Michael Hoffman
Certified InstructorField CTO – Oil and Gas at Dragos, Inc.
Specialities
Industrial Control Systems Security

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsIndustrial Control Systems Security

Michael teaches industrial cybersecurity the way it is practiced. He learned in the field working with instrumentation and analyzers, then moved into automation and industrial control systems / operational technology (ICS/OT) security roles that kept complex plants safe and reliable. Today, he is a SANS Certified Instructor and the Field CTO for Oil & Gas at Dragos, Inc., teaching SANS ICS410: ICS/SCADA Security Essentials, SANS ICS515: ICS Visibility, Detection, and Response, and SANS ICS612: ICS Cybersecurity In-Depth. With 25+ years across instrumentation, controls, and ICS/OT security, his classes stay grounded in how cybersecurity work in critical infrastructure actually gets done.
Michael’s 20-year career at Shell spanned across roles in instrumentation and electrical, laboratory, environmental, and process analyzers, measurement, and controls and automation, as well as the roles of site ICS security lead and global ICS cybersecurity lead across refining and chemical assets. Michael spent the last 5 years helping owners/operators as a Principal Consultant at Dragos before moving to his global Field CTO role. The broad experience, from plant support to global roles, is reflected in how he approaches teaching ICS410, where he explains core concepts through the realities of distributed control systems (DCS), supervisory control and data acquisition (SCADA), safety instrumented systems (SIS), programmable logic controllers (PLCs), workstations, and human-machine interfaces (HMIs), so students see how security fits alongside safety and uptime. Michael’s experience also informs ICS612, where he connects network design, monitoring, and secure change to what actually happens during maintenance windows, turnarounds, and recovery, giving students practical patterns they can adopt whether they work in oil and gas, manufacturing, power, water, or the public sector.
Michael holds the GIAC Security Expert (GSE) #320 and has earned more than a dozen GIAC certifications. He also holds a Master of Science in Information Security Engineering (MSISE) from the SANS Technology Institute. He contributes to the community through research, such as “Vulnerabilities on the Wire: Mitigations for Insecure ICS Device Communication” and “Gaining Endpoint Log Visibility in ICS Environments”, and by building approachable learning projects—like a PLC-powered coffee roaster—to make industrial concepts more tangible. Michael is also a faculty member of the SANS Technology Institute.
Beyond the classroom, Michael partners with asset owners worldwide on OT resilience, and his teaching style reflects his frontline perspective: meeting people where they are, translating complexity into clear steps, and never forgetting the operators who keep essential services running. Michael describes his mission simply as “helping to safeguard civilization.”
Mike is a great instructor. He has a huge amount of information to share and teach. He has a very relaxed, non-pushy, style of teaching that puts you at ease.
Mike has been such an awesome teacher for this course! It has been amazing to have such interesting material delivered by such an experienced ICS Cyber security practitioner.
Michael Hoffman an amazing fit for instructing this course. His background and experiences in Instrumentation/Automation/OT Security truly enrich the student's experience.
Mike has a wealth of knowledge, explains complex topics with ease and is ready to answer questions.
Here are upcoming opportunities to train with this expert instructor.
Explore content featuring this instructor’s insights and expertise.
AI transformed business and IT security. Now it's crossing into OT, bringing the same efficiency gains, the same defensive potential, and the same adversarial capabilities into environments that were never designed to absorb them.

Mike Hoffman will explain how Dispel’s OT-first remote access platform implements 5CC-aligned safeguards—covering architecture, deployment patterns, connection models, and operational controls. You’ll see how moving-target defense, disposable sessions, vaulted credentials, granular auditing, and compliance artifacts can reduce dwell time and simplify investigations—while preserving operator productivity.

Join us at the 2025 Government Security Forum on July 22nd at 10:00 AM ET to gain intelligence, tools, and real-world strategies needed to defend your agency against next-generation cyber threats. Register for free today!

This talk will cover various data sources and attacks on data, including data sources used for AI/ML processing. The focus will be on how to confront and mitigate these data attacks in ICS/OT environments.

The SANS ICS Five Critical Controls continue gaining traction among the community as well-regarded and must-needed security controls to achieve an organization's baseline ICS/OT Cybersecurity level.

This talk provides insights into designing and executing Tabletop Exercises (TTX) for Incident Response in Industrial Control Systems (ICS) and Operational Technology (OT) environments.

Review relevant educational resources made with contribution from this instructor.