Get in Touch

Course Outline

Day 1 — Agentic AI Security Deep Dive

Session 1 — 09:30 to 10:50 · Recap and Prompt Injection at Depth
  • Rapid recap of the OWASP LLM Top 10 (2025) — establishing an agreed baseline.
  • Advanced prompt injection techniques: indirect injection, multi-turn manipulation, and cross-modal injection.
  • Jailbreak techniques and defensive taxonomies.
  • System prompt leakage and information extraction patterns.
  • Interactive Slido poll: "What is the most sensitive tool your agents have access to today?"

Break — 10:50 to 11:10

Session 2 — 11:10 to 12:30 · Securing AI Pipelines — Data, Models, and RAG
  • Training data integrity: addressing poisoning, backdoors, and provenance.
  • Model supply chain risks: fine-tuning pipelines, adapter models, and registry hygiene.
  • RAG-specific attack surfaces: vector store poisoning, context manipulation, and retrieval attacks.
  • Embedding security: understanding what embeddings leak and how to protect them.
  • Hands-on lab (~30 minutes): Delegates poison a small RAG corpus and subsequently defend it. This is a paired exercise followed by a group debrief.

Lunch — 12:30 to 13:20

Session 3 — 13:20 to 14:40 · OWASP Top 10 for Agentic Applications (2026) — Part 1
  • Agent goal manipulation and objective subversion.
  • Tool-use permission abuse and privilege escalation via tool chains.
  • Memory manipulation: attacks on persistent, episodic, and shared memory.
  • Planning and reasoning exploits.
  • Identity and authentication in agent systems.
  • Short live demo: A goal-manipulation attack against a simple planning agent.

Break — 14:40 to 15:00

Session 4 — 15:00 to 16:30 · OWASP Top 10 for Agentic Applications (2026) — Part 2 + MCP Security
  • MCP (Model Context Protocol) architecture and trust boundaries.
  • MCP server security: authentication, tool scoping, and permission models.
  • Multi-step workflow attacks: chaining, indirect execution, and cascading failures.
  • Cross-agent communication and trust mechanisms.
  • Agent observability and forensic readiness.
  • Day 1 close: each delegate identifies one critical agentic risk within their own tech stack.
  • Q&A

Day 2 — Red-Teaming, Architecture, and Incident Response

Session 1 — 09:30 to 10:50 · AI Red-Teaming — Methodology
  • Understanding AI red-teaming (and what it is not) — distinguishing it from traditional pentesting.
  • Red-teaming frameworks: MITRE ATLAS, OWASP Agentic Top 10 mapping, and NIST AI RMF.
  • Scoping a red-team engagement for an LLM or agent system.
  • Manual techniques: prompt-engineering attacks, jailbreak libraries, and goal-hijacking.
  • Automated tooling landscape: Garak, PyRIT, Promptfoo, and custom harnesses.
  • Ethics, safety, and responsible disclosure for AI vulnerabilities.

Break — 10:50 to 11:10

Session 2 — 11:10 to 12:30 · Hands-On Red-Teaming Lab
  • Extended hands-on lab (~60 minutes): Delegates work in pairs against a prepared target — a multi-step agentic application containing at least three known vulnerabilities. Each pair produces a short red-team report, including attack path, impact assessment, and recommended mitigations.
  • Group share-back and collective debrief.

Lunch — 12:30 to 13:20

Session 3 — 13:20 to 14:40 · Secure Architecture Patterns for Agentic AI in Government
  • Defence-in-depth for agent systems: isolation, sandboxing, and blast-radius reduction.
  • Designing safe tool catalogues: allow-listing, parameter validation, and output inspection.
  • Human-in-the-loop patterns and criteria for requiring confirmation.
  • Sensitive data boundaries: defining where PII and OFFICIAL-SENSITIVE data can and cannot flow.
  • Alignment with UK AI Principles, NIST AI RMF, and ISO/IEC 42001 controls.
  • Architectural case study: a realistic government agentic service walkthrough.

Break — 14:40 to 15:00

Session 4 — 15:00 to 16:30 · Incident Response, Playbook Build, and Close
  • AI-specific incident classes: prompt-injection escalation, tool misuse, data exfiltration via agents, and model-misbehaviour incidents.
  • Detection signals and logging patterns for agent systems.
  • Response playbook structure: containment, eradication, recovery, and lessons learned.
  • Capstone exercise (~45 minutes): Delegates build a one-page agent security playbook for a representative service from their own domain.
  • Implementation planning: 30-day, 60-day, and 90-day actions.
  • Resources, further reading, and next steps.
  • Q&A and course close.

Requirements

  • Proficiency in at least one modern programming language (Python is strongly recommended for laboratory sessions).
  • Prior completion of 'AI Security Fundamentals for Developers' or equivalent working knowledge of the OWASP Top 10 for LLM Applications (2025).
  • Familiarity with REST APIs, basic containerisation concepts, and general secure development practices.
  • Experience with at least one LLM API (such as OpenAI, Anthropic Claude, Azure OpenAI, or similar) is beneficial but not essential.

Target Audience

  • Software engineers and AI/ML engineers constructing agentic or tool-using AI systems.
  • Security engineers and security champions working with AI-enabled products.
  • Platform and DevOps engineers responsible for LLM and agent infrastructure.
  • Technical leads and architects designing AI-powered government services.
  • Individuals who have completed 'AI Security Fundamentals for Developers' or possess equivalent experience.
 14 Hours

Custom Corporate Training

Training solutions designed exclusively for businesses.

  • Customized Content: We adapt the syllabus and practical exercises to the real goals and needs of your project.
  • Flexible Schedule: Dates and times adapted to your team's agenda.
  • Format: Online (live), In-company (at your offices), or Hybrid.
Investment

Price per private group, online live training, starting from 2600 € + VAT*

Contact us for an exact quote and to hear our latest promotions

Provisional Upcoming Courses (Contact Us For More Information)

Related Categories