All vendors

Vendor lineage

SANS Institute - the cooperative that became the security profession's school

Founded in 1989 by a former naval ship designer and his wife as a cooperative for exchanging technical information; now the largest security training organisation there is, with its own certification body, its own accredited college, and its own 2020 breach.

The SANS Institute is an American cybersecurity training and research organisation founded in 1989 by Alan Paller, operating the GIAC certification body and the SANS Technology Institute, the first accredited college devoted to cybersecurity.

Alan Paller had used computers to design ships for the Navy, co-founded a timesharing company in Hawaii and run a computer-graphics consultancy before, in 1989, he and his wife started a cooperative through which information-security people could exchange technical information and get training. The legal name is still the Escal Institute of Advanced Technologies; everyone calls it SANS. Paller's conviction, which the people who worked with him say never wavered, was that security could only be improved by raising the skill level of the people doing it - not by buying products - and he built the institution around that one idea for thirty-two years, until he stepped back in April 2021 and died that November at seventy-six.

Three things grew from the cooperative. The courses, taught by practitioners who still do the work, in week-long intensives that became the profession's common vocabulary - by 2021 some forty thousand people a year and by the organisation's own later count far more. GIAC, the affiliated certification body, whose thirty-five-odd hands-on examinations are the credentials the field's employers actually recognise, and which has issued over 230,000 of them. And the SANS Technology Institute, founded in 2005 - the first regionally accredited college devoted to cybersecurity, which means a security master's degree exists because a training company decided one should.

The record also holds the two criticisms that follow it everywhere, and one incident. The courses are expensive, and the debate about whether an individual practitioner recovers the cost is permanent. Some of the material - active defence, hacking back - sits in a legal grey area, and the institute teaches it anyway. And in 2020 the institute confirmed a breach of its own that exposed the personal information of thousands of the people it trains. The Trend Micro entry records a security vendor caught by its own insider; here the security school was caught by the thing it teaches people to catch. Neither is a reason to think less of the teaching. Both are the reason the teaching is needed.

For a networking and security instructor the institute is the standard against which the vendor-authorised model is measured. A vendor course teaches one product; a SANS course teaches a discipline that outlasts every product in it. The two are not rivals - a practitioner needs both - but they answer different questions, and the difference is the one that the encyclopedia's training-centre entries keep circling: whether the thing being certified is a tool or a person.

Sources