Unique courses created & delivered by the former OWASP-AISVS Co-Leader (v1.0) · Secure Coding with AI for Developers — Now Live →
Book now
Cybersecurity and AI Architecture Executive of the Year 2026
Executive of the Year 2026Cybersecurity & AI Architecture

Delivered by the former OWASP-AISVS Co-Leader (v1.0) — not trainers, but principal AI & cyber-security global leaders.

World-class
AI security training

Our AI advisory and training is delivered by principal architects who work in the field every day on consulting and advisory engagements worldwide. They bring real, hands-on implementation experience of real-world challenges, compliance and alignment, and deep cyber-security expertise. Verify and secure AI to the OWASP AISVS standard in live labs on DVMCP and DVRAG. Build it, break it, verify it, prove it.

BUILDReal implementation
12AISVS families
GPULive labs
CERTOn competence
Raza Sharif delivering payment-security training at a PCI conference
● Live trainingDelivering payment-security training to a packed room — PCI conference keynote.
Prompt InjectionRAG PoisoningAgent SecurityAISVS VerificationMCP SecurityAI ForensicsKill SwitchesDVMCP & DVRAG

What you'll master

The topics

Every course is hands-on across the real AI attack surface — you break it, then verify it against the standard.

C1–C4

Prompt Injection & Input Security

Hover for mitigations
MitigationsReal CVEs you need to know
  • CVE-2025-32711 EchoLeak — segregate untrusted content from instructions; block indirect-injection tool triggers
  • CVE-2024-5565 Vanna — never exec model output; sandbox & allow-list
  • CVE-2024-5184 EmailGPT — input screening + strict data/instruction separation
C8

RAG Poisoning & Retrieval

Hover for mitigations
MitigationsReal CVEs you need to know
  • CVE-2023-36258 LangChain code exec — sandbox chains; disable os.system / exec / eval paths
  • CVE-2024-21513 LangChain Experimental RCE — isolate experimental chains; no shell tools
  • CVE-2024-37032 Ollama "Probllama" — validate model digests; patch & restrict registry pulls
C9–C10

Autonomous Agent Security

Hover for mitigations
MitigationsReal CVEs you need to know
  • CVE-2025-6514 mcp-remote cmd injection — connect only to vetted MCP servers; allow-list & sandbox
  • CVE-2025-49596 MCP Inspector RCE — upgrade ≥0.14.1; bind localhost + require auth
  • CVE-2025-53110/53109 MCP Filesystem — constrain paths; least-privilege scopes
C11–C12

Rate Limits & Tamper-Evident Logging

Hover for mitigations
MitigationsReal CVE you need to know
  • CVE-2026-39313 mcp-framework HTTP DoS — bound request-body size; enforce quotas & timeouts; write append-only, tamper-evident logs

Founder-credited disclosure — the exact DoS & evidence-tampering surface you harden in the lab.

Forensics

Agentic Incident Response

Hover for detail
What you'll masterEvidence that holds up

Capture and preserve agent evidence — traces, tool calls, MCP sessions and model I/O — then reconstruct incidents like the CVEs opposite with a defensible chain of custody.

Assurance

Verification & Certification

Hover for detail
What you'll masterAuditor-ready proof

Turn lab findings into AISVS verification evidence: scope L1–L3, map controls, produce auditor-ready proof — and certify on demonstrated competence.

0
AISVS control families
0
Verification levels
0
Testable requirements
0
Courses & certifications

Curriculum paths

The training roadmap

Structured like the discipline itself: start at the standard, then follow your role — builder, auditor, architect or responder. Every path ends in proof, not attendance.

The catalogue

Courses & certifications

Eighteen courses across the full AI security lifecycle — govern, build, defend, attack, respond and certify. Filter to your role.

AISVS-501Flagship
AI SecurityVerification

AISVS Masterclass

Build, secure and verify AI to the OWASP AISVS standard. The foundation course every track builds on.

  • 2-day instructor-led
  • Live GPU hands-on labs
  • Covers all 12 AISVS families
View course →Foundation
AISVS-511Enterprise
Enterprise AIRemediation

AI Security for Enterprises

Secure enterprise AI to the standard, then fix it live in a hands-on remediation clinic.

