SEC536: Adversarial AI - Penetration Testing AI Systems

In-Person
SANS Cyber Crisis Exercises are immersive, scenario-based experiences that prepare organizations to navigate today’s complex cyber threat landscape. Designed for technical teams, business leaders, and executive stakeholders, these exercises replicate real-world cyber incidents in a controlled, facilitated environment with realistic injections. Each engagement includes a comprehensive performance report highlighting strengths and opportunities for improvement. By transforming strategy into practice, SANS Cyber Crisis Exercises validate response plans, strengthen cross-functional coordination, and elevate leadership decision-making. Ensure your organization is not reacting for the first time when a crisis strikes but executing a well-rehearsed response.
In-Person
In-Person
What strategies have cyber leaders used to successfully influence boards, CIOs, and executive stakeholders and what approaches have fallen short? Through practical lessons and real-world experiences, attendees will gain insight into communicating cyber risk in business terms, building executive trust, navigating competing priorities, and driving meaningful action at the leadership level. The discussion will focus on what today’s senior leaders expect from cybersecurity executives and how leaders can strengthen their executive presence and influence.
Emma Smith, CISO - Vodafone
In-Person
How can cyber service retainers strengthen incident response readiness and resilience during major cyber attacks? This session will examine the role of government support versus private-sector response capabilities, when organisations should engage external partners, and how senior leaders can make informed decisions before, during, and after an incident. Attendees will gain practical insights into building effective response strategies, managing stakeholder expectations, and aligning retainer services with organizational risk and business priorities.
Jules Gascoigne, CISO – Transport for London (TFL)
In-Person
Cybersecurity has transformed from a technical discipline focused on protecting IT systems into a strategic business function that influences organisational resilience, reputation, and growth. As cyber threats have become more sophisticated, organisations more interconnected, and technology more deeply embedded in every aspect of business, the expectations placed on security leaders have changed dramatically. Today's cybersecurity leaders must navigate evolving threats, shifting business priorities, talent shortages, increasing reliance on third parties, and the growing need to communicate risk in a way that resonates with executives and boards. Aart Jochem shares the lessons that emerge from leading cybersecurity through periods of significant change. Reflecting on real world experiences, he will examine the common mistakes organisations continue to make, what consistently separates successful security programmes from the rest, and why leadership, culture, and sound judgement often have a greater impact than technology alone
Aart Jochem, CISO - Centric
In-Person
In-Person
With Ciaran Martin and Lisa Forte (Partner - Red Goat Cyber Security LLP)
In-Person
AI is transforming the way organisations operate, and cybersecurity leaders must rethink how their teams are structured, governed, and positioned to support the business. This session will explore how AI is changing the security operating model, from governance and risk management to workforce capability, new ways of working, and cross-functional collaboration. Drawing on practical leadership experience, Renata will share how security leaders can evolve their organisations to enable innovation, manage emerging risks, and ensure cybersecurity remains a strategic business partner in an AI-driven future.
Renata Vincoletto, CISO – Civica
In-Person
In-Person
In-Person