SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsAt Postman, we recognized that traditional security awareness training was failing. It didn’t make the company safer but it did make our employees cranky. So we decided to take a step back and ask ourselves: How do we stay compliant while respecting employees' time? How do we deliver training that meets people where they are? How do we know it’s working? Our approach flipped training on its head. Instead of forcing everyone through the same mandatory course, we introduced a test-out option: prove you know the material, and you're done. For everyone else, we replaced passive video-and-quiz formats with one-minute micro-modules followed by hands-on experiential assessments. The results were immediate. Employees started vociferously and publicly praising security training — some even asked to take it again. Our security engineers called the positive feedback "genuinely wild." We also ran our first "Phish Fry" during Cybersecurity Awareness Month: a reporting-focused competition that rewarded employees for spotting and flagging threats rather than punishing those who clicked. This talk covers three actionable shifts any security awareness team can make: Offer a test-out. We'll share exactly how we structured ours, the completion data that justified it, and the message it sends to your workforce about respecting their expertise. Replace quizzes with experiential assessments. We'll walk through the difference between recognition-based and application-based testing and why it matters for actual behavior change. Reframe phishing simulations as celebrations, not gotchas. We'll break down the Phish Fry format — the contest mechanics, how we positioned reporting over clicking, and what we'd change next time. You'll leave with a concrete playbook for making these changes in your own program.


Harley Sugarman is the Founder and CEO of Anagram. A longtime cybersecurity enthusiast with a B.S. in Computer Science from Stanford, Harley founded Anagram to fix the industry's biggest gap: user behavior.
Read more about Harley Sugarman

Ashley Savageau is the Security Awareness Manager at Postman, where she leads security awareness and training, as well as Security communications for a global workforce.
Read more about Ashley Savageau