7 Things You Should Know About Data De-Identification and Anonymization
As the types and amounts of personal data increase, users and institutions need to strengthen the ways they protect the sensitive information they collect and use.
Randy Marchany recently retired as the Chief Information Security Officer for Virginia Tech, a role he held since 2010, capping a 50-year career at the university, 35 of them in cybersecurity. He was also the director of Virginia Tech's IT Security Lab, a “teaching hospital” model that has trained more than 3,000 students in hands-on incident response since 1999.
He remains an Adjunct Electrical and Computer Engineering professor.
What distinguishes his career is not just longevity but originship. When the security community first sat down to turn hard-won incident experience into consensus, actionable guidance that organizations could actually implement, he was at the table. He is a co-author of the SANS Institute's “Incident Handling: Step-by-Step” (1998), one of the first practitioner-consensus guides to translate incident response into a repeatable six-phase methodology: preparation, identification, containment, eradication, recovery, and follow-up, still the backbone of incident response frameworks today. He is a signatory and co-author of the original SANS Top Ten (and later Top Twenty) Internet Security Threats, the first industry-wide consensus list of the vulnerability clusters responsible for the majority of successful attacks, built by more than forty practitioners from government, industry, and academia. Following the February 2000 distributed denial-of-service attacks that took down major sites including Yahoo! and eBay, he was part of the team commissioned by the White House to produce the SANS Consensus Roadmap for Defeating DDoS Attacks, prepared for President Clinton's Partnership for Critical Infrastructure Security.
Each of these documents shares a common thread. tThey were not academic exercises but were built by the people who had actually handled the incidents, written to give system administrators concrete, immediately actionable steps rather than abstract principles. Virginia Tech's CIRT received the SANS Institute's 2000 Security Technology Leadership Award for its method for prioritizing risks, threats, and countermeasures that helped establish it as one of the nation's most effective university incident response teams.
Marchany has been a member of the SANS Institute's faculty since 1992, instructor #2, the longest-serving instructor in SANS history. He was a member of the Center for Internet Security's original development team, producing and testing the first CIS Unix and Windows 2000/XP security benchmarks, and more recently served on the working group that authored version 8 of the CIS Security Controls. He co-founded the Virginia Alliance for Secure Computing and Networking (VASCAN), the Virginia Cyber Range, and the US Cyber Challenge, for which he built the technical curriculum used at national training camps. He is a co-holder of three cybersecurity patents, including MT6D, a moving-target defense technique.
He has been a frequent speaker at EDUCAUSE, SANS, RSA, IEEE, and NIST, among others, and his work has been featured in the Chronicle of Higher Education. Outside cybersecurity, he is acknowledged as one of North America's masters of the hammered dulcimer, composed the original theme song for NPR's “World Café,” and performed for nearly 40 years with the band No Strings Attached.
In May 2026, Marchany was inducted as the 15th member of the Virginia Tech Department of Computer Science Academy of Distinguished Alumni.
As the types and amounts of personal data increase, users and institutions need to strengthen the ways they protect the sensitive information they collect and use.
| Status: | Yes, current member |