Group Purchasing
Group Purchasing
AI-FOCUSEDMAJOR UPDATES

LDR520: Emerging Trends for Cyber Leaders: AI and Cloud

LDR520Cybersecurity Leadership, Artificial Intelligence
  • 5 Days (Instructor-Led)
  • 30 Hours (Self-Paced)
Course authored by:
Jason Lam
Jason Lam
LDR520: Cloud Security for Leaders
Course authored by:
Jason Lam
Jason Lam
  • 30 CPEs

    Apply your credits to renew your certifications

  • In-Person, Virtual or Self-Paced

    Attend a live, instructor-led class at a location near you or remotely, or train on your time over 4 months

  • Advanced Skill Level

    Course material is geared for cyber security professionals with hands-on experience

  • 13 Hands-On Lab(s)

    Apply what you learn with hands-on exercises and labs

Drive enterprise resilience and innovation by shaping AI adoption strategy, modernizing cloud security foundations, and preparing for post-quantum disruption.

Course Overview

LDR520: Emerging Trends for Cyber Leaders: AI and Cloud empowers leaders to navigate the complex, interconnected risks of AI and cloud transformation. You will master AI security by establishing robust governance frameworks and building practical implementation roadmaps to defend against modern threats. The course then establishes a critical foundation in cloud security, covering everything from identity and infrastructure protection to advanced data operations and multicloud governance. Finally, you will look ahead to post-quantum cryptography and apply all learned concepts in a comprehensive, executive-level capstone exercise.

Adapt. Lead. Secure the Future of Cyber.

LDR520: Emerging Trends for Cyber Leaders: AI and Cloud prepares security leaders to master the strategic and defensive imperatives of artificial intelligence and modern cloud infrastructure. You will begin by building the urgent business case for AI security, establishing robust governance frameworks compliant with NIST, the EU AI Act, and ISO standards. Participants will learn to identify and counter modern vulnerabilities—from the OWASP LLM Top 10 and "Shadow AI" to sophisticated adversarial attacks—while building practical implementation roadmaps covering vendor selection and AI-powered SOC transformation.

With AI strategy established, the program builds critical cloud security foundations for identity management, infrastructure protection, and multi-account architecture, recognizing that modern AI workloads increasingly operate in cloud environments. You will then master cloud data protection, DevSecOps integration, and multicloud governance strategies while learning how AI and cloud security intersect—from securing AI training pipelines to leveraging AI-powered security operations. The course concludes by preparing you to lead post-quantum cryptographic transitions and synthesizing all knowledge in an executive-level capstone where you design a complete enterprise security modernization strategy bridging AI adoption, cloud transformation, and emerging cryptographic threats.

Hands-On Cloud Security Strategy Training

LDR520 equips students with both technical and management expertise using case scenarios, group discussions, and team-based security leadership simulations with embedded real-life technical components. This course is designed to develop cloud/AI security leaders by combining strategic leadership concepts with practical cloud-focused decision-making.  About 60 minutes per day is dedicated to these learning experiences using the Cyber42 leadership simulation game. This web application-based game is a continuous exercise where students play to improve security culture, manage budget and schedule, and improve security capabilities at a fictional organization. This puts you in real-world scenarios that spur discussion and critical thinking about situations you will encounter at work.

Author Statement

"Leaders in security organizations often face unprecedented pressure to embrace transformative technologies like artificial intelligence, cloud infrastructure, and next-generation cryptographic standards while simultaneously protecting their organizations from increasingly sophisticated attacks. I designed LDR520 to bridge this critical gap between business innovation and security imperatives. In this course, participants gain access to battle-tested methodologies that enable them to plan and execute strategic secure technology transformations that drive tangible business value. Drawing from real-world scenarios and practical security frameworks refined through years of experience in Global 500 organizations, I guide security leaders through proven approaches to systematically strengthen their organization's security posture while accelerating digital initiatives. By the end of this course, participants will have mastered the strategic decision-making frameworks, stakeholder engagement techniques, and technical implementation strategies necessary to confidently lead their organization's security transformation from initial planning through successful deployment."

