Developer docs
API playgroundTry for free, no card

Search company profiles

SANS Institute

Full company profile

uuid00029mw

Namestring
SANS Institute
Legal namestring
The Escal Institute of Advanced Technologies, Inc.
Websiteurl
sans.org
Company typeenum
Private
Founded yearint
1989
Descriptiontext

SANS Institute (legal entity The Escal Institute of Advanced Technologies, Inc.) is a private, founder-controlled cybersecurity training organization founded in 1989 and headquartered in North Bethesda, Maryland. It delivers 85+ instructor-led and self-paced courses covering offensive operations, cyber defense, cloud security, ICS/OT security, digital forensics, incident response, AI security, and cybersecurity leadership, delivered through three modalities — in-person at global events, live online instructor-led sessions, and self-paced on-demand subscriptions. The curriculum is paired with the GIAC (Global Information Assurance Certification) program, which has granted 230,000+ certifications, and is supported by hands-on learning infrastructure including Cyber Ranges, NetWars competitions, and the Internet Storm Center threat-sharing service. The organization holds ISO/IEC 27001:2022, SOC 2 Type 2, PCI DSS, Cyber Essentials, and Cyber Essentials Plus certifications, and operates academic programs through the SANS Technology Institute.

Revenue is generated across four streams: per-seat cybersecurity training course fees (in-person, live online, on-demand subscription), GIAC certification exam fees typically bundled with training, organizational/group purchasing and private training contracts for enterprise and government clients (often multi-year), and end-user security awareness training delivered to enterprise workforces. The go-to-market combines enterprise field sales, event-driven demand generation (SANS Network Security, SANSFIRE, Cloud Security Exchange Summit, DFIR Summit, RSAC presence, regional summits), and community-led funnel development via free resources, free community membership, webinars, podcasts, and the Internet Storm Center. Distribution channels include direct sales, group purchasing, the AWS Marketplace (for the CIS-bundled cloud security offering), and regional public-sector partnerships.

The customer base spans 492 Fortune 500 enterprises (with named customers including Microsoft, Xerox, and NetJets), 159 country governments, and 400,000+ individual practitioners trained annually. The organization operates through wholly-owned subsidiaries in the United Kingdom, Netherlands, Ireland, Australia, Singapore, and Japan, plus active strategic engagements with the UAE Cybersecurity Council, NATO (Locked Shields cyber range), the Maryland Department of Labor (Cyber Workforce Academy), India's DSCI, and the U.S. federal government (Securing the Next 250 campaign for critical infrastructure defenders). Headcount falls in the 501-1,000 employee band, and SANS is positioned as the practitioner-led, hands-on standard in cybersecurity education with no public listing or disclosed parent company.

Short descriptiontext

SANS Institute, founded in 1989 and headquartered in Bethesda, Maryland, is a private cybersecurity training organization offering 85+ instructor-led courses, GIAC certifications, and hands-on cyber range exercises. It serves 492 Fortune 500 companies, 159 country governments, and 400,000+ practitioners annually.

Operating statusenum
Operating
Ownership categoryenum
Headcount rangeband
501–1,000
akta.pro rankint
HeadquartersBethesda, United States
HQ citystring
Bethesda
HQ countrystring
United States
HQ regionstring
North America
Markets served

Serves global market

Offices7 records

Each record includes

City, Country, Type, Description, Source

Keyword5 values
cybersecurity training, professional certifications, cyber ranges, incident response training, cloud security training
Industry3 codes
1Cybersecurity Technical Skills (Security Engineering, SOC, Pen Testing)
CodeEDABAFAFPrimaryYes
2Cybersecurity Training & Awareness Programs
CodeBPAEANAFPrimaryNo
3Cybersecurity
CodeEDAAAPACPrimaryNo
NAICS code3 codes
  • Computer Training61142
  • Professional and Management Development Training611430
  • Business Schools and Computer and Management Training6114
SIC code1 code
  • Services-Educational Services8200
Product category
Cybersecurity Training and Certification
GTM motion3 records

Each record includes

Type, Description, Source

Revenue model4 records
1Cybersecurity Training Courses
TypeProfessional Services
Description

Instructor-led and self-paced cybersecurity training courses delivered in multiple formats (in-person, live online, on-demand). Course fees vary by duration, format, and specialization area.

sans.org
2GIAC Certification Exams
TypeProfessional Services
Description

Certification examination fees for GIAC credentials, often bundled with training at reduced rates

sans.org
3Organizational Training Programs
TypeSubscription Recurring
Description

Group purchasing and private/custom training programs for enterprise and government clients

sans.org
4Security Awareness Training
TypeSubscription Recurring
Description

End-user and role-based workforce security training for organizations

sans.org
Marketing channels7 records

Each record includes

Title, Type, Stage, Description, Source

Distribution channels6 records

Each record includes

Title, Type, Scope, Target buyer, Description, Source

Cost components5 values
Personnel, Operations, Marketing or Sales, Technology or R&D, Infrastructure
Pricing details4 tiers
1In-Person Training
ModelOne time/ perpetual licenseBilling cadenceMulti-year contract
Notes

Multi-day instructor-led courses delivered at training events and partner locations. Price varies by course and location.

sans.org
2Live Online Training
ModelOne time/ perpetual licenseBilling cadenceMulti-year contract
Notes

Real-time instructor-led training delivered virtually. Provides same curriculum as in-person with remote access.

