Secure Web App Development — AI Security, Privacy & Trust: Top-Up Day training course

AI Security, Privacy & Trust — Top-Up Day Extend your secure web application development skills into the rapidly evolving world of AI and LLM-enabled applications. This specialist third-day top-up builds directly on the application security foundations covered in the first two days of the Secure Web Application Development course.

JBI training course London UK

"Our tailored course provided a well rounded introduction and also covered some intermediate level topics that we needed to know. Clive gave us some best practice ideas and tips to take away. Fast paced but the instructor never lost any of the delegates"

Brian Leek, Data Analyst, May 2022

Public Courses

02/11/26 - 1 days
£2500 +VAT
14/12/26 - 1 days
£2500 +VAT
25/01/27 - 1 days
£2500 +VAT

Customised Courses

* Train a team
* Tailor content
* Flex dates
From £1200 / day
EDF logo Capita logo Sky logo NHS logo RBS logo BBC logo CISCO logo
JBI training course London UK

  • Understand why this top-up course exists and how it builds on Days 1–2

  • Understand AI Security Foundations & Secure Design

  • Explore AI/LLM Vulnerability Taxonomy & Automated Attacks

  • Learn about Privacy, GDPR & Automated Processing

  • Understand Editorial Integrity, Transparency & the EU AI Act

  • Apply Secure SDLC principles to AI security and identify trusted resources

Module 13: Why This Top-Up Course Exists (Orientation to Day 3)

Builds on: Core Security Knowledge & Skills from Days 1–2, including a targeted AI-security quiz with instant feedback, building on the familiar format of Days 1–2.

Case studies: BBC's November 2025 trust crisis set alongside Anthropic's AI-orchestrated espionage case.

Introduces the Top-Up day's governing three-thesis roadmap: AI Security, Lawful Data Use & Transparency.

Practical: Delegates sort AI-risk scenario cards against the day's three themes.

Module 14: AI Security Foundations & Secure Design

Builds on: Module 4 (OWASP/CWE/CVE/CVSS/ATT&CK), Module 10 (Threat Modelling), and Module 11 (NIST CSF).

Live prompt-injection demonstration against a simple chatbot wrapper.

Extends Module 4's OWASP/CWE/CVE/CVSS/MITRE ATT&CK relationships to AI through MITRE ATLAS.

Introduces the NIST AI Risk Management Framework (AI RMF) as the AI-specific sibling of Module 11's NIST Cybersecurity Framework.

Practical: Groups map the OWASP–MITRE relationships from Module 4 onto an AI feature.

Module 15: AI/LLM Vulnerability Taxonomy & Automated Attacks

Builds on: Module 5 (A07/A01), Module 6 (A05 Injection), and Module 8 (A02/A03).

Introduces the OWASP LLM Top 10, mapped directly onto the OWASP Top 10 categories covered in Modules 5, 6 and 8.

Introduces MITRE ATLAS as ATT&CK's AI-specific sibling, extending Module 4.

Hands-on exploitation of Juice Shop's native AI chatbot challenges.

Practical: Delegates exploit Chatbot Prompt Injection, Greedy Chatbot Manipulation, System Prompt Extraction or AI Debugging in Juice Shop, then remediate and self-check against OWASP AISVS.

Module 16: Privacy, GDPR & Automated Processing

Builds on: Module 2 (legal, ethical and data protection considerations).

Extends Module 2's legal, ethical and data protection grounding into automated decision-making.

Introduces the Data (Use and Access) Act 2025 and its provisions concerning automated decision-making.

Examines the BBC's stated lawful basis of “performance of its public task” in the context of Charter-mission continuity.

Practical: Delegates redesign a BBC-shaped automated decision-making scenario against a decision-tree worksheet.

Module 17: Editorial Integrity, Transparency & the EU AI Act

Builds on: A new strand with no direct Day 1/2 precedent.

Examines the BBC's three AI principles — public interest, talent and transparency — alongside EU AI Act Article 50.

Case study: BBC's Partnership on AI synthetic-media documentary compared with its Panorama deepfake investigation.

Explores disclosure decision-making for AI-assisted content.

Practical: Delegates work through a “Would this need disclosure?” decision-flow card set.

Module 18: Secure SDLC Synthesis, Signposting & Close

Builds on: Module 7 (SSDLC models, OWASP ASVS) and Module 12 (closing structure).

Introduces OWASP AISVS as the AI-specific sibling of ASVS, extending Module 7 directly.

Maps the NCSC/CISA four-stage AI lifecycle against the SSDLC models from Module 7.

Reflects on key learnings and how to improve AI security practice within the BBC.

Signposts trusted AI-security sources and completes end-of-course feedback.

Practical: Delegates re-sort Module 13's scenario cards against SDLC gates and draft team commitments. 

JBI training course London UK

This course is designed for delegates who have already completed Days 1–2 of the Secure Web Application Development course and want to extend their existing application security knowledge into the areas of AI security, privacy and trust.

It is particularly relevant to:

  • Web and application developers

  • Software engineers

  • Application security professionals

  • Security engineers and security architects

  • DevSecOps and secure SDLC practitioners

  • Technical leads and development team leads

  • Cybersecurity professionals involved in application security

  • Architects and technical specialists working with AI-enabled applications

  • Professionals responsible for assessing or managing security risks associated with AI and LLM technologies

  • Technical and governance professionals who need to understand the security and privacy implications of introducing AI into applications

Prerequisite

 

This is not intended as a standalone introductory AI security course. It is a third-day top-up to the original Secure Web Application Development security course.

