SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact Us
We check boxes. We run compliance scans. We hold meetings that feel like progress. But how much of what we call security actually reduces risk—and how much of it is just performance?
This session pulls back the curtain on the everyday rituals we mistake for security: the audits that change nothing, the policies nobody reads, the dashboards built to reassure rather than inform. Through sharp real-world examples and a healthy dose of humor, you will learn to spot security theater in your own environment — and leave with practical ways to swap performance for actual protection.
Ideal for CISOs, security managers, GRC and audit teams, and practitioners tired of reporting on work that does not move real risk.


Jan D’Herdt is a SANS Certified Instructor teaching LDR512 and SEC566. With experience across Deloitte, IBM, and UCB, he helps organizations implement and transform the CISO organization, and align cybersecurity with governance and business risk.
Read more about Jan D'Herdt