Brian Ventura
Principal InstructorPartner at Cyverity
Specialities
Cybersecurity Leadership

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsCybersecurity Leadership

Brian Ventura stands as a respected authority in cybersecurity leadership, serving as Partner at Cyverity and as course author and principal instructor at the SANS Institute. As the author of SEC566: Implementing and Auditing CIS Controls, and an instructor for LDR512: Security Leadership Essentials for Managers, he brings both strategic oversight and practical execution to the classroom.
Brian’s journey began in systems administration installing his first Unix/Linux system while pursuing an undergraduate degree in physics before transitioning to information technology and security. during in the early part of Brian’s career, he worked in information technology and security architecture and audit roles in global, complex environments. Starting in 2001, He worked at a fortune-100 company where he consolidated over 350 DNS and e-mail sub-domains, then pivoted into audit and compliance as Sarbanes-Oxley regulations came online. These formative roles gave him a foundational view of how technology, risk, and governance intersect and this experience shaped the labs and real-world scenarios he designs for the course.
Brian holds key credentials including Certified Information Systems Security Professional (CISSP), 8 GIAC certifications, and serve as a member of GIAC Advisory Board. He is also a faculty member of the SANS Technology Institute (SANS.edu). SANS.edu is designated as an NSA Center of Academic Excellence in Cyber Defense and is a multi-year winner of the National Cyber League competition. His course contributions span the CIS Controls suite, and his community work includes contributing to the CIS Controls, volunteering with the Oregon Cybersecurity Advisory Council, and publishing a free-to-use GRC management tool based on the NIST Cybersecurity Framework.
What distinguishes Brian in the classroom is his “real-world conversation” style: his labs do not only teach “what” but explore “why” and “how”, helping students translate theory into defensible security programs that speak to senior management. He loves the moment when students say, “that’s the way my organization should be doing this” and walk away confident. Off duty he’s likely pedaling around Portland’s bike paths, cheering on the Portland Thorns and Portland Timbers, or crawling through the wilderness in his Toyota truck, proof that his commitment to continuous movement spans both his career and his hobbies.
Sometimes you might think we're getting behind schedule, but that's not the case: Brian knows where to spend his time. He has a good balance between covering the material and providing extra background or anecdotes.
Brian is an excellent instructor and mentor. I feel confident speaking about the CIS Controls, while before this course I did not have that confidence. Now it's up to me to continue to develop my skills. Thank you, Brian.
Brian was very knowledgeable, and it was obvious he has a great deal of experience. His insight has broadened my thinking as to ways to address the Critical Security Controls. The different scenarios covered in SEC566 were valuable.
Here are upcoming opportunities to train with this expert instructor.
Explore content featuring this instructor’s insights and expertise.
This scenario-driven workshop challenges leaders to make high-impact security decisions under pressure, balance risk and business priorities, and sharpen operational judgment through fast-paced gameplay and practical situations.

Artificial Intelligence (AI) and Large Language Models (LLMs) are transforming business operations but also introduce new risks. In this one-hour webcast, hosted by the author and instructor of SANS SEC566: Implementing and Auditing CIS Controls, we will explore how to apply the CIS Controls to the AI lifecycle—covering data security, system hardening, access management, monitoring, and incident response.

A 90-minute, interactive, gamified leadership exerciseEnhance your proficiency in operational cybersecurity decision-making through immersive team-based simulations with Cyber42. Practice agile decision-making and information synthesis, key skills required for success in leadership roles. Engage in thought-provoking discussions and gain practical insights to improve your cybersecurity competencies.

In this webcast, we will review the attack at Achilles Systems, their previous security capabilities, and why their existing controls were insufficient to help them resist the attack. Then we will dive deep into what could have been done to better tailor and augment those controls to reduce or eliminate the impacts from the attack.

The Information Security industry has a large variety of solutions to stop attackers in their tracks! They claim to have tools to address every type of attack, and solutions that are silver bullets against all attackers. The current trends say machine learning and AI will solve our latest problems.

An organized, full-coverage risk register can maximize your cybersecurity resources while improving organizational security. Without including third-party risks, however, even the best risk register can fail to stop security incidents. Your risk framework needs to map to internal and external gaps to identify weaknesses and ensure complete coverage.

Review relevant educational resources made with contribution from this instructor.