SEC536: Adversarial AI - Penetration Testing AI Systems

In-Person
SANS Cyber Crisis Exercises are immersive, scenario-based experiences that prepare organizations to navigate today’s complex cyber threat landscape. Designed for technical teams, business leaders, and executive stakeholders, these exercises replicate real-world cyber incidents in a controlled, facilitated environment with realistic injections. Each engagement includes a comprehensive performance report highlighting strengths and opportunities for improvement. By transforming strategy into practice, SANS Cyber Crisis Exercises validate response plans, strengthen cross-functional coordination, and elevate leadership decision-making. Ensure your organization is not reacting for the first time when a crisis strikes but executing a well-rehearsed response.
In-Person
In-Person
What does it take to create lasting impact in cyber security? In this session, Emma Smith shares practical lessons from working with boards and senior leaders in complex, fast-moving environments. The session will explore how to earn executive trust, communicate cyber risk in language that resonates, and turn conversation into meaningful action. Expect honest insights into what works, what doesn't, and the leadership behaviours that deliver lasting impact in a role with no finish line.
Emma Smith, Global CISO - Vodafone
In-Person
How can cyber service retainers strengthen incident response readiness and resilience during major cyber attacks? This session will examine the role of government support versus private-sector response capabilities, when organisations should engage external partners, and how senior leaders can make informed decisions before, during, and after an incident. Attendees will gain practical insights into building effective response strategies, managing stakeholder expectations, and aligning retainer services with organizational risk and business priorities.
Jules Gascoigne, CISO – Transport for London (TFL)
In-Person
Cybersecurity has transformed from a technical discipline focused on protecting IT systems into a strategic business function that influences organisational resilience, reputation, and growth. As cyber threats have become more sophisticated, organisations more interconnected, and technology more deeply embedded in every aspect of business, the expectations placed on security leaders have changed dramatically. Today's cybersecurity leaders must navigate evolving threats, shifting business priorities, talent shortages, increasing reliance on third parties, and the growing need to communicate risk in a way that resonates with executives and boards. Aart Jochem shares the lessons that emerge from leading cybersecurity through periods of significant change. Reflecting on real world experiences, he will examine the common mistakes organisations continue to make, what consistently separates successful security programmes from the rest, and why leadership, culture, and sound judgement often have a greater impact than technology alone
Aart Jochem, CISO - Centric
In-Person
In-Person
With Ciaran Martin and Lisa Forte (Partner - Red Goat Cyber Security LLP)
In-Person
AI is transforming the way organisations operate, and cybersecurity leaders must rethink how their teams are structured, governed, and positioned to support the business. This session will explore how AI is changing the security operating model, from governance and risk management to workforce capability, new ways of working, and cross-functional collaboration. Drawing on practical leadership experience, Renata will share how security leaders can evolve their organisations to enable innovation, manage emerging risks, and ensure cybersecurity remains a strategic business partner in an AI-driven future.
Renata Vincoletto, CISO – Civica
In-Person
In-Person
In-Person