We've got real world answers for your cyber problems
IANS is your closed community of Faculty practitioners and peers.
No preaching theory or vendor pay-to-play here. Our Faculty help you implement your priorities at speed. You'll receive unbiased how-to guidance from people that have seen it, done that.

IANS Services

Want to see how deep we go?
Download - Infosec Tools & Guides

End-User Decision Support is our flagship offering delivered through an annual subscription service designed for CISOs and their teams. IANS connects you with independent experts and practitioners who have ‘been there, seen it, and done it,’ enabling you to accelerate your capabilities and make informed decisions. 

Ask-An-Expert

s_back_expert_icon

We connect you with the right IANS Faculty member who can answer your questions in a one-one-one call or written report. They'll share a point of view on a product or technology, provide recommendations for action, and help you come to a decision.

Learn More

Content Aggregator

s_back_expert_icon

Stop searching for content. We've curated it for you. We vet the most relevant third-party InfoSec content, then format it in PowerPoint to make it easy to repurpose.

Learn More

Executive Communications

s_back_expert_icon

How do you speak intelligently with executives and board members who aren't fluent in security lingo? Covering InfoSec topics from key news publications, IANS uses business language to help you brief the C-suite and key internal stakeholders.

Learn More

Tools & Templates

s_back_expert_icon

Get started quickly on a variety of common information security initiatives. Our tools, toolkits, templates, checklists, matrices, and maps provide the practical support you need to build your action plan.

Learn More

Insights Portal

s_back_expert_icon

IANS Decision Support clients have access to the Insights Portal, a resource with content organized by topic and product type. The portal includes Ask-An-Expert Writeups, Faculty Reports, Content Aggregator slides, Executive Communications materials, Podcasts, Tools and Templates, Topic Guides and Webinar Replays.

Learn More

We work with you to shape engagements and provision them with the right IANS Faculty experts. Your project will never be staffed with junior level consultants. Our expertise is built from hands-on experience. We staff your project with doers who recommend actions, and then help you take them.

Active Defense

s_back_expert_icon

Test controls while improving detection and response with simulated attacker, purple team, and threat hunting engagements.

Learn More

Penetration Testing

s_back_expert_icon

Gain knowledge of what an attacker can do by taking advantage of current vulnerabilities through network, web, and mobile application testing.

Learn More

Security Assessments

s_back_expert_icon

Understand what’s working well and what needs attention with comprehensive review of technical controls in place, governance, and process along with a roadmap of recommended action.

Learn More

Training & Keynotes

s_back_expert_icon

Increase skills and understanding through tailored, hands-on training of your IT and security staff.

Learn More

Our events feature IANS Faculty members who offer a breadth of in-the-weeds advice and high-level guidance for the entire security team. Designed for you to engage with like-minded security professionals in a supportive environment, you’ll learn from a variety of industry approaches and use cases.

CISO Roundtables

s_back_expert_icon

Get out of the trenches and prepare for interactions with the C-suite at these executive-only one-day sessions.

All CISO Roundtables

Forums

s_back_expert_icon

Bring your security team, network with like-minded security practitioners, and join keynote presentations and IANS Faculty breakouts.

All Forums

Symposiums

s_back_expert_icon

Immerse yourself on a specific technical or operational topic. Attend our half-day comprehensive deep dives.

All Symposiums

Webinars

s_back_expert_icon

Don't miss a beat. Tune in to monthly topical sessions led by IANS Faculty members.

All Webinars
Cloud Security Maturity

Check Out Our Cloud Security Maturity Model Diagnostic

IANS and Securosis have developed the Cloud Security Maturity Model (CSMM) to help organizations understand what their cloud security journey looks like and consciously determine how mature they want to be for each category. We’ve partnered with Cloud Security Alliance to integrate the CSMM into their cloud security research program as well as their certification and training initiatives.

Learn More About the CSMM Diagnostic Download - Cloud Security Maturity Benchmark Report
 

How you benefit

We help CISOs and their teams make well-informed decisions. Our insights come from IANS Faculty practitioners, who are living your challenges and deliver deep-domain, actionable advice on a wide range of security topics.

play_icon
Paul Hypki

Children's Hospital and Clinics of Minnesota

We're wired into the security community.

