Course Outline
Foundations: Threat Models for Agentic AI
- Categories of agentic threats: misuse, escalation, data leakage, and supply-chain risks.
- Adversary profiles and attacker capabilities unique to autonomous agents.
- Identifying assets, trust boundaries, and critical control points for agent operations.
Governance, Policy, and Risk Management
- Governance frameworks for agentic systems, including roles, responsibilities, and approval gates.
- Policy design covering acceptable use, escalation rules, data handling, and auditability.
- Addressing compliance requirements and collecting evidence for audits.
Non-Human Identity & Authentication for Agents
- Creating identities for agents: utilizing service accounts, JWTs, and short-lived credentials.
- Applying least-privilege access patterns and just-in-time credentialing.
- Managing the identity lifecycle, including rotation, delegation, and revocation strategies.
Access Controls, Secrets, and Data Protection
- Implementing fine-grained access control models and capability-based patterns for agents.
- Managing secrets, ensuring encryption-in-transit and at-rest, and practicing data minimization.
- Safeguarding sensitive knowledge sources and PII from unauthorized agent access.
Observability, Auditing, and Incident Response
- Designing telemetry for agent behavior, including intent tracing, command logs, and provenance.
- Integrating with SIEM tools, setting alerting thresholds, and preparing for forensics.
- Developing runbooks and playbooks for handling agent-related incidents and containment.
Red-Teaming Agentic Systems
- Planning red-team exercises: defining scope, rules of engagement, and safe failover procedures.
- Employing adversarial techniques such as prompt injection, tool misuse, chain-of-thought manipulation, and API abuse.
- Executing controlled attacks to measure exposure and impact.
Hardening and Mitigations
- Implementing engineering controls: response throttles, capability gating, and sandboxing.
- Applying policy and orchestration controls: approval flows, human-in-the-loop mechanisms, and governance hooks.
- Deploying model and prompt-level defenses: input validation, canonicalization, and output filters.
Operationalizing Safe Agent Deployments
- Adopting deployment patterns: staging, canary, and progressive rollout strategies for agents.
- Enforcing change control, testing pipelines, and pre-deploy safety checks.
- Coordinating cross-functional governance: integrating security, legal, product, and ops playbooks.
Capstone: Red-Team / Blue-Team Exercise
- Conducting a simulated red-team attack against a sandboxed agent environment.
- Defending, detecting, and remediating as the blue team by leveraging controls and telemetry.
- Presenting findings, remediation plans, and proposed policy updates.
Summary and Next Steps
Requirements
- A strong foundation in security engineering, system administration, or cloud operations.
- Proficiency with AI/ML concepts and an understanding of large language model (LLM) behavior.
- Hands-on experience with Identity & Access Management (IAM) and secure system design.
Target Audience
- Security engineers and red-team specialists.
- AI operations and platform engineers.
- Compliance officers and risk managers.
- Engineering leads overseeing agent deployments.
Custom Corporate Training
Training solutions designed exclusively for businesses.
- Customized Content: We adapt the syllabus and practical exercises to the real goals and needs of your project.
- Flexible Schedule: Dates and times adapted to your team's agenda.
- Format: Online (live), In-company (at your offices), or Hybrid.
Price per private group, online live training, starting from 4800 € + VAT*
Contact us for an exact quote and to hear our latest promotions
Testimonials (1)
inventory and identifying the different risk exposures within AI