Group Purchasing
Group Purchasing

LDR551: Building and Leading Security Operations Centers

LDR551Cybersecurity Leadership
  • 5 Days (Instructor-Led)
  • 30 Hours (Self-Paced)
Course authored by:
John HubbardMark Orlando
John Hubbard & Mark Orlando
LDR551: Building and Leading Security Operations Centers
Course authored by:
John HubbardMark Orlando
John Hubbard & Mark Orlando
  • GIAC Security Operations Manager (GSOM)
  • 30 CPEs

    Apply your credits to renew your certifications

  • In-Person, Virtual or Self-Paced

    Attend a live, instructor-led class at a location near you or remotely, or train on your time over 4 months

  • Advanced Skill Level

    Course material is geared for cyber security professionals with hands-on experience

  • 19 Hands-On Lab(s)

    Apply what you learn with hands-on exercises and labs

Stop reactive firefighting. Learn to build SOC operations from the ground up—with the right people, threat-focused detection, battle-tested incident response, and metrics that drive real results.

Course Overview

LDR551 is a transformative training program designed for senior security leaders who demand more than traditional Security Operations Center (SOC) management. This executive-level course equips technology leaders with advanced intelligence-driven methodologies to proactively defend against sophisticated threat landscapes. Navigate complex cyber environments with a strategic approach that aligns security operations directly with high-stakes organizational objectives.

Key executive outcomes include designing resilient defense strategies tailored to your enterprise's unique risk profile and transforming SOC capabilities from reactive to proactive. Additionally, you'll integrate cyber leadership principles with tactical threat management, while gaining hands-on experience through 19 immersive labs and the Cyber42 leadership simulation game.

Prevent - Detect - Respond | People - Process - Technology

Information technology is so tightly woven into the fabric of modern business that cyber risk has become business risk. SOC managers must align their operations to organizational priorities and demonstrate measurable value—a challenge when threats are hard to quantify and stakeholder expectations are often vague. How does a SOC leader communicate value, justify investments, and focus efforts on what truly protects the business?

LDR551 breaks down security operations into clear, measurable functions that can be tracked and continuously improved. We then connect these core SOC activities directly to organizational goals, giving you the frameworks to communicate impact with executives and stakeholders in language they understand.

Common questions SOC leaders face:

  • How do we ensure our security teams are aligned to the unique threats facing our organization?
  • How do we achieve consistent detection and response results that minimize business impact?
  • How can we build empowered, high-performing teams that solve problems proactively while avoiding burnout?
  • What metrics actually matter, and how do we demonstrate continuous improvement to leadership?

Whether you're building a new SOC from the ground up or elevating your current team's capabilities, LDR551 delivers the strategies, frameworks, and hands-on experience to transform your operations. Each section includes practical labs covering mission planning, threat modeling, detection engineering, playbook development, and quality improvement—culminating in Cyber42 SOC leadership simulation exercises that test decision-making under pressure.

You'll learn to combine people, processes, and technology in ways that produce measurable results across any infrastructure or organizational structure. Attackers continuously evolve—a SOC that stands still falls behind. LDR551 equips you with the leadership mindset, proven frameworks, and continuous improvement processes needed to build resilient teams that stay ahead of sophisticated threats over the long term.

Hands-On SOC Manager Training

While LDR551 is focused on management and leadership, it is by no means limited to non-technical processes and theory. The course uses the Cyber42 leadership simulation game to put you in real-world scenarios that spur discussion and critical thinking of situations that you will encounter at work. Throughout the five days of instruction, students will work on seventeen hands-on exercises covering everything from playbook implementation to use case database creation, attack and detection capability prioritization and visualization, purple team planning, threat hunting, and reporting. Attendees will leave with a framework for understanding where a SOC manager should be focusing efforts, how to track and organize defensive capabilities, and how to drive, verify, and communicate SOC improvements.

