Edge Rewrite
// request.cf · coarse context

A page that knows where it met you.

Only coarse request metadata is shown. This demo does not display or persist visitor IP addresses.

Country
US
Cloudflare location
CMH
Connection
HTTP/2
Language
Not provided

Ray ID: a4515e9e1e2f2a83

Jump to content

Draft:SANS Technology Institute

From Wikipedia, the free encyclopedia
  • Comment: This appears to have been assisted with AI, with WP:AIATTR showing throughout the Research and cybersecurity section. ChrysGalley (talk) 14:47, 27 September 2026 (UTC)

SANS Technology Institute
TypePrivate
Established2005
AccreditationMiddle States Commission on Higher Education
PresidentEd Skoudis
Location
North Bethesda
,
Maryland
,
United States
Websitewww.sans.edu

SANS Technology Institute (SANS.edu) is a private higher-education institution specializing in cybersecurity education. It is based in North Bethesda, Maryland, and offers undergraduate and graduate degree and certificate programs in cybersecurity. The institution is accredited by the Middle States Commission on Higher Education.[1]

History

[edit]

SANS Technology Institute was established in 2005 by cybersecurity educator Alan Paller, who had previously founded the SANS Institute in 1989. The institute was created to provide academic education in information security alongside the practical cybersecurity training associated with SANS.[2]

In December 2005, Washington Technology reported that the Maryland Higher Education Commission had approved the institution to offer graduate degrees in cybersecurity, with graduate instruction beginning in 2006.[3]

Paller died in November 2021. In its obituary, The Washington Post described him as an advocate for cybersecurity awareness and workforce development and noted that he had founded SANS Technology Institute in 2005, which later became a regionally accredited cybersecurity college and graduate school.[2]

Paller's death was also noted in a November 2021 Washington Post report concerning efforts in Congress to increase cybersecurity assistance for schools. The article quoted Johannes Ullrich, dean of research at SANS Technology Institute, discussing Paller's influence on cybersecurity education and on people working in the field.[4]

The institution received regional accreditation from the Middle States Commission on Higher Education in 2013.[1]

In October 2021, Ed Skoudis was appointed president of SANS Technology Institute. Security Magazine reported that he would oversee the institute's degree and certificate programs and its Internet Storm Center.[5]

Academic programs

[edit]

SANS Technology Institute provides undergraduate and graduate education focused on cybersecurity. Its programs include a bachelor's degree in applied cybersecurity, a master's degree in information security engineering, undergraduate certificates and graduate-level certificates in specialized cybersecurity subjects.[6][5]

The institute's academic model incorporates technical cybersecurity training and professional GIAC certifications. Its graduate programs originated with the information-security degrees approved by the Maryland Higher Education Commission in 2005.[3]

The institution's programs have also been discussed in independent reporting about cybersecurity education and training. Help Net Security included SANS Technology Institute in a 2024 overview of higher-education institutions offering cybersecurity programs.[6]

Internet Storm Center

[edit]

SANS Technology Institute is associated with the SANS Internet Storm Center (ISC), a cybersecurity monitoring and information service that publishes analysis of emerging threats. The Internet Storm Center has been used as a source by cybersecurity publications reporting on newly observed vulnerabilities and attack activity.[5]

In March 2025, Network World reported that the SANS Technology Institute had warned organizations about attempted exploitation of vulnerabilities in Cisco Smart Licensing Utility. The warning was issued by Johannes Ullrich, the institute's dean of research, after the Internet Storm Center detected exploit activity involving the vulnerabilities.[7]

The same activity was reported by The Hacker News, which said that the SANS Internet Storm Center had identified active exploitation attempts involving the Cisco Smart Licensing Utility vulnerabilities CVE-2024-20439 and CVE-2024-20440.[8]

In November 2025, KrebsOnSecurity cited Ullrich in its coverage of Microsoft's November Patch Tuesday security updates. The report also referred readers to the SANS Internet Storm Center's breakdown of Microsoft's individual security fixes.[9]

The Internet Storm Center has also been cited in reporting on social-engineering and malware campaigns. In October 2025, SC Media reported on a ClickFix attack in which malicious TikTok videos were used to persuade users to execute commands leading to malware installation. The report cited a post by security consultant Xavier Mertens published through the SANS Technology Institute's Internet Storm Center.[10]

Research and cybersecurity commentary

[edit]

Researchers and executives associated with SANS Technology Institute have contributed to public discussion of emerging cybersecurity issues.