Delegates should therefore have completed Days 1–2 (Modules 1–12), or have equivalent knowledge and practical experience in application and web security.

The Day 3 programme deliberately builds on concepts introduced during the prerequisite course, including:

  • OWASP and common application vulnerabilities

  • Threat modelling

  • Secure Software Development Lifecycle (SSDLC)

  • OWASP ASVS

  • Security frameworks and standards

  • Application security testing

  • Data protection and security considerations

The top-up then extends these foundations into AI/LLM security, AI-specific vulnerabilities, secure AI design, privacy and automated processing, transparency, AI governance and AI-aware secure development practices.


5 star

4.8 out of 5 average

"Our tailored course provided a well rounded introduction and also covered some intermediate level topics that we needed to know. Clive gave us some best practice ideas and tips to take away. Fast paced but the instructor never lost any of the delegates"

Brian Leek, Data Analyst, May 2022



“JBI  did a great job of customizing their syllabus to suit our business  needs and also bringing our team up to speed on the current best practices. Our teams varied widely in terms of experience and  the Instructor handled this particularly well - very impressive”

Brian F, Team Lead, RBS, Data Analysis Course, 20 April 2022

 

 

JBI training course London UK

Certification


Every delegate will be entitled to a certificate of achievement on completion of the course.

If you are missing your certificate - please use the link below to apply - you can also use this link to sign up for the JBI Training newsletter to receive technology tips directly from our instructors - Analytics, AI, ML, DevOps, Web, Backend and Security.
 



Secure Web Application Development — AI Security, Privacy & Trust: Top-Up Day is a specialist third-day extension to the original two-day Secure Web Application Development security course.

The first two days establish the core security knowledge and practical skills required for secure application development, covering areas such as OWASP, common application vulnerabilities, threat modelling, secure software development lifecycle practices, security standards and frameworks, and data protection considerations.

This third-day top-up builds directly on that foundation and applies it to the rapidly developing security, privacy and trust challenges associated with artificial intelligence and large language model (LLM)-enabled applications.

Rather than repeating the core security material from Days 1–2, the top-up day extends existing concepts into the AI security domain. Delegates revisit familiar security principles and apply them to AI-enabled applications, including prompt injection, LLM vulnerabilities, AI-specific threat modelling, automated attacks, secure AI design and AI-aware secure development practices.

The course also addresses the wider governance and regulatory considerations that arise when AI is used within applications and organisational workflows. This includes privacy and automated decision-making, GDPR considerations, transparency, editorial integrity, and relevant requirements and guidance associated with the EU AI Act, NCSC, OWASP and other recognised security frameworks.

Practical exercises throughout the day allow delegates to apply these concepts to realistic AI security scenarios and hands-on AI-enabled application challenges.

The course therefore provides a natural Day 3 progression from application security into AI security, helping delegates take the security knowledge developed during the original two-day course and apply it to modern AI-enabled web applications and services.

Application Security Training teaches developers, security professionals, architects, testers, and technical teams how to identify, prevent, and manage security vulnerabilities in software and web applications. JBI's Application Security training covers secure development practices, secure coding, OWASP Top 10, Python security, and practical cyber attack simulation.
The courses are suitable for software developers, web developers, application security professionals, cybersecurity specialists, solutions architects, QA and testing professionals, DevOps teams, data analysts, quantitative analysts, and technical leaders responsible for application security.
Depending on the course, delegates can learn how to identify common application vulnerabilities, apply secure coding techniques, protect web applications, address OWASP Top 10 risks, write more secure Python, Java, JavaScript, ASP.NET and PHP code, and understand how applications can be attacked and defended.
Secure Web Application Development focuses on building web applications with security incorporated throughout the development process. Training covers practical approaches to identifying vulnerabilities and implementing appropriate security controls to reduce application security risks.
The OWASP Top 10 is a widely recognised awareness document covering important categories of web application security risks. JBI's OWASP Top 10 Practical Web Application Security course provides practical training in understanding, identifying, exploiting, and mitigating common web application vulnerabilities.
Yes. JBI offers dedicated Python security training covering secure Python development as well as a specialised course for data analysts and quantitative analysts who use Python in their work.
Yes. The Application Security group includes a dedicated Python Security for Data Analysts & Quants course. It focuses on security considerations relevant to professionals using Python for data analysis, quantitative analysis, and related activities.
The Application Security training portfolio includes dedicated secure coding courses covering Java, JavaScript, ASP.NET, PHP, and Python. The exact topics and security techniques vary according to the individual course.
Secure coding is the practice of developing software in a way that reduces security vulnerabilities and protects applications, systems, and data from attack. It includes practices such as secure input handling, authentication, authorisation, data protection, error handling, and defensive programming.

CONTACT


+44 (0)20 8446 7555

enquiries@jbinternational.co.uk

 

Copyright © 2026 JBI Training. All Rights Reserved.
JB International Training Ltd  -  Company Registration Number: 08458005
Registered Address: Wohl Enterprise Hub, 2B Redbourne Avenue, London, N3 2BS

Modern Slavery Statement & Corporate Policies | Terms & Conditions | Contact Us

POPULAR

AI training courses                                                                        CoPilot training course

Threat modelling training course   Python for data analysts training course

Power BI training course                                   Machine Learning training course

Spring Boot Microservices training course              Terraform training course

Data Storytelling training course                                               C++ training course

Power Automate training course                               Clean Code training course