sans.org
3On-Demand Self-Paced Training
ModelSubscriptionBilling cadenceMonthly
Notes

Self-paced course access with recorded instruction, labs, and course materials.

sans.org
4GIAC Certification
ModelOne time/ perpetual licenseBilling cadenceMulti-year contract
Notes

Certification exam fees, often bundled with training registration at discounted rates.

sans.org
GTM typeB2B and B2C
B2B and B2C
Offering typeServices
Services
Brand1 of 5 records shown
1GIAC Certifications
Description

Global Information Assurance Certification program offering industry-recognized cybersecurity certifications including GPYC, GICSP, GCIP, GRID, GSEC, GSLC, GCSA, and others

sans.org
+4 more records
Core offering1 text field

SANS Institute delivers instructor-led and self-paced cybersecurity training through 85+ courses covering offensive operations, defensive security, cloud security, ICS/OT, digital forensics, incident response, AI security, and leadership, available in in-person, live online, and on-demand formats. The training is bundled with industry-recognized GIAC certifications and supported by hands-on Cyber Ranges simulation environments. Complementary offerings include security awareness training, workforce development programs, threat intelligence via the Internet Storm Center, and annual training events/summits.

Differentiator
Functional benefit
Problem solved
Quantifiable outcome1 of 4 values shown
  • 400,000+ cybersecurity practitioners trained
+3 more records
Product overview1 text field

SANS Institute is a cybersecurity training and certification organization offering 85+ instructor-led and self-paced courses delivered in-person, live online, and on-demand formats. The portfolio centers on technical cybersecurity courses (SEC401, SEC536, SEC573, SEC540), specialized tracks (ICS/SCADA, AI Security, Cloud Security), and leadership training (LDR512), all designed to prepare professionals for real-world threats through hands-on labs and expert instruction. GIAC certifications (GICSP, GCSL, GSEC, GPYC, GCSA) validate expertise across domains. Supporting offerings include Cyber Ranges for hands-on practice, the Holiday Hack Challenge for gamified learning, the Cyber Workforce Academy for career development, and the Internet Storm Center for threat intelligence. The organization serves 159 country governments, 492 Fortune 500 companies, and has trained over 400,000 practitioners.

Product and service12 records
1SEC401: Security Essentials
CategoryCybersecurity Training Course
Description

Foundational 6-day instructor-led cyber defense course covering network, endpoint, and cloud security essentials, bundled with the GIAC Security Essentials (GSEC) certification, designed for practitioners entering or building a foundation in cybersecurity.

2SEC536: Adversarial AI - Penetration Testing AI Systems
CategoryCybersecurity Training Course
Description

Intermediate-level 2-day instructor-led offensive operations course on penetration testing of AI systems, covering AI-specific attack vectors and defensive strategies against adversarial AI threats, designed for security professionals working in AI-driven environments.

3SEC573: AI-Powered Security Automation
CategoryCybersecurity Training Course
Description

Advanced 6-day instructor-led cyber defense course teaching practitioners to build security automation tools using Python, LLMs, and MCP, including 128 hands-on labs and preparation for the GIAC Python Coder (GPYC) certification.

4ICS410: ICS/SCADA Security Essentials
CategoryCybersecurity Training Course
Description

6-day instructor-led industrial control systems security essentials course covering essential practices for securing ICS/SCADA environments, with 15 hands-on labs and preparation for the GIAC Global Industrial Cyber Security Professional (GICSP) certification.

5SEC540: Cloud Native Security and DevSecOps Automation
CategoryCybersecurity Training Course
Description

Advanced cloud security course covering DevSecOps automation and cloud-native security architecture, with 19 hands-on labs and preparation for the GIAC Cloud Security Automation (GCSA) certification.

6LDR512: Security Leadership Essentials for Managers
CategoryCybersecurity Training Course
Description

5-day instructor-led cybersecurity leadership course for managers covering strategic planning, risk management, and team leadership, including 25 hands-on labs and preparation for the GIAC Security Leadership (GSLC) certification.

7FOR589: Cybercrime Investigations
CategoryCybersecurity Training Course
Description

Intermediate 5-day instructor-led digital forensics and incident response course covering cybercrime investigations, including 20 hands-on labs for practitioners working in DFIR.

8GIAC Certifications
CategoryCertification Program
Description

Industry-recognized cybersecurity certification examinations covering more than 50 specialized credentials (including GPYC, GICSP, GCSA, GSLC, GSEC, GCIP, GRID), aligned with SANS course curriculum and validating practitioner expertise.

9SANS Cyber Ranges
CategoryHands-on Training Platform
Description

Hands-on training simulation platform including NetWars competitions and cyber crisis exercises, enabling realistic cybersecurity skill development and team-based incident response scenarios.

10SANS AI Security Training
CategoryCybersecurity Training Focus Area
Description

Comprehensive AI cybersecurity training program covering AI-powered threats, defensive use of AI for security operations, and skills to navigate an AI-driven threat landscape, available across multiple practitioner levels and aligned to AI security focus area.

11SANS Cyber Workforce Academy
CategoryWorkforce Development Program
Description

Free virtual cybersecurity training program for Maryland residents offering technical training, GIAC certification attempts, and career services. Since 2018, has placed 310+ Marylanders in cybersecurity roles with 87% securing related positions within 12 months.

