SANS Cybersecurity Blog
Blog
Actions
Media Outlet details
| Scope | Trade/B2B |
|---|---|
| Language | English |
| Country | United States of America |
|
Similarweb UVM |
Request pricing |
|
Comscore UVM |
Request pricing |
Recent Articles
Search ArticlesWhat Happens When AI Gives Us Answers Before We’ve Learned How to Ask the Questions?
I use AI—a lot. I also find myself arguing with it—a lot. There isn’t a day that goes by when that doesn’t happen, and I don’t expect that to change any time soon. That may sound strange, but I think it illustrates something important about where we are headed in cybersecurity. It is undoubtedly true that AI can provide an extraordinary amount of information in seconds. It can explain a protocol, analyze code, suggest a configuration, interpret a log entry, or recommend how to secure a system.
Four Conversations to Have With Your Family This October
My work starts after something has gone wrong. A phone arrives on my desk, and my job is to find out what happened on it: who reached out to the child, when the money left, which app the conversation lived in. After more than two decades of examining criminal activity, I can tell you the hardest part of the job. It is seeing the moment in the timeline when one conversation at home would have changed everything.
Behavior Change Is Not the Finish Line
Security awareness programs have made progress over the past decade. Check-the-box training is giving way to programs that focus on managing behavioral change. But the 2026 SANS Security Awareness & Culture Report finds that changing behavior is not the same as building a security culture. Surveying more than 1,700 security awareness professionals, the report shows that 45% of programs are in Stage 3 of the SANS Security Awareness & Culture Maturity Model: Promoting Awareness and Behavior Change.
The Questions Critical Infrastructure Leaders Should Be Asking
Since this year’s SANS ICS Summit in June, we’ve seen cyberattacks that targeted and disrupted over a hundred water and wastewater systems (WWS) throughout the US, threats to exposed programmable logic controllers (PLCs) across multiple industrial sectors, and new government initiatives urging us to fortify critical infrastructure.
The Cybersecurity Claims in “We Must Pace the Frontier”
From the editor Dario Amodei’s letter put cybersecurity at the center of the case for slowing frontier AI: an agent swarm, a persistent botnet, the whole internet taken over inside a year. Reporters are going to ask SANS whether that holds up, and the questions they ask will not be policy questions. They will be mechanics questions. How does a botnet get built? What would it take to hold the internet once you had it? Where does a number like “hundreds of billions” come from?
What Comes After Behavior Change?
One of my favorite parts of working on the human side of cybersecurity for so long is seeing just how much our field has matured. It has been a long process and, at times, a frustratingly slow one. But the way we think about securing people today is fundamentally different from how we thought about it 15 years ago. I started in cybersecurity on the technical side.
Cloud-Native Forensic Imaging Part 2
Part 1 of this series covered why cloud acquisition outpaces physical imaging and walked through how to create a snapshot and provision a forensic disk from it. You now have a forensic disk, an isolated, point-in-time copy of the compromised instance's storage, as well as two paths forward: mount it to a forensic VM inside the cloud, or export and download it for local analysis.
A Visual Summary of SANS Security Awareness & Culture Summit 2026
On Thursday, August 27, and Friday, August 28, 2026, attendees joined us in Las Vegas and online for SANS Security Awareness & Culture Summit 2026. Across two days, practitioners shared real-world approaches to strengthening security culture, reducing human risk, and preparing programs for AI and a changing threat landscape. We invited Ashton Rodenhiser of Mind’s Eye Creative to create graphic recordings of the Summit presentations.
SEC501 Major Update: Applied Cyber Defense for AI-Accelerated Attacks
Artificial intelligence (AI) is changing how quickly an enterprise attack can develop and how much of it can be automated. Google Threat Intelligence Group reported a zero-day it assesses was developed with AI, as well as malware that generates commands from the state of the affected system, and attacks against AI components that exposed AWS keys and GitHub tokens inside build environments.
SANS Stay Ahead of Ransomware August 2026: Hot Off the Press
On the August 2026 episode of SANS Stay Ahead of Ransomware, we were joined by special guest Sean O’Connor, the author of SANS FOR589: Cybercrime Investigations and host of the SANS Threat Analysis Rundown (STAR). In this episode, Ryan and I each chose some recent ransomware-related articles and reports to break down and discuss with Sean. The first report was the Qilin (Agenda) Ransomware: Cyber Threat Intelligence Report by the Centre for Cybersecurity Belgium.