  • 2-day instructor-led
  • Remediation clinic
  • Maps AISVS to your stack
View course →Intermediate
AISVS-601Certification
AuditAssurance

Certified AISVS Auditor

Verify and certify AI systems against AISVS. Lab-based practical exam, certificate of competence.

  • 2-day + practical exam
  • Per-delegate GPU audit labs
  • Certificate on competence
View course →Advanced
AGSEC-521AI-Focused
AgentsIdentity

AI Agent Security

Secure autonomous agents end to end: identity, payments, kill switches and proof.

  • 2-day instructor-led
  • Identity, AML & payments
  • Hardware HITL kill switches
View course →Intermediate
FOR-521New
ForensicsIncident Response

Agentic Forensics

Capture, preserve and reconstruct what an AI agent did. Evidence that holds up.

  • 2-day instructor-led
  • Evidence across the AI stack
  • Build an in-house capability
View course →Advanced
AGPASS-5311-Day
AgentPassMCPSPKI

AgentPass Agent Deployment

Deploy production AI agents on AgentPass — PKI, MCPS signing, payments, OFAC checks and kill switches. One day, hands-on.

  • 1-day hands-on deployment
  • PKI + MCPS per-action signing
  • Payments, OFAC & kill switch
View course →Architect track
AGPASS-601Certification
AgentPassArchitectureMCPS

AgentPass Certified Architect

The 4-day flagship. Design, secure and prove AgentPass agent estates end to end. Enterprise + AgentPass courses earn the CyberSecAI ACA credential.

  • 4-day architect track
  • Design → deploy → prove
  • Earns CyberSecAI ACA
View course →Certification
MCP-5111-Day
MCPHTTP DoSReplay

Securing MCP

Secure MCP servers and clients end to end — transport, HTTP/DoS, auth, replay, tool poisoning and the new MCP Apps UI surface. Hands-on on DVMCP.

  • 1-day hands-on (DVMCP)
  • HTTP DoS → CVE-2026-39313
  • Replay, signing & MCP Apps
View course →MCP security
TOOL-101Toolkit
PromptsEvidence

AISVS Verification Prompt Pack

Prompts that audit, attack and verify AI systems, and produce the evidence to prove it.

  • Ready-to-run prompt library
  • Maps to AISVS controls
  • Self-paced resource
Get the pack →Resource
GOV-541Compliance
EU AI ActAISVSGovernance

AISVS & the EU AI Act — Implementations

Turn regulation into engineering: map AISVS controls to EU AI Act obligations and ship auditable, conformant AI.

  • 2-day instructor-led
  • Article-by-article control mapping
  • Conformity evidence packs
View course →Governance track
SOC-531Blue Team
SOCTriageDetection

AI Incident Response & Monitoring — SOC Teams & Triage

Detect, triage and respond to AI-specific incidents. Build the telemetry, alerts and playbooks your SOC is missing.

  • 2-day instructor-led
  • AI detections & triage playbooks
  • Live SOC simulation
View course →Detection & response
RED-541Offensive
Red TeamJailbreaksAdversarial ML

AI Red Teaming & Adversarial Testing

Attack LLMs and agents like a real adversary — jailbreaks, prompt injection, data extraction and model evasion.

  • 3-day instructor-led
  • Hands-on attack labs
  • Reusable red-team playbook
View course →Advanced
RAG-511AI-Focused
RAGVector DBsC8

Securing RAG & Vector Databases

Stop RAG poisoning, embedding attacks and retrieval data leakage. Hands-on on DVRAG.

  • 2-day hands-on (DVRAG)
  • Poisoning & leakage defenses
  • Access control on retrieval
View course →Intermediate
DEV-521Developer
Secure BuildGuardrailsLLM Top 10

LLM Application Security for Developers

Ship secure AI features: guardrails, output handling, tool-use safety and the OWASP LLM Top 10 — in code.

  • 2-day instructor-led
  • Secure-by-default patterns
  • Guardrails in your stack
View course →Intermediate
GRC-511GRC
ISO 42001NIST AI RMFRisk

AI Governance, Risk & Compliance

Stand up an AI management system that satisfies boards, auditors and regulators — ISO 42001 and NIST AI RMF, applied.

