Andy Smith
Certified InstructorHead of Security Architecture at Sage
Specialities
Cyber Defense

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsCyber Defense

Andy Smith helps defenders turn security architecture from a compliance task into a strategic advantage. As a Certified Instructor for the SANS Institute, he teaches SANS SEC530: Defensible Security Architecture and Engineering, guiding students to design secure, resilient systems that withstand complex real-world threats, giving professionals the confidence to champion architecture decisions within their organizations. In his current role as Head of Enterprise Security Architecture at Sage, Andy leads initiatives to embed scalable, reliable, and defensible security across customer-facing products, technology platforms, and internal IT services. His leadership experience helps students understand how architectural principles drive business resilience, Zero Trust maturity, and the secure integration of AI systems.
Before joining Sage, Andy spent 18 years at BP, progressing from IT Graduate to Principal Security Architect. Working there he designed strategies and operating models to secure emerging technologies, including AI and machine learning platforms, IoT, industrial control systems, blockchain, and multicloud environments. His work laid the architectural groundwork for scalable and accountable AI adoption, helping enterprises balance innovation with security assurance. He also served as BP’s Regional Information Security Officer for Europe and North America, balancing regulatory risk with the fast-moving transformation of the energy sector. Having spent two decades securing everything from energy infrastructure to global cloud ecosystems, Andy brings lessons forged in enterprises where security failures have real-world consequences.
Andy’s current research and community leadership extend deeply into AI security. As an entry lead and contributing author for the OWASP LLM Top 10, he helps shape the industry’s first open security standard for large language model applications. This work informs his teaching on securing AI integrations within modern enterprise architecture. His public talks and writing often explore the intersection of AI, architectural assurance, and practical risk management, helping defenders understand how to adapt trusted design principles to emerging technologies.
Andy’s approach blends technical mastery with architectural pragmatism. He holds advanced credentials including GIAC Defensible Security Architecture (GDSA), GIAC Defending Advanced Threats (GDAT), and Certified Cyber Risk Management Practitioner (CCRMP) certifications, alongside CISSP and CRISC. He earned a Master of Research in Security and Cryptography and a Bachelor of Engineering in Computers and Networks from the University of Essex. A frequent conference speaker, his recent publications include “How to Prepare for a Secure Post-Quantum Future” (TechTarget 2024) and “Taming the Chaotic Toddler: Threat Modeling LLM Apps” (SANS Amsterdam July 2025).
Students often describe Andy’s classes as the moment security architecture finally “clicked” for them. Known for his clarity, humor, and pragmatic teaching style, he ensures students leave class ready to apply what they have learned the very next day. He believes secure design starts with curiosity: the courage to ask why before deciding how. Outside of security, Andy enjoys outdoor activities, walking his dog, and DIY projects at home; outlets for the same curiosity and problem-solving instinct he brings to every class.
Andy Smith is a great instructor. Engaging, creative, and willing to dive deep into questions. An excellent, excellent instructor.
Andy was excellent in his timing, explanations, and answers to questions. Very friendly and competent!
Loved the energy exhibited by Andy throughout the entire course. He truly loves cybersecurity and it's obvious. He wants to see others do well; that's very refreshing.
Here are upcoming opportunities to train with this expert instructor.
Explore content featuring this instructor’s insights and expertise.
As businesses rush to embrace the perceived benefits of AI systems, security professionals must take a more pragmatic view. In this talk, Andy will highlight some of the surprising attack vectors that LLM-powered applications may vulnerable to - and what we can do to help prevent abuse.

Join us at the forefront of cybersecurity at "SANS Secure Your Fortress: 2024's Top Defense Strategies and Trends!"
