SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact Us
Apply your credits to renew your certifications
Attend a live, instructor-led class at a location near you or remotely, or train on your time over 4 months
Course material is geared for cyber security professionals with hands-on experience
Apply what you learn with hands-on exercises and labs
Drive enterprise resilience and innovation by shaping AI adoption strategy, modernizing cloud security foundations, and preparing for post-quantum disruption.
This type of training, i.e., cloud security from a management perspective, is rare and the quality of this one is definitely amazing.
LDR520: Emerging Trends for Cyber Leaders: AI and Cloud empowers leaders to navigate the complex, interconnected risks of AI and cloud transformation. You will master AI security by establishing robust governance frameworks and building practical implementation roadmaps to defend against modern threats. The course then establishes a critical foundation in cloud security, covering everything from identity and infrastructure protection to advanced data operations and multicloud governance. Finally, you will look ahead to post-quantum cryptography and apply all learned concepts in a comprehensive, executive-level capstone exercise.
LDR520: Emerging Trends for Cyber Leaders: AI and Cloud prepares security leaders to master the strategic and defensive imperatives of artificial intelligence and modern cloud infrastructure. You will begin by building the urgent business case for AI security, establishing robust governance frameworks compliant with NIST, the EU AI Act, and ISO standards. Participants will learn to identify and counter modern vulnerabilities—from the OWASP LLM Top 10 and "Shadow AI" to sophisticated adversarial attacks—while building practical implementation roadmaps covering vendor selection and AI-powered SOC transformation.
With AI strategy established, the program builds critical cloud security foundations for identity management, infrastructure protection, and multi-account architecture, recognizing that modern AI workloads increasingly operate in cloud environments. You will then master cloud data protection, DevSecOps integration, and multicloud governance strategies while learning how AI and cloud security intersect—from securing AI training pipelines to leveraging AI-powered security operations. The course concludes by preparing you to lead post-quantum cryptographic transitions and synthesizing all knowledge in an executive-level capstone where you design a complete enterprise security modernization strategy bridging AI adoption, cloud transformation, and emerging cryptographic threats.
LDR520 equips students with both technical and management expertise using case scenarios, group discussions, and team-based security leadership simulations with embedded real-life technical components. This course is designed to develop cloud/AI security leaders by combining strategic leadership concepts with practical cloud-focused decision-making. About 60 minutes per day is dedicated to these learning experiences using the Cyber42 leadership simulation game. This web application-based game is a continuous exercise where students play to improve security culture, manage budget and schedule, and improve security capabilities at a fictional organization. This puts you in real-world scenarios that spur discussion and critical thinking about situations you will encounter at work.
"Leaders in security organizations often face unprecedented pressure to embrace transformative technologies like artificial intelligence, cloud infrastructure, and next-generation cryptographic standards while simultaneously protecting their organizations from increasingly sophisticated attacks. I designed LDR520 to bridge this critical gap between business innovation and security imperatives. In this course, participants gain access to battle-tested methodologies that enable them to plan and execute strategic secure technology transformations that drive tangible business value. Drawing from real-world scenarios and practical security frameworks refined through years of experience in Global 500 organizations, I guide security leaders through proven approaches to systematically strengthen their organization's security posture while accelerating digital initiatives. By the end of this course, participants will have mastered the strategic decision-making frameworks, stakeholder engagement techniques, and technical implementation strategies necessary to confidently lead their organization's security transformation from initial planning through successful deployment."
- Jason Lam