- Jason Lam

What You'll Learn

  • Build and defend the AI security business case
  • Identify and mitigate AI-specific vulnerabilities
  • Design and execute AI implementation roadmaps
  • Establish secure cloud foundations
  • Protect cloud data and operations
  • Prepare for post-quantum cryptographic transitions

Business Takeaways

  • Reduce AI security incidents and associated costs
  • Avoid regulatory penalties and insurance premium increases
  • Prevent catastrophic deepfake and AI-enhanced fraud losses
  • Future-proof cryptographic infrastructure
  • Accelerate secure cloud adoption
  • Enhance board-level strategic decision making

Course Syllabus

Explore the course syllabus below to view the full range of topics covered in LDR520: Emerging Trends for Cyber Leaders: AI and Cloud.

Section 1AI Strategic Imperatives: Governance and Threat Assessment

This section builds the business case for AI security and establishes governance foundations through NIST AI RMF, EU AI Act, and ISO 42001. Practical governance structures and global regulatory perspectives lead into the Executive Playbook, equipping leaders with influence strategies, resistance management, and stakeholder communication for transformation.

Topics covered

  • AI business case, fundamentals, and Shadow AI risk
  • NIST AI RMF, EU AI Act, and ISO 42001 frameworks
  • Governance structures, oversight models, and third-party risk
  • Executive Playbook for influence and transformation
  • US, EU, and global regulatory strategy and emerging AI risks

Labs

  • Governance framework design and compliance mapping
  • Stakeholder mapping and resistance diagnostics
  • Governance communication and engagement strategy

Overview

This section builds comprehensive AI governance leadership capability. You will move from understanding the high-stakes business case and AI technology fundamentals through mastering governance frameworks and regulatory requirements to designing practical implementation structures. The Executive Playbook then transforms framework knowledge into leadership action—teaching you to build coalitions, overcome organizational resistance, and communicate governance value to diverse stakeholders. We focus on the "Govern AI" pillar, providing the strategic foundation for Section 2's threat-focused content.

Full Lab Details

  • Design governance frameworks for industry-specific compliance scenarios, mapping requirements across NIST AI RMF, EU AI Act, and ISO 42001 to organizational context
  • Conduct stakeholder mapping and resistance archetype analysis, identifying blockers and allies within your organizational structure using the Executive Playbook diagnostic framework
  • Develop targeted engagement strategies, communication plans, and action priorities for governance program

Full Topic Details

  • The AI Security Business Case and Fundamentals
    • Financial case for AI security with ROI data and insurance implications
    • AI technology fundamentals for security leaders
    • Shadow AI crisis and the Three-Pillar Framework: Governance, Safety, Security
  • Strategic AI Governance Frameworks
    • NIST AI RMF, EU AI Act, and ISO 42001: core requirements and framework selection
    • Cross-framework mapping and integration strategies
  • Practical Governance Structures
    • CAIO role, governance committees, AI registries, and approval workflows
    • Human oversight models (HITL, HOTL, HIC), monitoring, and third-party risk management
  • Leading AI Security Transformation: The Executive Playbook
    • Building influence and securing executive sponsorship
    • Eight resistance archetypes with diagnostic and engagement strategies
    • Phased execution, stakeholder communication, and measuring program value
  • Regulatory Compliance: US & EU Deep Dives
    • US federal policy, sector-specific regulations, and state-level AI legislation
    • EU AI Act technical requirements: accuracy, robustness, cybersecurity, and conformity assessment
    • Integrated compliance roadmaps across multiple frameworks
  • Global Perspectives & Emerging Frontiers
    • APAC, Americas, and Middle East regulatory approaches
    • Agentic AI governance, vendor supply chain management, and red teaming foundations

Section 2AI Defense and Enterprise Implementation

This section shifts from governance to operational security across three pillars. Safety and Assurance covers bias detection with hands-on auditing. System Security explores OWASP LLM Top 10 vulnerabilities and adversarial attacks. Threat Landscape examines AI-enhanced attacks, while AI-Enabled Defense builds SOC capabilities and investment roadmaps.

