SEC536: Adversarial AI - Penetration Testing AI Systems

The modern supply chain is no longer just a network of physical goods and software dependencies. Instead, it is increasingly an ecosystem powered by artificial intelligence. As vendors embed AI deeper into their operations, they unwittingly expand your attack surface along with them.
This presentation explores the dangerous convergence of supply chain risk and AI-driven vulnerabilities, examining how threat actors are now targeting not just code repositories or software updates, but the AI models, training data, and inference pipelines woven into your trusted partners' systems as well as your own.
From model poisoning and adversarial manipulation to shadow AI deployments and opaque third-party integrations, this session challenges security professionals and business leaders alike to not only rethink vendor risk management for an era where your supplier's AI is now your problem, but also equips them with the frameworks and strategies needed to fight back.
In-Person
As cyber threats targeting industrial environments continue to increase, the ability to conduct effective OT Cyber Security Risk Assessments is becoming an essential organizational capability. Whether driven by regulatory requirements, investment decisions, operational resilience objectives, or risk reduction initiatives, these assessments provide critical insight into an organization's cyber exposure and security priorities.
Yet conducting a meaningful assessment is often easier said than done. Limited resources, operational constraints, and a shortage of experienced OT security professionals can make the process challenging. This session provides a practical guide to preparing, executing, and reporting an OT Cyber Security Risk Assessment using the IEC 62443-3-2 methodology. Through proven approaches, common pitfalls, and real-world case studies, attendees will learn how to deliver assessments that produce actionable, risk-based outcomes and support informed business decisions.
In-Person