game
    • Final initiative selection
    • Final two challenge events and scoring

Full Topic Details

  • From Reactive to Proactive
    • Shifting to Proactive VM
    • Attack Path Modelling
    • Continuous Improvement Strategies
    • CTEM Lifecycle Overview
  • Deep Dive into CTEM
    • CTEM Lifecycle & Implementation
    • Adapting VM to CTEM
    • Automated Discovery & Prioritization
    • Overcoming CTEM Adoption Challenges
  • Adapting to Change
    • Integrating VM with Zero Trust
    • Identifying, Assessing, and Managing AI-Native Exposures
    • Taking the Leap – Remediation Without Testing

Things You Need To Know

Important! Bring your own system configured according to these instructions.

A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will not be able to fully participate in the exercises in your course. Therefore, please arrive with a system meeting all of the specified requirements.

Back up your system before class. Better yet, use a system without any sensitive/critical data. SANS is not responsible for your system or data.

Mandatory System Hardware Requirements

  • Wireless networking (802.11 standard) is required. There is no wired Internet access in the classroom.

Mandatory Host Configuration And Software Requirements

  • Your system must be able to open PDF, text, spreadsheet, and CSV files. Most standard office suites (Microsoft Office, LibreOffice, OpenOffice) will work. Note that you can get a Microsoft 365 Trial (free for 30 days).
  • You will access additional course materials through a dedicated Egnyte course drive provided to registered students. Ensure your system is not blocking access to Egnyte or file downloads from it.
  • Hands-on exercises use the Ranges.io platform. Access to this site is required to participate in the simulation exercises.
  • Labs use SANS-provided ChatGPT instance, accessed through a web browser. Ensure your system is not blocking access to ChatGPT web interfaces. Without this access you will be unable to complete the lab exercises.

If you have additional questions about the laptop specifications, please contact customer service.

LDR516 training is recommended for a diverse range of individuals, including:

  • Vulnerability program managers and analysts managing vulnerabilities in the enterprise or cloud
  • Information security managers, architects, analysts, officers, and directors
  • Aspiring information security leaders
  • Risk management, business continuity and disaster recovery professionals
  • IT operations managers and administrators
  • CISOs
  • Cloud service managers, administrators, integrators, developers, and brokers
  • Cloud service security and risk managers
  • Government IT professionals who manage vulnerabilities in the enterprise or cloud (FedRAMP, NIST CSF)

  • Student manuals containing the entire course content and lab introductions and debriefs
  • Access to lab materials and bonus content and videos on the class website
  • Access to the Cyber42 security leadership simulation game
  • MP3 audio files of the complete course lecture

A basic understanding of security operations—including concepts such as patching, vulnerability scanning, and configuration management—is recommended. While the course covers foundational material, it is designed for professionals seeking to advance their ability to lead or support enterprise vulnerability management and exposure reduction efforts.

LDR516 is part of the SANS Cybersecurity Leadership Curriculum and a core component of the Operational Cybersecurity Executive Triad alongside LDR551: Building and Leading Security Operations Centers and SEC566: Implementing and Auditing CIS Controls. This course focuses on vulnerability and exposure management leadership—equipping students to design scalable programs, enable risk-informed decisions, and strengthen communication with IT, cloud, compliance, and executive stakeholders. It builds strategic and operational excellence for those ready to advance into senior roles.

Vulnerability Management (VM) is a risk reduction discipline that identifies, evaluates, prioritizes, treats, and monitors security weaknesses across infrastructure, applications, and cloud environments. It combines technology, process, and governance to minimize the attack surface and improve organizational resilience.

Modern VM goes beyond just scanning and patching—it requires context-aware prioritization, business alignment, cross-functional coordination, and clear communication. A mature VM program enables organizations to stay ahead of threats, align with compliance mandates, and make informed decisions about where to invest remediation efforts.

LDR516 helps you become a more effective and strategic security leader. You’ll develop the skills to lead vulnerability management efforts, drive remediation decisions based on real-world risk, and communicate findings in ways that influence stakeholders. Through AI-powered labs and Cyber42 simulation challenges, you’ll gain practical experience in decision-making, prioritization, reporting, and stakeholder engagement—making you better prepared to lead, influence, and advance in your career.

Relevant Job Roles

Operational Cybersecurity Executive

Cybersecurity Leadership

Lead operational teams from the point of view of an adversary in order to protect your most sensitive assets.

Explore learning path

Security Manager Training, Salary, and Career Path

Cybersecurity Leadership

Daily focus is on the leadership of technical teams. Includes titles such as Manager, Information Security Specialist, and Program/Project Leader.

Explore learning path

Vulnerability Analysis (OPM 541)

NICE: Protection and Defense

Responsible for assessing systems and networks to identify deviations from acceptable configurations, enclave policy, or local policy. Measure effectiveness of defense-in-depth architecture against known vulnerabilities.

Explore learning path

Cybersecurity Researcher

European Cybersecurity Skills Framework

Research the cybersecurity domain and incorporate results in cybersecurity solutions.

Explore learning path

Chief Information Security Officers Training, Salary, and Career Path

European Cybersecurity Skills Framework

Chief Information Security Officers lead cybersecurity initiatives, aligning strategic vision with operational execution, fostering a resilient security culture, and proactively managing risks to safeguard organisational assets and reputation.

Explore learning path

Course Schedule and Pricing

Have Questions?Contact Us
  • Location & instructor

    Virtual (OnDemand)

    Instructed by
    Date & Time
    OnDemand (Anytime)Self-Paced, 4 months access
    Course price
    $8,260 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Amsterdam August 2026

    Amsterdam, NL & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    €7,715 EUR*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS DC Metro September 2026

    Bethesda, MD, US & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    $8,260 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS London October 2026

    London, GB & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    £6,715 GBP*Prices exclude applicable taxes | EUR price available during checkout
    Registration Options
  • Location & instructor

    SANS Cyber Safari 2026

    Riyadh, SA & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    $8,375 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Dallas 2026

    Dallas, TX, US & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    $8,260 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Nashville 2027

    Nashville, TN, US & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    $8,260 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS 2027

    Orlando, FL, US & Virtual (live)

    Date & Time
    Fetching schedule..
    Course price
    $8,260 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANSFIRE 2027

    Washington, DC, US & Virtual (live)

    Date & Time
    Fetching schedule..
    Course price
    $8,260 USD*Prices exclude applicable local taxes
    Registration Options
Showing 9 of 9

Benefits of Learning with SANS

Bryan Simon: Teacher Standing Next to Smartboard and Explaining Concept

Get feedback from the world’s best cybersecurity experts and instructors

OnDemand Mobile App

Choose how you want to learn - online, on demand, or at our live in-person training events

Close Up of Woman Holding a Pen and Documents

Get access to our range of industry-leading courses and resources