SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact Us
Apply your credits to renew your certifications
Attend a live, instructor-led class at a location near you or remotely, or train on your time over 4 months
Course material is geared for cyber security professionals with hands-on experience
Apply what you learn with hands-on exercises and labs
This course offers an MBA-level approach, preparing cybersecurity leaders to build strategic plans, craft effective policies, and lead across technical and business teams.
This course is a cyber leadership MBA in five days. As a security manager of many years, the class delivered material of great value that I can immediately apply to make a difference at my company.
Forge the crucial bridge between technical security teams and executive management through strategic planning and program development. This course equips security professionals with essential tools to create comprehensive cybersecurity strategy, develop sound security policies, and lead implementation teams effectively. Whether you’re seeking to elevate your leadership impact or prepare for the GSTRT certification (GIAC Strategic Planning, Policy, and Leadership), LDR514 delivers practical skills and executive-level insight.
Through this immersive experience, participants prepare executive presentations, analyze business case studies, address challenges faced by fictional organizations, and engage with 20 Cyber42 leadership simulation challenges. The course also utilizes 9 real-world scenarios and 3 in-depth business case studies to cultivate critical thinking and practical application.
Security leaders will develop the ability to implement strategic approaches aligned with organizational objectives and communicate security imperatives persuasively to business executives—skills that are essential for anyone pursuing a mature cyber security strategy or preparing for the GSTRT certification.
In 2026, LDR514 was updated to help cyber leaders address today’s evolving threats and rising executive expectations, with expanded focus on AI, strategic planning, and enterprise risk leadership.
For what’s new and how these enhancements strengthen leadership impact, download the flyer.
As security professionals, we have seen the landscape change. Cybersecurity is now more vital and relevant to the growth of your organization than ever before. As a result, information security teams have more visibility, more budget, and more opportunity. However, with this increased responsibility comes more scrutiny. This course gives you tools to become a security business leader who can build and execute strategic plans that resonate with other business executives, create effective information security policy, and develop management and leadership skills to better lead, inspire, and motivate your teams.
Policy is a manager's opportunity to express expectations for the workforce, set the boundaries of acceptable behavior, and empower people to do what they ought to be doing. These policies must be aligned with an organization's culture. In LDR514, we break down the steps to policy development so that you have the ability to design and assess policies that can successfully guide your organization’s cyber security strategy.
Leadership is a skill that must be learned, exercised, and developed to better ensure organizational success. Strong leadership is brought about primarily through selfless devotion to the organization and staff, tireless effort in setting the example, and having the vision to see and effectively use available resources toward the end goal. Effective leadership entails persuading team members to accomplish their objectives, removing the obstacles preventing them from doing it, and maintaining the well-being of the team in support of the organization's mission. LDR514 will teach you to use management tools and frameworks to better lead, inspire, and motivate your teams.
LDR514 uses business case studies, fictional companies, and the Cyber42 leadership simulation game to put you in real-world scenarios that spur discussion and critical thinking of situations that you will encounter at work.
This web-based game is a continuous tabletop exercise where students play to improve security culture, manage budget and schedule, and improve security capabilities at the fictional organizations in the course. This puts you in real-world scenarios that spur discussion and critical thinking of situations that you will encounter at work.
The course also uses case studies from Harvard Business School, case scenarios, team-based exercises, and discussions that put students in real-world situations. You will be able to use these same activities with your own team members at work.
"This is the course I wish I had taken when I first started my career. You don't have to wait until you are in a management position to focus on your strategic planning, management, and leadership skills. Have you ever found yourself in a situation where you thought, 'Something I'm doing isn't working'? This course will set you on the path to address that concern. It's commonly stated that to succeed as a modern security leader you need to understand and align with the business to support the organization's mission. But what does that actually mean in practice? Instead of trying to get there on your own, join us to learn practical tools and lessons that have worked for countless other leaders, security officers, and CISOs."
