Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Foundations: Threat Modeling for Agentic AI
- Categorizing agentic threats: misuse, privilege escalation, data leakage, and supply-chain vulnerabilities.
- Profiling adversaries and assessing attacker capabilities relevant to autonomous agents.
- Identifying assets, trust boundaries, and essential control points for agent operations.
Governance, Policy, and Risk Management
- Establishing governance frameworks for agentic systems, including roles, responsibilities, and approval gates.
- Crafting policies for acceptable use, escalation protocols, data handling, and auditability.
- Addressing compliance requirements and gathering evidence for audit purposes.
Non-Human Identity & Authentication for Agents
- Creating agent identities using service accounts, JWTs, and ephemeral credentials.
- Applying least-privilege access patterns and just-in-time credential issuance.
- Managing the identity lifecycle, including rotation, delegation, and revocation strategies.
Access Controls, Secrets, and Data Protection
- Implementing fine-grained access control models and capability-based patterns for agents.
- Managing secrets, ensuring encryption in transit and at rest, and practicing data minimization.
- Safeguarding sensitive knowledge bases and PII from unauthorized agent access.
Observability, Auditing, and Incident Response
- Designing telemetry for agent behavior, including intent tracing, command logging, and provenance tracking.
- Integrating with SIEMs, setting alert thresholds, and ensuring forensic readiness.
- Developing runbooks and playbooks for containing and responding to agent-related incidents.
Red-Teaming Agentic Systems
- Planning red-team exercises, defining scope, rules of engagement, and safe failover procedures.
- Employing adversarial techniques such as prompt injection, tool misuse, chain-of-thought manipulation, and API abuse.
- Executing controlled attacks to measure exposure and potential impact.
Hardening and Mitigations
- Implementing engineering controls like response throttling, capability gating, and sandboxing.
- Enforcing policy and orchestration controls through approval flows, human-in-the-loop mechanisms, and governance hooks.
- Applying model and prompt-level defenses via input validation, canonicalization, and output filtering.
Operationalizing Safe Agent Deployments
- Adopting deployment patterns such as staging, canary releases, and progressive rollouts for agents.
- Managing change control, testing pipelines, and pre-deployment safety checks.
- Facilitating cross-functional governance involving security, legal, product, and operations teams.
Capstone: Red-Team / Blue-Team Exercise
- Conduct a simulated red-team attack against a sandboxed agent environment.
- Act as the blue team to defend, detect, and remediate using established controls and telemetry.
- Present findings, outline a remediation plan, and suggest policy updates.
Summary and Next Steps
Requirements
- A strong foundation in security engineering, system administration, or cloud operations.
- Proficiency with AI/ML concepts and an understanding of large language model (LLM) behaviors.
- Practical experience in identity & access management (IAM) and secure system architecture.
Target Audience
- Security engineers and red-team specialists.
- AI operations and platform engineers.
- Compliance officers and risk management professionals.
- Engineering leaders overseeing the deployment of AI agents.
21 Hours
Testimonials (1)
inventory and identifying the different risk exposures within AI