SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsA new SANS Rapid Briefing makes the case that AI-era vulnerability volume has broken the old operating model and lays out what security leaders should run instead.

For years, a green remediation dashboard has been the number one item security leaders take into a board meeting: tickets closed on time, service level agreements met, and a program that, by those measures, appeared to be working.
Those metrics are now measuring the wrong thing. They track how fast a team closes tickets but say very little about how much exploitable exposure is still live in the environment, or for how long. As AI-assisted tools surface software vulnerabilities at a velocity and scale that manual workflows were never built to handle, the gap between what the dashboard reports and what an attacker can reach has widened.
That gap is the subject of a new SANS Rapid Briefing, VulnOps: A CISO’s Guide to Starting Implementation, featuring Ed Skoudis, President of the SANS Technology Institute, with SANS faculty and staff. The session is built for CISOs, security executives, and vulnerability management leaders, the people responsible for managing risk, not simply ticket throughput.
The argument is straightforward. The sequence most programs still follow, finding, scoring, and patching vulnerabilities, assumes a manageable volume of new findings and a patch window measured in weeks. Both assumptions have eroded.
VulnOps reframes vulnerability management as a continuous operation focused on reducing exploitability. It prioritizes remediation based on business risk and asset criticality instead of raw Common Vulnerability Scoring System scores. It also establishes a patch-decision loop that routes each system to one of three paths: automatic patching, test before deployment, or manual review, with a human owning the final call.
None of this removes people from the loop. AI can accelerate discovery and initial triage, but judgment, guardrails, rollback plans, and accountability stay with the team. The briefing is candid about what is still uncertain while identifying what defenders can put into practice now.
The briefing provides the leadership perspective. The companion VulnOps course shows teams how to build and operate the model in practice. After the session, SANS will also publish a VulnOps field guide, a practical reference security teams can use to begin implementing the model, which will be available alongside the on-demand replay.
Join us live for VulnOps: A CISO’s Guide to Starting Implementation on SANS.org and YouTube. No registration is required. Tune in on August 12 at 1 p.m. E.T. to learn how security leaders can begin moving from traditional vulnerability management to a continuous VulnOps model.


Launched in 1989 as a cooperative for information security thought leadership, it is SANS’ ongoing mission to empower cybersecurity professionals with the practical skills and knowledge they need to make our world a safer place.
Read more about SANS Institute