Group Purchasing
Group Purchasing

Robert M. Lee

FellowCEO at Dragos, Inc

Specialities

Industrial Control Systems Security, Digital Forensics and Incident Response

Robert M. Lee

About Robert M. Lee

Robert M. Lee sets the standard for modern industrial defense. A SANS Fellow and CEO and Co-Founder of Dragos, Inc., Robert is the author of SANS ICS515: ICS Visibility, Detection, and Response, lead author of SANS FOR578: Cyber Threat Intelligence, and co-author of SANS ICS310: ICS Cybersecurity Foundations. He brings real incidents, clear models, and hands-on labs to every class, showing not just how adversaries operate, but how defenders win.

Robert began as a U.S. Air Force Cyber Warfare Operations Officer assigned to the National Security Agency, where he helped stand up the first mission dedicated to tracking and countering threats to industrial infrastructure. He went on to be a go-to expert for major industrial cyber intrusions, co-authoring the E-ISAC/SANS analysis of the 2015 Ukraine power-grid attack and leading Dragos research that identified CRASHOVERRIDE, the 2016 malware built to disrupt grid operations. His team has supported responses to landmark events, including the Colonial Pipeline incident’s OT response effort. That experience drives ICS515, where students capture and interpret OT network data, apply threat intelligence to shape detections, and use the take-home ICS515 student kit: a PLC and simulator board used in the labs to practice visibility and response they can replicate when back at work. His experience also shapes ICS310, where students learn the fundamentals of mechanical and operational systems, examine how automation works across sectors through curated case studies, and convert those lessons into risk-prioritized actions, applying the five ICS critical controls they can tailor to any environment. Today, he keeps his courses current by working directly with asset owners, policymakers, and the global ICS community.

Robert’s leadership spans industry and public service. He contributes to cyber-resilience efforts at the World Economic Forum, serves on boards including the International Society of Automation and the National Cryptologic Foundation, and is a Lieutenant Colonel in the Army National Guard supporting OT cybersecurity and response. He has advised the U.S. Department of Energy as Vice Chair for the Grid Resilience for National Security subcommittee and testified before Congress on threats to critical infrastructure. He also co-created community resources such as The Five ICS Cybersecurity Critical Controls and earlier research on the ICS Cyber Kill Chain. Robert is also a faculty member of the SANS Technology Institute, which has been designated an NSA Center of Academic Excellence in Cyber Defense and is a multi-year winner of the National Cyber League competition.

In the classroom, Robert is energetic and intensely mission focused. He co-chairs the annual SANS ICS Security Summit and teaches with the same clarity and urgency he brings to industry response: see your environment, communicate with engineers, and implement improvements that respect safety and uptime. His message is clear and consistent: “ICS defense is doable.”

Qualifications Summary
  • SANS Fellow; SANS ICS/OT Practice Lead
  • CEO & Co-Founder, Dragos, Inc.
  • Course author: ICS515: ICS Visibility, Detection, and Response; lead author: FOR578: Cyber Threat Intelligence; co-author: ICS310: ICS Cybersecurity Foundations
  • Former U.S. Air Force Cyber Warfare Operations Officer assigned to the NSA; helped stand up the first mission focused on threats to industrial infrastructure
  • Lieutenant Colonel, Army National Guard, supporting OT cybersecurity and response
  • Board service: International Society of Automation (ISA); National Cryptologic Foundation; contributor to World Economic Forum cyber-resilience efforts
  • Led and advanced landmark investigations and public reporting: 2015 Ukraine power-grid attack (E-ISAC/SANS), CRASHOVERRIDE malware (Dragos/E-ISAC), Colonial Pipeline OT response, and PIPEDREAM, the first cross-industry reusable OT attack framework
  • Co-chair, SANS ICS Security Summit

Press & Media