Universal Skills · Foundation · S3
AI Security Awareness
Shadow AI, deepfakes, AI phishing and prompt injection, the security baseline for everyone
- Duration
- ½ day · 9:00–13:00 or 14:00–18:00 (3.75h contact, incl. 1 coffee break)
- Participant level
- Beginner: no AI experience needed
- Format
- Awareness workshop with a live fraud tabletop
- Participants
- 15 included · 30 maximum (flexible group size)
- Prerequisite
- None
- Price
- EUR 3,500 (EUR 125 per extra participant)
Amounts in EUR, excl. VAT.
Regulatory statusMandatory security-awareness baseline for all staff. Where NIS2 applies (EU essential/important entities, via each state’s transposition; reaches non-EU suppliers to them), it maps to the Art. 21(2)(g) training duty; France’s vital-importance operators sit under the national resilience regime
ai-generatedWhat participants will be able to do
- Recognise social engineering and AI-enabled phishing attempts
- Apply secure AI tool usage practices in your daily work
- Report an AI security incident through the right channels
- Identify NIS2-relevant AI security risks in your organisation
Tools & resources
What changes after this module
Every employee can recognise and resist the AI-era attacks now targeting organisations, deepfake voice and video fraud, AI-enhanced phishing, prompt-injection manipulation, and shadow-AI data leaks, and knows exactly how to verify and report.
Who should attend
Everyone. Beginner: no AI experience needed.
Programme
This agenda is indicative. Content, sequencing, and examples are adapted to your team's context, tools, and objectives.
Before you start
- No prerequisites: this is the AI-era counterpart to standard security-awareness training
- Applies to every employee
- A device to review sample messages (optional)
| 1 | 9:00–10:15 | The new threat landscape: Why “spot the bad grammar” is dead: AI phishing that mimics your colleagues; shadow AI leaking data (most employees have pasted company data into public chatbots); the AI-era fraud trend (real cases, not scare-percentages); and how, for NIS2 essential/important entities, this maps to the Art. 21(2)(g) cyber-hygiene-and-training duty (an EU directive, applied through your country’s transposition). Hands-onExamine real-style AI-phishing messages and identify what makes them convincing, and what still gives them away. |
| 2 | 10:15–11:15 | Deepfakes & impersonation: Voice clones from seconds of audio; deepfake video calls (the pattern behind the documented ~$25M Arup fraud, Hong Kong 2024: a multi-person fake video call); why seeing and hearing is no longer believing; verification that works (out-of-band, call-back, physical-action check). Hands-onRun the deepfake-CEO-fraud tabletop, an “urgent transfer” scenario, and practise the out-of-band verification steps under pressure; log what nearly worked on you (the raw material for your checklist). |
| 11:15–11:30 · ☕ Break | ||
| 3 | 11:30–12:20 | Prompt injection & shadow AI, as a user: How hidden instructions in documents or web pages can hijack an AI assistant; why unapproved tools are risky; using approved tools and reporting incidents fast. Hands-onSpot the injected instruction in a sample document, and map your team’s shadow-AI risks. |
| 4 | 12:20–13:00 | Wrap: Building your personal defence. Hands-onBuild your verification checklist (the red flags + the steps) from the tabletop, and complete the attestation: the per-attendee record that is your organisation’s training evidence (incl. for NIS2 Art. 21(2)(g)). |
Deliverables
- Personal verification checklist
- Team shadow-AI risk note
- Completed attestation
Interested in running this module for your team? Get in touch and we'll tailor the format, dates, and delivery to your context.
Request this trainingYour trainer
Security-awareness practitioner; current on deepfake and AI-fraud tactics; runs live tabletops
Discovery Session
This module requires a full day to deliver a meaningful learning experience. We only offer it in its complete format.
Part of a bigger path
- ProfessionalEUR 45,000 · 10 training days
- EnterpriseEUR 115,000 · up to 30 training days
Frequent questions
Can modules be taken individually?
Yes. Every module stands alone at a fixed price, and every module counts toward a programme if you continue.
Where does training happen?
At your premises or remote, on your dates, for private cohorts. Open sessions run on a fixed monthly calendar.
Which AI tools do you train on?
Yours. Every module ships in four ecosystem editions and runs its exercises on your real stack.
Who delivers?
Inforca's senior consultants and trainers. Flagged modules and the executive track are delivered at senior-expert level.
Discuss this module in a First Call: fit, dates, and the path around it.
No commitment · our team responds within one business day