CyberPeople

SANS Network Security 2026: Six Days of Hands-On Cybersecurity Training in Las Vegas

SANS Network Security 2026: Six Days of Hands-On Cybersecurity Training in Las Vegas
21 Sep 2026
Upcoming event
Mon, 21 Sep 2026, 08:30 – Sat, 26 Sep 2026, 17:00
Caesars Palace, 3570 Las Vegas Blvd South, Las Vegas, NV 89109, USA & Virtual (PT)
Register

SANS Network Security 2026 runs September 21-26 at Caesars Palace Las Vegas and virtual. 31 courses, Core & DFIR NetWars, and an AI-focused keynote.

What is SANS Network Security 2026?

SANS Network Security 2026 is a six-day cybersecurity training event organized by the SANS Institute, running September 21-26, 2026 at Caesars Palace in Las Vegas, with a live virtual option. It is one of the largest course lineups of the year, covering offensive operations, digital forensics, cloud security, and AI security — with two NetWars tournaments included for in-person attendees.

Cybersecurity concept

Dates, location and format

The event runs Monday, September 21 through Saturday, September 26, 2026 (Pacific Time). It is a hybrid event: join in person at Caesars Palace (3570 Las Vegas Blvd South, Las Vegas, NV 89109) or attend virtually. The venue sits across Flamingo Road from the Bellagio fountains, with the rest of the Strip within walking distance.

Topics and course tracks

With 31 courses running the same week, the program spans nearly every security specialty a team might need:

  • Advanced incident response, threat hunting, and digital forensics
  • Offensive operations and penetration testing (including wireless)
  • Detection engineering and SIEM analytics
  • Cloud-native security, DevSecOps automation, and cloud architecture
  • AI, machine learning, and emerging security innovations
  • ICS/SCADA security and cyber threat intelligence

Cyber security training

NetWars tournaments and keynote

In-person attendees get two NetWars tournaments — Core and DFIR — where the week's lessons are tested under pressure against a live scoreboard. They are free with the purchase of any 4-, 5-, or 6-day course. The program also features a featured keynote and SANS@Night talks:

  • Keynote (Tue, Sep 22, 6:00 PM PT): "Offense at Machine Speed: How AI Is Reshaping the Threat Landscape" by Stephen Sims — covering MFA bypass, Dark Web attacker tooling, and AI's growing role in offensive security.
  • SANS@Night (Wed, Sep 23, 6:00 PM PT): "Dr. Strangepwn or: How I Learned to Stop Worrying and Love the LLM" by Larry Pesce — on building AI pentesting agents for IoT and embedded devices.

Why attend

SANS Network Security is one of the few events broad enough that nearly any specialty a team needs runs the same week, making it a practical target for organizations sending people with very different roles. Attendees get hands-on labs, direct access to SANS faculty, the Welcome Reception, evening SANS@Night talks, and a community of peers working the same problems.

Who should attend

The program is built for cybersecurity analysts and security engineers, incident response and digital forensics professionals, penetration testers and ethical hackers, network, endpoint, cloud, and wireless security practitioners, threat intelligence and threat hunting teams, and IT/security leaders.

Tickets and pricing

Six-day courses are priced around $8,780 USD, with the optional GIAC certification exam at $999 USD (prices exclude applicable local taxes). WiCyS members can save $2,500 on any 4-6-day course with code SANS2500 through September 21, 2026. Discounted guest rooms at Caesars Palace and partner hotels are available to SANS attendees.

SANS Institute

Registration

Registration is open on the official event page. Choose your course, pick in-person or virtual attendance, and confirm your NetWars spot on site.

Speakers

Stephen Sims

Stephen Sims

Research Fellow, SANS Institute

Vulnerability researcher and exploit developer, author of SANS SEC760: Advanced Exploit Development for Penetration Testers, co-author of the Gray Hat Hacking series, and the 9th person in the world to earn the GIAC Security Expert (GSE) certification. Curriculum Lead for SANS Offensive Operations.

Jeff McJunkin

Jeff McJunkin

SANS Principal Instructor; Founder & Principal Consultant, Rogue Valley Information Security

Co-author of SEC560: Enterprise Penetration Testing and author of SEC580: Metasploit for Enterprise Penetration Testing. GIAC Security Expert (GSE #128), GXPN, GPEN. Architect of multiple generations of the SANS Core NetWars cyber range.

Larry Pesce

Larry Pesce

Vice President of Services, Finite State

Co-author of SANS flagship wireless and IoT penetration testing courses and a pioneer of SBOM exploitation techniques for supply chain defense. Presents the SANS@Night talk "Dr. Strangepwn or: How I Learned to Stop Worrying and Love the LLM".

Stay ahead of threats

Weekly cybersecurity intelligence in your inbox. No spam.

CyberPeople contributor