SEC504: Hacker Tools, Techniques, and Incident Handling

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usConnect, learn, and share with other cybersecurity professionals
Engage, challenge, and network with fellow CISOs in this exclusive community of security leaders
Become a member for instant access to our free resources.
Sign UpMission-focused cybersecurity training for government, defense, and education
Explore industry-specific programming and customized training solutions
Sponsor a SANS event or research paper
We're here to help.
Contact UsToday’s security awareness officer goes far beyond just annual CBT — they are experts in managing human risk.
In the past 18 months we have seen an explosion of interest in both the field of Security Awareness and the role of the Security Awareness Officer. This includes an exponential increase in companies posting job opportunities for awareness officers, a three-fold increase in attendees for the SANS Awareness Summit this year (over 7,000 attendees), and almost 700 people who have completed the SANS Security Awareness Professional (SSAP) credential. As such, today we are going to help define what Security Awareness is all about.
First, both this role and field is still very immature. Unlike other security fields like penetration testing or incident response which have been around for decades, awareness is a comparatively new, immature and not yet fully defined field. In fact, the NIST NICE Cybersecurity Workforce taxonomy has yet to create or define or role for this field (but this is in the works to soon change).
Traditionally, when people discuss Security Awareness they think of compliance, someone responsible for pushing out Computer Based security awareness Training (CBT) once a year and then tracking what percentage of the workforce took the training for audit / compliance purposes. This is an extremely outdated and no longer valid description. While compliance is still important, Security Awareness today is ultimately about managing human risk. Organizations can no longer take a purely technical approach to cybersecurity we must also address the human element. In fact, the VZ DBIR 2021 report identified people were involved in over 85% of all breaches globally. This is why organizations establish mature Security Awareness programs, to manage their human risk by changing organizational behavior. In fact, the most mature Awareness programs go beyond just behavior change and build a strong security culture and have the metrics framework to demonstrate that change.
Today’s security awareness officer goes far beyond just annual CBT, in many ways they are experts in managing human risk. Skill sets and responsibilities include:
This is an extremely exciting and fast growing field, as organizations struggle to better understand and manage their human risk. If you are interested in learning more or getting started in this field, I highly recommend you start with the blog post Getting Started in Cybersecurity With a Non-Technical Background and / or Career Path for Security Awareness Professionals.
Lance revolutionized cyber defense by founding the Honeynet Project. Over the past 25 years, he has helped 350+ organizations worldwide build resilient security cultures, transforming human risk management into a cornerstone of modern cybersecurity.
Read more about Lance Spitzner