Hands-on labs include:

  • Section 1: Creating a SOC Mission and Charter, Critical Asset Mapping, and Creating Priority Intelligence Requirements
  • Section 2: Threat Actor Assessment, Cyber Attack Threat Modeling and Data Source Assessments, ATT&CK Navigator for Attacker Technique Prioritization, SOC Capacity Planning
  • Section 3: Detection Rule Management, Measurement, and Visualization, Structuring, Documenting, and Organizing Use Cases, Planning a Threat Hunt, and Detection Quality Assessment
  • Section 4: Investigation Quality Review, Developing and Implementing SOC Playbooks, Incident Response Goals and Teamwork, Incident Containment
  • Section 5: Creating, Classifying, and Communicating Your Metrics, Purple Team Assessment Planning, Execution and Tracking, Improving SOC Quality and Resiliance

Syllabus Summary

  • Section 1: SOC Design and Operational Planning
  • Section 2: SOC Telemetry and Analysis
  • Section 3: Attack Detection, Threat Hunting, and Triage
  • Section 4: Leading Investigation and Response
  • Section 5: Metrics, Automation, and Continuous Improvement

Author Statement

"Written to complement my first SOC course (SEC450: SOC Analyst Training: Applied Skills for Cyber Defense Operations), LDR551 completes the security operations picture by introducing the best higher-level frameworks and organization tactics I've discovered throughout my career as a SOC analyst and SOC manager for a large pharmaceutical company. By including hands-on application with state of the art open-source tools and methods for security operations, LDR551 delivers the complete package for SOC leaders. This course condenses years of knowledge and real-life experience with months of additional research to bring you the most important information to effectively and efficiently lead your security team to success."

- John Hubbard

"As someone who has been the victim of less-than-ideal processes, tools, and team structure, my goal with this course is to help ensure every organization's blue team runs at peak efficiency and capability regardless of size and resources, and that no one must suffer through repeating mistakes so commonly made within the industry. This course is the culmination of 20 years of supporting, building, and leading security operations and I am incredibly excited to bring it to the SANS community."

- Mark Orlando

What You’ll Learn

  • Establish mission-driven SOC foundation aligned with organizational goals
  • Develop advanced threat intelligence and detection capabilities
  • Build and empower high-performance security teams
  • Create robust incident response and threat hunting strategies
  • Implement critical metrics for continuous SOC improvement
  • Master team development, retention, and performance optimization
  • Execute comprehensive security assessment through advanced testing methodologies

Business Takeaways

  • Implement strategies for aligning cyber defense to organizational goals
  • Decrease risk profile due to improved security validation tools and techniques
  • Apply methodologies for recruiting, hiring, training, and retaining talented cyber defenders
  • Streamline effective cross-team coordination and collaboration
  • Employ immediate security optimization improvements using current assets
  • Reduce financial spend due to smoother cyber security operations

Course Syllabus

Explore the course syllabus below to view the full range of topics covered in LDR551: Building and Leading Security Operations Centers.

Section 1SOC Design and Operational Planning

Section 1 introduces the core mission and foundational models of a modern SOC, establishing the strategic and operational context for effective leadership.

Topics covered

  • SOC Planning
  • Cyber Threat Intelligence for the SOC
  • Building the SOC
  • Hiring and Staffing for the SOC
  • Creating a Positive SOC Culture

Labs

  • Creating a SOC Mission and Charter
  • Critical Asset Mapping
  • Creating Priority Intelligence Requirements

Overview

LDR551 starts with the critical elements necessary to build your Security Operations Center: understanding your enemies, planning your requirements, making a physical space, and building your team. Throughout this course section, students will learn how to build a strong foundation upon which an SOC can operate, focusing first on the most important users and data, and tailoring defense plans to threats most likely to impact your organization. Through strategic planning, threat-informed intelligence requirements, and building the right team culture, you will learn how to establish a strong operational foundation that protects your organization's most critical assets.

Full Lab Details

  • Creating a SOC Mission and Charter
  • Critical Asset Mapping
  • Creating Priority Intelligence Requirements

Full Topic Details

  • The State of the Cyber Defense Industry - Trends, Problems, and Priorities
  • SOC Planning - Charters, Mission, Team Planning, Org. charts and more
  • Mapping the SOC Functions - Collection, Detection, Triage, Investigation, and Incident Response
  • Cyber Threat Intelligence for the SOC - Identifying, Collecting, and Processing the Most Important Sources
  • Staffing the SOC Organizations
  • Team Creation, Hiring, and Training - Building Job Specifications, Interviews, Hiring, Training and More
  • Building the SOC - Both Physical and Virtual

Section 2SOC Telemetry and Analysis

Section 2 of LDR551 focuses on expanding our understanding of attacker tactics, techniques, and procedures and how we might identify them in our environment.

