Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Foundations: Threat Models for Agentic AI
- Categorizing agentic threats, including misuse, escalation, data leakage, and supply-chain risks.
- Profiling adversaries and understanding attacker capabilities specifically targeting autonomous agents.
- Mapping critical assets, trust boundaries, and key control points within agent architectures.
Governance, Policy, and Risk Management
- Establishing governance frameworks for agentic systems, defining roles, responsibilities, and approval gates.
- Crafting policies that address acceptable use, escalation rules, data handling, and auditability.
- Addressing compliance requirements and strategies for collecting audit evidence.
Non-Human Identity & Authentication for Agents
- Structuring agent identities using service accounts, JWTs, and short-lived credentials.
- Applying least-privilege access patterns and implementing just-in-time credentialing.
- Managing the identity lifecycle, including rotation, delegation, and revocation strategies.
Access Controls, Secrets, and Data Protection
- Implementing fine-grained access control models and capability-based patterns for agents.
- Managing secrets, ensuring encryption-in-transit and at-rest, and practicing data minimization.
- Safeguarding sensitive knowledge sources and PII from unauthorized agent access.
Observability, Auditing, and Incident Response
- Developing telemetry for agent behavior, focusing on intent tracing, command logs, and provenance.
- Integrating with SIEM, setting alerting thresholds, and maintaining forensic readiness.
- Creating runbooks and playbooks for managing agent-related incidents and containment.
Red-Teaming Agentic Systems
- Planning red-team exercises, defining scope, rules of engagement, and safe failover procedures.
- Utilizing adversarial techniques such as prompt injection, tool misuse, chain-of-thought manipulation, and API abuse.
- Executing controlled attacks to measure potential exposure and impact.
Hardening and Mitigations
- Implementing engineering controls like response throttles, capability gating, and sandboxing.
- Establishing policy and orchestration controls, including approval flows, human-in-the-loop checks, and governance hooks.
- Deploying model and prompt-level defenses such as input validation, canonicalization, and output filters.
Operationalizing Safe Agent Deployments
- Adopting deployment patterns such as staging, canary, and progressive rollout for agents.
- Enforcing change control, testing pipelines, and pre-deploy safety checks.
- Coordinating cross-functional governance among security, legal, product, and ops teams.
Capstone: Red-Team / Blue-Team Exercise
- Executing a simulated red-team attack against a sandboxed agent environment.
- Acting as the blue team to defend, detect, and remediate using established controls and telemetry.
- Presenting findings, a detailed remediation plan, and necessary policy updates.
Summary and Next Steps
Requirements
- A strong foundation in security engineering, system administration, or cloud operations.
- Proficiency in AI/ML concepts and an understanding of large language model (LLM) behaviors.
- Practical experience with identity & access management (IAM) and the principles of secure system design.
Target Audience
- Security engineers and red-team specialists.
- AI operations and platform engineers.
- Compliance officers and risk management professionals.
- Engineering leaders accountable for agent deployment strategies.
21 Hours
Testimonials (1)
inventory and identifying the different risk exposures within AI