SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsConfront emerging threats, secure your environment, and strengthen cyber resilience with SANS
Equip yourself or your team with comprehensive hands-on cybersecurity training. Explore 85+ courses covering technical skills, leadership, and real-world defense against evolving cyber threats.









Don’t forget to submit your Holiday Hack Challenge 2025 report by January 5 for a chance to win a SANS OnDemand course or a SANS Skills Quest by NetWars subscription!
Your write-up helps showcase your journey — and while the contest wraps next month, the game remains open year-round for continued play and learning.

Unlock the full potential of your career in 2026 with cybersecurity training from SANS.
Immerse yourself in a learning environment that features industry-leading hands-on labs, simulations, and exercises, all geared towards practical application in your professional endeavors.

It’s a question every security leader is being forced to answer. In Season 3, the Cyber Leaders Podcast brings together the people making those calls—under pressure, in the moment, and with real consequences. In the age of machine-speed attacks, AI-assisted defense, and workforce transformation, these candid conversations provide a real-world lens on what effective decision-making looks like amid continuous change.

Join SANS ICS Europe in Munich for specialised training focused on securing critical industrial and operational technology systems. Learn from world-leading instructors in courses like ICS410: ICS/SCADA Security Essentials and ICS515: ICS Visibility, Detection, and Response, both mapped to GIAC certification.
Protect the infrastructure that powers our world—build the skills to safeguard industrial environments from evolving cyber threats.

Whether you're getting started or advancing your skills, choose from world-class training, industry-recognized certifications, or explore with free course demos. Start building your path with SANS.
Learn your way, whether in person, live instruction delivered in an online format, or self-paced, on your own schedule, with cybersecurity courses from top industry experts.
Master the skills to earn GIAC certifications, the industry's most rigorous credentials, with expert exam preparation from SANS.
Discover our global SANS Summits, running throughout the year covering a multitude of topics. This is the perfect way to experience the quality of SANS speakers and instructors!
The real value of this training lies at the intersection of quality content and delivery by a subject-matter expert actively working in the field, making it incredibly relevant and immediately applicable to my job.
You cannot beat the quality of SANS classes and instructors. I came back to work and was able to implement my skills learned in class on day one. Invaluable.
SANS is the best information security training you’ll find anywhere. World-class instructors, hands-on instruction, actionable information you can really use, and NetWars.
Effective cybersecurity operations rely on layers of offensive testing, defensive architecture and monitoring, forensics and incident response, cloud security, and leadership. Advancing your capabilities in these focus areas is our mission because it furthers your ability to protect us all.
Training in penetration testing, red teaming, purple teaming, and exploit development, provides the skills needed to simulate real-world attacks, evade defenses, and enhance security through adversary emulation and improving defense strategies.
Learn moreEffective Cyber Defense enables organizations to anticipate, withstand, and recover from cyber-attacks through proactive monitoring, threat detection, and incident response. It combines security operations, automation, and resilient architecture to reduce risk and minimize attack impact.
Learn moreCloud security encompasses technologies, policies, and controls that protect data, applications, and infrastructure in cloud environments. Knowing how to safeguard sensitive information in cloud environments is crucial for preventing cyber threats, ensuring compliance, and maintaining business continuity.
Learn moreAs organizations begin to integrate AI into defensive workflows, identity security becomes the foundation for trust. Every model, script, or autonomous agent operating in a production environment now represents a new identity—one capable of accessing data, issuing commands, and influencing defensive outcomes.




Governments around the world rely on SANS for best-in-class training, equipping local and international cybersecurity teams with the skills necessary to protect critical infrastructure and stay ahead of adversaries

Cybersecurity professionals of all skill levels train with SANS to learn from industry experts and gain hands-on, practical knowledge that can be applied immediately, effectively preparing them for real-world threats.

SANS Institute is GIAC’s preferred partner for exam preparation, offering focused curriculums that help individuals pass with confidence and validate their expertise in various cybersecurity domains.

Fortune 500 companies partner with SANS to recruit, build, and retain high-performing, outcome-driven teams through industry-leading training solutions that bolster cyber resilience.
Equip your team with cutting-edge cybersecurity skills, designed to address your organization’s most critical security needs.
Empower your leaders with strategies that drive better decision-making, stronger risk management, and improved cyber resilience.
Mitigate human risk and ensure compliance with advanced training that addresses evolving threats and security regulations.
Adapt to new SEC mandates with a 10-module training course designed to expand cyber literacy and help leaders facilitate an engaged, united cybersecurity culture.