  • 2-day instructor-led
  • ISO 42001 & NIST AI RMF
  • Risk register & controls
View course →Foundation
SCM-521Supply Chain
Model ProvenanceAI-SBOMC6

AI Supply Chain & Model Provenance Security

Trust what you deploy: detect poisoned models, sign artifacts and prove provenance across the AI supply chain.

  • 2-day instructor-led
  • Model scanning & signing
  • AI-SBOM & provenance
View course →Intermediate
ARCH-531Architect
Threat ModelingReference Architecture

AI Threat Modeling & Secure Architecture

Design AI systems that are secure before a line ships — threat model agents, RAG and pipelines against AISVS.

  • 2-day instructor-led
  • AI-specific threat models
  • AISVS reference patterns
View course →Intermediate
MAS-541AI-Focused
Multi-AgentOrchestrationA2A

Securing Multi-Agent Systems

Secure agent swarms end to end: orchestration, agent-to-agent trust, delegation limits and blast-radius control.

  • 2-day instructor-led
  • A2A trust & delegation
  • Kill switches & containment
View course →Advanced

Ways to train

Delivered your way

Every course runs in the format your organisation needs — always instructor-led, always hands-on, never a recording.

On-site private cohort

We come to you. Your stack, your threat model, your team in one room — anywhere worldwide.

Live online

Full labs streamed live with per-delegate GPU environments — same intensity, zero travel.

Sovereign & regional

Delivered in the UAE and Saudi Arabia, aligned to local regulation — long-standing Gulf presence.

GPU labs & certification

Per-delegate GPU lab environments on DVMCP & DVRAG, with certificates earned on competence.

Exemplar Labs

Exemplars of CyberSecAI training labs

AI, ML and threat-mitigation approaches and advisory — general information only. Access-controlled: please request access.

AI/ML LabAdvisory
AI AgentsMachine LearningEnterprise ML

AI Agents Labs

Comprehensive real-world ML implementations showcasing practical AI agent architectures, autonomous security systems, and enterprise-grade machine learning solutions.

Explore Lab →Members
AI/ML LabAdvisory
Fraud DetectionML AnalyticsReal-time AI

Enterprise AI Fraud Detection Suite

Advanced fraud detection laboratory demonstrating cutting-edge ML techniques, real-time anomaly detection, and AI-powered security analytics for enterprise environments.

Explore Lab →Members
AI/ML LabAdvisory
BlockchainSmart ContractsDeFi Security

DeFi Security Manual for Architects & Integrators

Comprehensive blockchain security architecture manual covering smart contract auditing, DeFi protocol security, and enterprise-grade cryptocurrency security frameworks.

Explore Lab →Members
AI/ML LabAdvisory
Identity SecurityData BreachAttack Paths

Identity Security Concerns for Data Breach Reduction

Comprehensive identity security architecture and attack path training manual covering authentication vulnerabilities, privilege escalation, and defensive strategies.

Request Info →By request
AI/ML LabAdvisory
LLM SecurityAI EnterpriseSecure Deployment

LLM Security Concerns for Integrators

Covers LLM use cases and secure deployments of AI LLMs for enterprises, including threat modeling, prompt injection defenses, and enterprise integration patterns.

Explore Lab →Members
AI/ML LabAdvisory
Threat IntelligenceML SolutionsAttack Simulation

Threat Intelligence Platform

Real-time threat intelligence aggregation and analysis platform with interactive ML simulations for proactive security posture management.

Explore Lab →Members
Raza Sharif at the e-Security Forum (Etisalat), UAE

Regional delivery

Available in the UAE & Saudi Arabia

Delivered on-site across the Gulf, with a long-standing regional presence (pictured: e-Security Forum, Etisalat, UAE). Labs and training run in KSA and the UAE, aligned to local regulation.

What's on

Events & webinars

Free community sessions and live training dates.