Topics covered

  • Critical SOC Tools and Technology
  • SOC Data Collection
  • Using MITRE ATT&CK to Plan Collection
  • Protecting SOC Data and Capabilities
  • SOC Capacity Planning

Labs

  • Threat Actor Assessment
  • Cyber Attack Threat Modeling and Data Source Assessments
  • ATT&CK Navigator for Technique Prioritization
  • Capacity Planning

Overview

This section covers the critical tools, data collection strategies, and MITRE ATT&CK framework necessary to ensure your team has comprehensive visibility into attacker tactics and techniques across your environment. Without proper telemetry and capacity planning, even the most skilled analysts are flying blind—this section ensures your SOC has the data foundation and sustainable operations needed to detect and respond to threats before they become breaches.

Full Lab Details

  • Threat Actor Assessment
  • Cyber Attack Threat Modeling and Data Source Assessments
  • ATT&CK Navigator for Technique Prioritization
  • Capacity Planning

Full Topic Details

  • Cyber Defense Theory and Mental Models
  • Critical SOC Tools and Technology
  • SOC Data Collection
  • Using MITRE ATT&CK to Plan and Prioritize Collection
  • SOC Analyst Capacity Planning
  • Protecting SOC Data and Capabilities from Interference

Section 3Attack Detection, Hunting, and Triage

Section 3 of LDR551 is all about building and improving your threat detection capability.

Topics covered

  • Analytic Frameworks for Improving Detection
  • Detection Engineering
  • Threat Hunting and Active Defense
  • The Keys to Efficient Alert Triage

Labs

  • Detection Rule Management and Visualization
  • Structuring, Document, and Organizing Use Cases
  • Threat Hunting Planning and Execution
  • Detection Quality Assessment

Overview

Starting with proven analytic frameworks and moving into detection engineering best practices, this section focuses on ensuring no attack goes unseen. We focus detection engineering as a core SOC discipline to be planned, tracked, and measured, show how to implement and manage detection use cases, and demonstrate how to plan and execute threat hunts. The results are a structured approach that leads to measurable improvements to your detection capability. Finally, we will look at active defense concepts and their role in a mature security operations capability. By mastering the detection engineering strategies and threat hunting methodologies in Section 3, you'll transform your SOC from reactive alert-chasing into a proactive threat-finding machine that consistently stays ahead of attackers.

Full Lab Details

  • Detection Rule Management and Visualization
  • Structuring, Document, and Organizing Use Cases
  • Threat Hunting Planning and Execution
  • Detection Quality Assessment

Full Topic Details

  • Analytic Frameworks and Tools
  • Threat Detection and Analytic Design
  • Detection Engineering
  • Threat Hunting Process and Tracking
  • Active Defense Tactics and Techniques
  • Systems Thinking and the LEAD Framework
  • The Keys to Efficient Alert Triage

Section 4Incident Response

From toolsets to proven frameworks to tips and tricks learned in countless real-world scenarios, section four covers the full response cycle, from preparation to identification to containment, eradication, and recovery, for operations managers.

Topics covered

  • Planning and Preparation for Incident Response
  • Incident Identification, Containment, and Response
  • Coordination During Incident Discovery

Labs

  • Investigation Quality Review
  • Developing and Implementing SOC Playbooks
  • Incident Response Goals and Teamwork
  • Example Incident Containment Scenario Exercise

Overview

The fourth section of LDR551 begins with preparing your people, processes, IT infrastructure, and forensics toolset to quickly identify and remediate incidents. In this section, we will review best practices in incident investigation, playbook development, cross-team coordination, and effective containment strategies that work across your entire environment. Lab exercises in section four include incident response playbook design and implementation, investigation review and quality control, incident response goal setting, and cross-team collaboration. You'll gain the leadership skills to orchestrate complex incident responses under pressure, ensuring your team can confidently contain threats before they escalate.

