SEC504: Hacker Tools, Techniques, and Incident Handling

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usConnect, learn, and share with other cybersecurity professionals
Engage, challenge, and network with fellow CISOs in this exclusive community of security leaders
Become a member for instant access to our free resources.
Sign UpMission-focused cybersecurity training for government, defense, and education
Explore industry-specific programming and customized training solutions
Sponsor a SANS event or research paper
We're here to help.
Contact UsGreg Notch is the Chief Information Security Officer (CISO) at Expel. As CISO (pronunciations may vary), he is responsible for ensuring the security of our systems, as well as keeping customers educated on the threat landscape and latest techniques for mitigating risk in their environments.
He’s been doing the security and tech thing for over 20 years — helping companies large and small through all three dot-com booms to build high-performing engineering teams, and improve their technology, process, and security.
Before Expel, Greg spent 15 years as the CISO and Senior Vice President of Technology at the National Hockey League (NHL), where he led their information security program. He also led the league’s technology strategy, digital transformation, and cloud initiatives.
Prior to the NHL, Greg worked on infrastructure, security, and software systems for Apple, Yahoo Search, eMusic, and several other NYC-based tech startups.
Explore content featuring this instructor’s insights and expertise.
There are plenty – perhaps too many – frameworks that security leaders and teams can use to benchmark their organization along a journey of cybersecurity maturity. However, even the most popular frameworks don’t use the same metrics and can cause confusion amongst security teams
Just how effective or mature is your security program? Given the multitude of assessment, rating, and cybersecurity frameworks, it can be challenging to determine security operations readiness and resilience through a single measurement or framework. Is effectiveness based on defending against an attack or the ability to mitigate attacks in the first place? Should compliance drive our security strategy, or should our security strategy enable compliance?
Just how effective or mature is your security program? Given the multitude of assessment, rating, and cybersecurity frameworks, it can be challenging to determine security operations readiness and resilience through a single measurement or framework. Is effectiveness based on defending against an attack or the ability to mitigate attacks in the first place? Should compliance drive our security strategy, or should our security strategy enable compliance?All these questions, and more, can lead to a confusing landscape when defining effectiveness and maturity. In this webcast on December 20, 2023, at 1:00am PT, Dave Shackleford from SANS and Greg Notch, CISO of Expel, discuss the frameworks, tools, and other techniques that organizations use to measure and assess their security programs.Register now for this webcast to be notified as soon as the accompanying white paper, written by Dave Shackleford, is available.