Maxim Deweerdt
Principal InstructorLeadership Team at NVISO
Specialities
Cyber Defense, Cybersecurity Leadership

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsCyber Defense, Cybersecurity Leadership

Maxim Deweerdt is a Principal Instructor at the SANS Institute and a Cyber Defense Expert at NVISO. He is the author of SEC559: Cloud and Hybrid Identity Security, and teaches SEC511: Cybersecurity Engineering: Advanced Threat Detection and Monitoring and LDR551: Building and Leading Security Operations Centers. As a Cyber Defense Expert within NVISO’s Managed Cyber Defense Services practice, he leads a team of engineers delivering detection and response capabilities to clients across industries. He has more than 15 years of experience in cyber defense, including work across policy and frameworks, risk and compliance, threat hunting, incident response, and security operations.
Max is very good at sharing practical tips and real-life events/scenarios which we can relate and can apply in our environment.
Maxim displayed the traits of an experienced instructor. Very knowledgeable, great timekeeping, enthusiastic about every topic, helpful with every question. Very impressive all around!
Maxim is a really talented instructor and his teaching approach is amazing as it involves everyone in the class to discuss and exchange ideas and knowledge.
Here are upcoming opportunities to train with this expert instructor.
Explore content featuring this instructor’s insights and expertise.
MFA alone can’t stop token theft and AITM attacks. This session shows defenders how phishing-resistant authentication, Conditional Access, Continuous Access Evaluation, and token controls can strengthen identity defenses.

AI agents are entering identity and SOC workflows fast. This session gives defenders a practical guide to agent identities, Microsoft Copilot, Entra Agent ID, and governance frameworks to secure AI without slowing adoption.

This session explores how agent identities work in Microsoft Entra ID, how to detect abuse, and how SOC teams can respond quickly without disrupting critical business workflows.

Empowering a modern SOC with AI: practical use cases with SANS Principal Instructor Maxim Deweerdt and Wiping Media in (Anti-)Forensics: Exploring Hard Drive Erasure Methods for DFIR with SANS Instructor Seth Enoka

This presentation explores the transformative role of Artificial Intelligence (AI) in modern SOCs, focusing on its application to improve threat detection, automate incident responses, and enable predictive analytics for a proactive defense strategy.

This talk navigates the landscape of HTTPS and TLS connections, distinguishing between encrypted and unencrypted HTTPS, and outlining methods to identify suspicious activities.

Review relevant educational resources made with contribution from this instructor.