- Frank Kim


SANS Fellow Frank Kim helps to develop the next generation of CISOs and cyber leaders while teaching LDR512 and LDR514.
Read more about Frank KimExplore the course syllabus below to view the full range of topics covered in LDR514: Security Strategic Planning, Policy, and Leadership.
Section one presents strategic planning tools to decipher the business and the threat landscape. This section examines stakeholder identification and ways to gain executive support. Through exercises including asset analysis, stakeholder management, and strategy maps, students practice creating plans that resonate with executives.
Overview
Creating security strategic plans requires a fundamental understanding of the business and a deep understanding of the threat landscape. Deciphering the history of the business ensures that the work of the security team is placed in the appropriate context. Stakeholders must be identified and appropriately engaged within this framework. This includes understanding their motivations and goals, which is often informed by the values and culture your organization espouses. Successful security leaders also need a deep understanding of business goals and strategy. This business understanding needs to be coupled with knowledge of the threat landscape—including threat actors, business threats, and attacker tactics, techniques, and procedures—that informs the strategic plan.
Full Lab Details
Full Topic Details
Section two establishes methodologies for analyzing security posture, identifying target states, and developing prioritized roadmaps. Students learn to assess organizational vision, conduct SWOT analysis, and apply security frameworks. The section covers business case creation and metrics for effectively marketing security initiatives.
Overview
With a firm understanding of the drivers of business and the threats facing the organization, you develop a plan to analyze the current situation, identify the target state, perform gap analysis, and develop a prioritized roadmap. In other words, you will be able to determine (1) what you do today (2) what you should be doing in the future (3) what you don't want to do, and (4) what you should do first. Once this plan is in place, you will learn how to build and execute it by developing a business case, defining metrics for success, and effectively marketing your security program.
Full Lab Details
Full Topic Details
Section three explores policy as a security leadership tool for guiding organizational behavior. Participants learn methods for developing policies aligned with corporate culture. The section covers policy lifecycle from creation to measurement, with a focus on governance and emerging technology considerations.
Overview
Policy is one of the key tools that security leaders have to influence and guide the organization. Security managers must understand how to review, write, assess, and support security policy and procedures. This includes knowing the role of policy in protecting the organization along with its data, systems, and people. In developing policy, you also need to know how to choose the appropriate language and structure so that it fits with your organization's culture. As policy is developed, you must manage the entire lifecycle from approval and socialization to measurement in order to make necessary modifications as time goes on. This is why assessing policy and procedure is so important. Policy must keep up to date with the changing business and threat landscape. This includes coverage of technologies like Generative Artificial Intelligence (GenAI).
Full Lab Details
Full Topic Details
Section four addresses critical skills for leading, motivating, and inspiring security teams. Participants develop knowledge and abilities essential for transitioning from management to leadership. The section establishes standards for effective leadership and explores methods for employee motivation aligned with organizational goals.
Overview
This course section will teach the critical skills you need to lead, motivate, and inspire your teams to achieve your organization's goals. By establishing a minimum standard for the knowledge, skills, and abilities required to develop leadership, you will understand how to motivate employees and develop from a manager into a leader.
Full Lab Details
Full Topic Details
Section five applies course concepts through Harvard Business School case studies focused on information security leadership. Participants analyze real-world scenarios that reinforce management competencies. The Strategic Planning Workshop serves as a capstone exercise where students synthesize methodologies and tools from previous sections.
Overview
Using case studies, students will work through real-world scenarios by applying the skills and knowledge learned throughout the course. The case studies are from Harvard Business School, which pioneered the case study method. The case studies focus specifically on information security management and leadership competencies. The Strategic Planning Workshop serves as a capstone exercise for the course, enabling students to synthesize and apply concepts, management tools, and methodologies learned in class.
Full Lab Details
Full Topic Details
Important! Bring your own system configured according to these instructions.
A laptop or mobile device with the latest web browser is required to play the Cyber42 leadership simulation game.