Jason Lam, SANS Senior Instructor and author of LDR520 and co-author of SEC522, guides cloud and application-security leaders with hands-on, strategic training.
Read more about Jason LamExplore the course syllabus below to view the full range of topics covered in LDR520: Emerging Trends for Cyber Leaders: AI and Cloud.
This section builds the business case for AI security and establishes governance foundations through NIST AI RMF, EU AI Act, and ISO 42001. Practical governance structures and global regulatory perspectives lead into the Executive Playbook, equipping leaders with influence strategies, resistance management, and stakeholder communication for transformation.
Overview
This section builds comprehensive AI governance leadership capability. You will move from understanding the high-stakes business case and AI technology fundamentals through mastering governance frameworks and regulatory requirements to designing practical implementation structures. The Executive Playbook then transforms framework knowledge into leadership action—teaching you to build coalitions, overcome organizational resistance, and communicate governance value to diverse stakeholders. We focus on the "Govern AI" pillar, providing the strategic foundation for Section 2's threat-focused content.
Full Lab Details
Full Topic Details
This section shifts from governance to operational security across three pillars. Safety and Assurance covers bias detection with hands-on auditing. System Security explores OWASP LLM Top 10 vulnerabilities and adversarial attacks. Threat Landscape examines AI-enhanced attacks, while AI-Enabled Defense builds SOC capabilities and investment roadmaps.
Overview
This section transitions from Day 1's governance foundations to operational security excellence. Building on the frameworks and structures already established, you will develop hands-on capabilities across three integrated pillars: Safety and Assurance, AI System Security, and AI-Enabled Defense. Two workshops produce actionable artifacts—bias audit findings and threat models—that translate directly into work products for your organization. By section end, you will have concrete investment roadmaps and implementation priorities grounded in real threat intelligence.
Full Lab Details
Full Topic Details
This section applies the 8-domain maturity framework to four foundational pillars: Identity and Access Management, Secure Infrastructure, Detection and Response, and Security Governance. Executives learn to assess organizational maturity, prioritize security investment, and lead transformation across the domains that define cloud security posture.
Overview
This session translates the maturity framework into leadership decisions across four domains: IAM, Infrastructure, Detection & Response, and Security Governance. Each domain progresses from strategic context through maturity assessment, capability building, case studies, and investment prioritization. Cyber42 exercises place you in the CISO role making consequential decisions under realistic organizational pressure.
Full Lab Details
Full Topic Details
This section completes the maturity framework across four remaining domains: Data Protection, Workload and Application Security, Security Assurance, and Workforce Transformation. A dedicated SaaS operational security module closes the course, equipping leaders to govern the fastest-growing and least-controlled segment of cloud adoption.
Overview
This session extends maturity assessment to data protection, application security, security assurance, and workforce transformation. A closing SaaS module addresses operational security for the fastest-growing cloud segment. Three Cyber42 exercises continue the CISO simulation with decisions spanning encryption strategy, DevSecOps scaling, and assurance program design.
Full Lab Details
Full Topic Details
This section addresses the modern crypto transition to post-quantum security management, a critical future-proofing strategy. It culminates in a capstone exercise where students apply all concepts and skills learned throughout the course in a practical, executive-level scenario.
Overview
In section five, we explore the preparation for the next wave of cryptographic challenges by focusing on post-quantum computing. This section covers the threats, the necessity of a crypto inventory, and strategic planning for migration. It all comes together in an executive-level capstone exercise to apply your holistic security knowledge.
Full Lab Details
Full Topic Details
Important! Bring your own system configured according to these instructions.
A laptop or mobile device with the latest web browser is required to play the Cyber42 leadership simulation game.
The Cyber42 game used in this course is hosted on the ranges.io platform. Students must have a computer that does not restrict access to ranges.io. Corporate machines may have a VPN, intercepting proxy, or egress firewall filter that causes connection issues communicating with third-party websites. Students must be able to configure or disable these services to be able to access the Cyber42 game.
If you have additional questions about the laptop specifications, please contact customer service.
This course is designed for managers, directors, and senior professionals responsible for leading or influencing enterprise decisions around AI adoption, cloud transformation, and emerging security risks. It is ideal for those shaping strategy, governance, and implementation across cybersecurity, risk, and IT functions.
Students should have three to five years of experience in IT and/or cybersecurity. This course covers the core areas of security leadership in migrating workloads to the cloud environment and assumes a basic understanding of technology, networks, and security.
LDR520 bridges SANS Cybersecurity Leadership and SANS Cloud Security curricula, expanding into AI governance, strategic execution, and emerging threats. It prepares leaders to align AI and cloud adoption with enterprise security, compliance, and business strategy.
To continue building depth skills across cybersecurity leadership, vulnerability management, and governance and compliance learners can pair this course with:
This course also is a core part of the Cloud ACE Journey for the Cloud Security Architect role. The 3-course journey helps develop skills in craft strategic blueprints for secure cloud adoption, aligning infrastructure and innovation with regulatory and security mandates. The fully journey includes:
AI strategic imperatives are core priorities that guide organizations in adopting and leveraging artificial intelligence to achieve competitive advantage, manage risk, drive innovation, and ensure responsible implementation.
These include developing business-aligned governance frameworks, understanding regulatory compliance requirements (such as the NIST AI RMF, ISO 42001, and the EU AI Act), and identifying and mitigating emerging threats such as Shadow AI, adversarial machine learning, and deepfake-enabled fraud. For cyber leaders, this means integrating AI into enterprise strategy with a clear understanding of both the innovation potential and the security risks.
Cloud Security Strategy is a comprehensive plan to protect an organization's data, workloads, and infrastructure in cloud environments. It addresses the unique security challenges of cloud computing, focusing on identity management, data protection, configuration security, and continuous monitoring . Effective cloud security strategies are a core responsibility for cloud security leadership tasked with enabling secure digital transformation.
LDR520 equips cybersecurity leaders with the strategic frameworks and decision-making skills needed to govern AI adoption, lead secure cloud transformation, and prepare for future challenges like post-quantum cryptography. You will learn to design risk-informed roadmaps, implement compliant governance models, and communicate effectively with executives. These capabilities are critical for leadership roles driving innovation, managing emerging threats, and aligning cybersecurity strategy with enterprise goals.
Developing cloud security roadmaps, plans and procurement models to mature cloud security.
Explore learning pathResponsible for overseeing and directly managing technology projects. Ensures cybersecurity is built into projects to protect the organization’s critical infrastructure and assets, reduce risk, and meet organizational goals. Tracks and communicates project status and demonstrates project value to the organization.
Explore learning pathResponsible for managing the cybersecurity of a program, organization, system, or enclave.
Explore learning pathDaily focus is on the oversight of technical teams while aligning them to overall business strategies. Includes titles such as Technical Director, Information Security Officer, and CISO.
Explore learning pathDesigns and secures the defensive architecture of secure cloud environments.
Explore learning pathThis role conducts supervises, manages and leads cybersecurity teams and work. Find the SANS courses that map to the Leadership SCyWF Work Role.
Explore learning pathResponsible for leading, coordinating, and the overall success of a defined program. Includes communicating about the program and ensuring alignment with agency or organizational priorities.
Explore learning pathChief Information Security Officers lead cybersecurity initiatives, aligning strategic vision with operational execution, fostering a resilient security culture, and proactively managing risks to safeguard organisational assets and reputation.
Explore learning pathEnroll your team as a group or arrange a private session for your organization. We’ll help you choose the format that fits your goals.
Great course, a lot of material to go through but it really shows the model an organization should follow to increase the security on cloud environments.
The game platform [Cyber42] and challenges are really interesting and add a nice dimension to the class.
Perfect for understanding the inner workings without getting too in the weeds.
Great way to break out of just the technical aspects of cloud and a step towards management level learning.

Get feedback from the world’s best cybersecurity experts and instructors

Choose how you want to learn - online, on demand, or at our live in-person training events

Get access to our range of industry-leading courses and resources