Enterprise · 2-Day Masterclass · Hands-on
Govern · Secure · Verify

AI Security for Enterprises, Aligned to the OWASP AISVS Standard

A two-day, hands-on programme for the teams running AI in production. Build, secure and verify enterprise AI systems against the OWASP AI Security Verification Standard, taught by the official former OWASP-AISVS Co-Leader (v1.0).

2 days · intensive, hands-on Enterprise-focused · real production pain points OWASP AISVS · verify to the standard On-site or private corporate cohort
Taught by

Taught by the former Co-Leader of the OWASP-AISVS standard (v1.0)

Delivered by the former Co-Leader of the OWASP-AISVS standard (v1.0).

Why this course

AI is in production. So is the risk.

Enterprises are shipping AI faster than they can secure it. Prompt injection in customer-facing assistants, data leakage through RAG, autonomous agents taking actions no one authorised, shadow AI, and unverified vendor models are now live risk, not theory. Most teams have no systematic way to prove their AI is secure.

VERIFY

Against a real standard

Move from "we think it's secure" to controls you can actually test, across 12 AISVS families and three levels.

GOVERN

Map to regulation

EU AI Act, ISO 42001 and NIST AI RMF, tied to concrete technical controls and evidence.

OPERATE

Secure at scale

Agents, RAG, MCP and vendor AI, hardened and monitored across the enterprise.

Who should attend

Built for the people accountable for enterprise AI

CISOs & Security Leaders

Own AI risk with a defensible, standards-based assurance model your board can understand.

Security Architects & AppSec

Design and verify AI systems against testable controls, not vague guidance.

AI, ML & Platform Engineering

Ship AI features that pass security review, with the controls baked in.

Risk, Compliance & GRC

Translate EU AI Act, ISO 42001 and NIST AI RMF into evidence you can audit.

Data Protection & Privacy

Control data leakage, retention and exposure across LLM and RAG pipelines.

Procurement & Vendor Assurance

Verify a supplier's AI against AISVS before you buy and deploy it.

AISVS-511 -- The syllabus

Two days, from governance to a hardened, verified enterprise AI stack

Classes are custom built from the following learning modules. Instructors select ~16 hours for a 2-day delivery, tailored to the audience. Custom formats from 1 to 3 days available. (Times are approximate.)

Enterprise AI Landscape

Where AI Sits in Your Organisation

10-00 AI in the Enterprise Today 1 hr

Where AI sits in your organisation: model serving, RAG pipelines, agent workflows, third-party APIs and embedded features. Mapping what you actually have.

10-01 The Enterprise Attack Surface 1 hr

What changes when AI is not a research project but a production system: data flows, trust boundaries, supplier dependencies and regulatory exposure.

10-02 Governance Structures That Work 1 hr

AI ownership models, security responsibility matrices and how to avoid the "data science built it, nobody secures it" gap.

AISVS for Enterprise Teams

The Standard, for the People Who Commission and Approve

11-00 The Standard: Guided Tour for Decision Makers 1.5 hrs

All 12 AISVS categories explained for the people who commission and approve, not just the people who code. What each family protects and why.

11-01 Levels and System Classification 1 hr

L1/L2/L3 in enterprise context: which systems need which level, how sector requirements map to AISVS targets, and the cumulative model.

11-02 Mapping AISVS to Existing Frameworks 1 hr

EU AI Act, NIST AI RMF, ISO 42001, SOC 2 and sector standards (financial services, healthcare, government) alongside AISVS. One assessment, multiple compliance outcomes.

11-03 Building the Business Case for AI Security 0.5 hr

Cost of remediation vs cost of breach; translating AISVS gaps into risk language the board understands.

Gap Analysis

Assess Your Stack Against the Standard

12-00 Running an AISVS Gap Assessment 1.5 hrs

Step-by-step method: scoping the system, selecting the target level, walking the controls and recording findings. Demonstrated on a live reference stack.

12-01 Automated Scanning with Claw 1 hr

Hands on: run the Claw scanner against the lab stack, read the gap report, understand severity and map findings to AISVS categories. Claw

12-02 Evidence Collection 1 hr

What counts as evidence for each control: screenshots, logs, configuration exports, signed attestations. Building the evidence pack that auditors accept.

12-03 Interpreting Results and Prioritising 1 hr

Triaging a gap report into "fix now", "plan for" and "accept with sign-off". Risk-based prioritisation that works inside procurement and change cycles.

Remediation Clinic

Fix It Live, Then Prove It

13-00 Remediation Planning Workshop 1.5 hrs

Build a real remediation plan from your gap analysis: controls to owners, timelines, dependencies and verification criteria. Uses CyberSecAI's remediation plan template.

13-01 Input and Output Guardrails 1.5 hrs

Hands on: deploy Presidio, prompt-guard and output-redaction controls to close C02 and C07 gaps on the lab stack.

13-02 Identity and Access Control 1.5 hrs

Hands on: stand up OPA policy-as-code, agent identity credentials and fail-closed authorization to close C05 gaps.

13-03 Supply Chain Controls 1 hr

Hands on: dependency scanning, container signing and SBOM generation to close C03 and C06 gaps.