Topics covered

  • Bias detection, fairness metrics, and oversight risks
  • OWASP LLM Top 10 and adversarial attack techniques
  • AI-powered phishing, deepfakes, and automated exploitation
  • MITRE ATLAS and AI-specific threat intelligence
  • AI-enabled SOC capabilities and investment strategy

Labs

  • Governance framework selection under pressure
  • Executive funding and influence strategy
  • International data architecture and regulatory trade-offs

Overview

This section transitions from Day 1's governance foundations to operational security excellence. Building on the frameworks and structures already established, you will develop hands-on capabilities across three integrated pillars: Safety and Assurance, AI System Security, and AI-Enabled Defense. Two workshops produce actionable artifacts—bias audit findings and threat models—that translate directly into work products for your organization. By section end, you will have concrete investment roadmaps and implementation priorities grounded in real threat intelligence.

Full Lab Details

  • Choosing the right governance framework when organizational maturity, political dynamics, and urgency don't all point to the same answer.
  • Applying coalition-building and timing principles to secure resources, weighing competing influence strategies with different organizational positioning tradeoffs.
  • How global expansion forces architectural decisions about data residency and federated governance across multiple regulatory regimes.

Full Topic Details

  • Safety and Assurance: Bias Detection and Mitigation
    • Bias types, sources, and the business case: legal, reputational, and operational risk
    • Quantitative fairness metrics and practical detection methodologies
    • Human oversight failure modes: complacency, fatigue, and atrophy countermeasures
  • AI System Security: OWASP LLM Top 10 and Adversarial Attacks
    • Prompt injection mechanics, defense-in-depth architectures, and real-world incident analysis
    • Sensitive information disclosure, supply chain vulnerabilities, and excessive agency controls
    • Adversarial attack techniques: evasion, poisoning, extraction, and backdoors
  • AI-Enhanced Threat Landscape
    • AI-powered phishing, deepfake fraud, and automated exploitation at machine speed
    • Defensive strategies and countermeasures for AI-enhanced attack vectors
    • MITRE ATLAS framework application for AI-specific threat intelligence
  • AI-Enabled Defense and Investment Planning
    • AI-SOC capability requirements, integration patterns, and maturity roadmaps
    • Risk-based investment frameworks and Three-pillar program integration

Section 3Cloud Security Foundations, Identity, and Infrastructure

This section applies the 8-domain maturity framework to four foundational pillars: Identity and Access Management, Secure Infrastructure, Detection and Response, and Security Governance. Executives learn to assess organizational maturity, prioritize security investment, and lead transformation across the domains that define cloud security posture.

Topics covered

  • Identity and access management strategy
  • Secure infrastructure, configuration, and architecture
  • Detection, response, and security analytics
  • Cloud security governance and cost management
  • Maturity assessment and investment prioritization

Labs

  • IAM privilege and credential strategy trade-offs
  • Infrastructure drift resolution under pressure
  • Detection and response investment decisions

Overview

This session translates the maturity framework into leadership decisions across four domains: IAM, Infrastructure, Detection & Response, and Security Governance. Each domain progresses from strategic context through maturity assessment, capability building, case studies, and investment prioritization. Cyber42 exercises place you in the CISO role making consequential decisions under realistic organizational pressure.

