Group Purchasing
Group Purchasing

Erik Van Buggenhout

Senior InstructorCo-Founder and Partner at NVISO

Specialities

Offensive Operations

Erik Van Buggenhout

About Erik Van Buggenhout

Erik Van Buggenhout is a SANS Senior Instructor, co-founder of NVISO, and lead author of SEC599: Defeating Advanced Adversaries – Purple Team Tactics & Kill Chain Defenses and SEC699: Advanced Purple Teaming – Adversary Emulation & Detection Engineering, and in the past, he also co-authored SEC560: Enterprise Penetration Testing. At NVISO, Erik is currently the head of Managed Security Services, which is primarily focused on 24x7 Managed Detection and Response services. Together with his team, Erik helps organizations improve how well they detect and respond to cyber security incidents.

Erik began his career at Ernst & Young, where he evolved from penetration tester into a subject matter expert supporting organizations throughout the EMEA region. Over time, his focus expanded from traditional red teaming into purple teaming, threat hunting, and security operations. That career progression directly shaped the course content he developed for SANS, where students learn how to emulate advanced adversaries, operationalize MITRE ATT&CK, and build scalable detection workflows grounded in real-world operations. Beyond client engagements, Erik also helped build NVISO into one of Europe’s respected cybersecurity firms while contributing to community initiatives such as the Belgian Cyber Security Challenge and the German Cyber Security Rumble.

Erik holds a Master of Science in Information Security from Royal Holloway, University of London, along with numerous GIAC certifications including GIAC Security Expert (GSE), GIAC Certified Incident Handler (GCIH), GIAC Certified Intrusion Analyst (GCIA), GIAC Certified Network Forensics Analyst (GNFA), GIAC Certified Penetration Tester (GPEN), and GIAC Web Application Penetration Tester (GWAPT). He is also a faculty member of the SANS Technology Institute, which has been designated an NSA Center of Academic Excellence in Cyber Defense and is a multi-year winner of the National Cyber League competition. In addition to teaching, Erik is a frequent speaker at RSA Conference and BruCON, where he shares practical insights on purple teaming, detection engineering, automation, and adversary simulation.

In the classroom, Erik is known for his practical, experience-driven teaching style that emphasizes learning by doing. He enjoys standing in front of a classroom and explaining deeply technical concepts by using war stories and adding a few funny anecdotes here and there. By the end of the course, learners are able to emulate advanced threats, improve detection engineering, and strengthen incident response processes. Outside of cybersecurity, Erik enjoys a few healthy things like road cycling (a STRAVA fanboy), indoor soccer, snowboarding, and a few less healthy things like BBQ, cigars, and whiskey (in no particular order). A self-confessed speed walker, if you see Erik rushing around at a conference, feel free to stop him and say "Hi!".

Qualifications Summary

Press & Media

More From Erik