SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals


With canapés and drinks
Artificial intelligence is now appearing in both sides of modern incidents: from adversary tradecraft attributed to state-backed actors experimenting with AI-assisted operations, to responder tooling embedded directly into investigation workflows. This session aims to examine where AI is genuinely adding value in DFIR today, including triage assistance, query generation, and analyst acceleration in platforms such as the AI-enabled SANS SIFT Workstation. We’ll contrast those gains with areas where AI remains unreliable, misleading, or actively dangerous if trusted without verification.
For many organisations, securing ICS/OT has become a top priority causing a flurry of activity to build up defences in preparation for the next attack. But what is the activity organisations are doing and are they contributing towards safe and reliable operations. This talk explores the benefits and tribulations surrounding these activities along with real-world experiences of self-inflicted pain and blind ignorance that leads to near misses and direct impacts.