Full Lab Details

  • Navigate IAM privileged access and credential strategy trade-offs
  • Resolve infrastructure configuration drift under organizational pressure
  • Prioritize detection and response investments under resource constraints

Full Topic Details

  • Cloud Security Leadership Foundation
    • The leadership imperative, threat landscape, and executive accountability
    • The 8-domain maturity framework and action planning methodology
  • Identity and Access Management
    • Segregation: blast radius reduction, multi-account strategy, and governance
    • Identity: architecture decisions, authentication evolution, and lifecycle management
    • Access: least privilege, privileged access, JIT/zero standing privilege, and machine identity
    • Case studies: Storm-0558, Snowflake breach, Capital One
    • Integrated IAM assessment, success metrics, and investment priorities
  • Secure Infrastructure and Architecture
    • Configuration management: CSPM, guardrails, and drift prevention
    • Resource management: Infrastructure as Code and security practices
    • Image management: VM and container lifecycle security
    • Architecture: landing zones, zero trust, immutable infrastructure, and threat modeling
    • Network controls: VPC segmentation and PaaS networking decisions
    • Case studies: Football Australia, Codecov
  • Detection and Response
    • Log management: strategy, retention, centralization, and cost decisions
    • Security intelligence: threat feeds, enrichment, and threat hunting
    • Analytics: SIEM/SOAR, detection engineering, and alert fatigue management
    • Incident response: cloud-specific challenges, forensics, runbooks, and simulations
    • Integrated assessment and success metrics
  • Security Governance
    • Leadership and oversight: committee formation, stakeholders, and charter
    • Cost management: attribution, tagging, budgeting, and FinOps
    • Security policy: cloud-specific policies, implementation, and enforcement
    • Third-party risk: vendor assessment and board-level reporting

Section 4Cloud Data Protection, Operations, and Governance

This section completes the maturity framework across four remaining domains: Data Protection, Workload and Application Security, Security Assurance, and Workforce Transformation. A dedicated SaaS operational security module closes the course, equipping leaders to govern the fastest-growing and least-controlled segment of cloud adoption.

Topics covered

  • Data protection: encryption, classification, resilience
  • Workload and DevSecOps security
  • Security assurance and compliance validation
  • Workforce transformation and operating models
  • SaaS operational security governance

Labs

  • Cross-region data protection trade-offs
  • Application security vs. business scale decisions
  • Assurance investment prioritization

Overview

This session extends maturity assessment to data protection, application security, security assurance, and workforce transformation. A closing SaaS module addresses operational security for the fastest-growing cloud segment. Three Cyber42 exercises continue the CISO simulation with decisions spanning encryption strategy, DevSecOps scaling, and assurance program design.

Full Lab Details

  • Resolve cross-region data protection gaps under regulatory pressure
  • Balance application security remediation against scale-out demands
  • Prioritize security assurance when audit findings conflict with risk reality

Full Topic Details

  • Data Protection
    • Encryption: key management models, BYOK/HYOK decisions, and confidential computing
    • Classification: discovery, protection controls, and common pitfalls
    • Backup: ransomware resilience, immutable storage, and cyber recovery
    • Case study: Toyota—the 8-year data exposure blind spot
    • Integrated assessment and executive success metrics
  • Securing Workloads and Applications
    • DevSecOps: CI/CD pipeline security, supply chain threats, and SBOM
    • Secrets management and IaC validation in deployment pipelines
    • Protection services: API security, WAF/DDoS, CWPP, and runtime protection
    • Workload assessment: security testing, threat modeling, and maturity progression
    • Case studies: Codecov, 3CX, xz Utils
  • Security Assurance
    • Posture validation: benchmarks, automated assessment, and CSP tools
    • Regulatory compliance: PCI-DSS, GDPR, and HIPAA in cloud
    • Security testing: penetration testing, MITRE ATT&CK, and purple teaming
    • Case studies: Oracle Legacy breach, Change Healthcare
    • Integrated assessment, metrics, and investment guidance
  • Workforce Transformation
    • Skills gap assessment, training frameworks, and CSP learning resources
    • DevSecOps culture, security operating models, and organizational alignment
    • Workforce metrics and measuring security skills effectiveness
  • SaaS Operational Security
    • Identity, configuration management, and shadow IT governance
    • Data protection, incident response, and business continuity
    • Executive action framework for SaaS security programs

Section 5Post Quantum Crypto and Capstone Exercise

This section addresses the modern crypto transition to post-quantum security management, a critical future-proofing strategy. It culminates in a capstone exercise where students apply all concepts and skills learned throughout the course in a practical, executive-level scenario.

