Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Foundations: Threat Modeling for Agentic AI
- Categories of agentic threats, including misuse, escalation, data leakage, and supply-chain risks
- Analysis of adversary profiles and attacker capabilities relevant to autonomous agents
- Identifying assets, trust boundaries, and critical control points within agent architectures
Governance, Policy, and Risk Management
- Governance frameworks for agentic systems, covering roles, responsibilities, and approval gates
- Policy design focusing on acceptable use, escalation rules, data handling, and auditability
- Compliance requirements and strategies for collecting evidence for audits
Non-Human Identity & Authentication for Agents
- Architecting agent identities using service accounts, JWTs, and short-lived credentials
- Applying least-privilege access patterns and just-in-time credentialing
- Managing identity lifecycles, including rotation, delegation, and revocation strategies
Access Controls, Secrets, and Data Protection
- Implementing fine-grained access control models and capability-based patterns for agents
- Managing secrets, ensuring encryption-in-transit and at-rest, and practicing data minimization
- Safeguarding sensitive knowledge sources and PII from unauthorized agent access
Observability, Auditing, and Incident Response
- Designing telemetry for agent behavior, including intent tracing, command logs, and provenance
- Integrating with SIEM solutions, defining alerting thresholds, and ensuring forensic readiness
- Developing runbooks and playbooks for managing agent-related incidents and containment
Red-Teaming Agentic Systems
- Planning red-team exercises, defining scope, rules of engagement, and safe failover procedures
- Employing adversarial techniques such as prompt injection, tool misuse, chain-of-thought manipulation, and API abuse
- Executing controlled attacks to measure exposure and impact
Hardening and Mitigations
- Implementing engineering controls like response throttles, capability gating, and sandboxing
- Establishing policy and orchestration controls, including approval flows, human-in-the-loop mechanisms, and governance hooks
- Applying model and prompt-level defenses such as input validation, canonicalization, and output filters
Operationalizing Safe Agent Deployments
- Utilizing deployment patterns such as staging, canary releases, and progressive rollouts for agents
- Managing change control, testing pipelines, and pre-deployment safety checks
- Fostering cross-functional governance through playbooks involving security, legal, product, and ops teams
Capstone: Red-Team / Blue-Team Exercise
- Conducting a simulated red-team attack against a sandboxed agent environment
- Defending, detecting, and remediating threats as the blue team using established controls and telemetry
- Presenting findings, remediation plans, and proposed policy updates
Summary and Next Steps
Requirements
- A strong foundation in security engineering, system administration, or cloud operations
- Proficiency in AI/ML concepts and an understanding of large language model (LLM) behavior
- Experience with identity and access management (IAM) and secure system design principles
Target Audience
- Security engineers and professional red-teamers
- AI operations and platform engineers
- Compliance officers and risk managers
- Engineering leads responsible for deploying agent systems
21 Hours
Testimonials (1)
inventory and identifying the different risk exposures within AI