SEC536: Adversarial AI - Penetration Testing AI Systems

Important! Bring your own system configured according to these instructions.
A laptop or mobile device with the latest web browser is required to play the Cyber42 leadership simulation game.
The Cyber42 game used in this course is hosted on the ranges.io platform. Students must have a computer that does not restrict access to ranges.io. Corporate machines may have a VPN, intercepting proxy, or egress firewall filter that causes connection issues communicating with third-party websites. Students must be able to configure or disable these services to be able to access the Cyber42 game.
If you have additional questions about the laptop specifications, please contact customer service.
This is a leadership course for the people who set a security program's direction and run its teams. Students learn to design and govern the AI-native security function, and the course expects no hands-on work with the tools.
LDR550: Leading Agentic Security Teams is part of the SANS Cybersecurity Leadership curriculum. It builds on the cybersecurity concepts covered in LDR512: Security Leadership Essentials for Managers and complements LDR520: Emerging Trends for Cyber Leaders: AI and Cloud. A leader who finishes LDR520 can secure the AI and cloud their business adopts; LDR550 helps that leader redesign the security function itself around governed AI.
An agentic security team is a security function that runs on governed AI under human direction. AI agents handle the routine work, such as alert triage, evidence gathering, and first-pass review, within limits a leader sets, while people set policy, make the hard calls, and supervise the system.
Leading such a team means deciding which work to delegate to AI, at what level of autonomy, and who stays accountable when the AI acts on its own. An agent that can isolate a host, suspend an account, or change a firewall rule needs a named person who answers for it and a clear point where a person can override it. This course teaches you to make those decisions deliberately, workflow by workflow, and to record them in a form your executives and counsel can act on.
Security leadership now includes deciding what AI may do on the team's behalf, and this course gives you a method for that decision and the vocabulary to explain it to executives and the board.
You leave with the start of a written record of which security work your AI agents may do on their own, who approves the rest, and who answers for each outcome, along with a sketched 90-day roadmap for your own organization, built from the budget, team, and tools you have today. For CISOs and senior leaders, the course ties those decisions to outcomes a CFO understands, such as analyst capacity, decision speed, and headcount leverage. For directors and team leads, it gives you a structured way to lead your team through a transition that can feel uncertain, including how roles change as AI takes on routine work.
Because you capture decisions rather than products, what you decide in class still applies after your AI tools change, and you have one place to revisit each call as the AI earns more trust or loses it.

Get feedback from the world’s best cybersecurity experts and instructors

Choose how you want to learn - online, on demand, or at our live in-person training events

Get access to our range of industry-leading courses and resources