The Cyber42 game used in this course is hosted on the ranges.io platform. Students must have a computer that does not restrict access to ranges.io. Corporate machines may have a VPN, intercepting proxy, or egress firewall filter that causes connection issues communicating with third-party websites. Students must be able to configure or disable these services to be able to access the Cyber42 game.
If you have additional questions about the laptop specifications, please contact customer service.
LDR514 training is recommended for a diverse range of individuals, including:
The GIAC Strategic Planning, Policy, and Leadership (GSTRT) certification validates a practitioner's understanding of developing and maintaining cyber security programs as well as proven business analysis, strategic planning, and management tools. GSTRT certification holders have demonstrated their knowledge of building and managing cyber security programs with an eye towards meeting the needs of the business, board members, and executives.
This course is designed for security leaders who want to go beyond technical skills, move into more senior roles, and effectively engage with the C-suite. While there are no specific technical prerequisites, students will benefit from basic understanding of security concepts and business operations. The course LDR512: Security Leadership Essentials for Managers is recommended but not required.
LDR514 is a part of the SANS Cybersecurity Leadership Curriculum and is one of three courses that make up the Transformational Cybersecurity Leaders Triad, alongside LDR512 and LDR521. This triad forms a comprehensive leadership development program designed to develop well-rounded security leaders capable of building, leading, and maturing effective cybersecurity initiatives.
What Comes Next:
The program supports a progression from core leadership skills to strategic influence and cultural transformation within cybersecurity.
Strategic security planning is the process of aligning information security initiatives with business objectives to create a roadmap for building effective security capabilities that protect organizational assets while enabling business growth.
This course equips you with executive-level skills in cybersecurity strategy development, policy creation, and leadership—critical competencies for advancement to CISO and senior security positions that require business acumen alongside technical knowledge.
Manages compliance with cybersecurity-related standards, legal and regulatory frameworks based on the organisation’s strategy and legal requirements.
Explore learning pathCo-ordination of detection, response, and recovery activities across teams and systems. Emphasis is placed on minimising impact, restoring services, and maintaining clear communication during disruptions.
Explore learning pathDevelopment of long-term technology roadmaps that support enterprise goals and capability development. Focus includes alignment of IT investments with business outcomes.
Explore learning pathResponsible for overseeing and directly managing technology projects. Ensures cybersecurity is built into projects to protect the organization’s critical infrastructure and assets, reduce risk, and meet organizational goals. Tracks and communicates project status and demonstrates project value to the organization.
Explore learning pathResponsible for managing the cybersecurity of a program, organization, system, or enclave.
Explore learning pathAnalysis of threats, vulnerabilities, and potential impacts to support prioritised risk mitigation. Outputs inform investment decisions and align cyber risk with business tolerance levels.
Explore learning pathDaily focus is on the oversight of technical teams while aligning them to overall business strategies. Includes titles such as Technical Director, Information Security Officer, and CISO.
Explore learning pathDevelopment of frameworks that align technology use with business objectives and regulatory requirements. Focus areas include policy design, risk controls, and enterprise accountability structures.
Explore learning pathEnroll your team as a group or arrange a private session for your organization. We’ll help you choose the format that fits your goals.
I love the lab and exercises. They are exactly what I am looking for as the new Marketplace Security PM on my team.
I have truly enjoyed the labs and exercises. They have broken up the course throughout the week. There has been a lot of information, but these exercises and labs helped us to put the knowledge into action.
SANS provides the absolute best training material. I'm ready to roll up my sleeves and implement what I’ve learned this week, which was challenging and made me think how I approach leadership and security strategy.
This course is a game changer for me. It has been very timely and inspirational at this point in my career. All of the tools reviewed in this course are applicable to program goals I am working on RIGHT NOW! Very useful!

Get feedback from the world’s best cybersecurity experts and instructors

Choose how you want to learn - online, on demand, or at our live in-person training events

Get access to our range of industry-leading courses and resources