SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsJoin us at the 2025 Government Security Forum on July 22nd at 10:00 AM ET to gain intelligence, tools, and real-world strategies needed to defend your agency against next-generation cyber threats.
AI is reshaping the cyber threat landscape at an unprecedented pace. From AI-enhanced attacks to deepfake-driven disinformation campaigns, government agencies are facing more sophisticated and relentless threats than ever before.
At the same time, the rapid evolution of AI is forcing agencies to rethink their approach to zero trust, compliance, cyber defense, and risk management in an increasingly complex digital environment.
Join us for in-depth discussions led by industry experts, featuring:
Why Register:
Whether you're securing federal, state, or local infrastructure, the time to adapt and fortify your defenses is now!
*We encourage you to use your .gov, .mil, .edu, .civ. or.us, email address when registering. However, all are welcomed to attend regardless of email domain!
SANS Slack:
Virtual
The rapid proliferation of Artificial Intelligence (AI) across the federal landscape presents both unprecedented opportunities and novel security challenges. As AI systems become increasingly integrated into critical infrastructure, decision-making processes, and citizen services, the traditional perimeter-based security model proves insufficient. This presentation will explore the imperative of adopting a Zero Trust architecture to effectively secure federal operations in this evolving AI-driven world. We will examine how the core principles of Zero Trust -- assume breach, explicit verification, and least privilege -- provide a robust framework for mitigating the unique risks introduced by AI, including sophisticated cyberattacks leveraging AI, data poisoning, and the potential for autonomous system compromise. By highlighting key considerations and practical strategies, this session aims to equip federal stakeholders with the knowledge necessary to implement Zero Trust principles and ensure the resilience and security of their AI-enabled environments.
Virtual
Confirmed Panelists:
Sean Frazier, Federal CSO, OKTA
Joe Boye, Solutions Consultant Manager, Palo Alto Networks
Moderated by
Ismael Valenzuela
Senior Instructor
Virtual
Historically, Operational Technology (OT) has been treated as distinct from Information Technology (IT), which traditionally focused solely on business environments. However, with the rise of digitalization, artificial intelligence (AI), cloud adoption, and the growing presence of IT-like tools such as virtual servers, software-defined networking (SDN), SD-WAN, and virtual I/O, this distinction is rapidly fading from a technology standpoint. Today, most systems run on Windows, Linux, or variants thereof, requiring a new, integrated approach. IT and OT are no longer isolated; they are now joint stakeholders working toward a shared mission.
Despite this integration, fundamental differences in how IT and OT operate remain and must be acknowledged. IT teams need to understand the constraints and priorities of operational environments, while OT teams must learn to manage and secure IT-based tools now embedded in industrial systems. The era of saying "OT is airgapped" is over. Both teams must collaborate to harness emerging technologies like AI and cloud in ways that drive business outcomes and efficiency, while simultaneously preserving operational resilience and safety.
Presented by
Michael Hoffman
Certified Instructor
Virtual
Virtual
Panelists: Robert Mathieson, Sales Engineering Director, Public Sector, Extrahop
Virtual
For decades, critical infrastructure has relied on centralized systems designed for scale. But AI is enabling a shift toward intelligent, decentralized, and highly customized solutions - microgrids, autonomous care, adaptive logistics - that reduce dependence on monolithic systems. This talk explores how AI can enhance national resilience, lower infrastructure risk, and redefine what we consider "critical." It's a call to rethink our infrastructure strategy for an era where the economic driver towards scale may no longer be necessary.
Presented by
Sounil Yu
Co-founder and Chief AI Safety Officer
Virtual
Confirmed Panelists:
Dr. Nash Borges, SVP Engineering, Sophos
Uriel Cohen, VP Products, VMRay
Moderated by
Greg Scheidel
Principal Instructor
Virtual
100% of all missions depend on operational technology and control systems. Enter: CROCS – no, not the rubber shoe – the DAF Cyber Resilience Office for Control Systems. CROCS is the first dedicated organization that addresses the growing cyber threats to Air and Space Force installation infrastructure, ensuring cyber safety at every turn. Learn 3 actions to take and 3 pitfalls to avoid in advancing OT cyber resilience.
Virtual
Confirmed Panelists:
Jennifer Bisceglie, Founder and Executive Vice Chair, Interos
Andy Lewis, Technical Marketing Manager, ReversingLabs
Moderated by
Tony Turner
Certified Instructor Candidate
Virtual
Presented by
Matt Bromiley
Certified Instructor
Virtual
Matt Bromiley is a Lead Solutions Engineer at LimaCharlie and SANS Certified Instructor. He serves as a GIAC Advisory Board member, a SME for the SANS Security Awareness, and a technical writer for the SANS Analyst Program.
Learn moreSounil Yu is the Founder and CTO of Knostic, and a leading voice in AI cybersecurity innovation. He is the creator of the Cyber Defense Matrix and the DIE Resiliency Framework.
Learn moreMike is a SANS Technology Institute graduate, earning his master’s degree in information security engineering with an Industrial Control Systems focus. Besides his work at Dragos, Inc. he teaches ICS612: ICS Cybersecurity In-Depth at SANS.
Learn moreGerald “Gerry” Caron has 20+ years of federal service and is currently serving as the Vice President of Cybersecurity at RIVA Solutions.
Learn moreAndy is a former Marine who's currently a Technical Marketing Manager at ReversingLabs, a company tackling Software Supply Chain Security head-on (including xBOMs).
Learn moreGehron “Ronny” Fredericks is Field CTO at Nozomi Networks. He holds a Master’s degree in Digital Forensics & Cyber Investigation and an additional MBA from University of Maryland.
Learn more