SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact Us
Most organizations now find more exposures than they can fix. Continuous discovery, attack surface management, cloud posture tooling, and threat-informed prioritization have helped close the visibility gap that defined exposure management’s early years. But visibility is no longer the finish line. The harder problem is turning findings into fixes.
This track focuses on that next gap: moving from exposure discovery to measurable risk reduction. It brings together practitioners and technology providers addressing the questions teams face across the exposure management lifecycle: Which exposures matter most in your environment? How do you confirm an attack path is real before committing remediation effort? How do you route fixes to the right asset owners, especially when they sit outside security? And how do you prove progress to leadership, boards, and regulators?
Through case studies, practitioner insights, and technology demonstrations, attendees will see how organizations are maturing exposure programs beyond dashboards and backlogs. Participants will leave with practical approaches to reduce prioritization noise, shorten the path from detection to remediation, strengthen accountability with asset owners, and report risk reduction in terms the business understands.


With more than 25 years of experience across security, infrastructure, and program leadership, Jonathan brings practical real-world insight to vulnerability management leadership and training.
Read more about Jonathan Risto