Full Lab Details

  • Investigation Quality Review
  • Developing and Implementing SOC Playbooks
  • Incident Response Goals and Teamwork
  • Example Incident Containment Scenario Exercise

Full Topic Details

  • Incident Investigation and Confirmation
  • Planning and Preparation for Incident Response
  • Initial Incident Identification Activities
  • Coordination During Incident Discovery
  • Incident Response Process in Hybrid Environments
  • Containment and Eradication Stage Activities
  • Recovery, Post-Incident Activity, and Practice

Section 5Metrics, Automation, and Continuous Improvement

The fifth and final section of LDR551 is all about measuring and improving security operations.

Topics covered

  • AI And Automation in Security Operations
  • Staff Retention and Burnout Mitigation
  • Metrics, Goals, and Effective Execution

Labs

  • Metric Creation, Classification, and Communication
  • Purple Team Assessment Planning and Execution
  • Improving Quality and Resilience

Overview

The fifth and final section of LDR551 is all about measuring and improving security operations. We focus on three critical areas: motivating your people and minimizing burnout, measuring SOC performance with meaningful metrics, and leveraging AI and automation to scale your operations efficiently. We will also cover some of the more challenging elements of managing people in a dynamic and often high-pressure environment: building the right culture, addressing damaging behaviors, and handling common pitfalls of daily operations. By focusing on our team and continuously improving quality toward a clear set of strategic goals, we can ensure long term growth and success. In section five, you'll receive the tools, techniques, and insights to do just that. You'll leave this section equipped to build a SOC that doesn't just survive—but continuously evolves and excels.

Full Lab Details

  • Metric Creation, Classification, and Communication
  • Purple Team Assessment Planning and Execution
  • Improving Quality and Resilience

Full Topic Details

  • Staff Retention and Burnout Mitigation
  • Metrics, Goals, and Effective Execution
  • Improving Measurement and Prioritization
  • AI and Automation in Security Operations
  • Analytic Testing and Adversary Emulation
  • SOC Capability Assessment
  • “The Lean SOC”

Things You Need To Know

Important! Bring your own system configured according to these instructions!

A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will not be able to fully participate in hands-on exercises in your course. Therefore, please arrive with a system meeting all of the specified requirements.

Back up your system before class. Better yet, use a system without any sensitive/critical data. SANS is not responsible for your system or data.

Mandatory System Hardware Requirements

  • CRITICAL NOTE: Apple Silicon devices with M-series chips cannot perform the required virtualization for this course and therefore cannot be used.
  • CPU: 64-bit Intel i5/i7 (8th generation or newer), or AMD equivalent. A x64 bit, 2.0+ GHz or newer processor is mandatory for this class.
  • BIOS settings must be set to enable virtualization technology, such as "Intel-VTx" or "AMD-V" extensions. Be absolutely certain you can access your BIOS if it is password protected, in case changes are necessary.
  • 8GB of RAM or more is required.
  • 80GB of free storage space or more is required.
  • At least one available USB 3.0 Type-A port. A Type-C to Type-A adapter may be necessary for newer laptops. Some endpoint protection software prevents the use of USB devices, so test your system with a USB drive before class.
  • Wireless networking (802.11 standard) is required. There is no wired Internet access in the classroom.