Topics covered

  • Post-quantum threats and cryptographic risk
  • Crypto inventory and agility strategy
  • Post-quantum migration planning

Labs

  • Executive-Level capstone exercise
  • Security strategy development presentation

Overview

In section five, we explore the preparation for the next wave of cryptographic challenges by focusing on post-quantum computing. This section covers the threats, the necessity of a crypto inventory, and strategic planning for migration. It all comes together in an executive-level capstone exercise to apply your holistic security knowledge.

Full Lab Details

  • Capstone: Large scale traditional enterprise is moving to the AI and cloud. Working in groups, students draft the roadmap to modernize the entire security program and present their approach to the class

Full Topic Details

  • Post-Quantum (PQC) Threats
    • Understanding the quantum threat
    • Impact on current encryption standards
    • Assessing organizational risk
  • Crypto-Agility and Inventory
    • Building a cryptographic inventory
    • Assessing service dependencies
    • Developing a crypto-agility strategy
  • PQC Transition and Migration
    • Planning the migration process
    • Phased rollout and hybrid approaches
    • Managing transition challenges
  • Executive Capstone Exercise
    • Applying course concepts to a scenario
    • Developing an enterprise security roadmap
    • Presenting strategy to "executives"

Things You Need To Know

Important! Bring your own system configured according to these instructions.

A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will not be able to fully participate in hands-on exercises in your course. Therefore, please arrive with a system meeting all of the specified requirements.

Back up your system before class. Better yet, use a system without any sensitive/critical data. SANS is not responsible for your system or data.

Mandatory System Hardware Requirements

  • Wireless networking (802.11 standard) is required. There is no wired Internet access in the classroom.

Mandatory Host Configuration And Software Requirements

  • Your host operating system must be the latest version of Windows 10, Windows 11, or macOS 11.7.x or newer.
  • Fully update your host operating system prior to the class to ensure you have the right drivers and patches installed.
  • Linux hosts are not supported in the classroom due to their numerous variations. If you choose to use Linux as your host, you are solely responsible for configuring it to work with the course materials and/or VMs.
  • Local Administrator Access is required. (Yes, this is absolutely required. Don't let your IT team tell you otherwise.) If your company will not permit this access for the duration of the course, then you should make arrangements to bring a different laptop.
  • You should ensure that antivirus or endpoint protection software is disabled, fully removed, or that you have the administrative privileges to do so. Many of our courses require full administrative access to the operating system and these products can prevent you from accomplishing the labs.
  • Any filtering of egress traffic may prevent accomplishing the labs in your course. Firewalls should be disabled or you must have the administrative privileges to disable it.

If you have additional questions about the laptop specifications, please contact customer service.

This course is designed for managers, directors, and senior professionals responsible for leading or influencing enterprise decisions around AI adoption, cloud transformation, and emerging security risks. It is ideal for those shaping strategy, governance, and implementation across cybersecurity, risk, and IT functions.

  • Printed and Electronic courseware
  • MP3 audio files of the course
  • Access to the Cyber42 web application

Students should have three to five years of experience in IT and/or cybersecurity. This course covers the core areas of security leadership in migrating workloads to the cloud environment and assumes a basic understanding of technology, networks, and security.

LDR520 bridges SANS Cybersecurity Leadership and SANS Cloud Security curricula, expanding into AI governance, strategic execution, and emerging threats. It prepares leaders to align AI and cloud adoption with enterprise security, compliance, and business strategy.

