Skip to content
AI Agency

The AI Forge · Mastery · F7

AI Security & Red Teaming

OWASP LLM & Agentic Top 10, prompt injection, agent security, defence, incident response

Duration
2 days · 9:00–17:00 each day (13h contact, incl. breaks + lunch)
Participant level
Advanced: experienced practitioners
Format
Instructor-led attack/defence labs
Participants
8 included · 12 maximum (flexible group size)
Prerequisite
F3 + F6 (or equivalent)
Ecosystem
Agnostic: any model provider or stack
Price
EUR 8,500 (EUR 450 per extra participant)

Amounts in EUR, excl. VAT.

A trainer presenting to participants working on laptops in a bright training roomai-generated

What participants will be able to do

  • Perform a structured red-team attack on an LLM system
  • Identify and mitigate prompt injection and data poisoning
  • Build an AI security review checklist for your organisation
  • Design and execute an AI incident response plan

Tools & resources

Garak (LLM red-teaming)PromptBenchOWASP LLM Top 10Python (attack scripting)Burp Suite (adapted)

What changes after this module

Security-minded engineers can attack, defend and monitor LLM and agentic systems against the current threat catalogs, building defence-in-depth and an incident capability on principles that outlast specific exploits.

Who should attend

Engineers and data professionals. Advanced: experienced practitioners.

Programme

This agenda is indicative. Content, sequencing, and examples are adapted to your team's context, tools, and objectives.

Before you start

  • A laptop with a working development environment and admin rights
  • Proficiency in at least one general-purpose language (Python and/or JavaScript/TypeScript)
  • A code editor/IDE with an approved AI coding assistant enabled
  • An API key for an approved model provider (issued by the company)
  • A Git repository and command-line comfort
  • Completion of F3 + F6 or equivalent
  • An LLM or agentic app you may attack in a safe/sandboxed environment
Day 19:00–10:30The AI threat landscape: OWASP Top 10 for LLM Apps and the newer Agentic (ASI) Top 10; the “lethal trifecta” (private data + untrusted content + external comms) as the root of injection risk Lab: Threat-model your app: the target you’ll attack and defend across both days: against the LLM and Agentic Top 10, and flag where the lethal trifecta applies (this map ranks every later lab).
10:30–10:45 · ☕ Coffee break
Day 110:45–12:30Prompt injection & output handling: Direct and indirect injection, data exfiltration, system-prompt leakage, and treating all model output as untrusted Lab: Successfully run direct and indirect injection attacks against your app and document the impact.
12:30–13:30 · 🍽 Lunch break
Day 113:30–15:30Agentic risks: Goal hijack, tool misuse, excessive agency, memory/context poisoning and unexpected code execution Lab: Exploit an over-privileged tool/agent, then re-scope it to least agency and re-test.
15:30–15:45 · ☕ Coffee break
Day 115:45–17:00Lab: red-team your app: Run a structured red-team pass Lab: Run a framework-based red-team suite and produce a ranked findings report.
Day 29:00–10:30Defence in depth: Least privilege, input/output filtering, guardrails, human approval for high-risk actions; why no single control suffices Lab: Add layered defences (filtering + guardrails + approval) and re-run the red-team to show risk reduction: filtering reduces, containment (least privilege + approval) is what actually stops the trifecta.
10:30–10:45 · ☕ Coffee break
Day 210:45–12:30Supply chain & data: Model/dependency supply-chain risk, poisoning, and securing the RAG/data path Lab: Audit your model/tool supply chain and add integrity checks on the retrieval path.
12:30–13:30 · 🍽 Lunch break
Day 213:30–15:30Monitoring & incident response: Detecting attacks in production, abuse signals, and an AI-specific incident playbook (contain, recover, review) Lab: Add attack-detection signals and run a tabletop incident on a simulated agent breach.
15:30–15:45 · ☕ Coffee break
Day 215:45–17:00Governance mapping & wrap: Mapping controls to MITRE ATLAS / NIST AI RMF / EU AI Act; continuous red-teaming cadence Lab: Map your controls to a recognised framework and set the ongoing red-team cadence: because a defence that passed today’s attacks can fall to an adaptive attacker tomorrow.

Deliverables

  • Threat model against LLM + Agentic Top 10
  • Red-team findings report (ranked)
  • Layered defences with before/after risk
  • Supply-chain + retrieval-path integrity checks
  • AI incident-response playbook (exercised)
  • Controls mapped to a governance framework

Interested in running this module for your team? Get in touch and we'll tailor the format, dates, and delivery to your context.

Request this training

Your trainer

Senior expert

Hands-on red-teamer of LLM and agentic systems; OWASP-fluent; defence experience

Discovery Session

This module requires a full day to deliver a meaningful learning experience. We only offer it in its complete format.

Part of a bigger path

  • EnterpriseEUR 115,000 · up to 30 training days
See the programmes

Frequent questions

Can modules be taken individually?

Yes. Every module stands alone at a fixed price, and every module counts toward a programme if you continue.

Where does training happen?

At your premises or remote, on your dates, for private cohorts. Open sessions run on a fixed monthly calendar.

Which AI tools do you train on?

Yours. Every module ships in four ecosystem editions and runs its exercises on your real stack.

Who delivers?

Inforca's senior consultants and trainers. Flagged modules and the executive track are delivered at senior-expert level.

Discuss this module in a First Call: fit, dates, and the path around it.

Book a First Call

No commitment · our team responds within one business day