Join the SANS CISO network, exclusively for senior security executives. Connect with experts and thought leaders, share ideas and lessons learned and help drive industry breakthroughs.

Gain exclusive access to free resources, tools, and expert content—news, training, podcasts, whitepapers, and more. Explore unique member benefits designed for cybersecurity professionals that you won’t find anywhere else.

When you join the SANS community, you gain access to free cybersecurity resources, including free training, 150+ instructor-developed tools, the latest industry updates, and more.
Organizations keep deploying AI "agents" without understanding what autonomy level they're getting or what governance it warrants. Chinese state-sponsored hackers used Claude Code to automate a cyberattack campaign across 30 organizations. Replit's AI coding agent deleted a production database, then tried to cover up its mistake. These aren't anomalies. They're predictable governance failures.

This isn't your typical "don't pay ransoms" talk. We'll explore the harsh realities where business continuity and regulatory pressure create impossible choices, providing practical frameworks for decision-making under duress, technical protocols for verifying attacker claims, and strategies for maintaining leverage when all seems lost.

Join the renowned investigators of Baker221b and step into the role of a digital detective.

In this webinar, experts from SANS and Cisco will explore the hybrid mesh firewall approach—what it is, why it’s critical today, and effective deployment at scale.

In this SANS First Look webcast, we explore how Zscaler’s Zero Trust Branch (ZTB) introduces a new, streamlined approach to securing branch and OT environments.

This talk is about how to bootstrap almost anything, whether it’s a company, an open source project, a personal pursuit, a charity, a conference, or just about anything else.

Mike Hoffman will explain how Dispel’s OT-first remote access platform implements 5CC-aligned safeguards—covering architecture, deployment patterns, connection models, and operational controls. You’ll see how moving-target defense, disposable sessions, vaulted credentials, granular auditing, and compliance artifacts can reduce dwell time and simplify investigations—while preserving operator productivity.

The SANS 2026 Kubernetes and CNAPP Forum is a focused, one-day event designed for security professionals, DevOps teams, and cloud architects seeking to secure modern, containerized applications.

The Model Context Protocol (MCP) is becoming increasingly important in enabling and expanding the capabilities of agents.

Join us for the grand finale of the Holiday Hack Challenge 2025 where we’ll reveal the names of the big winners as we bid farewell to another chapter of challenges, victories, and innovation!

Modern security leaders must deal with an endless barrage of changes to the business, technology, and threat landscape. This requires a combination of technical knowledge, understanding of risk, and the ability to lead teams in times of intense pressure.

This webcast will explore where conventional DLP programs fall short in the age of AI, including lack of context, overwhelming alert fatigue, and ineffective measurement.

This session explores the strategic shift toward unified DFIR platforms that merge forensic-grade investigation capabilities with incident response. Attendees will gain insight into how integrating evidence collection, artifact triage, endpoint isolation, and threat remediation into a single workflow reduces tool fatigue, shortens dwell time, and improves regulatory compliance.

As adversaries harness AI to deploy polymorphic malware, agentic automation, and high-speed deception, defenders must respond with intelligent, explainable, and resilient threat intelligence systems.

As adversaries harness AI to deploy polymorphic malware, agentic automation, and high-speed deception, defenders must respond with intelligent, explainable, and resilient threat intelligence systems.

Join Justin Searle, one of the leading experts in the industry and one of our Senior Instructors at SANS, for the first in a series of webcasts that will walk you through the most challenging aspects of launching a cybersecurity program in OT/ICS.

Grounded in current SANS research and frontline operational experience, this one-hour session brings together Tim Conway, Robert M. Lee, Jason D. Christopher, and Dean Parsons to deliver leadership-level guidance for practitioners and executives.

NIST SP 800-61 just got a major update with Revision 3. Learn what changed and how to mature your Incident Response program with actionable updates that you can use right away.

Join this SANS webcast to discover how to build a modern, AI-driven SOC powered by Cortex XSIAM—the industry’s leading AI-powered security operations platform.

Come to this webcast to learn how to translate cloud adoption and AI integration into effective defenses that can be applied consistently, at scale, and without slowing innovation.
