My-Ngoc Nguyen
Principal InstructorCEO at Secured IT Solutions
Specialities
Cybersecurity Leadership

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsCybersecurity Leadership

My-Ngoc Nguyen teaches cybersecurity leadership from the place where risk, compliance, people, process, and technology must work together, not just look good in a plan. A SANS Principal Instructor with the SANS Technology Institute, and CEO/Principal Consultant at Secured IT Solutions, she teaches LDR512: Security Leadership Essentials for Managers with 25 years of information systems and technology experience, including more than 20 years focused on cybersecurity. Her work across government and commercial sectors helps students connect security leadership and program management to the decisions leaders must make when technical controls meet organizational reality. Instructing for SANS for over 15 years, she connected dots for the students in the various classes (e.g. SEC 301, SEC 401, SEC466, SEC504, SEC560, and LDR551) she taught prior to focusing on LDR512.
My-Ngoc began her career leading and managing the cybersecurity program for the Department of Energy’s Yucca Mountain Project through Bechtel SAIC. She later supported Los Alamos National Laboratory after a cybersecurity incident and classified-information breach, work that helped launch her consulting career. She later expanded her consulting reach to support enterprises across the Department of Energy and National Nuclear Security Agency and other government Agencies. Today, through Secured IT Solutions, she helps public- and private-sector clients implement secure, compliant business processes and IT solutions using risk-based and defense-in-depth approaches. She draws on that experience while teaching the labs, helping students connect Cyber42 simulations, security frameworks, risk assessment, security policy, board briefings, cloud security, identity and access management, vulnerability management, privacy, vendor negotiation, and GenAI risk to situations they may already be facing at work.
My-Ngoc holds a Master of Science in Management Information Systems and a Bachelor of Science in Management Information Systems from the University of Nevada, Las Vegas, along with six GIAC certifications, Certified Information Systems Security Professional, and former Qualified Security Assessor experience. My-Ngoc Nguyen is also a faculty member of the SANS Technology Institute, which has been designated an NSA Center of Academic Excellence in Cyber Defense and is a multi-year winner of the National Cyber League competition. Her broader work includes service on University of Nevada, Las Vegas advisory boards and co-founding and chairing CyberSafeNV, a nonprofit created to raise cybersecurity awareness among Nevada residents.
My-Ngoc teaches from the belief that security leaders need to understand the technical work and the organizational realities around it. Her classroom style uses engagement, analogies, and real-life stories to make complex topics stick, especially for students moving between technical and management responsibilities. Students should leave able to assess risk, brief leadership, guide teams, build stronger programs, and communicate security decisions in terms the business can use. Outside of cybersecurity, My-Ngoc loves to dance, including choreographic hip-hop, swing, and ballroom classes, and enjoys board games such as Sequence, Codenames, Jaipur, Century, Istanbul, 7 Wonders, and Hanabi.
My-Ngoc’s passion for the material shows. She’s great at explaining!
My-Ngoc gives great analogies, which is very helpful for non-technical managers like myself.
My-Ngoc is a natural teacher and an expert in the subject material. The real-world perspective she brings to the course materials is invaluable.
Here are upcoming opportunities to train with this expert instructor.
Explore content featuring this instructor’s insights and expertise.
This webcast examines where air gaps still provide meaningful protection, where they fall short, and how modern architectures, from zero trust to classified cloud environments—are redefining isolation as a control objective rather than a fixed condition.

This presentation touches on the latest cybersecurity trends and challenges while highlighting key risks with them.

In an era where digital transformation drives business success, cybersecurity has emerged as a critical aspect for organizational leadership. As cyber threats grow in sophistication, understanding the latest trends and challenges is no longer optional—it's essential. This presentation offers a deep dive into the latest and evolving cybersecurity landscape, uncovering the most pressing areas that leaders must address today. We'll explore cutting-edge trends, from the rise of AI-driven attacks to the complexities of securing remote workforces, and present actionable strategies for mitigating and managing risks. Join us to learn how effective leadership can address cybersecurity challenges.

Hear the stories from top SANS faculty of how they became the cybersecurity experts they are today and how their stories can be applied to your career journey. Learn how they build their skills to become one of the top practitioners within cybersecurity.

This presentation will cover the following topics related to both artificial intelligence (AI) and generative artificial intelligence (GenAI): Evolution of AI to GenAI, Implications and concerns of GenAI, Mitigation and security approaches to GenAI implications

The modern enterprise, characterized by hybrid and mobile workforces supported by a hybrid cloud IT environment, brings many security challenges to the federal government, its agencies, entities, and sites. They face multi-faceted cybersecurity concerns due to the sensitive nature of their data, the critical infrastructure, and regulatory mandates involved. The distributed nature of operations, with numerous contractors and providers, introduces further complexities in securing endpoints, networks, and data, further amplifying the risks of nation-state cyber-attacks, phishing, malware, and data breaches. Secure Access Service Edge (SASE)/Security Services Edge (SSE) solutions, like Cisco Umbrella, offer comprehensive protection that meets the unique needs and compliance requirements of government organizations and others that depend upon FedRAMP.

Review relevant educational resources made with contribution from this instructor.