12CIS Hardened Images and SANS Cloud Security Training Bundle
CategoryCloud Security Training and Infrastructure Bundle
Description

Bundled offering on AWS Marketplace combining CIS Hardened Images pre-configured benchmark-aligned infrastructure with SANS cloud security training, helping organizations migrate to AWS securely while reducing configuration drift and strengthening team expertise.

Scale indicator6 records

Each record includes

Type, Value, Description, Source

Partnership14 partners
Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2026-06-11
Description

CIS and SANS Institute partnership to bundle CIS Hardened Images with SANS cloud security training, available through AWS Marketplace. The combined offering pairs pre-configured, benchmark-aligned infrastructure with practitioner-led courses to help organizations migrate to AWS securely while reducing configuration drift and strengthening team expertise. Integrates with AWS services including Control Tower, Application Migration Service, and Database Migration Service.

Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2026-06-09
Description

Securing the Next 250 campaign offering specialized ICS security training for U.S. federal agencies, National Guard units, and contractors defending critical infrastructure, coinciding with America's 250th anniversary. Curriculum comprises seven courses with GIAC certifications (GICSP, GCIP, GRID) organized into role-based learning paths.

Strategic tierRegionalTypeStrategic or Co-development PartnerAnnounced on2026-06-01
Description

SANS Cyber Workforce Academy funded through Maryland Department of Labor EARN Maryland grant, running through spring 2027. Program aims to support 60+ participants with technical training, GIAC certification attempts, and career services. Since 2018 launch, Academy has placed 310+ Marylanders in cybersecurity roles with 87% securing related positions within 12 months.

4NATO
Strategic tierFlagshipTypeStrategic or Co-development PartnerAnnounced on2026-04-21
Description

SANS Institute selected to provide fully operational cyber range for NATO's annual Locked Shields defensive exercise (16th edition) in Tallinn, Estonia. Deploying real ICS and physical equipment with 16 teams defending national-scale power grid under live cyber attack.

computerweekly.com
Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2026-04-17
Description

Joint industry report 'The AI Vulnerability Storm: Building a Mythos-Ready Security Program' developed by SANS Institute, Cloud Security Alliance, [un]prompted, and OWASP GenAI with contributions from 250+ CISOs. Report warns that AI models like Anthropic's Mythos will accelerate vulnerability discovery and exploitation.

Strategic tierCoreTypeGTM or Marketing PartnerAnnounced on2026-04-15
Description

SANS Institute launched Find Evil! hackathon at RSAC 2026 with 1,100+ participants competing to make Protocol SIFT production-ready by June 15, 2026. $22,000 prize competition prompted by AI models discovering thousands of zero-day vulnerabilities.

Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2026-02-17
Description

SANS and siberX partnership introducing NOW // AI simulation program to enhance AI risk management, security governance, and compliance. Program includes operational pillars: Protect AI, Utilize AI, and Govern AI.

Strategic tierRegionalTypeStrategic or Co-development PartnerAnnounced on2026-02-17
Description

WiCyS launched AI Security Accelerator Program in Maryland supporting women transitioning into AI cybersecurity roles with training, certification, mentorship, and industry engagement, funded by Maryland's EARN Maryland Grant Program.

Strategic tierNationalTypeStrategic or Co-development PartnerAnnounced on2025-12-18
Description

Strategic partnership aimed at enhancing UAE's cybersecurity capabilities and workforce readiness. Includes initiatives such as training programs, workshops, and information sharing to improve national cyber defense and resilience.

Strategic tierNationalTypeStrategic or Co-development PartnerAnnounced on2025-12-04
Description

SANS Institute and DSCI launched India's first comprehensive study on cybersecurity skilling landscape to identify talent gaps and improve industry alignment. Study aims to evaluate training effectiveness and inform future workforce development.

Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2025-11-20
Description

OPSWAT-sponsored SANS State of ICS/OT Cybersecurity 2025 report finding that 21.5% of organizations experienced cyber incidents affecting industrial control systems, with 37.9% from ransomware and 40.3% causing operational downtime.

Strategic tierRegionalTypeStrategic or Co-development PartnerAnnounced on2025-11-04
Description

SANS Gulf Region 2025 cybersecurity training event in Dubai from November 8-27, 2025, with 14 specialized courses addressing Middle East's cybersecurity skills shortage and supporting UAE's digital transformation ambitions.

Strategic tierCoreTypeTechnology or IntegrationAnnounced on2025-11-03
Description

AWS and SANS Institute released joint whitepaper 'AI for Security and Security for AI: Navigating Opportunities and Challenges' addressing securing generative AI applications and using AI to strengthen cloud security posture.

Strategic tierRegionalTypeStrategic or Co-development PartnerAnnounced on2025-10-27
Description

siberX partnered with MISA Ontario and SANS Institute to deliver cybersecurity training workshop and escape room experience at 2025 MISA Ontario InfoSec Conference. Event focused on practical, municipal-specific training including hands-on workshops and gamified simulations.

Recent move8 records

Each record includes

Date, Type, Title, Description, Source

Expansion highlight6 records

Each record includes

Type, Description

Peers10 records
TypeEmerging player
Description

Gamified, hands-on cybersecurity learning platform with strong appeal to entry-level practitioners. Adjacent to SANS's lower-tier training and Holiday Hack-style gamified offerings.

TypeEmerging player
Description

Hands-on cybersecurity upskilling platform with CTFs, labs, and enterprise team training. Competes with SANS Cyber Ranges and NetWars for practitioner skill development budgets.

