SEC536: Adversarial AI - Penetration Testing AI Systems


Artificial intelligence is already embedded across industries, often quietly and without clear accountability, but in healthcare, mistakes carry a uniquely human cost. This talk walks through an escalating series of AI use cases, beginning with low-risk administrative support and documentation tools, and progressing into clinical decision support where bias, drift, and over-reliance begin to shape patient outcomes. It then examines semi-autonomous and autonomous systems, such as treatment recommendations and adaptive hospital operations, where failures can cascade across patients and care teams. At the highest risk, we explore AI influencing triage, coverage decisions, population health, and mental health interventions, where opacity and lack of contestability introduce profound ethical, clinical, and societal risks. Rather than arguing against AI, this session provides a risk-aware framework to help healthcare leaders, clinicians, and technologists determine where AI is appropriate, where it must be constrained, and where deployment may be fundamentally unsafe without new safeguards.
Virtual
This interactive cyber event walkthrough examines both Left of Boom strengthening security culture, privacy protections, planning, and cross-functional readiness and Right of Boom… coordinating patient care, technical response, privacy and legal obligations, and communications during a breach.
Through a realistic healthcare data-breach scenario, participants will explore how preparation can protect patient privacy, preserve trust, and guide the organization through its worst day.
Virtual
Hospitals are no longer just healthcare IT environments, they are cyber-physical systems that include IT, OT, IoMT, clinical platforms, facilities infrastructure, cloud services, vendors, and AI-enabled workflows. When any one of these layers fails, the consequences aren't confined to a network; they extend into patient safety, care access, financial stability, and organizational trust, as the Change Healthcare incident made clear on a national scale.
Too often, cybersecurity is framed in terms of protecting confidentiality, availability, and integrity of systems, networks, and data. We lose site of the core mission, which for hospitals is to provide quality and timely care – period.
This session challenges healthcare security leaders to rethink what "OT" really means in a hospital setting, not simply as industrial control systems, but as any technology whose failure or compromise could compromise the mission and prevent, degrade, or delay patient care.
Ultimately, the goal isn't to protect everything equally, it’s to identify risk to, and stemming from, any of the cyber-physical systems that make up a modern healthcare environment and prioritize cybersecurity measures to protect what matters most.This session explores how security programs can shift from broad, undifferentiated protection to a resilience-focused strategy that keeps care delivery safe even under degraded conditions.
Virtual
Cybersecurity risk isn't a side dish—it belongs at the head table of enterprise risk management, right alongside the clinical, operational, and financial risks healthcare leaders navigate every day. In this session, Ian Frist, SANS Instructor, explores how organizations can stop treating cyber risk as a siloed technical concern and start integrating it into their broader risk appetite framework. Using real-world stories from the trenches (without naming names), Ian will unpack the consequences of misaligned appetites—where security teams over-restrict or under-protect due to unclear enterprise priorities. He’ll challenge the common misconception that cybersecurity risk appetite is just about controls and compliance, and show how it’s really about leadership, business context, and strategic clarity.
Attendees will leave with:
Whether you’re a seasoned GRC leader or just pulling up a chair to the risk table, this session will help you bring your appetite—and leave with a full plate of actionable insights.
Virtual
Breakout time is down to roughly 29 minutes, and the chain that gets there now runs largely without a human in it. Every defensive playbook assumes one: a human attacker to detect, a human analyst to approve, a human pace to respond at. That assumption is the vulnerability. This talk walks what breaks, patch cycles, incident response, the SOC, the annual pentest, and what replaces each. Not the old play faster. A different play.
Virtual
Virtual