SEC536: Adversarial AI - Penetration Testing AI Systems

In-Person
In-Person
SANS Cyber Crisis Exercises are immersive, scenario-based experiences that prepare organizations to navigate today’s complex cyber threat landscape. Designed for technical teams, business leaders, and executive stakeholders, these exercises replicate real-world cyber incidents in a controlled, facilitated environment with realistic injections. Each engagement includes a comprehensive performance report highlighting strengths and opportunities for improvement. By transforming strategy into practice, SANS Cyber Crisis Exercises validate response plans, strengthen cross-functional coordination, and elevate leadership decision-making. Ensure your organization is not reacting for the first time when a crisis strikes but executing a well-rehearsed response.
In-Person
Security teams are inundated with new vulnerabilities, threat advisories, and patching priorities every day, yet only a small percentage of CVEs become actively exploited in the wild. Drawing on insights from CrowdSec's global network of more than 500,000 connected systems, this session will examine how attackers are identifying, weaponizing, and exploiting vulnerabilities at scale. Attendees will gain a data-driven perspective on which vulnerabilities are attracting the most attention from threat actors, how quickly exploitation follows disclosure, and the key trends shaping today's threat landscape. The session will provide practical insights to help security leaders better prioritize remediation efforts, focus resources on the risks that matter most, and make more informed vulnerability management decisions.
Philippe Humeau, CEO – CrowdSec
In-Person
Cyber resilience cannot be achieved by organisations acting alone. It requires trusted cooperation between government, critical sectors, businesses, technology providers and citizens. Drawing on Belgium’s experience, Miguel De Bruycker will examine how a national cybersecurity authority can turn threat intelligence, incident reporting and public-private collaboration into practical protection at scale. He will share lessons from initiatives including targeted early warning, Safeonweb, the Belgian Anti-Phishing Shield and the CyberFundamentals Framework, illustrating how shared information can lead to faster preventive action and measurable impact. The session will explore the governance, trust and operational capabilities needed to build a resilient national cyber ecosystem and identify practical elements that security leaders can apply within their own organisations, sectors and supply chains.
Miguel De Bruycker, Managing Director – CCB Belgium
In-Person
AI is reshaping the cybersecurity landscape, but who actually controls the AI you rely on? A frontier model constitutes a completely new element in the IT stack that can be subject to many novel attack vectors: what strategies can you put in place to mitigate them? Some tech leaders state that the entire cybersecurity ecosystem has to be redesigned from the grounds up in order to respond to these challenges. Mario Beccia breaks down the five layers of AI cybersecurity, from training data to end-user application, and maps the strategic dependencies hidden in each. Drawing on his experience as Former NATO Deputy CIO, he connects AI frontier models architecture to defence and cybersecurity posture, providing a coherent picture. A sharp, strategic perspective on what it truly means to own (or not own) the AI challenges hiding in your systems
Mario Beccia, Former Deputy CIO – NATO
In-Person
In-Person
Dr Megan Edwards, Director of Cyber Readiness and Operations – NATO
In-Person
Based on a number of spectacular cases in the past years, digital sovereignty has appeared on the agenda of many boards and executive meetings. Security leaders have experience with business continuity and security risk management and are also asked to balance innovation with the need for greater control over the supply chain in which the organisation navigates. In this session Marc Vael will shed light on what digital sovereignty means for cybersecurity today and tomorrow and how security leaders help build digital resilience in an increasingly complex and fast-moving environment.
Marc Vael, Chief Digital Trust Officer – Esko
In-Person
In-Person
European cyber policy is entering a more strategic and assertive phase. The focus is shifting beyond compliance towards resilience by design, secure technology and supply chains, stronger collective response capabilities, and greater European cyber sovereignty. Despina will explore the forces shaping that next chapter. From geopolitical instability and systemic supply-chain risk to AI, emerging technologies and the growing interdependence between governments and industry. Where is policy heading? How are expectations of organisations and their leaders changing? Where are new operational pressures likely to emerge? Europe is raising the bar. The question is whether security leaders can stay ahead of it.
Despina Spanou, Deputy Director-General, Directorate-General for Communications Networks, Content and Technology (DG CONNECT) - European Commission
In-Person
Drawing on the Darwinian idea of “survival of the fittest,” organizational fitness today is no longer defined by preventing every attack. Instead, resilient enterprises shift from a narrow defense mindset to a broader continuity‑focused approach. Fitness is measured by the ability to anticipate, withstand, recover from, and adapt to adverse conditions. This shift is accelerated by AI, which now amplifies every phase of the kill chain: expanding attacker speed, scale, and sophistication. The session examines how AI reshapes the overall risk landscape and provides leaders with a 20‑point action plan to strengthen cyber resilience and fight back effectively.
Dr Manfred Boudreaux-Dehmer, Former CIO & CISO - NATO
In-Person
In-Person