Group Purchasing
Group Purchasing
AI-FOCUSEDNEW

LDR550: Leading Agentic Security Teams

LDR550Cybersecurity Leadership, Artificial Intelligence
  • 2 Days (Instructor-Led)
  • 12 Hours
Course authored by:
Lenny Zeltser
Lenny Zeltser
LDR550: Leading Agentic Security Teams
Course authored by:
Lenny Zeltser
Lenny Zeltser
  • 12 CPEs

    Apply your credits to renew your certifications

  • Virtual

    Attend a live, instructor-led class remotely from anywhere.

  • Advanced Skill Level

    Course material is geared for cyber security professionals with hands-on experience

  • 8 Hands-On Lab(s)

    Apply what you learn with hands-on exercises and labs

Learn to design a security organization built on governed AI, using a durable framework to decide how much autonomy each workflow gets and who stays accountable.

Course Overview

Get Notified About LDR550 Training Events

Want to be the first to know when LDR550 registration opens? Complete the interest form to receive updates on upcoming training events, OnDemand availability, and more. Be among the first to learn how to redesign the security function around governed AI, determine what AI may do on its own, and keep people accountable for the outcome.

Interest Form

Security leaders are under pressure to do more with AI, but most add it piecemeal without changing how the team operates. This course teaches you to design the security function, so your team delivers more, with routine work handed to AI under your direction. You'll decide which work to delegate, at what level of autonomy, and who stays accountable, practice them in the SANS Cyber42 simulation, and start the plan for your own organization.

Most security teams add AI at the edges of the work, an assistant here and a review tool there, and the gains stay marginal because the operating model has not changed. AI can do more when it handles the routine work, with people setting policy, making the hard calls, and supervising the system.

You'll learn how to decide, for every security workflow, which actions AI may take on its own, who approves or overrides it, and who answers for the outcome. You'll learn to weigh each grant of autonomy against the damage a wrong action could do and how hard it would be to undo.

You'll practice on a fictional organization in the SANS Cyber42 simulation, where each decision becomes a row in the organization's Security Autonomy Matrix, the single table you can use to capture decisions. In the capstone you start the same plan for your own security function, from the budget, team, and tools you have today.

Author Statement

I've watched security teams add AI to their security program in incremental ways without meaningful results. The problem was the lack of an approach for putting AI at the core of the program without taking on undue risk.

I designed this course around two questions a leader faces when progressing to an AI-enabled security program. What may the AI do on its own, and who answers for the outcome? You'll learn how to make such calls for each aspect of the security team's work in a deliberate, measured way. This way, you’ll place people where their judgment matters most, deploy AI where it offers value, and adjust AI agents’ authority as they gain or lose trust.

- Lenny Zeltser

What You’ll Learn

  • Redesign the security operating model around governed AI so teams can deliver more without losing accountability
  • Set an appropriate level of autonomy for each security workflow
  • Place human approval where an incorrect action would be costly or difficult to reverse
  • Select AI capabilities the team can oversee without becoming dependent on one vendor
  • Build a phased roadmap toward AI-native cybersecurity operations
  • Prepare for automation bias, skill atrophy, and situations when AI is wrong or unavailable
  • Explain the approach to executives and colleagues to gain organizational support

Business Takeaways

  • Reduce analyst toil and cost through governed automation
  • Accelerate security decisions without surrendering oversight
  • Strengthen accountability for AI-driven actions, with a named owner for each one
  • Lower concentration risk in the AI tools the team depends on
  • Expand the depth and breadth of the security team’s capabilities to improve outcomes

Course Syllabus

Explore the course syllabus below to view the full range of topics covered in LDR550: Leading Agentic Security Teams.

Section 1What Good Looks Like, and the Framework for Getting There

Section one covers what a strong AI-native security program looks like and the decision framework behind it, the autonomy spectrum and the Security Autonomy Matrix. You'll baseline a security team's current autonomy, map its workflows, set oversight tiers, and apply the framework to security operations.

Topics covered

  • The AI-native security organization
  • The autonomy spectrum and the decision framework
  • Governance, accountability, and human oversight
  • Security operations as the lead example

Labs

  • Baseline the security team's current autonomy
  • Classify the security team's workflows into an autonomy map
  • Set the governance and oversight tiers
  • The 2 a.m. scenario: decide how the SOC's AI agent should handle endpoint isolation

Overview

  • The AI-native security organization.
    • Why the shift is happening now, what a strong AI-native security program looks like, and how it relates to securing AI itself.
    • Lab: Baseline the security team's current autonomy.
  • The autonomy spectrum and the decision framework.
    • The five levels by action class, and how to decide which security work to make autonomous, from alert triage to containment.
    • Lab: Classify the security team's workflows into an autonomy map.
  • Governance, accountability, and human oversight.
    • Where to place the human gate, judged by the blast radius and reversibility of a security action, such as isolating endpoints or disabling accounts. How to give each AI agent a scoped identity and an audit trail. A named human stays accountable even when no one reviewed the decision before it took effect.
    • Lab: Set the governance and oversight tiers.
  • Security operations as the lead example.
    • How agentic triage, hunting, and response change the SOC, and where autonomy belongs.
    • Lab: The 2 a.m. scenario, a single Cyber42 round in which the team decides, well before any alert fires, how the SOC's AI agent should handle endpoint isolation for a high-confidence detection that could affect 40 endpoints. The team weighs speed against a false-positive risk, names who is accountable for what the AI does on its own, and sets the human gate based on how quickly an isolation can be undone versus how fast the harm could spread.

