SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact Us
For years, critical infrastructure organizations have built their cybersecurity strategies around a familiar set of assumptions: cyber incidents are isolated events, communications remain available, response resources can scale, mutual aid will arrive, and recovery will be measured in days. Today’s nation-state threat landscape is exposing the limits of those assumptions.
As organizations face increasingly coordinated and persistent threats, preparedness must evolve beyond preventing cyber incidents to include sustaining operations, making decisions under degraded conditions, coordinating across the enterprise, and recovering when traditional support systems may be delayed or unavailable. The challenge is no longer simply defending critical infrastructure - it’s understanding what organizations should prioritize before, during, and after a nation-state campaign, and building the capabilities to support those priorities.
Join Tim Conway, Brian Harrell, Mark Bristow, and Robert M. Lee for an executive roundtable exploring how critical infrastructure leaders should rethink preparedness in response to a changing nation-state threat landscape. Together, they’ll discuss where organizations should focus their people, planning, and investments, examine the organizational capabilities needed to prepare for prolonged disruption, and share practical guidance and insights to help leaders rethink their preparedness priorities and build the capabilities needed to prepare for what’s next.


SANS Fellow Tim Conway, co-author of ICS456, ICS310, and ICS612, blends decades of hands-on ICS/OT security and compliance expertise with ongoing frontline consulting, helping students turn complex industrial challenges into practical skills.
Learn more

SANS Fellow and Dragos CEO Robert M. Lee, author of ICS515 and FOR578 and co-author of ICS310, teaches from landmark industrial cyber investigations, turning real adversary tradecraft into visibility, detection, and response skills in OT.
Learn more

Brian currently serves as the Vice President and Chief Security Officer (CSO) at FirstEnergy. He is responsible for the company’s cybersecurity (IT and OT), physical security, and business continuity programs.
Learn more

Mark loves the ever-changing landscape of security and views it as a puzzle that must be solved. He especially loves the challenges in ICS security, where the cyber meets the physical. There is no greater success than a safe and effective process.
Learn more