Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Foundations: Threat Models for Agentic AI
- Identifying agentic threats such as misuse, privilege escalation, data leakage, and supply-chain vulnerabilities.
- Analyzing adversary profiles and attacker capabilities specifically targeting autonomous agents.
- Mapping assets, trust boundaries, and critical control points associated with agent operations.
Governance, Policy, and Risk Management
- Implementing governance frameworks for agentic systems, including roles, responsibilities, and approval gates.
- Crafting policies for acceptable use, escalation rules, data handling, and auditability.
- Navigating compliance requirements and collecting evidence for audits.
Non-Human Identity & Authentication for Agents
- Designing agent identities using service accounts, JWTs, and short-lived credentials.
- Applying least-privilege access patterns and just-in-time credentialing.
- Managing the identity lifecycle, including rotation, delegation, and revocation strategies.
Access Controls, Secrets, and Data Protection
- Utilizing fine-grained access control models and capability-based patterns for agents.
- Managing secrets, ensuring encryption-in-transit and at-rest, and practicing data minimization.
- Safeguarding sensitive knowledge sources and PII from unauthorized agent access.
Observability, Auditing, and Incident Response
- Designing telemetry for agent behavior, covering intent tracing, command logs, and provenance.
- Integrating with SIEM, setting alerting thresholds, and ensuring forensic readiness.
- Developing runbooks and playbooks for handling agent-related incidents and containment.
Red-Teaming Agentic Systems
- Planning red-team exercises, defining scope, rules of engagement, and safe failover protocols.
- Exploring adversarial techniques like prompt injection, tool misuse, chain-of-thought manipulation, and API abuse.
- Executing controlled attacks to measure exposure and impact.
Hardening and Mitigations
- Implementing engineering controls such as response throttles, capability gating, and sandboxing.
- Establishing policy and orchestration controls, including approval flows, human-in-the-loop mechanisms, and governance hooks.
- Deploying model and prompt-level defenses through input validation, canonicalization, and output filters.
Operationalizing Safe Agent Deployments
- Applying deployment patterns like staging, canary releases, and progressive rollouts for agents.
- Managing change control, testing pipelines, and pre-deployment safety checks.
- Coordinating cross-functional governance involving security, legal, product, and operations teams.
Capstone: Red-Team / Blue-Team Exercise
- Executing a simulated red-team attack against a sandboxed agent environment.
- Defending, detecting, and remediating threats as the blue team using established controls and telemetry.
- Presenting findings, outlining the remediation plan, and suggesting policy updates.
Summary and Next Steps
Requirements
- A strong foundation in security engineering, system administration, or cloud operations.
- A working knowledge of AI/ML concepts and the behavioral characteristics of large language models (LLMs).
- Hands-on experience with identity & access management (IAM) and secure system design principles.
Target Audience
- Security engineers and red-team specialists.
- AI operations and platform engineers.
- Compliance officers and risk managers.
- Engineering leads overseeing agent deployments.
21 Hours
Testimonials (1)
inventory and identifying the different risk exposures within AI