SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsLet's name the thing nobody says out loud: most security awareness officers are the only person on the security team who's never invited into operational conversations. The SOC doesn't ask for your input. GRC doesn't include you in risk assessments. Security Architecture doesn't consult you on control design. You make posters. You send phishing simulations. You wonder if anyone takes you seriously. This workshop exists to change that - permanently! In 120 minutes, you'll build three integration playbooks drawn from real processes we've run across +30 organizations. Not theory. Not "wouldn't it be nice." Actual workflows you can adapt and execute starting Monday. Playbook 1: SOC Partnership. You'll map human risk indicators - role, data access, behavioral risk signals, VIP trust relationships - to alert prioritization in your incident management workflow, giving analysts the context they need and taking low-risk incidents off their plate entirely. You'll design a user self-remediation process that reduces SOC noise by 60%. Playbook 2: GRC Partnership. You'll build a human risk overlay for a real security risk assessment. Most risk registers account for Process and Technology. People are either missing or reduced to "training completed: yes/no." You'll fix that, ensuring risk assessments and associated risk treatment plans reflect actual human risk factors. Playbook 3: Security Architecture Partnership. You'll identify controls that introduce security friction, call out where human risk factors drive exposure, and redesign controls so the secure path is the easy path. You'll leave with three ready-to-deploy playbooks, conversation scripts for approaching each team, and a 90-day integration roadmap. This workshop is for security awareness officers who are done being the poster people and ready to become indispensable partners to their CISO and security team. Take and implement the playbooks that earn you a permanent seat at the table.


Flavius Plesu is the Founder of OutThink, a Human Risk Management platform serving large enterprises.
Read more about Flavius Plesu

Damon has spent 6 years designing security awareness and human risk management programs.
Read more about Damon DePaolo