The AI Forge · Mastery · F7
AI Security & Red Teaming
OWASP LLM & Agentic Top 10, prompt injection, agent security, defence, incident response
- Duration
- 2 days · 9:00–17:00 each day (13h contact, incl. breaks + lunch)
- Participant level
- Advanced: experienced practitioners
- Format
- Instructor-led attack/defence labs
- Participants
- 8 included · 12 maximum (flexible group size)
- Prerequisite
- F3 + F6 (or equivalent)
- Ecosystem
- Agnostic: any model provider or stack
- Price
- EUR 8,500 (EUR 450 per extra participant)
Amounts in EUR, excl. VAT.
ai-generatedWhat participants will be able to do
- Perform a structured red-team attack on an LLM system
- Identify and mitigate prompt injection and data poisoning
- Build an AI security review checklist for your organisation
- Design and execute an AI incident response plan
Tools & resources
What changes after this module
Security-minded engineers can attack, defend and monitor LLM and agentic systems against the current threat catalogs, building defence-in-depth and an incident capability on principles that outlast specific exploits.
Who should attend
Engineers and data professionals. Advanced: experienced practitioners.
Programme
This agenda is indicative. Content, sequencing, and examples are adapted to your team's context, tools, and objectives.
Before you start
- A laptop with a working development environment and admin rights
- Proficiency in at least one general-purpose language (Python and/or JavaScript/TypeScript)
- A code editor/IDE with an approved AI coding assistant enabled
- An API key for an approved model provider (issued by the company)
- A Git repository and command-line comfort
- Completion of F3 + F6 or equivalent
- An LLM or agentic app you may attack in a safe/sandboxed environment
| Day 1 | 9:00–10:30 | The AI threat landscape: OWASP Top 10 for LLM Apps and the newer Agentic (ASI) Top 10; the “lethal trifecta” (private data + untrusted content + external comms) as the root of injection risk Lab: Threat-model your app: the target you’ll attack and defend across both days: against the LLM and Agentic Top 10, and flag where the lethal trifecta applies (this map ranks every later lab). |
| 10:30–10:45 · ☕ Coffee break | ||
| Day 1 | 10:45–12:30 | Prompt injection & output handling: Direct and indirect injection, data exfiltration, system-prompt leakage, and treating all model output as untrusted Lab: Successfully run direct and indirect injection attacks against your app and document the impact. |
| 12:30–13:30 · 🍽 Lunch break | ||
| Day 1 | 13:30–15:30 | Agentic risks: Goal hijack, tool misuse, excessive agency, memory/context poisoning and unexpected code execution Lab: Exploit an over-privileged tool/agent, then re-scope it to least agency and re-test. |
| 15:30–15:45 · ☕ Coffee break | ||
| Day 1 | 15:45–17:00 | Lab: red-team your app: Run a structured red-team pass Lab: Run a framework-based red-team suite and produce a ranked findings report. |
| Day 2 | 9:00–10:30 | Defence in depth: Least privilege, input/output filtering, guardrails, human approval for high-risk actions; why no single control suffices Lab: Add layered defences (filtering + guardrails + approval) and re-run the red-team to show risk reduction: filtering reduces, containment (least privilege + approval) is what actually stops the trifecta. |
| 10:30–10:45 · ☕ Coffee break | ||
| Day 2 | 10:45–12:30 | Supply chain & data: Model/dependency supply-chain risk, poisoning, and securing the RAG/data path Lab: Audit your model/tool supply chain and add integrity checks on the retrieval path. |
| 12:30–13:30 · 🍽 Lunch break | ||
| Day 2 | 13:30–15:30 | Monitoring & incident response: Detecting attacks in production, abuse signals, and an AI-specific incident playbook (contain, recover, review) Lab: Add attack-detection signals and run a tabletop incident on a simulated agent breach. |
| 15:30–15:45 · ☕ Coffee break | ||
| Day 2 | 15:45–17:00 | Governance mapping & wrap: Mapping controls to MITRE ATLAS / NIST AI RMF / EU AI Act; continuous red-teaming cadence Lab: Map your controls to a recognised framework and set the ongoing red-team cadence: because a defence that passed today’s attacks can fall to an adaptive attacker tomorrow. |
Deliverables
- Threat model against LLM + Agentic Top 10
- Red-team findings report (ranked)
- Layered defences with before/after risk
- Supply-chain + retrieval-path integrity checks
- AI incident-response playbook (exercised)
- Controls mapped to a governance framework
Interested in running this module for your team? Get in touch and we'll tailor the format, dates, and delivery to your context.
Request this trainingYour trainer
Senior expert
Hands-on red-teamer of LLM and agentic systems; OWASP-fluent; defence experience
Discovery Session
This module requires a full day to deliver a meaningful learning experience. We only offer it in its complete format.
Frequent questions
Can modules be taken individually?
Yes. Every module stands alone at a fixed price, and every module counts toward a programme if you continue.
Where does training happen?
At your premises or remote, on your dates, for private cohorts. Open sessions run on a fixed monthly calendar.
Which AI tools do you train on?
Yours. Every module ships in four ecosystem editions and runs its exercises on your real stack.
Who delivers?
Inforca's senior consultants and trainers. Flagged modules and the executive track are delivered at senior-expert level.
Discuss this module in a First Call: fit, dates, and the path around it.
No commitment · our team responds within one business day