With close to 100 end-user security events annually, we are unmatched in the level of peer-to-peer interaction we offer our clients. We provide a safe environment to network, share experiences and discuss challenges.

Learn More

Paul Hypki

Children's Hospital and Clinics of Minnesota

IT governance management professional with strong business acumen, employing a pragmatic and consultative approach. Risk and controls experience rests on a foundation of solid experience within corporate IT. Leveraged collaboration skills to involve all silos of the company, including legal, CFO, customer service, business operations and information technology, to promote management awareness and facilitate remediation efforts. Motivated by the challenge of identifying opportunities to significantly improve and streamline business operations, while working effectively with the business stakeholders responsible for implementing the process improvement or controls 

play_icon
John Strand

IANS Faculty

Our Faculty are in the trenches.

IANS Faculty members are expert information security practitioners. Their insights are based on real-world experiences. They understand the key issues you face and deliver actionable recommendations, research, and step-by-step guidance.

Learn More

John Strand

IANS Faculty

John is the Owner of Black Hills Information Security (BHIS) where he leads the Hunt Teaming, Command & Control (C2)/Data Exfiltration and Pivot testing development. He is also a SANS Institute Senior Instructor. In these roles, John has both consulted and taught hundreds of organizations in the areas of security, regulatory compliance, and penetration testing.

play_icon
Janet Oren

Legg Mason

We focus exclusively on security.

Security is all we do, and it always has been. What matters to the CISO and team matters to us. We specialize in providing in-depth knowledge and practical insights you can use both with your team and when interacting with the C-suite.

Learn More

Janet Oren

Legg Mason

Janet Oren leads global cybersecurity initiatives at Legg Mason Global Asset Management. Her career path includes 32 years at the National Security Agency (NSA) where she was responsible for the protection of classified information and other cybersecurity standards. She on large weapon systems; wrote national encryption policy; and was the senior cybersecurity representative in the NSA’s 24-hour watch center. In between NSA and Legg Mason, she was a managing director at PricewaterhouseCoopers.

Our Faculty

This group of over 100 hands-on practitioners understands the key issues you face and delivers actionable recommendations, research, and step-by-step guidance on achieving fast and successful results.

Summer Fowler

IANS Faculty

Summer is a three-time CISO in the autonomous vehicle industry currently at Torc Robotics, which specializes in AI software for long-haul trucking. She is also a faculty member at Carnegie Mellon University where she teaches a graduate course in cybersecurity policy and multiple courses on cybersecurity metrics and product cybersecurity for executive education programs. In addition, Summer serves on the board of directors for Brentwood Bank, a regional bank in Pittsburgh, PA. She is also an active board member for the Forte Group, an advocacy and education non-profit focused on amplifying women in technology, cybersecurity, and privacy. Summer is often requested to speak at conferences and events, and she has provided expert testimony on cybersecurity risk in the US Congress.

Prior to her role at Torc Robotics, Summer worked at Motional and Argo AI, both AI companies focused on robo-taxi technology. She also led cybersecurity risk and resilience at Carnegie Mellon University's CERT program and Johns Hopkins University's Applied Physics Lab. Summer started her career as a software engineer at Northrop Grumman Corporation after receiving her MS and BS in Computer Science from the University of Pittsburgh.

Achievements & Noteworthy Contributions

  • Summer was named as one of the Top 25 Women in Cyber Security by The Software Report (2021)

Hobbies & Fun Facts

Traveling with family, Managing her son’s hockey team (her real full-time job), Running and Peloton workouts

Wolfgang Goerlich

IANS Faculty

Wolf is an Advisory CISO of Duo Security, the leading provider of unified access security and multi-factor authentication delivered through the cloud. He has held senior management roles in IT and IT security in the financial services and healthcare verticals. In addition, Wolf has held senior leadership roles in consulting firms specializing in identity and access management, governance risk and compliance, and security programs. Wolf advises clients primarily in risk management, incident response, business continuity, and secure development.