Section 2Applying the Framework and Leading the Change

Section two covers the use of the Security Autonomy Matrix beyond the SOC, the operating-model and team changes that follow, how to select AI capabilities, and how to manage the risks of running security on AI. You'll leave with a started matrix and a sketched 90-day roadmap for your own organization.

Topics covered

  • Applying the framework across the security function
  • The operating model and the team
  • Selecting AI capabilities for the security team
  • Risks, failure, and the roadmap

Labs

  • Apply the framework to a second security domain
  • Redesign the security team's operating model
  • Build a tool-selection rubric
  • Capstone: Start the Security Autonomy Matrix for your own organization and sketch a 90-day roadmap

Overview

  • Across the security function.
    • The framework applied quickly to product security, GRC, and cloud, to show its reach beyond the SOC.
    • Lab: Apply the framework to a second security domain.
  • The operating model and the team.
    • How security roles shift from doing the work to supervising it, and how to lead analysts and engineers through that change.
    • Lab: Redesign the security team's operating model.
  • Selecting AI capabilities for the security team.
    • How to choose by capability rather than product, weighing portability and the risk of concentrating detection and response on one vendor. A capability that can't enforce the matrix's approval gates doesn't make the list.
    • Lab: Build a tool-selection rubric.
  • Risks, failure, and the roadmap.
    • Plan for second-order risks such as automation bias and analyst skill atrophy. Know what to do when the security AI is wrong or unavailable, including the fallback autonomy level, and how to sequence the change.
    • Lab: Capstone: start a matrix for your own organization and sketch a 90-day roadmap.

Things You Need To Know

Important! Bring your own system configured according to these instructions.

A laptop or mobile device with the latest web browser is required to play the Cyber42 leadership simulation game.

The Cyber42 game used in this course is hosted on the ranges.io platform. Students must have a computer that does not restrict access to ranges.io. Corporate machines may have a VPN, intercepting proxy, or egress firewall filter that causes connection issues communicating with third-party websites. Students must be able to configure or disable these services to be able to access the Cyber42 game.

If you have additional questions about the laptop specifications, please contact customer service.

This is a leadership course for the people who set a security program's direction and run its teams. Students learn to design and govern the AI-native security function, and the course expects no hands-on work with the tools.

  • CISOs and Senior Security Leaders
    • Leaders who own strategy, budget, and the security operating model
  • Security Directors and Team Leads
    • Leaders who put the transition into practice within their teams

  • Printed and electronic courseware
  • Access to the Cyber42 security leadership simulation game
  • MP3 audio files of the complete course lecture
  • A Security Autonomy Matrix template, a starter list of common security workflows, and reference cards for the autonomy levels and action classes, for starting your own matrix in class and finishing it at work

LDR550: Leading Agentic Security Teams is part of the SANS Cybersecurity Leadership curriculum. It builds on the cybersecurity concepts covered in LDR512: Security Leadership Essentials for Managers and complements LDR520: Emerging Trends for Cyber Leaders: AI and Cloud. A leader who finishes LDR520 can secure the AI and cloud their business adopts; LDR550 helps that leader redesign the security function itself around governed AI.

An agentic security team is a security function that runs on governed AI under human direction. AI agents handle the routine work, such as alert triage, evidence gathering, and first-pass review, within limits a leader sets, while people set policy, make the hard calls, and supervise the system.

Leading such a team means deciding which work to delegate to AI, at what level of autonomy, and who stays accountable when the AI acts on its own. An agent that can isolate a host, suspend an account, or change a firewall rule needs a named person who answers for it and a clear point where a person can override it. This course teaches you to make those decisions deliberately, workflow by workflow, and to record them in a form your executives and counsel can act on.

Security leadership now includes deciding what AI may do on the team's behalf, and this course gives you a method for that decision and the vocabulary to explain it to executives and the board.

You leave with the start of a written record of which security work your AI agents may do on their own, who approves the rest, and who answers for each outcome, along with a sketched 90-day roadmap for your own organization, built from the budget, team, and tools you have today. For CISOs and senior leaders, the course ties those decisions to outcomes a CFO understands, such as analyst capacity, decision speed, and headcount leverage. For directors and team leads, it gives you a structured way to lead your team through a transition that can feel uncertain, including how roles change as AI takes on routine work.

Because you capture decisions rather than products, what you decide in class still applies after your AI tools change, and you have one place to revisit each call as the AI earns more trust or loses it.

Course Schedule and Pricing

Have Questions?Contact Us

We couldn't find a match for your selection

Please try a different combination of filters and search again.

Benefits of Learning with SANS

Bryan Simon: Teacher Standing Next to Smartboard and Explaining Concept

Get feedback from the world’s best cybersecurity experts and instructors

OnDemand Mobile App

Choose how you want to learn - online, on demand, or at our live in-person training events

Close Up of Woman Holding a Pen and Documents

Get access to our range of industry-leading courses and resources