SEC536: Adversarial AI - Penetration Testing AI Systems

Important! Bring your own system configured according to these instructions.
A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will not be able to fully participate in hands-on exercises in your course. Therefore, please arrive with a system meeting all the specified requirements.
This is common sense, but back up your system before class. Better yet, use a system without any sensitive/critical data. SANS is not responsible for your system or data.
Mandatory System Requirements
If you have additional questions about the laptop specifications, please contact customer service.
LDR519 training is recommended for a diverse range of individuals, including:
A basic understanding of cybersecurity concepts and business risk management is helpful but not required. Experience with frameworks such as NIST, ISO, or CIS will be beneficial. LDR519 is designed for assessors, auditors, and second-line GRC professionals looking to build the technical and organizational skills needed to own and operationalize a full GRC program.
LDR519 is part of the Cybersecurity Leadership Curriculum and is one of three courses that make up the Cyber Risk Officer Triad. The Cyber Risk Officer Triad equips you to build effective security programs, strengthen governance, manage incidents, and demonstrate compliance. This path develops the skills needed to lead and manage cybersecurity risk as a core business function.
Cybersecurity GRC is the integrated practice of governing security programs, managing risk systematically, and validating compliance so that cybersecurity decisions are defensible and aligned with business outcomes. Effective GRC ensures that security investments are prioritized based on real business risk, accountability is clearly defined, and the organization can demonstrate compliance with confidence.
GRC engineering is the practice of turning governance, risk, and compliance into repeatable operational workflows. In LDR519, students learn how to apply that approach through safeguard selection, policy and documentation, validation, AI-assisted analysis, continuous monitoring, data integration, metrics, dashboards, and risk reporting. The result is a more measurable, defensible, and sustainable way to run a GRC program.
LDR519 builds the hands-on skills that separate GRC practitioners who execute tasks from those who own and lead programs. You will leave equipped to build governance structures, conduct defensible risk assessments, govern third-party and AI-related risk, and communicate cybersecurity outcomes in business terms—capabilities that are increasingly critical for senior GRC, audit, and compliance roles.

Get feedback from the world’s best cybersecurity experts and instructors

Choose how you want to learn - online, on demand, or at our live in-person training events

Get access to our range of industry-leading courses and resources