SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsIndustrial Control Systems rarely fail because of “advanced hackers.” They fail because governance, engineering, and security do not meet where real work happens. In this session, we will deconstruct real-world ICS and OT security incidents drawn from audits, incident reviews, and post-incident remediation efforts across industrial environments. Each case shows how small, everyday decisions - vendor access, asset visibility gaps, emergency bypasses, weak change management - cascade into exploitable conditions. Rather than focusing on tools or fear-based threat narratives, this talk maps each incident directly to practical defensive actions aligned with the SANS ICS 5 Critical Controls, showing what actually prevented recurrence and what failed despite good intentions. Attendees will leave with concrete, immediately applicable steps to strengthen ICS environments without disrupting operations, including governance patterns that work on the plant floor, not just on paper.


Elena Bobkova audits and consults headquarters of some of the world's largest enterprises, working directly with security controls, incident response processes, and continuous improvement programs.
Read more about Elena Bobkova