TypeDirect peer
Description

Provider of hands-on offensive security training and the OSCP certification. Direct competitor to SANS in practitioner-led technical cybersecurity training and credentialing.

TypeDirect peer
Description

Operator of the Certified Ethical Hacker (CEH) and other cybersecurity certification programs. Competes head-to-head with GIAC for entry-level and mid-tier practitioner credentials.

TypeDirect peer
Description

Issuer of the CISSP and a broad portfolio of cybersecurity certifications. Competes with GIAC for employer-recognized credentials and with SANS-aligned training in management and architecture tracks.

TypeBroad incumbent
Description

Major IT certification body offering Security+ and related credentials. A broadly adopted, lower-priced alternative to GIAC for foundational cybersecurity skills validation.

7INE
TypeDirect peer
Description

Hands-on technical training platform with cybersecurity learning paths and eLearnSecurity certifications. Competes directly with SANS in lab-driven offensive and defensive training at lower price points.

TypeDirect peer
Description

Online cybersecurity training platform targeting individual practitioners and teams. Competes with SANS OnDemand on price-sensitive, self-paced segments of the same buyer base.

TypeBroad incumbent
Description

Large-scale technology skills platform with a security catalog and enterprise subscriptions. Competes with SANS OnDemand and organizational programs on breadth, pricing, and enterprise procurement.

TypeBroad incumbent
Description

Massive online learning marketplace partnering with universities and tech companies to deliver cybersecurity specializations. Competes at the entry-level, low-price tier where SANS is least defended.

Market position
Strengths5 records

Each record includes

Headline, Details, Source

Weaknesses5 records

Each record includes

Headline, Details, Source

Competitive moat7 records

Each record includes

Type, Details

Key risks5 records

Each record includes

Headline, Details, Source

Key highlights7 records

Each record includes

Headline, Details, Source

Customer concentration

Classification, Details

Named customers3 records

Each record includes

Name, Industry, Type, Use case, Source, UUID

Segment4 records

Each record includes

Title, Type, Primary, Description, Pain point addressed, Use case, Source

Ideal customer profile4 records

Each record includes

Profile, Firmographic size, Sales motion, Sales cycle length, Buying structure, Purchase trigger, Buyer persona, Geography, Industry vertical, Primary use case, Description, Pain points, Evidence proof points, Target buyer

Technology focused
Yes
API detail
Has APIbool
No

Docs URL, Description

AI capability11 records

Each record includes

Type, Description, Source

AI maturity
App detail

Has app

Feature3 records

Each record includes

Title, Differentiator, Description, Source

Core technology
Revenue estimate
Valuation estimate
Number of profiles
Profiles10 records

Each record includes

Name, Designation, Designation category, Overview, Profile commentary, Source

Subsidiaries8 records

Each record includes

Name, Acquired on, Relationship type, Type, Business focus

Compliance5 records

Each record includes

Name, Class, Description

Funding overview

Funding stage, Last funding date, Total funding USD

Funding rounds

Each record includes

Round, Amount USD, Date, Pre money valuation, Total investors, Investors, News

Investors

Each record includes

Name, Type, Date of entry, Rounds participated, Website

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

M&A

Each record includes

Name, Acquisition type, Announced date, Completed date, Status, Website, News

Investment

Each record includes

Name, Round, Announced date, Lead investor, Website, News

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

SANS Institute

Cybersecurity Training and Certificationsans.org

SANS Institute, founded in 1989 and headquartered in Bethesda, Maryland, is a private cybersecurity training organization offering 85+ instructor-led courses, GIAC certifications, and hands-on cyber range exercises. It serves 492 Fortune 500 companies, 159 country governments, and 400,000+ practitioners annually.

What SANS Institute does

SANS Institute (legal entity The Escal Institute of Advanced Technologies, Inc.) is a private, founder-controlled cybersecurity training organization founded in 1989 and headquartered in North Bethesda, Maryland. It delivers 85+ instructor-led and self-paced courses covering offensive operations, cyber defense, cloud security, ICS/OT security, digital forensics, incident response, AI security, and cybersecurity leadership, delivered through three modalities — in-person at global events, live online instructor-led sessions, and self-paced on-demand subscriptions. The curriculum is paired with the GIAC (Global Information Assurance Certification) program, which has granted 230,000+ certifications, and is supported by hands-on learning infrastructure including Cyber Ranges, NetWars competitions, and the Internet Storm Center threat-sharing service. The organization holds ISO/IEC 27001:2022, SOC 2 Type 2, PCI DSS, Cyber Essentials, and Cyber Essentials Plus certifications, and operates academic programs through the SANS Technology Institute.

Revenue is generated across four streams: per-seat cybersecurity training course fees (in-person, live online, on-demand subscription), GIAC certification exam fees typically bundled with training, organizational/group purchasing and private training contracts for enterprise and government clients (often multi-year), and end-user security awareness training delivered to enterprise workforces. The go-to-market combines enterprise field sales, event-driven demand generation (SANS Network Security, SANSFIRE, Cloud Security Exchange Summit, DFIR Summit, RSAC presence, regional summits), and community-led funnel development via free resources, free community membership, webinars, podcasts, and the Internet Storm Center. Distribution channels include direct sales, group purchasing, the AWS Marketplace (for the CIS-bundled cloud security offering), and regional public-sector partnerships.

