P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

Four weeks, face to face

AI Security and Governance

Securing and governing AI systems. 104 contact hours covering how AI is attacked and defended, and how it is governed against the frameworks now in force.

Every organisation is deploying AI, and almost none can answer the two questions their board is about to ask: how do we secure this, and how do we prove we are governing it responsibly? Security teams understand networks and endpoints but not model behaviour. Compliance teams understand frameworks but cannot assess a retrieval pipeline. Very few people sit across both. This course builds that combination, and finishes with a governance pack you have built yourself and defended in front of a mock board.

5

Modules

Two blocks, available separately.

0

Programming required

You read and modify short scripts. You do not build models.

This is for you if

  • You already understand networks, operating systems and security fundamentals at Security+ level or through working experience.
  • You are a working security analyst or engineer now being asked to cover AI systems.
  • You are in risk, audit or compliance and need technical grounding to assess AI deployments credibly.
  • You are an IT manager or consultant fielding AI governance questions you cannot currently answer.

It is not, if

  • You are new to IT or security. This is not a beginners' course. Take the Career Pathway first.
  • You want to build or train models. This is about securing and governing them.
  • You are looking for a certification. This course deliberately carries none, for reasons set out below.

What you will be able to do

  • Explain how large language models and machine learning systems work, at the level needed to reason about failure modes.
  • Identify and exploit the major classes of AI vulnerability in a controlled lab, including prompt injection, data poisoning and agentic abuse.
  • Design defensive architecture for AI: least privilege for agents, output handling, human oversight, and monitoring.
  • Run an AI risk assessment and produce a governance pack a board would accept.
  • Map an organisation against the NIST AI Risk Management Framework, ISO/IEC 42001 and the EU AI Act.
  • Build and internally audit an ISO 27001 aligned management system at foundation level.
  • Write policies, test controls, collect evidence and prepare an organisation for audit.

Curriculum

Session days are either four or six hours, so day counts are approximate while the hours are exact. 24 days, 104 contact hours in total.

Module 1

AI foundations for security practitioners

5 days · 20 hours · Technical literacy

Model families and what distinguishes them. Training, fine-tuning and inference. Tokens, context windows and why length matters. Embeddings, vector databases and retrieval-augmented generation. Agents, tool use and orchestration. Where AI genuinely helps a security team, and where it introduces more risk than value.

Module 2

AI security: offensive and defensive

6 days · 28 hours · AI red team skills

Offensive: the OWASP Top 10 for LLM Applications as the frame. Prompt injection direct and indirect, jailbreaks, training data poisoning and backdoors, model extraction and inversion, adversarial examples, agentic risk and confused deputy problems, AI supply chain risk. Defensive: securing retrieval pipelines and document ingestion, least privilege for agents, output handling, human-in-the-loop design that works, and monitoring. Includes an extended red team exercise against a deliberately vulnerable LLM application, then remediating what you found.

Module 3

AI governance and assurance

6 days · 24 hours · Governance pack

The NIST AI RMF and its govern, map, measure and manage functions. ISO/IEC 42001 and how it sits alongside ISO 27001. The EU AI Act: risk tiers, prohibited practices, transparency obligations in force, and the revised high-risk timeline following the Digital Omnibus. The UK's sector-led approach. Then the artefacts: an AI use policy people will follow, a model inventory, model and system cards, an AI risk assessment and how it interacts with a DPIA, third-party AI vendor assessment, and auditing a live AI system.

Module 4

GRC fundamentals

5 days · 24 hours · ISMS and audit skills

Governance structures, roles and the three lines model. Risk management end to end: identification, assessment, treatment, registers, appetite and tolerance. ISO 27001 and Annex A, building an ISMS, running an internal audit, and how certification actually works. NIST CSF 2.0. Cyber Essentials. UK GDPR and the Data Protection Act 2018. Policy writing, control testing and evidence collection. Third-party risk. Preparing for and surviving an audit.

Module 5

Capstone and board presentation

2 days · 8 hours · Portfolio piece

You build a complete AI security governance pack for a fictional organisation: use policy, model inventory, risk assessment, control set and board summary, then present and defend it in a mock board session. Deliberately uncomfortable, because that is the skill the role actually requires. Closes with a certification roadmap and a personal development plan.

Taken in blocks, or in full

The programme runs end to end, and each block can also be taken on its own if you would rather commit one at a time.

Block 1: AI Security

Modules 1 to 2 · 11 days · 48 hours

Foundations and the offensive and defensive work. Available separately.

