Security culture isn't built in a day. But this summit is a great place to start.
Policies don't change behavior. Culture does. And building a security culture that actually sticks — one where people think before they click, speak up when something looks off, and treat security as their problem too — is one of the hardest things in this industry.
The 13th annual SANS Security Awareness & Culture Summit is where that work gets done.
More than a conference
This is a gathering of thousands of security awareness, behavior, and culture professionals from around the world — all here to compare notes, share what's working, and push the field forward. Whether you're in the room at Caesars Palace or joining live online, you'll leave with more than slides to flip through later.
What's on the agenda
Top practitioners bring the real stuff — original research, honest case studies, and proven techniques for shifting not just what people do, but how they think about cybersecurity. Sessions go deep on engaging workforces, communicating security without crying wolf, and building programs that actually move the needle on human risk.
For in-person attendees, hands-on workshops round out the experience with practical, take-it-back-Monday takeaways you can put to work immediately.
Two ways to attend
Go in-person for the full experience — workshops included — or join Live Online for access to select talks. Either way, you'll earn 12 CPEs and walk away with a clearer picture of what good security culture looks like and how to build it.
👉 Learn more at sans.org
Because the weakest link isn't a system. It's an unaware human, and that's fixable.