SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsYour AI systems are traveling at Warp 9. Your security defenses are stuck at impulse power. By 2026, enterprises face 109 autonomous agents for every human, threats evolving monthly, 3-6 month technology refresh cycles. Traditional security planning (18-24 month cycles) can't keep up. Based on real-world experience securing AI systems at scale at Salesforce, this talk addresses both the technical patterns that work AND the organizational transformation required to operate at AI speed. Technical: Why three-layer defense (IAM + Perimeter + Guardrails) is mandatory. How API-layer enforcement blocks exfiltration from authenticated agents. Real attack patterns: prompt injection (68.8% violation rate) and supply chain attacks. Which frameworks matter: NIST AI RMF, CSA AI Controls Matrix, OWASP LLM Top 10. Leadership: How to enable safe experimentation through risk-tiered environments. Why engineers should only do new things (repetitive work becomes shared skills). Moving from activity metrics to outcome metrics. Scaling from managing 50 people to supervising 200+ agents. Implementing weekly deployment cadence. Attendees leave with actionable frameworks: three-layer architecture, risk-based experimentation, 60-day fail-fast cycles, outcome metrics, and weekly deployment roadmaps. Target Audience: CISOs, security architects, SOC managers leading AI security at scale


Hakeem Oseni is a Director of Security Operations at Salesforce, where he leads the Cybersecurity Operations Center's SecOps team and drives the company's transformation toward an Agentic SOC.
Read more about Hakeem Oseni