Achievements & Noteworthy Contributions

  • Former organizer of annual BSides and Converge conferences in Detroit
  • Former Senior VP of Strategic Security Programs at CBI, an information security solutions firm
  • Former VP of Consulting Services at VioPoint Inc., an information security consulting firm

Certifications & Credentials

  • CISSP - (ISC)2
  • Certified Information Systems Auditor (CISA) - ISACA

Shamla Naidoo

IANS Faculty

Shamla is the Head of Cloud Strategy and Innovation at Netskope and a former Managing Partner and Global CISO at IBM. She is a Board Director at both QBE and Stonebridge Acquisition Capital and a Board Member at ReferencePoint. Shamla’s experience spans 38+ years in a variety of sectors and 6 continents, making her an expert in cross-cultural collaboration and working across industries. She is recognized as a leader in applying security to enable priorities of the business. Her background also includes authoring and teaching several courses for the University of Illinois Chicago School of Law in technology, security, and privacy law. Shamla coaches professionals on leadership, board communication and how to align security with strategic business initiatives. 

Achievements & Noteworthy Contributions

  • Presenter at WCD, NACD, American Bar Association, several federal agencies, and many conferences
  • Interviewed by Forbes, New York Times, and Wall Street Journal
  • Member of the Security 50, a community of World 50, NACD (National Association of Corporate Directors), and WCD (Women's Corporate Directors)

Certifications & Credentials

  • JD -- University of Illinois Chicago School of Law
  • Bachelor’s degree, Information Systems and Economics – University of South Africa 
  • Diploma in MIS from South African Institute of Management

Jake Williams

IANS Faculty

Jake Williams (aka MalwareJake) is a seasoned security researcher with decades of experience in the technology and security. Jake is a former startup founder, former senior SANS instructor and course author, and an intelligence community and military veteran. He loves forensics, incident response, cyber threat intelligence, and offensive methodologies. Today, Jake is an IANS faculty member, an independent security consultant, and is performing security-focused research to benefit the broader community. He has had the honor of twice winning the DoD Cyber Crime Center (DC3) annual digital forensics challenge. You may also know Jake from one of his many conference talks, webcasts, media appearances, or his postings about cybersecurity.

Achievements & Noteworthy Contributions

  • Two-Time Winner of the Annual DC3 Forensics Challenge
  • Speaker at information security conferences such as Black Hat, DEF CON, ShmooCon, RSA, and DC3
  • Designated a Master Computer Network Exploitation (CNE) Operator by the NSA
  • Former Vulnerability Analyst at US Department of Defense
  • Former Senior Systems Engineer at Dell Services

Certifications & Credentials

  • MSIA, Information Assurance –Capitol College
  • GSE, GSNA, GCFE, GREM, GCWN, GCIA, GCIH, GPEN, GCFA, GXPN, GSEC –GIAC

George Gerchow

IANS Faculty

George is currently Head of Trust at MongDB and was formerly Sumo Logic's Chief Security Officer & SVP of IT. George Gerchow brings over 20 years of information technology and systems management expertise to the application of IT processes and disciplines. His background includes the security, compliance, and cloud computing disciplines. Mr. Gerchow has years of practical experience in building agile security, compliance and, IT teams in rapid development organizations. These insights make him a highly regarded speaker, and invited panelist on topics including, cloud secure architecture design, compliance and operational security including a TedX talk.

George has been on the bleeding edge of public cloud security, privacy and modernizing IT systems since being a co-founder of the VMware Center for Policy & Compliance. He is a Faculty Member for IANS  - Institute of Applied Network Security  and sits on several industry advisory boards. Mr. Gerchow is also a known philanthropist and CEO of a nonprofit corporation, XFoundation.

Achievements & Noteworthy Contributions

  • Co-Founder of VMware Center for Policy and Compliance
  • Co-Author of Center for Internet Security QuickStart Cloud Infrastructure Benchmark v1.0.0
  • Author of the MIS|TI Fundamentals in Cloud Security course
  • Speaker at information security conferences such as RSA, AWS reInvent, Cloud Expo Silicon Valley, SANS Institute Cloud Security Summit
  • Former Global Director of Security Evangelism and Product Strategy and Director of VMware Policy and Compliance at VMware
  • Former Cloud Business Director at EMC

Hobbies & Fun Facts

George’s first language is Spanish. He is an avid snowboarder, golfer, and yogi who is always looking for the best sandwich and IPA in any city that he visits.

 

Want to know more? Let us know how we can help you.

* Required Fields