Jump to content

Tony Sager

From Wikipedia, the free encyclopedia

Tony Sager is an American cybersecurity professional who serves as Senior Vice President and Chief Evangelist at the Center for Internet Security (CIS). A retired 34-year veteran of the National Security Agency (NSA), Sager contributed to the development of the CIS Critical Security Controls, a widely implemented framework for cybersecurity best practices. He has also served on federal advisory boards focused on national cybersecurity policy and infrastructure protection.[1]

Tony Sager
Tony Sager at NSA conference
Sager (right) presenting at NSA Trusted Computing Conference, 2011
NationalityAmerican
Alma materWestern Maryland College (BA), Johns Hopkins University (MS)
OccupationCybersecurity expert
Years active1978–present
EmployerCenter for Internet Security
Known forCIS Critical Security Controls, NSA vulnerability analysis
AwardsPresidential Rank Award (Meritorious), NSA Exceptional Civilian Service Award, Global Cyber Security Hall of Fame

Early life and education

[edit]

Sager earned a bachelor's degree in mathematics from Western Maryland College (now McDaniel College) and later received a master's degree in computer science from Johns Hopkins University.[2]

Career

[edit]

Tony Sager’s career in cybersecurity spans more than four decades, beginning with his work at the National Security Agency and continuing through his leadership at the nonprofit Center for Internet Security.

National Security Agency (late 1970s–2012)

[edit]

Sager joined the NSA in the late 1970s through its COMSEC Intern Program. During his tenure, he held positions as a mathematical cryptographer, software vulnerability analyst, and head of the System and Network Attack Center. He later led the Vulnerability Analysis and Operations Group. In 2001, he initiated efforts to publish public security guidance and promote open standards.[1][2]

Center for Internet Security (2012–present)

[edit]

Following his retirement from the NSA, Sager transitioned to public-interest work by joining the Center for Internet Security (CIS). At CIS, he played a central role in developing the CIS Critical Security Controls—a framework used worldwide to help organizations implement prioritized cybersecurity practices.[3] In his current role, he leads outreach, collaboration efforts, and public policy initiatives to strengthen cyber resilience.[1]

Collaboration with NIST and Ron Ross

[edit]

In parallel with his work at CIS, Sager has frequently partnered with fellow cybersecurity leaders, including Ron Ross of the National Institute of Standards and Technology (NIST). Their public appearances and joint commentary have emphasized the alignment between CIS Controls and NIST frameworks, such as the CSF and SP 800-53.[4]

Public service and advisory roles

[edit]

Sager’s contributions have extended beyond technical work into public service. In February 2022, he was appointed to the inaugural Cyber Safety Review Board by the DHS and Cybersecurity and Infrastructure Security Agency (CISA).[5][1] He also serves on several advisory panels and nonprofit boards related to cybersecurity education and public safety.[1]

Congressional testimony

[edit]

Sager’s cybersecurity leadership has also included direct engagement with U.S. lawmakers. In 2009 Senate testimony, he described an NSA red team exercise that exposed vulnerabilities in U.S. Air Force systems. The NSA’s resulting guidance, deployed across 500,000 systems, led to measurable improvements—reducing patch times from 57 days to 72 hours, cutting costs by over $100 million annually, and lowering help desk demand. He emphasized that these outcomes were due not only to technical measures, but also to strategic procurement policies, including collaboration with Microsoft.[6]

Awards and honors

[edit]
  • Inducted into the Global Cyber Security Hall of Fame in 2023.[7]
  • Recipient of the SANS Difference Makers Lifetime Achievement Award in 2024.[8]
  • Awarded the Presidential Rank Award (Meritorious Level) twice during his NSA career.[1][2]
  • Received the NSA Exceptional Civilian Service Award.[1][2]
  • His NSA teams were recognized by SC Magazine, SANS, and Government Executive magazine.[1]

Publications and presentations

[edit]
  • "Vulnerability Analysis and Operations (VAO): A National Security Agency Perspective" (July 2009). NSA Information Assurance Symposium presentation. "Vulnerability Analysis and Operations" (PDF). NIST. Retrieved June 15, 2025.
  • "Cybersecurity at Scale: Piercing the Fog of More", Center for Internet Security blog (2023). "Cybersecurity at Scale: Piercing the Fog of More". Center for Internet Security. Retrieved June 15, 2025.
  • Contributor to "CIS Community Defense Model 2.0", CIS white paper (2021). "CIS Community Defense Model 2.0". Center for Internet Security. Retrieved June 15, 2025.
  • "I Tell Our Story", LinkedIn article by Tony Sager (November 2020). "I Tell Our Story". LinkedIn. Retrieved June 15, 2025.
  • "My Summer of Information Superiority", LinkedIn article by Tony Sager (October 2020). "My Summer of Information Superiority". LinkedIn. Retrieved June 15, 2025.