Mandatory Host Configuration And Software Requirements

  • Your host operating system must be the latest version of Windows 10, Windows 11, or macOS 10.15.x or newer.
  • Fully update your host operating system prior to the class to ensure you have the right drivers and patches installed.
  • Linux hosts are not supported in the classroom due to their numerous variations. If you choose to use Linux as your host, you are solely responsible for configuring it to work with the course materials and/or VMs.
  • Local Administrator Access is required. (Yes, this is absolutely required. Don't let your IT team tell you otherwise.) If your company will not permit this access for the duration of the course, then you should make arrangements to bring a different laptop.
  • You should ensure that antivirus or endpoint protection software is disabled, fully removed, or that you have the administrative privileges to do so. Many of our courses require full administrative access to the operating system and these products can prevent you from accomplishing the labs.
  • Any filtering of egress traffic may prevent accomplishing the labs in your course. Firewalls should be disabled or you must have the administrative privileges to disable it.
  • Download and install VMware Workstation Pro 16.2.X+ or VMware Player 16.2.X+ (for Windows 10 hosts), VMware Workstation Pro 17.0.0+ or VMware Player 17.0.0+ (for Windows 11 hosts), or VMWare Fusion Pro 12.2+ or VMware Fusion Player 11.5+ (for macOS hosts) prior to class beginning. If you do not own a licensed copy of VMware Workstation Pro or VMware Fusion Pro, you can download a free 30-day trial copy from VMware. VMware will send you a time-limited serial number if you register for the trial at their website. Also note that VMware Workstation Player offers fewer features than VMware Workstation Pro. For those with Windows host systems, Workstation Pro is recommended for a more seamless student experience.
  • On Windows hosts, VMware products might not coexist with the Hyper-V hypervisor. For the best experience, ensure VMware can boot a virtual machine. This may require disabling Hyper-V. Instructions for disabling Hyper-V, Device Guard, and Credential Guard are contained in the setup documentation that accompanies your course materials.
  • Download and install 7-Zip (for Windows Hosts) or Keka (for macOS hosts). These tools are also included in your downloaded course materials.

Your course media is delivered via download. The media files for class can be large. Many are in the 40-50GB range, with some over 100GB. You need to allow plenty of time for the download to complete. Internet connections and speed vary greatly and are dependent on many different factors. Therefore, it is not possible to give an estimate of the length of time it will take to download your materials. Please start your course media downloads as soon as you get the link. You will need your course media immediately on the first day of class. Do not wait until the night before class to start downloading these files.

Your course materials include a "Setup Instructions" document that details important steps you must take before you travel to a live class event or start an online class. It may take 30 minutes or more to complete these instructions.

Your class uses an electronic workbook for its lab instructions. A second monitor and/or a tablet device can be useful for keeping class materials visible while you are working on your course's labs.

If you have additional questions about the laptop specifications, please contact customer service.

LDR551 training is recommended for a diverse range of individuals, including:

This course is intended for those who are looking to build a Security Operations Center for the first time or improve the one their organization is already running. Ideal student job roles for this course include:

  • Security Operations Center Managers or Leads
  • Security Directors
  • Security Program Managers
  • Lead / Senior SOC Analysts
  • Technical CISOs and Security Directors

The GIAC Security Operations Manager (GSOM) certification validates a practitioner's ability to effectively manage a technical team and strategically operate a Security Operations Center (SOC) to align with an organization's business goals and security requirements.

  • Designing, planning, and managing an effective SOC program
  • Prioritization and collection of logs, development of alert use cases, and response playbook generation
  • Selecting metrics, analytics, and long-term strategies to assess and continuously improve SOC operations

More Certification Details

  • Custom distribution of the Linux Virtual Machine containing free open-source SOC tools
  • MP3 audio files of the complete course lecture
  • Printed and Electronic Courseware
  • A digital download package that includes the above and more
  • Access to the Cyber42 leadership simulation exercise

This course does not have any specific prerequisites, but it is suggested that students have some experience in an operational security role. SANS courses such as SEC450: Blue Team Fundamentals: Security Operations and Analysis or LDR512: Security Leadership Essentials for Managers will give students a solid base-level understanding of the concepts that will be discussed.

The LDR551 course is part of the Cybersecurity Leadership focus area and is part of the Advanced courses that cover leadership skills in specific areas of security. Additional courses that could be beneficial to round out advanced leadership specialties include LDR520: Emerging Trends for Cyber Leaders: AI and Cloud and LDR514: Security Strategic Planning, Policy, and Leadership, among others.

SOC Management oversees the operations, personnel, and tools within a Security Operations Center to ensure effective threat detection and response. It focuses on team coordination, resource allocation, and continuous improvement.

SOC Management is essential for a robust cybersecurity defense and strong cyber posture. It enables rapid threat detection and mitigation, minimizing potential damage from cyberattacks. By streamlining operations, it ensures optimal use of resources and enhances overall efficiency. Effective management also supports regulatory compliance, helping organizations meet cybersecurity standards and avoid penalties. Additionally, a well-managed SOC improves preparedness for incident handling, reducing response times and recovery efforts. Finally, proactive vulnerability identification and mitigation reduce risks, safeguarding the organization against evolving threats.