The customer base spans 492 Fortune 500 enterprises (with named customers including Microsoft, Xerox, and NetJets), 159 country governments, and 400,000+ individual practitioners trained annually. The organization operates through wholly-owned subsidiaries in the United Kingdom, Netherlands, Ireland, Australia, Singapore, and Japan, plus active strategic engagements with the UAE Cybersecurity Council, NATO (Locked Shields cyber range), the Maryland Department of Labor (Cyber Workforce Academy), India's DSCI, and the U.S. federal government (Securing the Next 250 campaign for critical infrastructure defenders). Headcount falls in the 501-1,000 employee band, and SANS is positioned as the practitioner-led, hands-on standard in cybersecurity education with no public listing or disclosed parent company.

SANS Institute firmographics

Firmographics
Name
SANS Institute
Legal name
The Escal Institute of Advanced Technologies, Inc.
Website
https://sans.org
Company type
Private
Founded year
1989
Operating status
Operating
Headcount range
501–1,000 employees
Short description
SANS Institute, founded in 1989 and headquartered in Bethesda, Maryland, is a private cybersecurity training organization offering 85+ instructor-led courses, GIAC certifications, and hands-on cyber range exercises. It serves 492 Fortune 500 companies, 159 country governments, and 400,000+ practitioners annually.
Ownership category
akta.pro rank

SANS Institute industry classification

Industry
Product category
Cybersecurity Training and Certification
NAICS
Computer Training (61142), Professional and Management Development Training (611430), Business Schools and Computer and Management Training (6114)
SIC
Services-Educational Services (8200)
akta.pro primary industry
Cybersecurity Technical Skills (Security Engineering, SOC, Pen Testing) (EDABAFAF)
akta.pro secondary industries
Cybersecurity Training & Awareness Programs (BPAEANAF), Cybersecurity (EDAAAPAC)

Keywords

  • Cybersecurity training
  • Professional certifications
  • Cyber ranges
  • Incident response training
  • Cloud security training

Where SANS Institute is headquartered

Location

Headquarters

HQ city
Bethesda
HQ country
United States
HQ region
North America

Offices7 records

Markets served

SANS Institute business model

Business model
GTM type
B2B and B2C
Offering type
Services
Cost components
Personnel, Operations, Marketing or Sales, Technology or R&D, Infrastructure

Revenue model

  1. Cybersecurity Training Courses: Instructor-led and self-paced cybersecurity training courses delivered in multiple formats (in-person, live online, on-demand). Course fees vary by duration, format, and specialization area.
  2. GIAC Certification Exams: Certification examination fees for GIAC credentials, often bundled with training at reduced rates
  3. Organizational Training Programs: Group purchasing and private/custom training programs for enterprise and government clients
  4. Security Awareness Training: End-user and role-based workforce security training for organizations

Pricing tiers

ModelBillingPrice
One time/ perpetual licenseMulti-year contractIn-Person Training
One time/ perpetual licenseMulti-year contractLive Online Training
SubscriptionMonthlyOn-Demand Self-Paced Training
One time/ perpetual licenseMulti-year contractGIAC Certification

Go-to-market motion3 records

Distribution channels6 records

Marketing channels7 records

SANS Institute product offering

Product offering

Core offering

SANS Institute delivers instructor-led and self-paced cybersecurity training through 85+ courses covering offensive operations, defensive security, cloud security, ICS/OT, digital forensics, incident response, AI security, and leadership, available in in-person, live online, and on-demand formats. The training is bundled with industry-recognized GIAC certifications and supported by hands-on Cyber Ranges simulation environments. Complementary offerings include security awareness training, workforce development programs, threat intelligence via the Internet Storm Center, and annual training events/summits.

Product overview

SANS Institute is a cybersecurity training and certification organization offering 85+ instructor-led and self-paced courses delivered in-person, live online, and on-demand formats. The portfolio centers on technical cybersecurity courses (SEC401, SEC536, SEC573, SEC540), specialized tracks (ICS/SCADA, AI Security, Cloud Security), and leadership training (LDR512), all designed to prepare professionals for real-world threats through hands-on labs and expert instruction. GIAC certifications (GICSP, GCSL, GSEC, GPYC, GCSA) validate expertise across domains. Supporting offerings include Cyber Ranges for hands-on practice, the Holiday Hack Challenge for gamified learning, the Cyber Workforce Academy for career development, and the Internet Storm Center for threat intelligence. The organization serves 159 country governments, 492 Fortune 500 companies, and has trained over 400,000 practitioners.

Differentiator

Problem solved

Functional benefit

Brands

  • GIAC Certifications: Global Information Assurance Certification program offering industry-recognized cybersecurity certifications including GPYC, GICSP, GCIP, GRID, GSEC, GSLC, GCSA, and others
  • SANS Technology Institute
  • SANS Cyber Workforce Academy
  • Internet Storm Center
  • Holiday Hack Challenge

