Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Day 1 — Agentic AI Security Deep Dive
Session 1 — 09:30 to 10:50 · Recap and Prompt Injection at Depth
- Rapid recap of the OWASP LLM Top 10 (2025) — establishing an agreed baseline.
- Advanced prompt injection techniques: indirect injection, multi-turn manipulation, and cross-modal injection.
- Jailbreak techniques and defensive taxonomies.
- System prompt leakage and information extraction patterns.
- Interactive Slido poll: "What is the most sensitive tool your agents have access to today?"
Break — 10:50 to 11:10
Session 2 — 11:10 to 12:30 · Securing AI Pipelines — Data, Models, and RAG
- Training data integrity: addressing poisoning, backdoors, and provenance.
- Model supply chain risks: fine-tuning pipelines, adapter models, and registry hygiene.
- RAG-specific attack surfaces: vector store poisoning, context manipulation, and retrieval attacks.
- Embedding security: understanding what embeddings leak and how to protect them.
- Hands-on lab (~30 minutes): Delegates poison a small RAG corpus and subsequently defend it. This is a paired exercise followed by a group debrief.
Lunch — 12:30 to 13:20
Session 3 — 13:20 to 14:40 · OWASP Top 10 for Agentic Applications (2026) — Part 1
- Agent goal manipulation and objective subversion.
- Tool-use permission abuse and privilege escalation via tool chains.
- Memory manipulation: attacks on persistent, episodic, and shared memory.
- Planning and reasoning exploits.
- Identity and authentication in agent systems.
- Short live demo: A goal-manipulation attack against a simple planning agent.
Break — 14:40 to 15:00
Session 4 — 15:00 to 16:30 · OWASP Top 10 for Agentic Applications (2026) — Part 2 + MCP Security
- MCP (Model Context Protocol) architecture and trust boundaries.
- MCP server security: authentication, tool scoping, and permission models.
- Multi-step workflow attacks: chaining, indirect execution, and cascading failures.
- Cross-agent communication and trust mechanisms.
- Agent observability and forensic readiness.
- Day 1 close: each delegate identifies one critical agentic risk within their own tech stack.
- Q&A
Day 2 — Red-Teaming, Architecture, and Incident Response
Session 1 — 09:30 to 10:50 · AI Red-Teaming — Methodology
- Understanding AI red-teaming (and what it is not) — distinguishing it from traditional pentesting.
- Red-teaming frameworks: MITRE ATLAS, OWASP Agentic Top 10 mapping, and NIST AI RMF.
- Scoping a red-team engagement for an LLM or agent system.
- Manual techniques: prompt-engineering attacks, jailbreak libraries, and goal-hijacking.
- Automated tooling landscape: Garak, PyRIT, Promptfoo, and custom harnesses.
- Ethics, safety, and responsible disclosure for AI vulnerabilities.
Break — 10:50 to 11:10
Session 2 — 11:10 to 12:30 · Hands-On Red-Teaming Lab
- Extended hands-on lab (~60 minutes): Delegates work in pairs against a prepared target — a multi-step agentic application containing at least three known vulnerabilities. Each pair produces a short red-team report, including attack path, impact assessment, and recommended mitigations.
- Group share-back and collective debrief.
Lunch — 12:30 to 13:20
Session 3 — 13:20 to 14:40 · Secure Architecture Patterns for Agentic AI in Government
- Defence-in-depth for agent systems: isolation, sandboxing, and blast-radius reduction.
- Designing safe tool catalogues: allow-listing, parameter validation, and output inspection.
- Human-in-the-loop patterns and criteria for requiring confirmation.
- Sensitive data boundaries: defining where PII and OFFICIAL-SENSITIVE data can and cannot flow.
- Alignment with UK AI Principles, NIST AI RMF, and ISO/IEC 42001 controls.
- Architectural case study: a realistic government agentic service walkthrough.
Break — 14:40 to 15:00
Session 4 — 15:00 to 16:30 · Incident Response, Playbook Build, and Close
- AI-specific incident classes: prompt-injection escalation, tool misuse, data exfiltration via agents, and model-misbehaviour incidents.
- Detection signals and logging patterns for agent systems.
- Response playbook structure: containment, eradication, recovery, and lessons learned.
- Capstone exercise (~45 minutes): Delegates build a one-page agent security playbook for a representative service from their own domain.
- Implementation planning: 30-day, 60-day, and 90-day actions.
- Resources, further reading, and next steps.
- Q&A and course close.
Requirements
- Proficiency in at least one modern programming language (Python is strongly recommended for laboratory sessions).
- Prior completion of 'AI Security Fundamentals for Developers' or equivalent working knowledge of the OWASP Top 10 for LLM Applications (2025).
- Familiarity with REST APIs, basic containerisation concepts, and general secure development practices.
- Experience with at least one LLM API (such as OpenAI, Anthropic Claude, Azure OpenAI, or similar) is beneficial but not essential.
Target Audience
- Software engineers and AI/ML engineers constructing agentic or tool-using AI systems.
- Security engineers and security champions working with AI-enabled products.
- Platform and DevOps engineers responsible for LLM and agent infrastructure.
- Technical leads and architects designing AI-powered government services.
- Individuals who have completed 'AI Security Fundamentals for Developers' or possess equivalent experience.
14 Hours
Custom Corporate Training
Training solutions designed exclusively for businesses.
- Customized Content: We adapt the syllabus and practical exercises to the real goals and needs of your project.
- Flexible Schedule: Dates and times adapted to your team's agenda.
- Format: Online (live), In-company (at your offices), or Hybrid.
Price per private group, online live training, starting from 2600 € + VAT*
Contact us for an exact quote and to hear our latest promotions