← All Workshops
Technical · Hands-on

AI Security
for Developers

Shadow AI is what employees do. This is about what your systems do — LLM apps and agents that can be manipulated, leak data, or take actions nobody intended. A hands-on day for teams building with AI.

Full-day (6h) 4–12 developers On-site or remote English or German

Why this workshop

Your LLM app is an attack surface.
Most teams haven't looked at it.

The moment you connect a language model to your data and your tools, you inherit a class of vulnerabilities that classical application security doesn't cover. A cleverly crafted document in your RAG pipeline can rewrite your agent's instructions. A support chatbot can be talked into revealing its system prompt — or another customer's data. An agent with tool access can be steered into actions no one designed for.

These aren't theoretical: prompt injection remains effectively unsolved, and every integration — retrieval, tools, memory, multi-agent handoffs — widens the surface. The teams that ship secure AI systems aren't the ones with a magic defence; they're the ones who know their attack surface and layer their defences accordingly.

This training is deliberately offensive first: your team attacks a deliberately vulnerable LLM application, sees the exploits work, and then hardens it step by step. Security lessons stick when you've personally broken the thing.


Agenda

What we work through

01

The LLM threat landscape

OWASP Top 10 for LLM applications, mapped to your architecture: which risks are real for you, which are noise, and where your current design stands.

02

Prompt injection & jailbreaks — live

Direct and indirect injection, role-play exploits, encoding tricks. You attack a demo app and watch each technique succeed before we discuss why.

03

Data exfiltration through the side doors

RAG poisoning, tool-call abuse, markdown/image exfiltration channels, memory manipulation — how data leaves systems that "only answer questions".

04

Agents: when AI takes actions

Excessive agency, confused-deputy problems, privilege escalation across multi-agent systems — and why tool permissions are your real security boundary.

05

Defence in depth

Input/output guardrails, sandboxing, least-privilege tool design, human-in-the-loop patterns — what each layer stops, and what it provably doesn't.

06

Red-teaming your own system

We threat-model one of your real applications together and draft the red-team plan your team runs after the workshop.


Who it's for

Developers and architects building LLM-powered features, RAG pipelines or agent systems
Security engineers who need to extend their threat models to AI components
Tech leads who have to sign off on AI features going to production

What you leave with

First-hand experience of the attacks — your team has run every exploit themselves
A threat model for one of your real AI applications, built during the session
A layered hardening checklist mapped to the OWASP LLM Top 10
A red-team playbook your team can rerun before every release
Clear criteria for when an AI feature is — and isn't — ready for production

At a glance
Duration
Full-day (6h)
Group size
4–12
Location
On-site or remote
Pricing
On request

Good to know

Is this workshop off-the-shelf?

No. Before every workshop we run a 30-minute briefing call and tailor examples, exercises and depth to your industry, your stack and your team's starting point. The agenda above is the frame — the content inside it is yours.

What does it cost?

Pricing depends on group size, location and how much customisation your context needs. We'll give you a fixed quote after the briefing call — no surprises, no hidden day rates.

On-site or remote?

Both work. On-site tends to be stronger for group discussion and hands-on exercises; remote splits well into two half-sessions. We run workshops across Europe in English or German.

Do we need an existing LLM app to benefit?

No — the attack labs run on our prepared vulnerable application. But if you bring a real system (even at design stage), the threat-modelling module works on yours, which is where the most value lands.

Break your AI system
before someone else does.

Book a free strategy call

A free 30-minute get-to-know call — we look at your situation, confirm this is the right format and find out if it’s a fit. No pitch, no commitment.

Book a Free Call →

Send a detailed request

Prefer to write it down first? Tell us about your team and what you're working on — we'll get back to you within 24 hours.

✓ Got it — we'll be in touch within 24 hours.