James Tarala
Senior InstructorManaging Partner at Cyverity
Specialities
Cybersecurity Leadership

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsCybersecurity Leadership

James Tarala is a Managing Partner at Cyverity and a Senior Instructor at the SANS Institute, where he leads instruction and authorship of high-impact leadership courses such as LDR519: Cybersecurity Governance, Risk, and Compliance (GRC) and LDR419: Performing a Cybersecurity Risk Assessment (retired). In his dual role as consultant and educator, he guides organizations and students alike through the challenges of risk, governance and compliance from boardroom to SOC.
James’s career began not in computers, but in education: with a Bachelor of Science in Linguistics and early work teaching in remote global locations, he developed a passion for translating complex ideas into accessible learning. He then turned his boyhood hobby of computers into a technology teaching career, eventually moving into enterprise IT, infrastructure architecture and security consultancy. Over several decades he has designed large-scale infrastructure, engineered security architectures and delivered independent assessments for major organizations—and those real-world consulting experiences directly shaped his SANS labs and scenarios. As the author of the course LDR419, he brings his field work into the classroom, so students conduct assessments, build threat models and brief executives in real time. With LDR519, he trains leaders to build governance and risk-management programs that span the enterprise—not just technology teams.
James holds key credentials including Certified Information Systems Security Professional (CISSP), Certified Information Systems Auditor (CISA), Project Management Professional (PMP), and 14 GIAC certifications. He is also a faculty member of the SANS Technology Institute, which has been designated an NSA Center of Academic Excellence in Cyber Defense and is a multi-year winner of the National Cyber League competition. And his long-time community contributions include technical editorship for the CIS Controls, founding member of the Cybersecurity Risk Foundation, and volunteer work turning control frameworks into usable assessments. His tools and templates and open-source taxonomies support measurable risk management and compliance.
In the classroom, James tells students the truth: cybersecurity isn’t wizardry, it’s disciplined work. He emphasizes focus over distraction, helping practitioners “eat their vegetables” rather than chase every shiny tool. He designs labs where students simulate board-briefings, validate safeguards and link control frameworks to business outcomes. Past participants say that his sessions “tie theory to practical use” and “are fun to listen to while being deeply relevant.” Outside the classroom he lives in Florida, enjoys boating or paddle-boarding under the sun, and brings that same zest for clarity and calm risk-management into his teaching: staying anchored, focused and ready to navigate complexity.
SANS is the best in the biz because of instructors like James Tarala.
James is an amazing presenter, very fun to listen to on top of being knowledgeable.
James Tarala is a wealth of knowledge. He shared his great real-world experience to show us how to tie theory and practical use together.
Here are upcoming opportunities to train with this expert instructor.
Explore content featuring this instructor’s insights and expertise.
Build a 2027 audit plan that does more than check boxes. Join James Tarala to align audits with risk, governance, and emerging requirements, turning limited resources into a roadmap that delivers assurance and business value.

Make sense of the 2026 cybersecurity standards landscape. Join Senior Instructor James Tarala for a research-based scorecard comparison of popular frameworks and learn how to use a Cyber Rosetta Stone to simplify control selection and prioritization.

In this presentation, James Tarala, Senior Faculty at the SANS Institute and Managing Partner at Cyverity, will delve into the core principles of effective cyber risk management, emphasizing the necessity of making informed decisions when allocating limited resources among good, better, and best safeguards.

This session focuses on what’s new in the spring 2026 releases—updated SANS policies, refreshed CRF safeguards, expanded threat and governance models, and new supporting tools designed to help teams mature faster without adding complexity.

Cybersecurity policies are the foundation of any governance program, setting expectations for workforce behavior and establishing the rules that support compliance and risk management.

This session explores how cyber defense teams can modernize their operations to keep pace with AI-driven threats. Attendees will gain practical insights into integrating automation responsibly, preparing for the emergence of agentic AI in both offense and defense.

As organizations prepare for 2026, security leaders face a challenging audit environment shaped by new regulations, updated standards, and an evolving threat landscape.

In the 1990s government agencies, industry groups, and cybersecurity researchers started creating cybersecurity standards and these standards led to cybersecurity regulations and laws that dictate to organizations what they must do to protect their data.

This talk will look at how attackers are actually making use of artificial intelligence to attack organizations through social engineering attacks, and what organizations can do to try and actually address these threats.

In this webcast we will delve into the critical process of selecting a Governance, Risk, and Compliance (GRC) software tool that aligns with your organization's needs. In today's complex cybersecurity landscape, the ability to effectively track risks and communicate them to business stakeholder's is essential for informed decision-making and strategic growth.

This webcast, led by James Tarala, Senior Faculty at the SANS Institute and Managing Partner at Cyverity, is designed to empower small businesses with the knowledge and resources they need to effectively manage cybersecurity risks without breaking the bank.

In this webcast, we'll be focusing on the advancements in the NIST Cybersecurity Framework (CSF) 2.0. As organizations worldwide have adopted the NIST CSF to prioritize essential cybersecurity safeguards and enhance communication with stakeholders, the release of version 2.0 calls for a governance update and refinement of existing strategies.

The webcast "Understanding the Risk Management Mandates in 2024 Cybersecurity Regulations" is designed to enlighten students about the critical updates in cybersecurity regulations, including those defined by ENISA's NIS2 requirements.

Every organization should be performing risk assessments as a part of their cybersecurity program. Regular risk assessments allow organizations to create practical strategies for defense and evaluate where there are weaknesses in their cybersecurity program that could keep them from achieving their goals. Listen to this session for key insights into foundational knowledge and tools to consider in planning a risk assessment for your organization.

In this webcast, James Tarala, Senior Faculty at the SANS Institute and Managing Partner at Cyverity, will explain the state of cybersecurity standards in 2024 with a scorecard comparison of popular standards based on specific, measurable research.

In this webcast, James Tarala, Senior Faculty at the SANS Institute and Managing Partner at Cyverity, will offer an in-depth exploration of the Cybersecurity Risk Foundation's Audit Framework (AF), providing participants with a structured approach to cybersecurity audits that not only meet compliance requirements but are also intricately aligned with their organization's cybersecurity goals.

With technology's ongoing advancement and the rising complexity of digital systems, constructing exhaustive threat models from the ground up can be daunting. In this presentation, James Tarala, Senior Faculty at the SANS Institute and Managing Partner at Cyverity, will discuss a solution: community-driven threat modeling templates.

Balancing the scales between safeguarding information assets and enabling business growth demands not just technical acumen but a strategic mindset.

As we head into the last quarter of 2023, three major mandate changes are occurring, each positioned to make a large impact on how businesses, governmental bodies, and critical sector organizations operate. The goal of the SANS Cyber Compliance Countdown is to focus on what you need to know in these complicated and broad requirements and to offer solutions on how to meet these directives.

In this webcast, James Tarala, Senior Faculty at the SANS Institute and Principal Consultant at Enclave Security, will explain the state of cybersecurity standards in 2023 with a scorecard comparison of popular standards based on specific, measurable research.

Review relevant educational resources made with contribution from this instructor.