Chief AI Officer and Chief of Research at SANS Institute, and a globally recognized authority on cybersecurity and AI strategy — known across the industry as the Godfather of DFIR.

A fully autonomous attack, reviewed by the responders who lived through it.
Your AI tools may refuse to help mid-incident. Frontier models declined the forensics. A model you control is a control.
Deception just got cheap and effective. Agents cannot tell a honeypot from production. Decoy credentials turn an attacker's speed into your alarm.
Someone must be able to shut a high-risk agent down. Without waiting for a meeting. On this one, four days passed before anyone did.
Recent conference keynotes, podcast interviews, and press features on AI security.

Annual keynote panel featuring the latest threats and defensive strategies from leading security researchers.
Defined how modern incident response works, shaped national security policy, and trained the teams defending the world's most critical systems.
Developing methodologies for discovering and managing unauthorized AI deployments
Creating comprehensive frameworks for responsible AI implementation and compliance
Researching attack vectors and defense strategies for AI system security
Advancing risk assessment methodologies for enterprise AI deployments
Rob leads the world's most trusted AI security training and research at SANS — developed by practitioners, for practitioners.
Visit SANS AI Security HubEvery executive is prioritizing AI, but confusion and uncertainty still dominate its adoption. Success depends on owning AI securely, which means addressing all three dimensions at once. Protecting AI without utilizing it leaves capability on the table. Utilizing it without governance risks chaos. And governance without technical protections creates a false sense of security.
Defend models, applications, and data pipelines from tampering, poisoning, prompt injection, and other adversarial techniques — from development through deployment.
Leverage AI and ML to improve detection, response, and resilience by integrating AI into SOC workflows, threat hunting, and incident analysis to match attacker speed and scale.
Translate complex AI regulations into actionable governance frameworks that boards can implement — establishing clear structures, ensuring compliance, and aligning AI with enterprise risk.



What boardrooms need isn't another jargon-heavy AI strategy session. They need someone who's built the programs, advised the agencies, and seen the breach reports. Rob gives directors a clear language and structure for AI literacy and board engagement.
Everyone talks about AI transformation. Few are building teams who can use it, secure it, and respond to it. Rob draws from decades building the global cyber workforce to show what readiness actually looks like, from SOCs to C-suites to startups, and how to lead toward it.
A sharp, operationally grounded session for executives and boards on what AI adoption looks like in the wild, when tools get ahead of policy, when teams go rogue, and when 'pilot projects' turn into attack surfaces. Rob breaks down how to set the right guardrails early, ask better questions, and reduce real exposure without killing momentum.
Drawing from his work in national security and incident response, Rob shows how adversaries are already using AI systems to scale attacks, break defenses, and shift speed in ways most leaders haven't prepared for. A critical briefing for anyone responsible for protecting systems or investing in them.
The Godfather of DFIR
Rob T. Lee is Chief AI Officer and Chief of Research at SANS Institute, where he advises boards, CISOs, and government leaders on how to govern, deploy, and defend AI at scale. He authored the SANS Secure AI Blueprint, which organizes secure AI adoption around Protect AI, Utilize AI, and Govern AI, and led development of the SANS Critical AI Security Guidelines. He co-authored The AI Vulnerability Storm: Building a Mythos-Ready Security Program and the initial post-mortem of the OpenAI/Hugging Face breach.
Rob created the original SIFT Workstation, pioneered the use of forensic timeline analysis, and coined the terms DFIR (digital forensics and incident response) and CTI (cyber threat intelligence). His recent work includes Protocol SIFT, an experimental initiative testing how AI can help trained responders triage investigations, and FIND EVIL!, the first hackathon for autonomous AI incident response.
Rob's career spans government, industry, and academia. A U.S. Air Force officer and founding member of the first information warfare unit, he later served with the NSA and CIA before becoming Director of Threat Intelligence and Threat Hunting at Mandiant, where he co-authored the first M-Trends report.
Rob serves as a Technical Advisor to the Foreign Intelligence Surveillance Court, has authored flagship SANS courses, co-developed GIAC certifications, and trained more than 100,000 professionals. He speaks at conferences including RSA Conference and AI4 and has appeared in The Wall Street Journal, CNN, Forbes, Wired, Rolling Stone, and Security Magazine.
For interviews, podcast appearances, and speaking engagements on AI security, cybersecurity leadership, and digital forensics.