Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
Foundations: Threat Models for Agentic AI
- Categorizing agentic threats: misuse, escalation, data leakage, and supply-chain risks.
- Understanding adversary profiles and attacker capabilities tailored to autonomous agents.
- Mapping key assets, trust boundaries, and critical control points specific to agent operations.
Governance, Policy, and Risk Management
- Implementing governance frameworks for agentic systems, including roles, responsibilities, and approval gates.
- Crafting policies for acceptable use, escalation rules, data handling, and auditability.
- Addressing compliance considerations and collecting evidence for rigorous audits.
Non-Human Identity & Authentication for Agents
- Defining agent identities using service accounts, JWTs, and short-lived credentials.
- Applying least-privilege access patterns and implementing just-in-time credentialing.
- Managing the identity lifecycle, including rotation, delegation, and revocation strategies.
Access Controls, Secrets, and Data Protection
- Establishing fine-grained access control models and capability-based patterns for agents.
- Managing secrets with encryption-in-transit and at-rest, alongside data minimization practices.
- Safeguarding sensitive knowledge sources and PII from unauthorized agent access.
Observability, Auditing, and Incident Response
- Developing telemetry for agent behavior, including intent tracing, command logs, and provenance.
- Integrating with SIEM systems, setting alerting thresholds, and ensuring forensic readiness.
- Creating runbooks and playbooks for managing agent-related incidents and containment.
Red-Teaming Agentic Systems
- Planning red-team exercises with defined scope, rules of engagement, and safe failover protocols.
- Applying adversarial techniques such as prompt injection, tool misuse, chain-of-thought manipulation, and API abuse.
- Executing controlled attacks to measure exposure and assess impact.
Hardening and Mitigations
- Deploying engineering controls like response throttles, capability gating, and sandboxing.
- Implementing policy and orchestration controls, including approval flows, human-in-the-loop mechanisms, and governance hooks.
- Applying model and prompt-level defenses through input validation, canonicalization, and output filters.
Operationalizing Safe Agent Deployments
- Adopting deployment patterns such as staging, canary, and progressive rollout for agents.
- Enforcing change control, testing pipelines, and pre-deployment safety checks.
- Coordinating cross-functional governance across security, legal, product, and operations teams.
Capstone: Red-Team / Blue-Team Exercise
- Executing a simulated red-team attack against a sandboxed agent environment.
- Defending, detecting, and remediating as the blue team using established controls and telemetry.
- Presenting findings, remediation plans, and necessary policy updates.
Summary and Next Steps
Requirements
- A strong foundation in security engineering, system administration, or cloud operations.
- Proficiency in AI/ML concepts and a clear understanding of large language model (LLM) behavior.
- Practical experience with identity & access management (IAM) and secure system design principles.
Target Audience
- Security engineers and red-team specialists.
- AI operations and platform engineers.
- Compliance officers and risk management professionals.
- Engineering leads overseeing agent deployments.
Testimonials (1)
inventory and identifying the different risk exposures within AI