Public commentary and media

[edit]
  • Featured speaker at Center for Internet Security and SANS Institute conferences.[1]
  • Interviewed by Cybercrime Magazine on the Community Defense Model.[9]
  • Appeared on CyberSecurity TV panel: "Making Policy Compliance Work for You."[10]
  • Guest on Forcepoint podcast: “Demystifying Security’s Wizards.”[11]
  • Featured on SC Media’s “CISO Stories” podcast.[12]
  • Keynote speaker at SANS Security East 2025.[13]
  • Quoted in The Washington Post on NSA disclosure and surveillance policy.[14][15]
  • Featured on Bloomberg Television's *The American Dream* (March 2025).[16][17]

Legacy and impact

[edit]

Sager’s work influenced public and private risk management and systems security practices. His involvement in CIS Controls contributed to their global adoption as a cybersecurity standard. His ongoing advisory roles underscore his influence on U.S. cybersecurity policy and practice.

See also

[edit]
[edit]

References

[edit]
  1. ^ a b c d e f g h i "Tony Sager". Center for Internet Security. Retrieved June 14, 2025.
  2. ^ a b c d "Tony Sager". SANS Institute. Archived from the original on October 26, 2022. Retrieved June 15, 2025.
  3. ^ "The CIS Critical Security Controls". Center for Internet Security. Retrieved June 14, 2025.
  4. ^ "CDM Program Prepping Data Protection Push at Select Agencies". The CRE. Retrieved June 15, 2025.
  5. ^ "DHS Launches First-Ever Cyber Safety Review Board". DHS. Retrieved June 14, 2025.
  6. ^ "Cyber Security: Hearing Before the Committee on Homeland Security and Governmental Affairs, 111th Cong. (2009)" (PDF). U.S. Senate Committee on Homeland Security and Governmental Affairs. p. 15–16. Retrieved June 15, 2025.
  7. ^ "The Center for Internet Security's Tony Sager to be Inducted into the Global Cyber Security Hall of Fame". Center for Internet Security. October 16, 2023. Retrieved June 15, 2025.
  8. ^ "SANS Difference Makers Awards". SANS Institute. Archived from the original on February 1, 2025. Retrieved June 15, 2025.
  9. ^ "Podcast: Tony Sager Discusses The Community Defense Model". Cimcor/Cybercrime Magazine. Retrieved June 14, 2025.
  10. ^ "Making Policy Compliance Work for You – CIS Benchmarks & DISA". CyberSecurity TV. Retrieved June 14, 2025.
  11. ^ "Replay: Demystifying Security's Wizards – Tony Sager". Forcepoint. Retrieved June 15, 2025.
  12. ^ "Listen: Former NSA analyst Tony Sager tackled 'fog of more'". SC Media. July 1, 2021. Retrieved June 15, 2025.
  13. ^ "Cybersecurity Pioneer Tony Sager to Keynote SANS Security East 2025". GlobeNewswire. February 18, 2025. Retrieved June 15, 2025.
  14. ^ Zakrzewski, Cat (February 6, 2020). "The Cybersecurity 202: Here's why NSA rushed to expose a dangerous computer bug". The Washington Post. Retrieved June 15, 2025.
  15. ^ Rucker, Phillip (December 18, 2013). "NSA shouldn't keep phone database, review board recommends". The Washington Post. Retrieved June 15, 2025.
  16. ^ "The Center for Internet Security to be Featured on Bloomberg Television's "The American Dream"". Fox5 San Diego. March 24, 2025. Retrieved June 15, 2025.
  17. ^ "The Center for Internet Security to be Featured on Bloomberg Television's "The American Dream"". CBS42. March 24, 2025. Retrieved June 15, 2025.