SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsFor a long time, Security Awareness and Incident Response teams operated as separate silos. CSIRT handles technical breaches, while Awareness teams lead compliance and education initiatives. However, there is little structured exchange between these functions. This disconnect creates a critical intelligence gap: CSIRT sees the "how" of a breach, but Awareness teams lack the real-world data to prevent the "why." Drawing on my experience at a leading cryptocurrency company, I will provide a framework to establish a data-driven alliance between the Awareness team and CSIRT, enabling companies to move beyond generic training and deploy highly targeted strategies to implement behavioral interventions that make sense for each organization's unique environment. By leveraging real-world incident data, companies can more effectively mitigate a broad spectrum of unintentional insider risks, starting with phishing, but extending to critical vulnerabilities like leaked credentials, unauthorized shadow IT, and social engineering. Attendees will leave with practical strategies to: Initiate the Partnership and Deconstruct the Silos: Tips for Awareness leaders to "speak the language" of the CSIRT to open communication channels and build a recurring “risk sync”. Look Beyond the Inbox: Identifying human risks that go far beyond phishing by leveraging the direct support of CSIRT data. Close The Intelligence Loop: Proven methods for translating technical IR post-mortems into actionable security interventions that provide clear, "human-ready" guidance for your users. Ensure Measurable Impact: KPIs that prove how awareness reduces IR ticket volume, change behavior of the users and improves mean-time-to-remediate (MTTR). Through this partnership, security awareness becomes more deeply embedded into the organizational culture, transforming it from a compliance requirement into a core business value. This data-driven approach provides the clear, operational evidence needed to secure executive buy-in and demonstrate the tangible ROI of human risk management.


Grazielle Alessa (CA1-005 and the CERT Incident Response Process Professional Certificate) is a Sr. Cybersecurity Lead at Mercado Bitcoin, a Brazilian crypto exchange, leading the Blue Team and Security Operations Center.
Read more about Grazielle Alessa