Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Foundations: Threat Modelling for Agentic AI
- Categories of agentic threats: misuse, privilege escalation, data leakage, and supply-chain risks.
- Adversary profiles and attacker capabilities specifically relevant to autonomous agents.
- Mapping assets, trust boundaries, and critical control points for agent operations.
Governance, Policy, and Risk Management
- Governance frameworks for agentic systems, including roles, responsibilities, and approval gates.
- Policy design covering acceptable use, escalation rules, data handling, and auditability.
- Compliance considerations and strategies for evidence collection during audits.
Non-Human Identity & Authentication for Agents
- Creating identities for agents using service accounts, JWTs, and short-lived credentials.
- Least-privilege access patterns and just-in-time credentialing methods.
- Strategies for identity lifecycle management, rotation, delegation, and revocation.
Access Controls, Secrets, and Data Protection
- Fine-grained access control models and capability-based patterns for agents.
- Secrets management, encryption in-transit and at-rest, and data minimisation practices.
- Safeguarding sensitive knowledge sources and PII from unauthorised agent access.
Observability, Auditing, and Incident Response
- Designing telemetry for agent behaviour, including intent tracing, command logs, and provenance.
- SIEM integration, alerting threshold configuration, and forensic readiness.
- Developing runbooks and playbooks for handling agent-related incidents and containment.
Red-Teaming Agentic Systems
- Planning red-team exercises: defining scope, rules of engagement, and safe failover procedures.
- Adversarial techniques such as prompt injection, tool misuse, chain-of-thought manipulation, and API abuse.
- Executing controlled attacks to measure exposure and impact.
Hardening and Mitigations
- Engineering controls including response throttling, capability gating, and sandboxing.
- Policy and orchestration controls such as approval flows, human-in-the-loop mechanisms, and governance hooks.
- Model and prompt-level defences: input validation, canonicalisation, and output filtering.
Operationalising Safe Agent Deployments
- Deployment patterns for agents, including staging, canary, and progressive rollout strategies.
- Change control, testing pipelines, and pre-deployment safety checks.
- Cross-functional governance involving security, legal, product, and operations playbooks.
Capstone: Red-Team / Blue-Team Exercise
- Execute a simulated red-team attack against a sandboxed agent environment.
- Defend, detect, and remediate as the blue team, utilising established controls and telemetry.
- Present findings, remediation plans, and proposed policy updates.
Summary and Next Steps
Requirements
- A strong foundation in security engineering, system administration, or cloud operations.
- Familiarity with AI/ML concepts and the behaviour of large language models (LLMs).
- Practical experience with Identity & Access Management (IAM) and secure system design.
Target Audience
- Security engineers and red-team specialists.
- AI operations and platform engineers.
- Compliance officers and risk managers.
- Engineering leads overseeing agent deployments.
21 Hours
Testimonials (1)
inventory and identifying the different risk exposures within AI