Major crises and AI threats to dominate agenda at landmark SANS conference for cyber threat hunting community
SANS CyberThreat Summit brings together security practitioners from offensive and defensive fields for a technically driven agenda focused on AI weaponisation, malware evasion and supply chain
In a month which saw official British economic statistics attribute slower than expected economic growth directly to a cyber attack on one of the country’s most prestigious carmakers, SANS Institute has unveiled the themes for the sixth edition of CyberThreat. The Summit is Europe’s premier conference for the technical community of threat hunters and other threat specialists and will take place on 3-4 December at the iconic Stamford Bridge Football Stadium in London. SANS also polled cyber professionals planning to attend, who overwhelmingly agree that while cyber threats have not become any more sophisticated, the volume has increased over the past two years, straining existing resources and teams.
At the same time, most attendees also believe there’s been little or no improvement in organisational readiness against cyber threats. Those polled also highlighted that the industry’s shortage of clearly defined and appropriately compensated roles remains a key issue, as do lack of visibility and underinvestment.
Designed specifically for cybersecurity practitioners, from blue‑team defenders to red‑team adversarial specialists, the SANS CyberThreat Summit returns with fresh content, hands‑on challenges, and unique networking opportunities. The two-day event will deliver deep technical insights in both offensive and defensive disciplines. Attendees will engage with keynote presentations, advanced workshops, an elite CTF (Capture The Flag) competition, “Hackable Badge” challenges, team problem‑solving sessions and peer‑networking.
CyberThreat 2025 highlights include:
· No pAIn no gAIn: World renowned bug bounty pioneer Katie Moussouris will warn that AI cyber security tools, if mishandled, will displace the very skilled workers it’s supposed to empower.
· Former GCHQ Director Robert Hannigan will explain why some organisations fail the cyber incident test – and why some succeed, looking at the lessons of the many major incidents to hit the headlines this year.
· The latest analysis of the threat and threat techniques from the National Cyber Security Centre’s Operations Director Paul Chichester, in conversation with the NCSC’s first CEO Ciaran Martin, now Director at the SANS Institute and Oxford University Professor.
· Heli Tiirma-Klaar, Visiting Distinguished Fellow at GMF Technology and a global expert on cyber conflict and revealing the latest lessons from Ukraine.
· A unique “Hackable Badge” challenge designed for the most technically advanced delegates, offering a rare blend of puzzle, code‑breaking and real‑world exploit mechanics.
· A custom designed CTF competition: This is Operation Meltdown, a live, narrative-driven CTF experience where you step into the breach to uncover the truth, contain the chaos, and outsmart the adversary. Participants can join for an immersive challenge that fuses storytelling, technical mastery, and team-driven strategy. Whether you’re defending Kiron Power Station or hunting the handlers behind the digital sabotage, every clue, packet, and command counts. It’s played in teams with one mission, and no room for error.
· The Summit’s location provides world‑class networking with like‑minded professionals, from incident response practitioners and threat hunters to cloud security architects and CISO‑level strategists.
James Lyne, Chief Strategy and Innovation Officer at SANS Institute, said, “Over 20 years of my career, I’ve watched cyber criminals innovate to a disgustingly effective degree. They sell services and products to each other; they collaborate in forums, sharing tactics and focusing on what works, even if technically unimpressive. Our community fails if we do not do the same. CyberThreat exists to do exactly that. We bring together public and private sector defenders to swap war stories and specifics, to provide practical lessons for attendees to take away and apply in their own environments. It’s about fostering a collaborative community: time spent learning, practising, solving and geeking out — not just hand-waving about the next cybergeddon — is where the real value lies and what makes CyberThreat different than other conferences. People learning together, getting better, and making life harder for cyber criminals, plus, the hackable badges are ridiculously cool.”
“We’ve seen more serious cyber incidents in 2025 than we’ve had for several years. There’s been a lot of progress, but the attackers are smart too, and they’re adapting,” said Ciaran Martin, President, CISO Network EMEA at SANS Institute. “That’s why the SANS CyberThreat Summit continues to be essential: the best place in the world for the technical community to come together to look at both the threat actors and the tools they are using, and what we can do about it.”
Read more stories like this on our LinkedIn page.











