Rob T. Lee
AI AgentsSunlight AICoursePress & MediaSpeakingAbout
Cybersecurity & AI

Rob
T. Lee

Chief AI Officer at SANS and the godfather of DFIR, he helps businesses adopt AI securely— where AI security and cybersecurity go hand in hand, and you can't forgo either.

Get in touch
Chief AI Officer
SANS Institute
Technical Advisor
FISA Court
Formerly
U.S. Air Force · NSA · CIA · Mandiant
Featured in
CNNForbesThe New York TimesWall Street JournalRolling StoneWiredCBS NewsAxiosFast CompanyNewsweekThe HillNBC NewsCNBC

Latest

New Paper/July 2026/Cloud Security Alliance

Post-Mortem: The OpenAI and Hugging Face Breach

A fully autonomous attack, reviewed by the responders who lived through it.

  1. 01

    Your AI tools may refuse to help mid-incident.

  2. 02

    Deception just got cheap and effective.

  3. 03

    Someone must be able to shut a high-risk agent down.

Read the full post-mortem
Just Launched/LinkedIn Learning

Become an AI Security Champion

A 16-minute Skill Sprint on partnering with security, classifying data risk, and evaluating AI tools.

Recent Appointments

  • Commission on U.S. Cyber Force Generation

    Examining whether the U.S. should create a dedicated military service for cyberspace.

  • Presidential AI Challenge

    Regional Judge for AI.GOV's national student competition.

Selected Writing

All writing →
  • 01Cloud Security Alliance · 2026

    The AI Vulnerability Storm

    Machine-speed exploitation, a 13-item risk register, and 11 priority actions for security leaders.

  • 02SANS Institute · 2026

    The Secure AI Blueprint

    Protect, Utilize, Govern — a three-pillar model for adopting AI without losing control.

  • 03Substack · 2026

    The Framework of No: Why Your Security Team Is Killing Your AI Momentum

    How traditional security approaches drive shadow AI adoption — and what to do instead.

  • 04robtlee.com · 2026

    Sunlight AI: A Governance Framework That Works in 30 Days

    Practical steps to move from shadow AI chaos to working governance without 18-month frameworks.

  • 05Dark Reading · 2026

    AI Chat Data: History's Most Thorough Record of Enterprise Secrets

    Why AI conversation logs represent an unprecedented security challenge for organizations.

Recent Highlights

Keynotes & media
RSAC 2026 — Five Most Dangerous New Attack Techniques
RSAC 2026

Five Most Dangerous New Attack Techniques

Annual keynote panel on the latest threats and defensive strategies from leading security researchers.

[un]prompted Conference — Claude Code on SIFT Workstation
[un]prompted Conference

Claude Code on SIFT Workstation

CXOTalk Episode 910 — The AI Attack Lifecycle
CXOTalk Episode 910

The AI Attack Lifecycle

Agents of Scale — Why "No" to AI Creates More Risk
Agents of Scale

Why "No" to AI Creates More Risk

SANS Leadership

Chief of Research · Chief AI Officer

Defined how modern incident response works, shaped national-security policy, and trains the teams defending the world's most critical systems.

01

Shadow AI Research

Methodologies for discovering and managing unauthorized AI deployments across the enterprise.

02

AI Governance Frameworks

Comprehensive frameworks for responsible AI implementation and compliance.

03

Adversarial AI Defense

Attack vectors and defense strategies for securing AI systems in production.

04

AI Risk Management

Risk assessment methodologies built for real enterprise AI deployments.

Rob leads the world's most trusted AI security training and research at SANS — developed by practitioners, for practitioners.

Visit the SANS AI Security Hub

The Approach

Protect · Utilize · Govern

Owning AI securely means addressing all three dimensions at once. Protecting AI without utilizing it leaves capability on the table. Utilizing it without governance risks chaos. And governance without technical protection creates a false sense of security.

01

Protect AI

Securing AI Systems

Defend models, applications, and data pipelines from tampering, poisoning, prompt injection, and other adversarial techniques — from development through deployment.

02

Utilize AI in Cybersecurity

Enhancing Defense with AI

Integrate AI into SOC workflows, threat hunting, and incident analysis to improve detection, response, and resilience — matching attacker speed and scale.

03

Govern AI

Regulation, Compliance & Oversight

Translate complex AI regulations into actionable governance frameworks boards can implement — clear structures, real compliance, aligned with enterprise risk.

Download the SANS AI Security Blueprint
Rob T. Lee
About

Twenty years turning how the world investigates digital crime into how it will defend against autonomous AI.

A former U.S. Air Force officer who later served with the NSA and CIA, Rob is Chief AI Officer and Chief of Research at SANS Institute and a Technical Advisor to the Foreign Intelligence Surveillance Court. He created the SIFT Workstation, coined the terms DFIR and CTI, and has trained more than 100,000 professionals.

Full biography

Speaking

Themes he returns to

Boards can't pretend to understand AI. They have to learn.

A clear language and structure for AI literacy at the board level — from someone who has built the programs and read the breach reports.

AI moves fast. Governance can't lag.

What adoption actually looks like when tools get ahead of policy, and how to set guardrails early without killing momentum.

Attackers don't wait for your next planning cycle.

How adversaries already use AI to scale attacks and break defenses — drawn from national-security and incident-response work.

The workforce you need is already behind.

What readiness looks like across SOCs, C-suites, and startups, from decades spent building the global cyber workforce.

Newsletter

Sleep. Diet. Exercise. AI.

Occasional, practical notes on leading secure AI transformation.

Enter your email
Subscribe to Rob's newsletter

For speaking, media, and advisory inquiries.

Media kit
Rob T. Lee

Chief AI Officer and Chief of Research, SANS Institute.

Elsewhere
LinkedInX / TwitterYouTubeSubstack
SANS AI
sans.org/ai

© 2026 Rob T. Lee