Delivered by the former OWASP-AISVS Co-Leader (v1.0) — not trainers, but principal AI & cyber-security global leaders.
Our AI advisory and training is delivered by principal architects who work in the field every day on consulting and advisory engagements worldwide. They bring real, hands-on implementation experience of real-world challenges, compliance and alignment, and deep cyber-security expertise. Verify and secure AI to the OWASP AISVS standard in live labs on DVMCP and DVRAG. Build it, break it, verify it, prove it.
What you'll master
Every course is hands-on across the real AI attack surface — you break it, then verify it against the standard.
CVE-2025-32711 EchoLeak — segregate untrusted content from instructions; block indirect-injection tool triggersCVE-2024-5565 Vanna — never exec model output; sandbox & allow-listCVE-2024-5184 EmailGPT — input screening + strict data/instruction separationCVE-2023-36258 LangChain code exec — sandbox chains; disable os.system / exec / eval pathsCVE-2024-21513 LangChain Experimental RCE — isolate experimental chains; no shell toolsCVE-2024-37032 Ollama "Probllama" — validate model digests; patch & restrict registry pullsCVE-2025-6514 mcp-remote cmd injection — connect only to vetted MCP servers; allow-list & sandboxCVE-2025-49596 MCP Inspector RCE — upgrade ≥0.14.1; bind localhost + require authCVE-2025-53110/53109 MCP Filesystem — constrain paths; least-privilege scopesCVE-2026-39313 mcp-framework HTTP DoS — bound request-body size; enforce quotas & timeouts; write append-only, tamper-evident logsFounder-credited disclosure — the exact DoS & evidence-tampering surface you harden in the lab.
Capture and preserve agent evidence — traces, tool calls, MCP sessions and model I/O — then reconstruct incidents like the CVEs opposite with a defensible chain of custody.
Turn lab findings into AISVS verification evidence: scope L1–L3, map controls, produce auditor-ready proof — and certify on demonstrated competence.
Curriculum paths
Structured like the discipline itself: start at the standard, then follow your role — builder, auditor, architect or responder. Every path ends in proof, not attendance.
The catalogue
Eighteen courses across the full AI security lifecycle — govern, build, defend, attack, respond and certify. Filter to your role.
Build, secure and verify AI to the OWASP AISVS standard. The foundation course every track builds on.
Secure enterprise AI to the standard, then fix it live in a hands-on remediation clinic.
Verify and certify AI systems against AISVS. Lab-based practical exam, certificate of competence.
Secure autonomous agents end to end: identity, payments, kill switches and proof.
Capture, preserve and reconstruct what an AI agent did. Evidence that holds up.
Deploy production AI agents on AgentPass — PKI, MCPS signing, payments, OFAC checks and kill switches. One day, hands-on.
The 4-day flagship. Design, secure and prove AgentPass agent estates end to end. Enterprise + AgentPass courses earn the CyberSecAI ACA credential.
Secure MCP servers and clients end to end — transport, HTTP/DoS, auth, replay, tool poisoning and the new MCP Apps UI surface. Hands-on on DVMCP.
Prompts that audit, attack and verify AI systems, and produce the evidence to prove it.
Turn regulation into engineering: map AISVS controls to EU AI Act obligations and ship auditable, conformant AI.
Detect, triage and respond to AI-specific incidents. Build the telemetry, alerts and playbooks your SOC is missing.
Attack LLMs and agents like a real adversary — jailbreaks, prompt injection, data extraction and model evasion.
Stop RAG poisoning, embedding attacks and retrieval data leakage. Hands-on on DVRAG.
Ship secure AI features: guardrails, output handling, tool-use safety and the OWASP LLM Top 10 — in code.
Stand up an AI management system that satisfies boards, auditors and regulators — ISO 42001 and NIST AI RMF, applied.
Trust what you deploy: detect poisoned models, sign artifacts and prove provenance across the AI supply chain.
Design AI systems that are secure before a line ships — threat model agents, RAG and pipelines against AISVS.
Secure agent swarms end to end: orchestration, agent-to-agent trust, delegation limits and blast-radius control.
Ways to train
Every course runs in the format your organisation needs — always instructor-led, always hands-on, never a recording.
We come to you. Your stack, your threat model, your team in one room — anywhere worldwide.
Full labs streamed live with per-delegate GPU environments — same intensity, zero travel.
Delivered in the UAE and Saudi Arabia, aligned to local regulation — long-standing Gulf presence.
Per-delegate GPU lab environments on DVMCP & DVRAG, with certificates earned on competence.
Exemplar Labs
AI, ML and threat-mitigation approaches and advisory — general information only. Access-controlled: please request access.
Comprehensive real-world ML implementations showcasing practical AI agent architectures, autonomous security systems, and enterprise-grade machine learning solutions.
Advanced fraud detection laboratory demonstrating cutting-edge ML techniques, real-time anomaly detection, and AI-powered security analytics for enterprise environments.
Comprehensive blockchain security architecture manual covering smart contract auditing, DeFi protocol security, and enterprise-grade cryptocurrency security frameworks.
Comprehensive identity security architecture and attack path training manual covering authentication vulnerabilities, privilege escalation, and defensive strategies.
Covers LLM use cases and secure deployments of AI LLMs for enterprises, including threat modeling, prompt injection defenses, and enterprise integration patterns.
Real-time threat intelligence aggregation and analysis platform with interactive ML simulations for proactive security posture management.
Regional delivery
Delivered on-site across the Gulf, with a long-standing regional presence (pictured: e-Security Forum, Etisalat, UAE). Labs and training run in KSA and the UAE, aligned to local regulation.
What's on
Free community sessions and live training dates.
Why us
Courses are designed and delivered by the former OWASP-AISVS Co-Leader (v1.0) and recognised authorities in cyber security — UK Government Security Cleared — teaching on the open standards we help author.
Creators of AgentPass & MCPS. All courses, course materials and certifications are copyright © and the property of CyberSecAI Ltd, a UK-registered company.
MCP 2026-07 update · why signing still matters
The July 2026 MCP release candidate makes the protocol stateless — the initialize handshake and Mcp-Session-Id are gone (SEP-2243), and the new routing headers are unauthenticated. Its six authorization SEPs harden OAuth 2.0 / OIDC — issuer validation (RFC 9207, SEP-2468), DCR application_type (SEP-837), issuer-bound credentials (SEP-2352) — but they still rely on bearer tokens. Sender-constrained tokens (DPoP) and hardware attestation remain a proposal (SEP #1461), not in the shipping spec. Until that lands, a stolen token is replayable and no message is individually authenticated. That is exactly the gap we close. OAuth authenticates the client; MCPS authenticates every message.
Taught straight from the OWASP-AISVS standard and the open IETF agent-trust internet-drafts we author — not a proprietary black box or a vendor slide deck.
Every agent gets a passport; every action gets a signature; authority is earned through graduated trust levels — and you build it in the lab.
Tamper-evident receipts and control mappings that stand up to auditors, incident reviews and the EU AI Act.
A cyber-security leader of 25+ years and author of Breach 20/20. Former OWASP-AISVS Co-Leader (v1.0), IETF agent-trust draft author, credited on CVE-2026-39313 — FBCS, CISSP, CSSLP.
Free resource
Get access to full recommendations and reference architecture patterns for deploying AI securely — Cloud and On-Premise. Mapped to the OWASP AISVS standard: identity, guardrails, retrieval, monitoring, evidence and kill switches.
Get access →Every course runs as a private corporate or sovereign cohort, on-site or remote, GPU-backed labs included. Delivered by the former OWASP-AISVS Co-Leader (v1.0).
Enquire about training