To continue building depth skills across cybersecurity leadership, vulnerability management, and governance and compliance learners can pair this course with:

This course also is a core part of the Cloud ACE Journey for the Cloud Security Architect role. The 3-course journey helps develop skills in craft strategic blueprints for secure cloud adoption, aligning infrastructure and innovation with regulatory and security mandates. The fully journey includes:

AI strategic imperatives are core priorities that guide organizations in adopting and leveraging artificial intelligence to achieve competitive advantage, manage risk, drive innovation, and ensure responsible implementation.

These include developing business-aligned governance frameworks, understanding regulatory compliance requirements (such as the NIST AI RMF, ISO 42001, and the EU AI Act), and identifying and mitigating emerging threats such as Shadow AI, adversarial machine learning, and deepfake-enabled fraud. For cyber leaders, this means integrating AI into enterprise strategy with a clear understanding of both the innovation potential and the security risks.

Cloud Security Strategy is a comprehensive plan to protect an organization's data, workloads, and infrastructure in cloud environments. It addresses the unique security challenges of cloud computing, focusing on identity management, data protection, configuration security, and continuous monitoring . Effective cloud security strategies are a core responsibility for cloud security leadership tasked with enabling secure digital transformation.

LDR520 equips cybersecurity leaders with the strategic frameworks and decision-making skills needed to govern AI adoption, lead secure cloud transformation, and prepare for future challenges like post-quantum cryptography. You will learn to design risk-informed roadmaps, implement compliant governance models, and communicate effectively with executives. These capabilities are critical for leadership roles driving innovation, managing emerging threats, and aligning cybersecurity strategy with enterprise goals.

Relevant Job Roles

Cloud Security Manager

Cloud Security

Developing cloud security roadmaps, plans and procurement models to mature cloud security.

Explore learning path

Secure Project Management (OPM 802)

NICE: Oversight and Governance

Responsible for overseeing and directly managing technology projects. Ensures cybersecurity is built into projects to protect the organization’s critical infrastructure and assets, reduce risk, and meet organizational goals. Tracks and communicates project status and demonstrates project value to the organization.

Explore learning path

Systems Security Management (OPM 722)

NICE: Oversight and Governance

Responsible for managing the cybersecurity of a program, organization, system, or enclave.

Explore learning path

Senior Security Leader

Cybersecurity Leadership

Daily focus is on the oversight of technical teams while aligning them to overall business strategies. Includes titles such as Technical Director, Information Security Officer, and CISO.

Explore learning path

Cloud Security Architect Training, Salary, and Career Path

Cloud Security

Designs and secures the defensive architecture of secure cloud environments.

Explore learning path

Leadership

SCyWF: Leadership And Workforce Development

This role conducts supervises, manages and leads cybersecurity teams and work. Find the SANS courses that map to the Leadership SCyWF Work Role.

Explore learning path

Program Management (OPM 801)

NICE: Oversight and Governance

Responsible for leading, coordinating, and the overall success of a defined program. Includes communicating about the program and ensuring alignment with agency or organizational  priorities.

Explore learning path

Chief Information Security Officers Training, Salary, and Career Path

European Cybersecurity Skills Framework

Chief Information Security Officers lead cybersecurity initiatives, aligning strategic vision with operational execution, fostering a resilient security culture, and proactively managing risks to safeguard organisational assets and reputation.

Explore learning path

Course Schedule and Pricing

Have Questions?Contact Us
Showing 10 of 13

Benefits of Learning with SANS

Bryan Simon: Teacher Standing Next to Smartboard and Explaining Concept

Get feedback from the world’s best cybersecurity experts and instructors

OnDemand Mobile App

Choose how you want to learn - online, on demand, or at our live in-person training events

Close Up of Woman Holding a Pen and Documents

Get access to our range of industry-leading courses and resources