SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsI spent six months redesigning a security team's materials. New structure, clearer guidance, knowledge organised around the questions people ask. It looked great. Within six months, the team reverted to blocking behaviours. We'd rearranged the furniture without changing how security saw itself. That failure taught me something most security culture programmes miss. We spend effort on the visible layer: policies, awareness campaigns, reporting dashboards. When nothing sticks, we blame "the culture." But the root cause is deeper: the security function's own identity. How a security team defines its purpose shapes every interaction the organisation has with it. Existing frameworks target the awareness programme and its maturity. This talk targets what sits beneath: the security team's self-concept. "We protect the organisation" and "we serve the organisation" produce completely different behaviours, metrics, and relationships with the business. I'll introduce a sequenced model for identity-first culture change, tested across two organisations: a technology consultancy and a UK government body. The sequence matters. Change identity, then incentives, then narratives, then systems. The visible behaviours follow. Reverse that order (start with systems, hope behaviours stick) and you get my failure story. I'll share specific artefacts: persona cards for security's customers, service menus that replaced document libraries, and the metrics that replaced "exceptions denied." I'll address the risk nobody calculates: the cost of security information not reaching the people who need it. You'll leave with: A five-step sequence for identity-first culture change A customer experience audit you can run next week Measurement approaches that show the shift is working Language for making the case to leadership, even if you don't set the metrics yourself


Lee Richardson focuses on strategic security leadership across UK government, critical national infrastructure, and regulated sectors.
Read more about Lee Richardson