A two-day, hands-on programme for the teams running AI in production. Build, secure and verify enterprise AI systems against the OWASP AI Security Verification Standard, taught by the official former OWASP-AISVS Co-Leader (v1.0).
Delivered by the former Co-Leader of the OWASP-AISVS standard (v1.0).
Enterprises are shipping AI faster than they can secure it. Prompt injection in customer-facing assistants, data leakage through RAG, autonomous agents taking actions no one authorised, shadow AI, and unverified vendor models are now live risk, not theory. Most teams have no systematic way to prove their AI is secure.
Move from "we think it's secure" to controls you can actually test, across 12 AISVS families and three levels.
EU AI Act, ISO 42001 and NIST AI RMF, tied to concrete technical controls and evidence.
Agents, RAG, MCP and vendor AI, hardened and monitored across the enterprise.
Own AI risk with a defensible, standards-based assurance model your board can understand.
Design and verify AI systems against testable controls, not vague guidance.
Ship AI features that pass security review, with the controls baked in.
Translate EU AI Act, ISO 42001 and NIST AI RMF into evidence you can audit.
Control data leakage, retention and exposure across LLM and RAG pipelines.
Verify a supplier's AI against AISVS before you buy and deploy it.
Classes are custom built from the following learning modules. Instructors select ~16 hours for a 2-day delivery, tailored to the audience. Custom formats from 1 to 3 days available. (Times are approximate.)
Where AI sits in your organisation: model serving, RAG pipelines, agent workflows, third-party APIs and embedded features. Mapping what you actually have.
What changes when AI is not a research project but a production system: data flows, trust boundaries, supplier dependencies and regulatory exposure.
AI ownership models, security responsibility matrices and how to avoid the "data science built it, nobody secures it" gap.
All 12 AISVS categories explained for the people who commission and approve, not just the people who code. What each family protects and why.
L1/L2/L3 in enterprise context: which systems need which level, how sector requirements map to AISVS targets, and the cumulative model.
EU AI Act, NIST AI RMF, ISO 42001, SOC 2 and sector standards (financial services, healthcare, government) alongside AISVS. One assessment, multiple compliance outcomes.
Cost of remediation vs cost of breach; translating AISVS gaps into risk language the board understands.
Step-by-step method: scoping the system, selecting the target level, walking the controls and recording findings. Demonstrated on a live reference stack.
Hands on: run the Claw scanner against the lab stack, read the gap report, understand severity and map findings to AISVS categories. Claw
What counts as evidence for each control: screenshots, logs, configuration exports, signed attestations. Building the evidence pack that auditors accept.
Triaging a gap report into "fix now", "plan for" and "accept with sign-off". Risk-based prioritisation that works inside procurement and change cycles.
Build a real remediation plan from your gap analysis: controls to owners, timelines, dependencies and verification criteria. Uses CyberSecAI's remediation plan template.
Hands on: deploy Presidio, prompt-guard and output-redaction controls to close C02 and C07 gaps on the lab stack.
Hands on: stand up OPA policy-as-code, agent identity credentials and fail-closed authorization to close C05 gaps.
Hands on: dependency scanning, container signing and SBOM generation to close C03 and C06 gaps.
Hands on: deploy tamper-evident logging, hash-chained receipts and anomaly alerting to close C12 gaps.
Run Claw again after remediation. Compare before and after. Prove closure with evidence. Claw
A guided walkthrough of the tooling landscape for each AISVS family: what is free, what is commercial, what is proven and what is marketing.
Three reference deployments (AWS, Azure, on-prem) mapped to AISVS controls. Where each tool sits and how they connect.
Assessments map to controls, never to products. How to stay honest when you are also the team that builds the fix.
Run a full gap assessment on the provided enterprise reference stack. Document findings. Present to the room.
Fix real gaps on a live stack: guardrails, identity, supply chain, monitoring. Re-scan to prove closure. dvmcp dvrag
Build a complete remediation plan from a provided gap report using the template. Peer review with another team.
Every cohort includes a dedicated remediation clinic and planning session, where our former OWASP-AISVS Co-Leader (v1.0) works directly with your team on your own systems. Consulting and advisory, built into the course.
You do not leave with theory. You leave with a specific, prioritised AISVS remediation plan, technical and operational, mapped to your environment and ready to execute.
Free attendee access to dvmcp™, our deliberately vulnerable MCP server, to attack and defend.
Free attendee access to dvrag™, our deliberately vulnerable RAG stack, to break and harden.
A copy of the CLAW project, our scanner that grades a system against the OWASP AISVS controls.
A reference architecture and a build-and-verify checklist for each verification level.
EU AI Act, ISO 42001 and NIST AI RMF mapped to the controls, with the questions to ask any AI deployment.
A template program your teams can run to take AISVS across the enterprise.
No laptop GPU, no setup. You stand up, attack and secure real AI systems on real GPUs in the cloud, then verify the controls hold. Real infrastructure, not a sandbox slideshow.
Serve or fine-tune a model in the cloud, no local hardware.
Break the controls, apply the AISVS fixes, prove they hold.
Findings mapped to AISVS, ready for your own assurance.
If you build or fine-tune AI in-house, you carry a deeper surface than teams who only consume it. The course covers securing the model you build, not only the AI you buy.
Provenance, poisoning controls and lineage of your training data.
Versioning, approval and change control of the model itself.
Weights, dependencies and provenance, secured at source.
For consultancies and in-house security teams who want to deliver AISVS training themselves. Get certified by CyberSecAI to teach this programme, assessed by the former OWASP-AISVS Co-Leader (v1.0)s, then build your own AI-security training practice and join our trainer network.
Certified to teach the full two-day course, assessed by the former Co-Leader.
The curriculum, slides, and licensed access to the dvmcp™ and dvrag™ labs for your cohorts.
Deliver the gap-analysis and remediation-clinic methodology under your own brand.
Referrals, co-delivery, and a place in the growing AISVS trainer community.
Curriculum updates as AISVS evolves, straight from the people who write it.
Run paid AISVS training and assessments as your own offering.
You leave with a verified approach to enterprise AI security, the tooling to run it, and the rare ability to govern, secure and prove it to a formal standard. Seats are deliberately limited so the hands-on stays hands-on.
Corporate & sovereign cohorts, and bespoke on-site delivery, on request.