Products and services

  • SEC401: Security Essentials Foundational 6-day instructor-led cyber defense course covering network, endpoint, and cloud security essentials, bundled with the GIAC Security Essentials (GSEC) certification, designed for practitioners entering or building a foundation in cybersecurity.
  • SEC536: Adversarial AI - Penetration Testing AI Systems Intermediate-level 2-day instructor-led offensive operations course on penetration testing of AI systems, covering AI-specific attack vectors and defensive strategies against adversarial AI threats, designed for security professionals working in AI-driven environments.
  • SEC573: AI-Powered Security Automation Advanced 6-day instructor-led cyber defense course teaching practitioners to build security automation tools using Python, LLMs, and MCP, including 128 hands-on labs and preparation for the GIAC Python Coder (GPYC) certification.
  • ICS410: ICS/SCADA Security Essentials 6-day instructor-led industrial control systems security essentials course covering essential practices for securing ICS/SCADA environments, with 15 hands-on labs and preparation for the GIAC Global Industrial Cyber Security Professional (GICSP) certification.
  • SEC540: Cloud Native Security and DevSecOps Automation Advanced cloud security course covering DevSecOps automation and cloud-native security architecture, with 19 hands-on labs and preparation for the GIAC Cloud Security Automation (GCSA) certification.
  • LDR512: Security Leadership Essentials for Managers 5-day instructor-led cybersecurity leadership course for managers covering strategic planning, risk management, and team leadership, including 25 hands-on labs and preparation for the GIAC Security Leadership (GSLC) certification.
  • FOR589: Cybercrime Investigations Intermediate 5-day instructor-led digital forensics and incident response course covering cybercrime investigations, including 20 hands-on labs for practitioners working in DFIR.
  • GIAC Certifications Industry-recognized cybersecurity certification examinations covering more than 50 specialized credentials (including GPYC, GICSP, GCSA, GSLC, GSEC, GCIP, GRID), aligned with SANS course curriculum and validating practitioner expertise.
  • SANS Cyber Ranges Hands-on training simulation platform including NetWars competitions and cyber crisis exercises, enabling realistic cybersecurity skill development and team-based incident response scenarios.
  • SANS AI Security Training Comprehensive AI cybersecurity training program covering AI-powered threats, defensive use of AI for security operations, and skills to navigate an AI-driven threat landscape, available across multiple practitioner levels and aligned to AI security focus area.
  • SANS Cyber Workforce Academy Free virtual cybersecurity training program for Maryland residents offering technical training, GIAC certification attempts, and career services. Since 2018, has placed 310+ Marylanders in cybersecurity roles with 87% securing related positions within 12 months.
  • CIS Hardened Images and SANS Cloud Security Training Bundle Bundled offering on AWS Marketplace combining CIS Hardened Images pre-configured benchmark-aligned infrastructure with SANS cloud security training, helping organizations migrate to AWS securely while reducing configuration drift and strengthening team expertise.

Quantifiable outcome

  • 400,000+ cybersecurity practitioners trained
  • +3 more outcomes

Companies that use SANS Institute

Customer profile

Named customers3 records

Segments4 records

Ideal customer profiles4 records

SANS Institute technology and API

Technology

Technology focussed Yes

API detail

Has API
No
API docs
API detail

Core technology

AI maturity

App detail

AI capability11 records

Feature3 records

SANS Institute partnerships and signals

Strategic signal

Partnerships

14 partnerships are on record, tiered core, regional, flagship and national.

  • Center for Internet Security (CIS)coreStrategic or Co-development Partner · 11 June 2026CIS and SANS Institute partnership to bundle CIS Hardened Images with SANS cloud security training, available through AWS Marketplace. The combined offering pairs pre-configured, benchmark-aligned infrastructure with practitioner-led courses to help organizations migrate to AWS securely while reducing configuration drift and strengthening team expertise. Integrates with AWS services including Control Tower, Application Migration Service, and Database Migration Service.
  • U.S. Federal Agencies (Various)coreStrategic or Co-development Partner · 9 June 2026Securing the Next 250 campaign offering specialized ICS security training for U.S. federal agencies, National Guard units, and contractors defending critical infrastructure, coinciding with America's 250th anniversary. Curriculum comprises seven courses with GIAC certifications (GICSP, GCIP, GRID) organized into role-based learning paths.
  • Maryland Department of LaborregionalStrategic or Co-development Partner · 1 June 2026SANS Cyber Workforce Academy funded through Maryland Department of Labor EARN Maryland grant, running through spring 2027. Program aims to support 60+ participants with technical training, GIAC certification attempts, and career services. Since 2018 launch, Academy has placed 310+ Marylanders in cybersecurity roles with 87% securing related positions within 12 months.
  • NATOflagshipStrategic or Co-development Partner · 21 April 2026SANS Institute selected to provide fully operational cyber range for NATO's annual Locked Shields defensive exercise (16th edition) in Tallinn, Estonia. Deploying real ICS and physical equipment with 16 teams defending national-scale power grid under live cyber attack.
  • Cloud Security AlliancecoreStrategic or Co-development Partner · 17 April 2026Joint industry report 'The AI Vulnerability Storm: Building a Mythos-Ready Security Program' developed by SANS Institute, Cloud Security Alliance, [un]prompted, and OWASP GenAI with contributions from 250+ CISOs. Report warns that AI models like Anthropic's Mythos will accelerate vulnerability discovery and exploitation.
  • RSAC 2026coreGTM or Marketing Partner · 15 April 2026SANS Institute launched Find Evil! hackathon at RSAC 2026 with 1,100+ participants competing to make Protocol SIFT production-ready by June 15, 2026. $22,000 prize competition prompted by AI models discovering thousands of zero-day vulnerabilities.
  • siberXcoreStrategic or Co-development Partner · 17 February 2026SANS and siberX partnership introducing NOW // AI simulation program to enhance AI risk management, security governance, and compliance. Program includes operational pillars: Protect AI, Utilize AI, and Govern AI.
  • Women in CyberSecurity (WiCyS)regionalStrategic or Co-development Partner · 17 February 2026WiCyS launched AI Security Accelerator Program in Maryland supporting women transitioning into AI cybersecurity roles with training, certification, mentorship, and industry engagement, funded by Maryland's EARN Maryland Grant Program.
  • UAE Cybersecurity CouncilnationalStrategic or Co-development Partner · 18 December 2025Strategic partnership aimed at enhancing UAE's cybersecurity capabilities and workforce readiness. Includes initiatives such as training programs, workshops, and information sharing to improve national cyber defense and resilience.
  • Data Security Council of India (DSCI)nationalStrategic or Co-development Partner · 4 December 2025SANS Institute and DSCI launched India's first comprehensive study on cybersecurity skilling landscape to identify talent gaps and improve industry alignment. Study aims to evaluate training effectiveness and inform future workforce development.
  • OPSWATcoreStrategic or Co-development Partner · 20 November 2025OPSWAT-sponsored SANS State of ICS/OT Cybersecurity 2025 report finding that 21.5% of organizations experienced cyber incidents affecting industrial control systems, with 37.9% from ransomware and 40.3% causing operational downtime.
  • Dubai EntitiesregionalStrategic or Co-development Partner · 4 November 2025SANS Gulf Region 2025 cybersecurity training event in Dubai from November 8-27, 2025, with 14 specialized courses addressing Middle East's cybersecurity skills shortage and supporting UAE's digital transformation ambitions.
  • Amazon Web Services (AWS)coreTechnology or Integration · 3 November 2025AWS and SANS Institute released joint whitepaper 'AI for Security and Security for AI: Navigating Opportunities and Challenges' addressing securing generative AI applications and using AI to strengthen cloud security posture.
  • MISA OntarioregionalStrategic or Co-development Partner · 27 October 2025siberX partnered with MISA Ontario and SANS Institute to deliver cybersecurity training workshop and escape room experience at 2025 MISA Ontario InfoSec Conference. Event focused on practical, municipal-specific training including hands-on workshops and gamified simulations.