08
JUL
Free webinar · online

AISVS Explained: Verifying AI to the Standard

Wed 8 July 2026 · 2:00 PM BST · live walkthrough on DVMCP & DVRAG
Register
Q3
2026
Private cohort

AISVS Masterclass — Enterprise cohorts

On-site or remote · GPU labs included · dates on request
Enquire
15
SEP
Live training · Riyadh, Saudi ArabiaTBC

AISVS Masterclass — Riyadh Cohort

Tue 15 Sep 2026 · 2-day AI security training with GPU labs · aligned to SDAIA & NCA direction
Register
24
SEP
Live training · London, UKTBC

Securing MCP — One-Day Intensive

Thu 24 Sep 2026 · hands-on on DVMCP · transport, DoS, replay & tool poisoning
Register
14
OCT
Live training · Dubai, UAETBC

AI Agent Security — GITEX Week Edition

Wed 14 Oct 2026 · agent identity, kill switches & payments · 2-day cohort
Register
22
OCT
Live training · Amsterdam, NetherlandsTBC

AI Security for Enterprises — Benelux Cohort

Thu 22 Oct 2026 · secure & remediate enterprise AI to the AISVS standard
Register
03
NOV
Live training · Brussels, BelgiumTBC

AISVS & the EU AI Act — Compliance Workshop

Tue 3 Nov 2026 · mapping AISVS controls to EU AI Act obligations · hands-on evidence lab
Register
NOV
2026
Conference · Stockholm

Nordic Software Security Summit

Verifying AI to OWASP AISVS — talk + hands-on workshop
Details
18
NOV
Live training · Frankfurt, GermanyTBC

Certified AISVS Auditor — DACH Cohort

Wed 18 Nov 2026 · 2 days + practical exam · per-delegate GPU audit labs
Register
08
DEC
Live training · Abu Dhabi, UAETBC

Agentic Forensics — Incident Response Lab

Tue 8 Dec 2026 · capture, preserve & reconstruct agent activity · evidence that holds up
Register
10
DEC
Live training · Jeddah, Saudi ArabiaTBC

AI & Cyber Security Briefing — Executive Session

Thu 10 Dec 2026 · half-day briefing for CISOs & AI leaders · AISVS, agents & the threat landscape
Register

Why us

Built by the former Co-Leader of the OWASP-AISVS standard

Courses are designed and delivered by the former OWASP-AISVS Co-Leader (v1.0) and recognised authorities in cyber security — UK Government Security Cleared — teaching on the open standards we help author.

Creators of AgentPass & MCPS. All courses, course materials and certifications are copyright © and the property of CyberSecAI Ltd, a UK-registered company.

MCP 2026-07 update · why signing still matters

The July 2026 MCP release candidate makes the protocol stateless — the initialize handshake and Mcp-Session-Id are gone (SEP-2243), and the new routing headers are unauthenticated. Its six authorization SEPs harden OAuth 2.0 / OIDC — issuer validation (RFC 9207, SEP-2468), DCR application_type (SEP-837), issuer-bound credentials (SEP-2352) — but they still rely on bearer tokens. Sender-constrained tokens (DPoP) and hardware attestation remain a proposal (SEP #1461), not in the shipping spec. Until that lands, a stolen token is replayable and no message is individually authenticated. That is exactly the gap we close. OAuth authenticates the client; MCPS authenticates every message.

Standards-first

Taught straight from the OWASP-AISVS standard and the open IETF agent-trust internet-drafts we author — not a proprietary black box or a vendor slide deck.

Verify, don't trust

Every agent gets a passport; every action gets a signature; authority is earned through graduated trust levels — and you build it in the lab.

Regulator-ready

Tamper-evident receipts and control mappings that stand up to auditors, incident reviews and the EU AI Act.

The practitioner

A cyber-security leader of 25+ years and author of Breach 20/20. Former OWASP-AISVS Co-Leader (v1.0), IETF agent-trust draft author, credited on CVE-2026-39313 — FBCS, CISSP, CSSLP.

Free resource

Secure AI Deployment Blueprint

Get access to full recommendations and reference architecture patterns for deploying AI securely — Cloud and On-Premise. Mapped to the OWASP AISVS standard: identity, guardrails, retrieval, monitoring, evidence and kill switches.

Get access →

Next up

The free AISVS webinar starts in

0
Days
0
Hours
0
Mins
0
Secs
Reserve your free seat

Train your team.
Prove your AI is secure.

Every course runs as a private corporate or sovereign cohort, on-site or remote, GPU-backed labs included. Delivered by the former OWASP-AISVS Co-Leader (v1.0).

Enquire about training