Maxim Deweerdt
Principal InstructorLeadership Team at NVISO
Specialities
Cyber Defense, Cybersecurity Leadership, Cloud Security

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsCyber Defense, Cybersecurity Leadership, Cloud Security

Maxim Deweerdt is a Principal Instructor at the SANS Institute and a Cyber Defense Expert at NVISO. He is the author of SEC559: Cloud and Hybrid Identity Security, and teaches SEC511: Cybersecurity Engineering: Advanced Threat Detection and Monitoring and LDR551: Building and Leading Security Operations Centers. As a Cyber Defense Expert within NVISO’s Managed Cyber Defense Services practice, he leads a team of engineers delivering detection and response capabilities to clients across industries. He has more than 15 years of experience in cyber defense, including work across policy and frameworks, risk and compliance, threat hunting, incident response, and security operations.
Maxim’s first experience with cybersecurity was during an ISO/IEC 27001 audit project while completing his education at Howest University College. Following that project, he was hired as a Cybersecurity Officer. He has been involved in incident response for private and public sector organizations, including incidents that often make the news. He previously served as Technical Team Lead for Belgium’s national CERT, where he worked on digital forensics and incident response at a national level. He has also worked as a Cyber Defense consultant in the Middle East. His work has included building and maturing Security Operations Centers, conducting threat hunting, developing detection strategies, and supporting incident response activities.
Maxim holds multiple GIAC certifications, including GIAC Penetration Tester (GPEN), GIAC Continuous Monitoring (GMON), GIAC Certified Forensic Analyst (GCFA), GIAC Network Forensic Analyst (GNFA), GIAC Industrial Cyber Security Professional (GICSP), and GIAC Certified Incident Handler (GCIH). He holds a bachelor’s degree in computer science from Howest University College in Belgium. He has spoken at SANS Summits, RSA, and private events. Maxim Deweerdt is also a faculty member of the SANS Technology Institute, which has been designated an NSA Center of Academic Excellence in Cyber Defense and is a multi-year winner of the National Cyber League competition.
Maxim has been involved in incident response activities and has conducted threat hunting and compromise assessments in environments of varying size. He has worked with governments, large corporations, and businesses in the EMEA region. He has also contributed to initiatives supporting cybersecurity education, including programs focused on helping individuals transition into cybersecurity careers. Outside of his professional work, he enjoys reading, diving, swimming, and volunteering for not-for-profit projects.
Max is very good at sharing practical tips and real-life events/scenarios which we can relate and can apply in our environment.
Maxim displayed the traits of an experienced instructor. Very knowledgeable, great timekeeping, enthusiastic about every topic, helpful with every question. Very impressive all around!
Maxim is a really talented instructor and his teaching approach is amazing as it involves everyone in the class to discuss and exchange ideas and knowledge.
Here are upcoming opportunities to train with this expert instructor.
Explore content featuring this instructor’s insights and expertise.
MFA alone can’t stop token theft and AITM attacks. This session shows defenders how phishing-resistant authentication, Conditional Access, Continuous Access Evaluation, and token controls can strengthen identity defenses.

This session explores how agent identities work in Microsoft Entra ID, how to detect abuse, and how SOC teams can respond quickly without disrupting critical business workflows.

Empowering a modern SOC with AI: practical use cases with SANS Principal Instructor Maxim Deweerdt and Wiping Media in (Anti-)Forensics: Exploring Hard Drive Erasure Methods for DFIR with SANS Instructor Seth Enoka

This presentation explores the transformative role of Artificial Intelligence (AI) in modern SOCs, focusing on its application to improve threat detection, automate incident responses, and enable predictive analytics for a proactive defense strategy.

This talk navigates the landscape of HTTPS and TLS connections, distinguishing between encrypted and unencrypted HTTPS, and outlining methods to identify suspicious activities.

Review relevant educational resources made with contribution from this instructor.