In 2022, KrebsOnSecurity quoted Ullrich, dean of research at SANS Technology Institute, in reporting on the development of passwordless authentication based on the FIDO standards. Ullrich described the approach as a significant development in addressing authentication problems and discussed the use of existing mobile devices as authenticators.[11]

In August 2024, IT Brew interviewed Ullrich about preparations for the transition to post-quantum cryptography. He recommended that organizations begin by inventorying their existing cryptographic systems and testing new post-quantum algorithms alongside existing infrastructure.[12]

In 2024, IBM published an account of the SANS Institute's annual discussion of emerging attack techniques. The article identified Ullrich, as dean of research at SANS Technology Institute, as a speaker who discussed the security implications of technical debt and deepfakes in identity verification.[13]

The 2025 SANS cybersecurity keynote at the RSA Conference was also covered by SC Media. The publication reported that Skoudis, as president of SANS Technology Institute, opened the session and discussed emerging threats including authorization sprawl, attacks against industrial control systems, inadequate logging and the use of artificial intelligence in cybersecurity.[14]

In June 2026, B2B Cyber Security reported on the SANS cybersecurity keynote at the RSA Conference and identified Skoudis as president of SANS Technology Institute. The report discussed the role of artificial intelligence in emerging attack techniques and quoted researchers associated with SANS on subjects including AI-assisted exploitation, software supply-chain security, industrial-control-system monitoring and automated attack campaigns.[15]

SC Media also covered the 2026 RSA Conference keynote, reporting that Skoudis hosted the SANS Technology Institute panel on emerging attack techniques and that the discussion examined the use of artificial intelligence by both attackers and security operations centers.[16]

In April 2026, IT Brew interviewed Skoudis about Anthropic's use of artificial intelligence to identify software vulnerabilities. Skoudis said that automated vulnerability discovery could help defenders address the growing volume of vulnerabilities and exploits.[17]

Cybersecurity competitions

[edit]

Students compete as the SANS.edu Sentinels in the National Cyber League, a collegiate cybersecurity skills competition. SANS Technology Institute was ranked as the top school in the Experienced Bracket in the National Cyber League Cyber Power Rankings in spring 2025, fall 2025, and spring 2026.[18][19][20] The institute also placed among the top institutions in the National Security Agency's annual Codebreaker Challenge, finishing third in 2024 and second in 2025, according to NSA announcements.[21][22]

See also

[edit]

References

[edit]
  1. 1 2 "SANS Technology Institute". Middle States Commission on Higher Education. Retrieved 20 August 2026.
  2. 1 2 Nakashima, Ellen (29 November 2021). "Alan Paller, early leader in cybersecurity awareness, dies at 76". The Washington Post. Retrieved 20 August 2026.
  3. 1 2 Jackson, William (14 December 2005). "SANS to offer graduate degrees in cybersecurity". Washington Technology. Retrieved 20 August 2026.
  4. ↑ "Senators want a surge in cyber help for schools". The Washington Post. 12 November 2021. Retrieved 20 August 2026.
  5. 1 2 3 "Ed Skoudis named President of SANS Technology Institute". Security Magazine. 22 October 2021. Retrieved 20 August 2026.
  6. 1 2 "10 colleges and universities shaping the future of cybersecurity education". Help Net Security. 23 April 2024. Retrieved 20 August 2026.
  7. ↑ Dunn, John E. (21 March 2025). "Attackers probing backdoor flaw in popular Cisco Smart Licensing Utility, warns SANS". Network World. Retrieved 20 August 2026.
  8. ↑ Lakshmanan, Ravie (21 March 2025). "Ongoing Cyber Attacks Exploit Critical Vulnerabilities in Cisco Smart Licensing Utility". The Hacker News. Retrieved 20 August 2026.
  9. ↑ Krebs, Brian (16 November 2025). "Microsoft Patch Tuesday, November 2025 Edition". KrebsOnSecurity. Retrieved 20 August 2026.
  10. ↑ "Illicit TikTok videos harnessed in ClickFix attack". SC Media. 20 October 2025. Retrieved 20 August 2026.
  11. ↑ Krebs, Brian (7 May 2022). "Your Phone May Soon Replace Many of Your Passwords". KrebsOnSecurity. Retrieved 20 August 2026.
  12. ↑ Hurley, Billy (27 August 2024). "How to start using post-quantum encryption". IT Brew. Retrieved 20 August 2026.
  13. ↑ Nadeau, Josh (2024). "SANS Institute: Top 5 dangerous cyberattack techniques in 2024". IBM. Retrieved 20 August 2026.
  14. ↑ Spring, Tom (2 May 2025). "2025's most dangerous new attack techniques: AI, ICS sabotage, and 'auth sprawl'". SC Media. Retrieved 20 August 2026.
  15. ↑ "Security researchers are observing new attack techniques in the AI age". B2B Cyber Security. 12 June 2026. Retrieved 20 August 2026.
  16. ↑ "RSAC 2026: 5 ways AI is our worst enemy, and 3 ways to make it SOC's best friend". SC Media. 2026. Retrieved 20 August 2026.
  17. ↑ Hurley, Billy (9 April 2026). "Security pros see Anthropic's AI assistance as boost for bug fixers—mostly". IT Brew. Retrieved 20 August 2026.
  18. ↑ "The National Cyber League Announces Official Spring 2025 Cyber Power Rankings for High Schools and Colleges". PRWeb. 2025.
  19. ↑ "The National Cyber League Announces Official Fall 2025 Cyber Power Rankings for High Schools and Colleges". PRWeb. 2025.
  20. ↑ "The National Cyber League Announces Official Spring 2026 Cyber Power Rankings for High Schools and Colleges". PRWeb. 2026.
  21. ↑ "Georgia Tech wins NSA's Codebreaker Challenge for third consecutive year". National Security Agency. 2024.
  22. ↑ "Georgia Tech wins NSA's Codebreaker Challenge for fourth consecutive year". National Security Agency. 2025.
[edit]