Block 2: Governance and GRC

Modules 3 to 5 · 13 days · 56 hours

Frameworks, artefacts, GRC fundamentals and the capstone. Available separately.

Week by week

Six days a week, 26 contact hours: five days of four hours and one longer day of six, which is reserved for extended lab work because that needs uninterrupted blocks.

WeekFocusModules
1How models actually work: training, inference, tokens and context, embeddings, vector stores, retrieval-augmented generation, agents and tool use. Where AI helps a SOC and where it does not. OWASP Top 10 for LLM Applications introduced.M1 / M2
2Prompt injection direct and indirect. Jailbreaks and guardrail evasion. Data poisoning and backdoors. Model extraction, inversion and membership inference. Agentic risk and excessive agency. Hands-on red teaming against a vulnerable LLM application. Defensive architecture.M2 / M3
3NIST AI RMF. ISO/IEC 42001 and its relationship to ISO 27001. The EU AI Act: risk tiers, prohibited practices, transparency obligations, and the revised high-risk timeline. AI use policy, model inventory, model cards, AI risk assessment and its interaction with a DPIA.M3 / M4
4Governance structures and the three lines model. Risk registers, appetite and tolerance. ISO 27001 and Annex A, building an ISMS, internal audit. NIST CSF 2.0. Cyber Essentials. UK GDPR and DPA 2018. Policy writing, control testing, evidence. Capstone build and mock board presentation.M4 / M5

Labs and tooling

The offensive and defensive modules are lab-led. The governance modules are workshop-led, producing real documents rather than notes: you complete the templates rather than reading them.

  • A deliberately vulnerable LLM application for red team exercises, running locally.
  • Local and hosted model access, including a retrieval-augmented generation pipeline you build and then attack.
  • AI red teaming and evaluation tooling.
  • Document templates for policies, risk assessments, model cards and control sets.

Equipment: The same laptop specification as the Career Pathway: 16 GB RAM minimum, 32 GB preferred. Cloud credits for hosted model access are provided.

What almost nobody else does

You build the lab, and you keep it

The vulnerable LLM application and the retrieval pipeline you attack are not handed to you finished. You stand them up yourself, which is the only way to understand where the weaknesses actually come from, and the environment stays on your machine afterwards.

  • You build the retrieval-augmented pipeline before you attack it, so the failure modes are ones you can trace.
  • The environment runs locally and does not expire when the course does.
  • You can point it at your own documents afterwards and test your own deployment safely.
  • It becomes portfolio material: a documented red team exercise against a system you built is worth more in interview than a certificate.

How it can be delivered

All three programmes are instructor-led and live. That is the distinction that matters: almost everything sold as online security training is recorded video you watch alone. This is a person teaching, answering the question when you ask it rather than in a forum three days later.

Face to face

Cambridge, or at your site

In the room. Best where a team is learning together, where the discussion matters as much as the material, or where somebody benefits from being able to turn a screen round and point at it.

Live online

Anywhere

The same sessions, same schedule, same labs, delivered over video with screen sharing both ways. Every lab already runs on your own laptop, so the practical work is identical rather than reduced.

Hybrid

Mixed

Common for corporate delivery where part of a team is on site and part is not, and for individuals who want the intensive blocks in person and the rest remote.

What actually differs

The material, the labs and the schedule do not change between modes. Two things genuinely do. Reading a room is easier in person, so remote delivery relies more on asking directly whether something has landed, which I do more often as a result. And the informal conversation either side of a session, the question somebody asks while the laptops are booting, happens less online. Neither is a reason to avoid remote delivery, and both are worth knowing before choosing.

Certification: an honest note

This course carries no certification exam, and that is deliberate rather than a gap. The credentials matching this material are all gated behind prerequisites you will not yet meet. What you leave with instead is a governance pack you built and defended, a documented AI red team exercise, and the working knowledge those certifications test. In interviews for this kind of role the portfolio does more work than the badge.

ISACA AAISM

Requires an active CISM or CISSP before you can register for the exam.

ISACA CISM

Requires five years of information security management experience.

ISO/IEC 27001 Lead Auditor

A sensible next step once you have ISMS exposure. Sat with an accredited body.

ISO/IEC 42001 Lead Implementer

Emerging credential, best attempted with practical AI governance work behind you.

Next step

Start with a conversation.

Every delivery is scoped to who is in the room. Before anything is quoted we talk through where you are starting from, what you need to be able to do afterwards, and whether this programme is honestly the right one. If it is not, I will say so.

Last reviewed:

← All training