Shadow AI is what employees do. This is about what your systems do — LLM apps and agents that can be manipulated, leak data, or take actions nobody intended. A hands-on day for teams building with AI.
The moment you connect a language model to your data and your tools, you inherit a class of vulnerabilities that classical application security doesn't cover. A cleverly crafted document in your RAG pipeline can rewrite your agent's instructions. A support chatbot can be talked into revealing its system prompt — or another customer's data. An agent with tool access can be steered into actions no one designed for.
These aren't theoretical: prompt injection remains effectively unsolved, and every integration — retrieval, tools, memory, multi-agent handoffs — widens the surface. The teams that ship secure AI systems aren't the ones with a magic defence; they're the ones who know their attack surface and layer their defences accordingly.
This training is deliberately offensive first: your team attacks a deliberately vulnerable LLM application, sees the exploits work, and then hardens it step by step. Security lessons stick when you've personally broken the thing.
OWASP Top 10 for LLM applications, mapped to your architecture: which risks are real for you, which are noise, and where your current design stands.
Direct and indirect injection, role-play exploits, encoding tricks. You attack a demo app and watch each technique succeed before we discuss why.
RAG poisoning, tool-call abuse, markdown/image exfiltration channels, memory manipulation — how data leaves systems that "only answer questions".
Excessive agency, confused-deputy problems, privilege escalation across multi-agent systems — and why tool permissions are your real security boundary.
Input/output guardrails, sandboxing, least-privilege tool design, human-in-the-loop patterns — what each layer stops, and what it provably doesn't.
We threat-model one of your real applications together and draft the red-team plan your team runs after the workshop.
No. Before every workshop we run a 30-minute briefing call and tailor examples, exercises and depth to your industry, your stack and your team's starting point. The agenda above is the frame — the content inside it is yours.
Pricing depends on group size, location and how much customisation your context needs. We'll give you a fixed quote after the briefing call — no surprises, no hidden day rates.
Both work. On-site tends to be stronger for group discussion and hands-on exercises; remote splits well into two half-sessions. We run workshops across Europe in English or German.
No — the attack labs run on our prepared vulnerable application. But if you bring a real system (even at design stage), the threat-modelling module works on yours, which is where the most value lands.
A free 30-minute get-to-know call — we look at your situation, confirm this is the right format and find out if it’s a fit. No pitch, no commitment.
Book a Free Call →Prefer to write it down first? Tell us about your team and what you're working on — we'll get back to you within 24 hours.