Randy Marchany
Senior InstructorChief Information Security Officer at Virginia Tech
Specialities
Cybersecurity Leadership

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsCybersecurity Leadership

Randy Marchany teaches cybersecurity from a long view of the field: from mainframes and Unix systems to modern control frameworks, risk measurement, and security programs built to survive real incidents. A SANS Senior Instructor, Chief Information Security Officer at Virginia Tech, and Director of the Virginia Tech IT Security Lab, Randy teaches SEC566: Implementing and Auditing CIS Controls. His work helps students connect defensible controls, audit strategy, and operational security to the practical challenge of reducing risk across complex environments.
Randy has been involved in computing since the 1970s and joined SANS in 1992, making him the longest-running SANS instructor. His path includes work as an IBM systems programmer, data acquisition software developer, VAX and Unix administrator, IT auditor, consultant, and university security leader. At Virginia Tech, he has helped shape security architecture, policy, standards, and guidance for protecting university systems and sensitive data. He draws on that experience while teaching the course, helping students connect CIS Controls implementation, audit methods, security benchmarks, risk measurement, and real-world failure analysis to the work of building security programs that can be tested, improved, and explained.
Randy holds a BSCS/MSEE in computer security from Virginia Tech. Randy Marchany is also a faculty member of the SANS Technology Institute, which has been designated an NSA Center of Academic Excellence in Cyber Defense and is a multi-year winner of the National Cyber League competition. He co-authored the original SANS Top 10 Internet Threats, the SANS Top 20 Internet Threats, the SANS Consensus Roadmap for Defeating DDoS Attacks, and SANS Incident Response: Step-by-Step guides. He was also part of the original Center for Internet Security benchmark development work and later contributed to CIS Controls version 8. As a frequent speaker at national and international conferences including EDUCAUSE, SANS, SANS Summits, IEEE, NIST, ISACA, BSides and RSA, Marchany shared Virginia Tech’s pioneering approaches to cybersecurity. The university was among the first to offer practical cybersecurity courses starting in 1998, and under Marchany’s leadership, has remained at the forefront of cybersecurity education and research.
Randy teaches by challenging students to think, fail safely, and connect “book” knowledge to actual defensive work. He does not just explain controls; he pushes students to understand why the control matters, what evidence proves it is working, and where assumptions break. His broader community work includes the US Cyber Challenge, Virginia Cyber Range, VASCAN, EDUCAUSE, and REN-ISAC. Away from security, Randy is a hammer dulcimer master, wrote the original theme song for NPR’s World Cafe, played for decades with the band No Strings Attached, NAIRD INDIE (Independent music version of the Grammy) winner, coached college volleyball, rides bicycles and motorcycles, and reads history whenever a museum is not available.
Randy knows his stuff. I am amazed at his depth and breadth of knowledge.
Randy has a wealth of knowledge and is a fantastic communicator. I will have much to take back with me.
[Randy] is very knowledgeable and approachable for questioning and clarification.
Here are upcoming opportunities to train with this expert instructor.
Explore content featuring this instructor’s insights and expertise.
This session argues that modern cyber incidents are not the result of novel or sophisticated threats, but of the industry’s repeated failure to fix problems we have understood since the 1990s.

This session will describe the differences between version 7.1 and version 8 of the Center for Internet Security Twenty Critical Security Controls. This major rewrite of the twenty CSCs reflects core changes in today\'s computing and infrastructure environments.

The 20 Critical Controls are quick wins that allow you to rapidly improve your cybersecurity without major procedural or technical change. International cybersecurity experts developed the 20 Critical Controls to be the most effective and specific set of technical measures to counter the most common and damaging computer attacks. The controls address the root causes of these attacks to ensure your security measures are effective. This presentation will also discuss how VA Tech is implementing the 20 Critical Controls as part of its overall security strategy.
