Skip to content
AI Agency

Universal Skills · Foundation · S3

AI Security Awareness

Shadow AI, deepfakes, AI phishing and prompt injection, the security baseline for everyone

Duration
½ day · 9:00–13:00 or 14:00–18:00 (3.75h contact, incl. 1 coffee break)
Participant level
Beginner: no AI experience needed
Format
Awareness workshop with a live fraud tabletop
Participants
15 included · 30 maximum (flexible group size)
Prerequisite
None
Price
EUR 3,500 (EUR 125 per extra participant)

Amounts in EUR, excl. VAT.

Regulatory statusMandatory security-awareness baseline for all staff. Where NIS2 applies (EU essential/important entities, via each state’s transposition; reaches non-EU suppliers to them), it maps to the Art. 21(2)(g) training duty; France’s vital-importance operators sit under the national resilience regime

A trainer presenting to participants working on laptops in a bright training roomai-generated

What participants will be able to do

  • Recognise social engineering and AI-enabled phishing attempts
  • Apply secure AI tool usage practices in your daily work
  • Report an AI security incident through the right channels
  • Identify NIS2-relevant AI security risks in your organisation

Tools & resources

Phishing simulation examplesSecure AI usage checklistSecurity incident reporting formNIS2 awareness reference card

What changes after this module

Every employee can recognise and resist the AI-era attacks now targeting organisations, deepfake voice and video fraud, AI-enhanced phishing, prompt-injection manipulation, and shadow-AI data leaks, and knows exactly how to verify and report.

Who should attend

Everyone. Beginner: no AI experience needed.

Programme

This agenda is indicative. Content, sequencing, and examples are adapted to your team's context, tools, and objectives.

Before you start

  • No prerequisites: this is the AI-era counterpart to standard security-awareness training
  • Applies to every employee
  • A device to review sample messages (optional)
19:00–10:15The new threat landscape: Why “spot the bad grammar” is dead: AI phishing that mimics your colleagues; shadow AI leaking data (most employees have pasted company data into public chatbots); the AI-era fraud trend (real cases, not scare-percentages); and how, for NIS2 essential/important entities, this maps to the Art. 21(2)(g) cyber-hygiene-and-training duty (an EU directive, applied through your country’s transposition).
Hands-onExamine real-style AI-phishing messages and identify what makes them convincing, and what still gives them away.
210:15–11:15Deepfakes & impersonation: Voice clones from seconds of audio; deepfake video calls (the pattern behind the documented ~$25M Arup fraud, Hong Kong 2024: a multi-person fake video call); why seeing and hearing is no longer believing; verification that works (out-of-band, call-back, physical-action check).
Hands-onRun the deepfake-CEO-fraud tabletop, an “urgent transfer” scenario, and practise the out-of-band verification steps under pressure; log what nearly worked on you (the raw material for your checklist).
11:15–11:30 · ☕ Break
311:30–12:20Prompt injection & shadow AI, as a user: How hidden instructions in documents or web pages can hijack an AI assistant; why unapproved tools are risky; using approved tools and reporting incidents fast.
Hands-onSpot the injected instruction in a sample document, and map your team’s shadow-AI risks.
412:20–13:00Wrap: Building your personal defence.
Hands-onBuild your verification checklist (the red flags + the steps) from the tabletop, and complete the attestation: the per-attendee record that is your organisation’s training evidence (incl. for NIS2 Art. 21(2)(g)).

Deliverables

  • Personal verification checklist
  • Team shadow-AI risk note
  • Completed attestation

Interested in running this module for your team? Get in touch and we'll tailor the format, dates, and delivery to your context.

Request this training

Your trainer

Security-awareness practitioner; current on deepfake and AI-fraud tactics; runs live tabletops

Discovery Session

This module requires a full day to deliver a meaningful learning experience. We only offer it in its complete format.

Part of a bigger path

  • ProfessionalEUR 45,000 · 10 training days
  • EnterpriseEUR 115,000 · up to 30 training days
See the programmes

Frequent questions

Can modules be taken individually?

Yes. Every module stands alone at a fixed price, and every module counts toward a programme if you continue.

Where does training happen?

At your premises or remote, on your dates, for private cohorts. Open sessions run on a fixed monthly calendar.

Which AI tools do you train on?

Yours. Every module ships in four ecosystem editions and runs its exercises on your real stack.

Who delivers?

Inforca's senior consultants and trainers. Flagged modules and the executive track are delivered at senior-expert level.

Discuss this module in a First Call: fit, dates, and the path around it.

Book a First Call

No commitment · our team responds within one business day