Flagship AI security course
Secure AI Development and OWASP LLM Top 10
Convert LLM and agent security risks into developer, architecture and release practices before your GenAI systems reach sensitive data, tools and production users.
LLM applications change the security conversation. Traditional controls assume inputs are code and data you control; a GenAI system takes arbitrary user text, composes it into prompts, and turns the result into actions — an attack surface where prompt injection, data leakage, tool misuse and supply-chain poisoning are the norm rather than edge cases. The OWASP LLM Top 10 exists because these failures have real consequences, and the teams that handle them well treat security as a design constraint from the first architecture diagram, not a review at the end.
This two-day course turns the OWASP LLM Top 10 into working developer and release practices. You start by building the AI threat model — trust boundaries and data flow across LLM apps, RAG, agents and tools — then work through the risk catalogue: direct and indirect prompt injection, sensitive data disclosure, supply chain risk, model poisoning and improper output handling. From there it becomes practical: mitigations for prompt injection and data leakage (retrieval poisoning, system-prompt leakage), tool and MCP security with authorization, approval flows, audit logging and excessive-agency controls, and secrets and identity done properly with managed identity, least privilege and vaults. The course closes on governance that sticks: risk acceptance, release gates, monitoring, incident response and security review playbooks your teams can adopt immediately.
You leave with a security practice, not just a checklist: the threat model template, the OWASP Top 10 mapping to concrete mitigations, the release-gate and incident-response playbooks, and the vocabulary to talk to both developers and auditors. The course is for developers, security engineers, architects and AppSec leads who are building or reviewing LLM, RAG and agent systems — and for the engineering managers who need a repeatable review process before GenAI touches sensitive data. By the final day you will be able to threat-model an AI feature, apply the right mitigation for each OWASP risk, and run a security review that teams actually follow.
Security Outcomes
The workshop teaches teams how to spot insecure AI flows, contain excessive agency, protect retrieval pipelines and build practical AI release checklists.
Threat model AI apps
Map trust boundaries across prompts, retrieval, APIs, tools, users, identities and data stores.
Defend against misuse
Identify prompt injection, data leakage, insecure tool use, retrieval poisoning and excessive permissions.
Create release gates
Build review practices for AI APIs, secrets, identity, logging, monitoring and governance evidence.
Course Modules
AI threat model
LLM apps, RAG, agents, tools, trust boundaries and data flow.
OWASP LLM risks
Prompt injection, sensitive disclosure, supply chain, poisoning and improper output handling.
Prompt injection and data leakage
Direct and indirect injection, retrieval poisoning, system prompt leakage and mitigations.
Tool and MCP security
Tool authorization, approval flows, audit logging and excessive agency controls.
Secrets and identity
Managed identity, tokens, least privilege, API keys, vaults and secure configuration.
Governance
Risk acceptance, release gates, monitoring, incident response and security review playbooks.
Capstone
Participants perform a security review of a sample AI application and produce findings, mitigations and release recommendations.
Included templates
- OWASP LLM Top 10 review checklist
- Agent and tool security checklist
- Secure AI API checklist
- AI threat-modeling worksheet
Bring Secure AI Training To Your Teams
Use this as a developer workshop, security enablement program or pre-production review accelerator for GenAI, RAG and agentic AI initiatives.