13-04 Monitoring and Audit Trails 1 hr

Hands on: deploy tamper-evident logging, hash-chained receipts and anomaly alerting to close C12 gaps.

13-05 Re-scan and Verify 1 hr

Run Claw again after remediation. Compare before and after. Prove closure with evidence. Claw

The Stack Map

Tooling and Reference Architectures

14-00 Open-Source and Commercial Tooling by Category 1 hr

A guided walkthrough of the tooling landscape for each AISVS family: what is free, what is commercial, what is proven and what is marketing.

14-01 Reference Architectures 1 hr

Three reference deployments (AWS, Azure, on-prem) mapped to AISVS controls. Where each tool sits and how they connect.

14-02 Vendor-Neutral Assessment Discipline 0.5 hr

Assessments map to controls, never to products. How to stay honest when you are also the team that builds the fix.

Labs

Hands-On Lab Options

15-00 Enterprise Gap Analysis Lab 2 hrs

Run a full gap assessment on the provided enterprise reference stack. Document findings. Present to the room.

15-01 Remediation Clinic Lab 3 hrs

Fix real gaps on a live stack: guardrails, identity, supply chain, monitoring. Re-scan to prove closure. dvmcp dvrag

15-02 Remediation Plan Lab 1.5 hrs

Build a complete remediation plan from a provided gap report using the template. Peer review with another team.

~30 hrs
Total instructional hours (all modules)
22
Individual modules across 6 sections
1-3 days
Flexible delivery, tailored to audience
Included with every cohort

More than training: a remediation clinic and planning session

Every cohort includes a dedicated remediation clinic and planning session, where our former OWASP-AISVS Co-Leader (v1.0) works directly with your team on your own systems. Consulting and advisory, built into the course.

You do not leave with theory. You leave with a specific, prioritised AISVS remediation plan, technical and operational, mapped to your environment and ready to execute.

Your systems, assessed against AISVS A prioritised technical & operational plan Direct advisory from the former Co-Leader
What you get

You leave with the tools, not just the slides

HANDS-ON TOOLING

dvmcp™ access

Free attendee access to dvmcp™, our deliberately vulnerable MCP server, to attack and defend.

HANDS-ON TOOLING

dvrag™ access

Free attendee access to dvrag™, our deliberately vulnerable RAG stack, to break and harden.

SCANNER

A copy of CLAW

A copy of the CLAW project, our scanner that grades a system against the OWASP AISVS controls.

REFERENCE

AISVS reference architecture

A reference architecture and a build-and-verify checklist for each verification level.

COMPLIANCE

Regulatory mapping

EU AI Act, ISO 42001 and NIST AI RMF mapped to the controls, with the questions to ask any AI deployment.

ROADMAP

AISVS adoption roadmap

A template program your teams can run to take AISVS across the enterprise.

GPU-backed labs

Hands-on, on real GPUs

No laptop GPU, no setup. You stand up, attack and secure real AI systems on real GPUs in the cloud, then verify the controls hold. Real infrastructure, not a sandbox slideshow.

BUILD

Stand up a model on a GPU

Serve or fine-tune a model in the cloud, no local hardware.

SECURE

Attack it, then harden it

Break the controls, apply the AISVS fixes, prove they hold.

VERIFY

Evidence the controls

Findings mapped to AISVS, ready for your own assurance.

Building, not just buying

For enterprises training their own models

If you build or fine-tune AI in-house, you carry a deeper surface than teams who only consume it. The course covers securing the model you build, not only the AI you buy.

C1

Training data integrity

Provenance, poisoning controls and lineage of your training data.

C3

Model lifecycle

Versioning, approval and change control of the model itself.

C6

Supply chain

Weights, dependencies and provenance, secured at source.

Train the trainer

Become a certified AISVS trainer

For consultancies and in-house security teams who want to deliver AISVS training themselves. Get certified by CyberSecAI to teach this programme, assessed by the former OWASP-AISVS Co-Leader (v1.0)s, then build your own AI-security training practice and join our trainer network.

CERTIFICATION

Licensed to deliver

Certified to teach the full two-day course, assessed by the former Co-Leader.

CURRICULUM + LABS

Everything you need

The curriculum, slides, and licensed access to the dvmcp™ and dvrag™ labs for your cohorts.

METHODOLOGY

The remediation playbook

Deliver the gap-analysis and remediation-clinic methodology under your own brand.

NETWORK

Join the trainer network

Referrals, co-delivery, and a place in the growing AISVS trainer community.

ALWAYS CURRENT

Updates from the source

Curriculum updates as AISVS evolves, straight from the people who write it.

YOUR PRACTICE

Your brand, your margin

Run paid AISVS training and assessments as your own offering.

Apply to become a trainer
Reserve your seat

Two days that change how your enterprise secures AI.

You leave with a verified approach to enterprise AI security, the tooling to run it, and the rare ability to govern, secure and prove it to a formal standard. Seats are deliberately limited so the hands-on stays hands-on.

2 days intensive, hands-on Limited cohort seats Private corporate cohorts available
Reserve Your Seat

Corporate & sovereign cohorts, and bespoke on-site delivery, on request.