Scale indicators6 records

Recent moves8 records

Expansion highlights6 records

SANS Institute competitors and assessment

Company assessment

Emerging players

  • TryHackMe: Gamified, hands-on cybersecurity learning platform with strong appeal to entry-level practitioners. Adjacent to SANS's lower-tier training and Holiday Hack-style gamified offerings.
  • Hack The Box: Hands-on cybersecurity upskilling platform with CTFs, labs, and enterprise team training. Competes with SANS Cyber Ranges and NetWars for practitioner skill development budgets.

Direct peers

  • Offensive Security: Provider of hands-on offensive security training and the OSCP certification. Direct competitor to SANS in practitioner-led technical cybersecurity training and credentialing.
  • EC-Council: Operator of the Certified Ethical Hacker (CEH) and other cybersecurity certification programs. Competes head-to-head with GIAC for entry-level and mid-tier practitioner credentials.
  • (ISC)²: Issuer of the CISSP and a broad portfolio of cybersecurity certifications. Competes with GIAC for employer-recognized credentials and with SANS-aligned training in management and architecture tracks.
  • INE: Hands-on technical training platform with cybersecurity learning paths and eLearnSecurity certifications. Competes directly with SANS in lab-driven offensive and defensive training at lower price points.
  • Cybrary: Online cybersecurity training platform targeting individual practitioners and teams. Competes with SANS OnDemand on price-sensitive, self-paced segments of the same buyer base.

Broad incumbents

  • CompTIA: Major IT certification body offering Security+ and related credentials. A broadly adopted, lower-priced alternative to GIAC for foundational cybersecurity skills validation.
  • Pluralsight: Large-scale technology skills platform with a security catalog and enterprise subscriptions. Competes with SANS OnDemand and organizational programs on breadth, pricing, and enterprise procurement.
  • Coursera: Massive online learning marketplace partnering with universities and tech companies to deliver cybersecurity specializations. Competes at the entry-level, low-price tier where SANS is least defended.

Market position

Strengths5 records

Weaknesses5 records

Competitive moat7 records

Key risks5 records

Key highlights7 records

Customer concentration

SANS Institute social profiles

Digital presence

SANS Institute compliance and trust

Trust signal

Compliance5 records

SANS Institute financial estimates

Financial estimate

Revenue estimate

Valuation estimate

SANS Institute leadership team

Management profile

Number of profiles

Profiles10 records

SANS Institute subsidiaries and ownership

Company hierarchy

Subsidiaries8 records

SANS Institute funding detail

Funding detail

Funding overview

Funding rounds

Investors

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

SANS Institute M&A and investment

M&A and investment

M&A

Investments

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Frequently asked questions about SANS Institute

What does SANS Institute do?

SANS Institute delivers instructor-led and self-paced cybersecurity training through 85+ courses covering offensive operations, defensive security, cloud security, ICS/OT, digital forensics, incident response, AI security, and leadership, available in in-person, live online, and on-demand formats. The training is bundled with industry-recognized GIAC certifications and supported by hands-on Cyber Ranges simulation environments. Complementary offerings include security awareness training, workforce development programs, threat intelligence via the Internet Storm Center, and annual training events/summits.

Is SANS Institute a public or private company?

SANS Institute is a private company. It is classified as founder individual operated bootstrapped and is currently operating.

When was SANS Institute founded?

SANS Institute was founded in 1989. It employs 501 to 1,000 people.

Where is SANS Institute based?

SANS Institute is headquartered in Bethesda, United States, in the North America region.