LDR551: Building and Leading Security Operations Centers equips you with essential skills to excel as a SOC leader. This course provides practical knowledge in managing SOC teams, optimizing processes, and leveraging tools to enhance organizational cybersecurity.

By completing LDR551 training, you will:

  • Develop Leadership Skills: Learn to build and manage effective SOC teams, improving your ability to lead in high-pressure environments.
  • Enhance Career Growth: Position yourself as a key decision-maker and strategic leader within your organization.
  • Gain Practical Expertise: Master techniques for SOC operations, including threat detection, incident response, and continuous improvement.
  • Boost Your Credentials: Attain recognition as a SOC management expert, enhancing your professional reputation and opening opportunities for advancement.

Whether you're aiming for a management role or looking to enhance your leadership capabilities, LDR551 training provides the tools to elevate your career in cybersecurity.

Relevant Job Roles

Operational Cybersecurity Executive

Cybersecurity Leadership

Lead operational teams from the point of view of an adversary in order to protect your most sensitive assets.

Explore learning path

Technology Research and Development (OPM 661)

NICE: Design and Development

Responsible for conducting software and systems engineering and software systems research to develop new capabilities with fully integrated cybersecurity. Conducts comprehensive technology research to evaluate potential vulnerabilities in cyberspace systems.

Explore learning path

Security Manager Training, Salary, and Career Path

Cybersecurity Leadership

Daily focus is on the leadership of technical teams. Includes titles such as Manager, Information Security Specialist, and Program/Project Leader.

Explore learning path

Blue Teamer - All Around Defender

Cyber Defense

This job, which may have varying titles depending on the organization, is often characterized by the breadth of tasks and knowledge required. The all-around defender and Blue Teamer is the person who may be a primary security contact for a small organization, and must deal with engineering and architecture, incident triage and response, security tool administration and more.

Explore learning path

SOC Manager

Cybersecurity Leadership

Security Operations Center (SOC) managers bridge the gap between business processes and the highly technical work that goes on in the SOC. They direct SOC operations and are responsible for hiring and training, creating and executing cybersecurity strategy, and leading the company’s response to major security threats.

Explore learning path

Enterprise Architecture (OPM 651)

NICE: Design and Development

Responsible for developing and maintaining business, systems, and information processes to support enterprise mission needs. Develops technology rules and requirements that describe baseline and target architectures.

Explore learning path

Secure Systems Development (OPM 631)

NICE: Design and Development

Responsible for the secure design, development, and testing of systems and the evaluation of system security throughout the systems development life cycle.

Explore learning path

Leadership

SCyWF: Leadership And Workforce Development

This role conducts supervises, manages and leads cybersecurity teams and work. Find the SANS courses that map to the Leadership SCyWF Work Role.

Explore learning path

Course Schedule and Pricing

Have Questions?Contact Us
  • Location & instructor

    Virtual (OnDemand)

    Instructed by
    Date & Time
    OnDemand (Anytime)Self-Paced, 4 months access
    Course price
    $8,260 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Virginia Beach 2026

    Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    $8,260 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Paris September 2026

    Paris, FR

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    €7,715 EUR*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Munich October 2026

    Munich, DE

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    €7,715 EUR*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Cyber Safari 2026

    Riyadh, SA & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    $8,375 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Amsterdam December 2026

    Amsterdam, NL & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    €7,715 EUR*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Cyber Defense Initiative 2026

    Washington, DC, US & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    $8,260 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Nashville 2027

    Nashville, TN, US & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    $8,260 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS London March 2027

    London, GB & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    £6,715 GBP*Prices exclude applicable taxes | EUR price available during checkout
    Registration Options
  • Location & instructor

    SANS 2027

    Orlando, FL, US & Virtual (live)

    Date & Time
    Fetching schedule..
    Course price
    $8,260 USD*Prices exclude applicable local taxes
    Registration Options
Showing 10 of 11

Benefits of Learning with SANS

Bryan Simon: Teacher Standing Next to Smartboard and Explaining Concept

Get feedback from the world’s best cybersecurity experts and instructors

OnDemand Mobile App

Choose how you want to learn - online, on demand, or at our live in-person training events

Close Up of Woman Holding a Pen and Documents

Get access to our range of industry-leading courses and resources