
Share
A fresh batch of SANS events for 2026 spans Las Vegas to Santiago, but the real signal is how much real estate AI security now occupies on the schedule, from dedicated bootcamps to a standalone summit.
SANS Institute has published its 2026 lineup of live and in-person training events, and if you've been putting off refreshing your incident response or vulnerability assessment skills, there's now a pretty wide window to do it. The catalog spans 29 Americas-region events (plus 52 in Europe/Middle East and 18 in Asia Pacific), split between 28 Live Online sessions and 24 in-person ones. That's a meaningful amount of choice for practitioners trying to fit certification-track training around actual work schedules.
For anyone unfamiliar with how SANS operates: it's one of the more established names in hands-on cybersecurity education, running week-long "events" that bundle multiple courses under one roof (or one Zoom room). Instructors are typically working practitioners rather than full-time academics, and the courses often map directly to GIAC certifications, which matters if your employer or contract requires specific credentials for compliance or clearance reasons.
The headline events for 2026 include the usual geographic spread:
There's also a Spanish-language track, with events in Mexico City (Aug 31 - Sep 5, 3 courses) and an ICS-focused session in Santiago, Chile (Sep 28 - Oct 3, 1 course), reflecting SANS's push to serve Latin American security teams directly rather than relying purely on translated English-language material.
The part worth flagging for anyone tracking industry trends: AI security isn't a footnote anymore, it's getting dedicated real estate on the calendar.
There's a standalone "AI Security Training August 2026" event (Aug 31 - Sep 5, virtual, 6 courses), and separately, an "AI Cybersecurity Summit" in Arlington (Nov 2-3) explicitly pitched at "security leaders and practitioners" who need to understand AI-powered threats and figure out how to adopt AI tooling without blowing a hole in their attack surface.

That's a notable shift in framing. A couple years ago, most vendor training around AI and security was either "how to use an LLM copilot for SOC work" or vague hand-waving about "AI threats." What SANS is doing here is treating AI security as its own discipline with its own curriculum track, sitting alongside more traditional offerings like network security, forensics, and ICS (industrial control systems) training. If you're a hiring manager or team lead trying to figure out where to send junior analysts for AI-specific upskilling, this is a concrete signal that the market now expects it as a distinct skill line, not just a bolt-on to existing threat detection training.
It also tracks with what's been happening on the threat side. Security teams are increasingly dealing with two separate problems: attackers using AI to scale phishing, reconnaissance, and exploit generation, and defenders needing to secure the AI systems and pipelines their own organizations are standing up. A single course rarely covers both well, which is probably why SANS is running this as a multi-course block rather than a one-off session.
The DFIR Summit deserves a mention too, since it's explicitly framed around "new tools, research, and real-world cases," which suggests the forensics curriculum is getting refreshed alongside everything else rather than running on autopilot. For teams doing incident response against increasingly automated attack chains, that kind of curriculum refresh matters more than it used to. Attack tooling moves fast, and training that lags six months behind current tradecraft isn't worth much.
A few practical notes if you're weighing whether to book time and budget for one of these:
None of this is revolutionary in isolation, training calendars get refreshed every year, and conferences add new city stops or drop old ones. But the emphasis shift toward AI-specific security curriculum is worth tracking as a leading indicator. When a training provider with SANS's reach starts treating a topic as its own discipline, complete with dedicated events and multi-course tracks, that's usually a sign the underlying skills gap has become too large to patch with a single afternoon webinar. If you're budgeting professional development spend for 2026, it's worth checking whether your team's gaps line up with where this curriculum is actually growing.
Tags
Original Sources
About the author
Kai built ML infrastructure at a Bay Area startup before developing an obsession with transformer architectures and inference optimisation that eventually pulled him out of product work entirely. A stint at a compute research lab sharpened his instinct for what actually matters in a model release versus what is marketing. He writes from the inside — from the perspective of someone who has debugged the systems he is describing at three in the morning. He is allergic to hype and instinctively drawn to the unglamorous plumbing questions that everyone else skips over.
More from The Engineer →This Week's Edition
8 September 2026
41 articles
Related Articles
Related Articles
More Stories
© 2026 Cedar & Bloom. All rights reserved.