63 views
1 hour ago

“You might be good today, but not tomorrow”: what ends a cybersecurity career, according to SANS

Jan D’Herdt, SANS Instructor, SANS Institute, told GEC Newswire that regulation has moved the question in the region from whether an organisation will be breached to how quickly it recovers and how honestly it tells its customers.

For years the hardest problem in the industry had nothing to do with attackers. Jan D’Herdt, SANS Instructor, SANS Institute, who teaches the LDR512 and LDR566 management courses, said security teams and the businesses employing them were talking past each other everywhere. “That was a gap which there was clearly an issue with,” he said. “And not only in this region, in every region.” SANS now runs a large leadership portfolio built to close it.

Public spending on cybersecurity followed a recognition that critical infrastructure could be attacked “not only physically, but also on the internet”, D’Herdt said. What followed the budgets was regulation. He pointed to NIS2 in Europe and to rules introduced in Saudi Arabia and the UAE over the past 5 years, now actively enforced on companies.

The regulatory shift carries an assumption that many boards have yet to absorb. “It’s no longer the question that can it happen to us. No, it can happen to anybody,” D’Herdt said. “But then the question is, how are we able to respond to this? How fast can we recover from this?”

He extended that to disclosure, and his position on it is unambiguous. A compromised bank holds customer data that belongs to people who have no idea it is exposed. Organisations should “do the ethical thing”, he said, telling customers what happened without handing over every detail, so they know their information may have leaked. Regulators in several jurisdictions now require it.

A senior analyst should be experimenting with AI. A graduate should not

Asked what practitioners should do about AI, D’Herdt drew a line by seniority, stressing the word senior as he did so. Experienced analysts should be working with AI tools, environments and MCPs to understand where familiar risks reappear, because the speed of these systems has reproduced mistakes the industry already made once. “They can take it and look at AI with their experience and see potentially some issues,” he said.

Juniors need something slower. D’Herdt said a defender cannot be built in 1 or 2 years, and that graduates require on-the-job groundwork before the experience becomes useful against new tooling. Boot camps help without substituting for it.

The one disqualifying failure is refusal. Incident responders will have to learn how to handle incidents involving AI, D’Herdt said, because it is not going away.

Leave a Reply

Don't Miss

Ned Baltagi, Managing Director – Middle East, Turkey and Africa, SANS Institute.

SANS Institute to lead AI and critical infrastructure training at GISEC 2026

SANS Institute will participate in GISEC Global 2026, delivering certified training and
(L-R) Ned Baltagi, Managing Director, Middle East, Africa, and Turkey, at SANS Institute and Chris Cochran, Field CISO and Vice President of AI Security at the SANS Institute.

SANS Institute launches Gulf edition of AI security maturity model

The SANS Institute has introduced the Gulf edition of its AI Security

Welcome to

By signing or creating an account you agree with our Code of conduct & Privacy policy