Jonathan Risto
Principal InstructorTechnical Director, Cyber Posture Management Program at Government of Canada
Specialities
Cybersecurity Leadership
Experience SANS training through course previews.
Learn MoreLet us help.
Contact usConnect, learn, and share with other cybersecurity professionals
Engage, challenge, and network with fellow CISOs in this exclusive community of security leaders
Become a member for instant access to our free resources.
Sign UpMission-focused cybersecurity training for government, defense, and education
Explore industry-specific programming and customized training solutions
Sponsor a SANS event or research paper
We're here to help.
Contact UsCybersecurity Leadership
With a career spanning over 20 years that has included working in network design, IP telephony, service development, security and project management, Jonathan has a deep technical background that provides a wealth of information he draws upon when teaching. Currently, Jonathan works for the Canadian Government conducting cyber security research in the areas of vulnerability management and automated remediation. He is also an independent security consultant. Jonathan is a co-author and instructor for SANS LDR516: Building and Leading Vulnerability Management Programs.
Jonathan is an outstanding instructor. He always exceeded expectations by going above & beyond to ensure students received the best experience.
Jonathan was great. He’s fun and knew his stuff. Plus, he’s easy to listen to.
Jonathan was amazing! He has to be exhausted from being upbeat and carrying us all week. A+.
Here are upcoming opportunities to train with this expert instructor.
Explore content featuring this instructor’s insights and expertise.
In this CloudSecNext 2022 session of Cyber42 Vulnerability Management you will play to win! In this 90-minute game day you will play individually to improve the state of a fictional organization and more effectively handle the vulnerability management.
Do you ever run into problems with your vulnerability management program that you wished you had at your fingertips just one more little piece of information? To help conduct some prioritization, or to know who the business owner is, or to inform people this was an end of life system… All valuable and great to have readily available. But alas, we often are missing information, or it is not easy to access.
So you have a vulnerability management program. Great. Excellent. But are you able to let the management team know if it is being effective or not?
Use the newest tool to self-assess your organization's vulnerability management maturity, built on the renowned SANS Vulnerability Management Maturity Model (VMMM).
They promised it would be a breeze! Serverless functions, containers, and infrastructure as code were supposed to simplify vulnerability management. But hold onto your seats, because we'll dive into why these technologies demanding a whole new set of skills, tools, and a mindset shift for anyone in the game. Are you ready to shake up your vulnerability management game? Join us as we discover the must-have skills and attitude adjustments for staying on top.
In this webcast, we will quickly review the incident affecting Achilles Systems, including their basic “block and tackle” approach to vulnerability management.
In today’s dynamic cybersecurity landscape, traditional vulnerability management often falls short due to the continual changes, modifications, and adoption of new technologies. Continuous Threat Exposure Management (CTEM) offers a transformative approach, enabling organizations to anticipate, prioritize, and address vulnerabilities more effectively.
Vulnerability management is no longer just about finding CVEs and deploying patches—it's about closing the gap between what you know and what you don’t see coming.
Not all vulnerabilities are created equal—and fixing everything just isn’t realistic. This session shows how to align vulnerability prioritization with real-world risk.
You’ve patched systems and prioritized risk—but if your stakeholders don’t understand what you’re doing or why it matters, progress stalls.
Review relevant educational resources made with contribution from this instructor.