How does SANS Institute make money?

Four revenue lines are on record. Cybersecurity Training Courses are the primary driver. The others are GIAC Certification Exams, organizational Training Programs and security Awareness Training.

Who are SANS Institute's main competitors?

Emerging players on record are TryHackMe and Hack The Box. Direct peers are Offensive Security, EC-Council, (ISC)², INE and Cybrary. Broad incumbents are CompTIA, Pluralsight and Coursera.

Does SANS Institute have an API?

No public API is recorded for SANS Institute.

What industry is SANS Institute in?

SANS Institute's product category is Cybersecurity Training and Certification. Its primary akta.pro industry code is EDABAFAF, Cybersecurity Technical Skills (Security Engineering, SOC, Pen Testing), with a secondary code of BPAEANAF, Cybersecurity Training & Awareness Programs. Its NAICS code is 61142 and its SIC code is 8200.

Unlock the full company data

50 free credits on sign-up, no credit card required.

Contact sales
Live signals
IndustrialcyberCyberSafe and SANS award AI security fellowships to women cybersecurity professionals across AfricaCyberSafe Foundation and SANS Institute launched an AI security fellowship for women in cybersecurity across Africa, awarding ten fellowships. The program covers a four-course SANS curriculum and two GIAC certifications, with 63% of sub-Saharan African organizations reporting a cybersecurity skills shortage. The training runs from October 21, 2026 through July 30, 2027.EIN PresswireSkills Gaps Now Outrank Staffing Shortages in Cybersecurity Hiring, New Workforce Research FindsA 2026 SANS | GIAC report found skills gaps outrank staffing shortages by 20 points in cybersecurity hiring, with 60% of leaders citing skills gaps versus 40% staffing shortages. Canadian job postings hit a seven-quarter high, with protection and defence roles dominating. Employers validate skills through certifications and assessments.IndustrialcyberSANS launches new Dynamic Incident Response framework to help security teams adapt as attacks evolveSANS Institute published Dynamic Incident Response, a 720-page book by Joshua Wright, the first major rebuild of its incident response framework in two decades. The free book introduces an adaptive, iterative model to replace the traditional prepare-identify-contain-eradicate-recover process, with chapters on cloud, operational technology, and ransomware. It is available in multiple digital formats and print-on-demand.GulfNewsBuilding cyber resilience through AI with SANS InstituteSANS Institute is using GISEC 2026 to help cybersecurity professionals develop practical skills for emerging threats. The UAE faces AI-powered phishing, deepfakes, state-sponsored attacks, ransomware, and DDoS campaigns in 2026, with critical infrastructure and financial services targeted. Resilience depends on building expertise across AI, cloud, zero-trust, and ICS/OT security.Security BoulevardDaily OT Security News: September 11, 2026CISA released four advisories on September 10 covering NextGen Mirth Connect, Orthanc DICOM Server, AVEVA Pipeline Integrity Monitor, and an updated advisory for ST Engineering iDirect iQ-Series terminals. SANS data shows 74.4% of reported incidents were non-ransomware, with remote services and internet-accessible devices as top initial access vectors. Fortinet announced extended IoT and CPS visibility through passive and active device discovery.IndustrialcyberSANS Institute signs German government cybersecurity training deal to strengthen national cyber resilienceSANS Institute and Germany's Bundeswehr signed a multi-year framework agreement to train and GIAC-certify thousands of cybersecurity professionals across federal security agencies. The program covers offensive security, incident response, and cloud security, aiming to strengthen Germany's cyber resilience. The partnership builds on collaboration since 2022.LogisticsGulfSANS Institute to bring AI and cybersecurity expertise to GISEC Global 2026SANS Institute will deliver certified training and three technical workshops on AI security, ICS/OT, and cybersecurity leadership at GISEC Global 2026 in Dubai. The programs support UAE cyber readiness under its National Cybersecurity Strategy, backed by a partnership with the UAE Cybersecurity Council formalized via an MoU in December 2025.YahooAI Is the Second-Biggest Human Risk in the Workplace, SANS Institute's 2026 Security Awareness & Culture Report FindsThe SANS Institute's 2026 Security Awareness & Culture Report, based on more than 1,700 practitioners across six continents, finds AI now ranks second among human risks, behind only social engineering. The report adds a dedicated AI risk section covering unauthorized generative AI use, "vibe coding" and unreviewed AI agents, and notes 75% of teams use AI for program management. It also introduces an Interactive Benchmarking Tool.The Hacker NewsFrontier AI: Vulnerability Management's Systemic RevolutionA contributed piece by SANS instructor Kevin Garvey argues that Frontier AI models such as Anthropic's Mythos are forcing vulnerability management programs to overhaul their risk prioritization, exposure management, and patching processes. The author recommends moving beyond CVSS, EPSS and KEV scoring, adding exposure management, and adopting automated, ring-based patching. He promotes two upcoming LDR516 courses at SANS DC Metro in September 2026 and Dallas in December 2026.IndustrialcyberSANS Institute joins OTCC to strengthen critical infrastructure cybersecurity workforce developmentThe SANS Institute has joined the Operational Technology Cybersecurity Coalition (OTCC) to enhance cybersecurity workforce development for critical infrastructure. This membership integrates SANS's specialized training and certification programs into the coalition’s efforts to address persistent staffing challenges in protecting industrial control systems. The move emphasizes a collaborative approach between public and private entities to build defender capacity.