SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact Us
Attack surface management helps security teams see what is exposed. Vulnerability management helps them identify and address weaknesses. But as assets, findings, and alerts multiply, a harder question remains: Are organizations getting better at reducing the exposures attackers can actually use?
The 2027 SANS Exposure Management Survey examines how organizations turn visibility into action. It explores how teams combine vulnerability data, asset context, threat intelligence, identity risk, cloud posture, business criticality, and attack-path analysis to decide what matters most and drive remediation.
The survey will also investigate the role of AI, automation, continuous threat exposure management (CTEM), and security validation. Are these capabilities helping teams identify exploitable exposures, prioritize more accurately, and confirm that fixes worked? Or are they adding more signals and complexity without improving outcomes?
Beyond technology, the research will look at how these programs work in practice: who owns exposure risk, how security and IT teams coordinate remediation, how exceptions are governed, and which metrics show whether risk is being reduced.
The findings will give security leaders and practitioners benchmarks for evaluating their programs and identifying practical improvements. Ultimately, the research asks: Are organizations getting better at finding exposures—or at eliminating the ones most likely to lead to compromise?
Why Join?


Jonathan Risto is a Principal Instructor at the SANS Institute and Technical Director for the Canadian Cyber Posture Program. Co-author of LDR516: Strategic Vulnerability and Threat Management, he helps leaders turn exposure data into actionable risk programs through frameworks like VMMM and CTEMMM.
Read more about Jonathan Risto