SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact Us
Infrastructure as Code (IaC) gives teams speed, repeatability, and auditability, but only when it’s done securely. In this session, we’ll walk through the real advantages of IaC, then spotlight a growing anti pattern: “vibe coding” cloud templates with loose, under specified prompts and trusting whatever the AI hands back.
We’ll demonstrate by generating an IaC template intentionally, running it through a third-party scanning tool to surface misconfigurations and policy violations, and then iteratively hardening both the prompt and the code.
Along the way, we’ll quantify the blast radius of shipping an insecure “it looked fine to me” template (e.g., data exfiltration, privilege escalation, compliance, and financial issues that dwarf the cost of doing it right).
Finally, we’ll confront an uncomfortable truth: without humans who understand cloud security fundamentals, automation can accelerate us straight into trouble.
This webcast supports content and knowledge from SEC502: Cloud Security Tactical Defense. To learn more about this course and explore upcoming sessions, click here.


Ryan Nicholson, SANS Senior Instructor and SEC502 and SEC541 author, brings DoD and cloud security experience to help practitioners detect threats, secure modern environments, and apply defensive strategies that work in real-world operations.
Read more about Ryan Nicholson