Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Foundations: Threat Models for Agentic AI
- Classifying agentic threats: misuse, privilege escalation, data leakage, and supply-chain vulnerabilities.
- Understanding adversary profiles and attacker capabilities relevant to autonomous agents.
- Mapping assets, defining trust boundaries, and identifying critical control points for agents.
Governance, Policy, and Risk Management
- Establishing governance frameworks for agentic systems, including roles, responsibilities, and approval gates.
- Designing policies for acceptable use, escalation protocols, data handling, and auditability.
- Addressing compliance requirements and collecting evidence for audits.
Non-Human Identity & Authentication for Agents
- Creating identities for agents using service accounts, JWTs, and short-lived credentials.
- Applying least-privilege access patterns and just-in-time credentialing strategies.
- Managing the identity lifecycle, including rotation, delegation, and revocation.
Access Controls, Secrets, and Data Protection
- Implementing fine-grained access control models and capability-based patterns for agents.
- Managing secrets, encryption in transit and at rest, and enforcing data minimization.
- Safeguarding sensitive knowledge sources and PII from unauthorized agent access.
Observability, Auditing, and Incident Response
- Designing telemetry for agent behavior, including intent tracing, command logging, and provenance tracking.
- Integrating with SIEM tools, setting alerting thresholds, and ensuring forensic readiness.
- Developing runbooks and playbooks for managing agent-related incidents and containment.
Red-Teaming Agentic Systems
- Planning red-team exercises with defined scope, rules of engagement, and safe failover mechanisms.
- Employing adversarial techniques such as prompt injection, tool misuse, chain-of-thought manipulation, and API abuse.
- Executing controlled attacks to measure exposure and impact.
Hardening and Mitigations
- Implementing engineering controls like response throttles, capability gating, and sandboxing.
- Applying policy and orchestration controls, including approval flows, human-in-the-loop mechanisms, and governance hooks.
- Utilizing model and prompt-level defenses such as input validation, canonicalization, and output filtering.
Operationalizing Safe Agent Deployments
- Adopting deployment patterns such as staging, canary releases, and progressive rollouts for agents.
- Establishing change control, testing pipelines, and pre-deployment safety checks.
- Fostering cross-functional governance through security, legal, product, and operations playbooks.
Capstone: Red-Team / Blue-Team Exercise
- Conducting a simulated red-team attack against a sandboxed agent environment.
- Defending, detecting, and remediating as the blue team using established controls and telemetry.
- Presenting findings, a remediation plan, and recommended policy updates.
Summary and Next Steps
Requirements
- A strong foundation in security engineering, system administration, or cloud operations.
- Working knowledge of AI/ML concepts and the behavior of large language models (LLMs).
- Hands-on experience with identity & access management (IAM) and secure system design.
Target Audience
- Security engineers and red-team specialists.
- AI operations and platform engineers.
- Compliance officers and risk management professionals.
- Engineering leads overseeing agent deployments.
21 Hours
Testimonials (1)
inventory and identifying the different risk exposures within AI