SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsKey findings:
Across every dimension examined, the paper frames Zero Trust not as a product to install but as an organizational shift that succeeds or fails based on culture and buy-in as much as technology. The consistent theme is that human factors, stakeholder alignment, and change management determine whether a Zero Trust framework actually matures, while the technical architecture itself is the more solvable half of the problem. The paper structures Zero Trust adoption around seven system components: user, devices, network and environment, applications and workloads, data, visibility and analytics, and automation and orchestration, and references CISA's Zero Trust Maturity Model 2.0 as the standard for phased rollout.
More than 80% of all data breaches are attributed to employee error or negligence, and Verizon's 2024 DBIR found humans were involved in 68% of breaches through error or social engineering.
Supply chain attacks go unnoticed for an average of 235 days after the initial entry point, according to IBM's 2023 Cost of a Data Breach Report.
Forrester research found that more than 63% of enterprises struggle to implement Zero Trust frameworks, often due to organizational resistance and poor alignment between security and business risk management rather than purely technical obstacles.
The median cost per BEC breach is $50,000, according to Verizon's 2024 Data Breach Investigations Report.
Gartner predicts only 10% of large enterprises will have a mature and measurable Zero Trust program in place by 2026.


Launched in 1989 as a cooperative for information security thought leadership, it is SANS’ ongoing mission to empower cybersecurity professionals with the practical skills and knowledge they need to make our world a safer place.
Read more about SANS Institute















