SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals

Industrial environments are not being compromised by deployed AI models, but by uncontrolled AI use by engineers, analysts, and vendors interacting with OT data. This session presents a real world case study where shadow AI introduced new risks to safety, availability, and integrity in an ICS adjacent environment.
Network segmentation is a core requirement of a defensible ICS architecture, yet many OT networks remain flat or rely on segmentation approaches that are difficult to deploy and sustain. This session focuses on SANS Critical Control 2 (Defensible Architecture) and Critical Control 3 (ICS Network Visibility and Monitoring), presenting a practical crawl, walk, run approach to segmentation in industrial environments.
Speaker: Nick Ford | Associate Director, Connected Factory | Raytheon
Many industrial architectures never move beyond diagrams, often dismissed as too complex, too expensive, or too risky for production environments.
Speaker: Prashant | Senior Cyber Security Advisor | Enbridge Inc.
This talk will focus on introducing a novel idea on Consequence-driven Cyber-informed Engineering championed by Idaho National Labs in USA.
We built command-and-control over DNP3. Then we realized we'd solved the wrong problem.
Defenders of industrial control systems are often focused to respond late in the attack lifecycle, after adversaries have already reached sensitive operational environments. This session presents findings from Palo Alto Networks’ OT Threat Research Lab based on large-scale analysis of 2023/2024/2025 security telemetry collected from more than 61,000 firewalls inspecting industrial application traffic.
MITRE recently hosted the Critical Infrastructure Cybersecurity Tabletop Exercise (CICS TTX), bringing together approximately 200 participants from 70 organizations—including federal, state, and local governments, emergency managers, and industry representatives from pipelines, electricity, IT, communications, and rail—across five metropolitan areas.
Speakers: Marco Ayala and Eric Forner
This presentation pulls back the curtain on how a protocol meant to simplify industrial data can instead become a powerful weapon in the wrong hands.
The first 72 hours after an OT-ICS incident are dominated by operational constraints: safety, uptime, vendor dependencies, and limited maintenance windows.
AI is the latest craze that makes the world go round lately, and to satisfy the demand we are witnessing a desperate gold rush of compute. This has transformed data centers from boring server farms into the critical infrastructure of the modern era, diverting supply chains and packing as much compute to feed the LLM machine.
As businesses accelerate AI adoption, the demand for real-time OT data is skyrocketing. This creates a unique challenge: how do we enable AI-driven insights without compromising operational integrity or cybersecurity?
Based on my experience supporting and later leading an OT cybersecurity program, this talk explores the evolution from a NIST Cybersecurity Framework–aligned strategy to a more operations-driven approach built on the SANS Five Critical Controls for OT Cybersecurity.
Speaker: Ryan Sharpnack | Independent Security Researcher IEC 61850 GOOSE (Generic Object-Oriented Substation Event) messages enable millisecond-speed protection relay coordination in electric substations worldwide.
Registration: All students who register for a 4–6 day course will be eligible to play NetWars for free. Registration for this event will be through your SANS Account Dashboard the week of the event.
About ICS NetWars: Focused on factory machinery operations, this experience brings players onto the factory floor, exposing them to the challenges of detecting and defending physical equipment and manufacturing components from cyberattacks.
Registration: All students who register for a 4–6 day course will be eligible to play NetWars for free. Registration for this event will be through your SANS Account Dashboard the week of the event.
About ICS NetWars: Focused on factory machinery operations, this experience brings players onto the factory floor, exposing them to the challenges of detecting and defending physical equipment and manufacturing components from cyberattacks.