Highlights
-
Understand why this top-up course exists and how it builds on Days 1–2
-
Understand AI Security Foundations & Secure Design
-
Explore AI/LLM Vulnerability Taxonomy & Automated Attacks
-
Learn about Privacy, GDPR & Automated Processing
-
Understand Editorial Integrity, Transparency & the EU AI Act
-
Apply Secure SDLC principles to AI security and identify trusted resources
Course Details
Module 13: Why This Top-Up Course Exists (Orientation to Day 3)
Builds on: Core Security Knowledge & Skills from Days 1–2, including a targeted AI-security quiz with instant feedback, building on the familiar format of Days 1–2.
Case studies: BBC's November 2025 trust crisis set alongside Anthropic's AI-orchestrated espionage case.
Introduces the Top-Up day's governing three-thesis roadmap: AI Security, Lawful Data Use & Transparency.
Practical: Delegates sort AI-risk scenario cards against the day's three themes.
Module 14: AI Security Foundations & Secure Design
Builds on: Module 4 (OWASP/CWE/CVE/CVSS/ATT&CK), Module 10 (Threat Modelling), and Module 11 (NIST CSF).
Live prompt-injection demonstration against a simple chatbot wrapper.
Extends Module 4's OWASP/CWE/CVE/CVSS/MITRE ATT&CK relationships to AI through MITRE ATLAS.
Introduces the NIST AI Risk Management Framework (AI RMF) as the AI-specific sibling of Module 11's NIST Cybersecurity Framework.
Practical: Groups map the OWASP–MITRE relationships from Module 4 onto an AI feature.
Module 15: AI/LLM Vulnerability Taxonomy & Automated Attacks
Builds on: Module 5 (A07/A01), Module 6 (A05 Injection), and Module 8 (A02/A03).
Introduces the OWASP LLM Top 10, mapped directly onto the OWASP Top 10 categories covered in Modules 5, 6 and 8.
Introduces MITRE ATLAS as ATT&CK's AI-specific sibling, extending Module 4.
Hands-on exploitation of Juice Shop's native AI chatbot challenges.
Practical: Delegates exploit Chatbot Prompt Injection, Greedy Chatbot Manipulation, System Prompt Extraction or AI Debugging in Juice Shop, then remediate and self-check against OWASP AISVS.
Module 16: Privacy, GDPR & Automated Processing
Builds on: Module 2 (legal, ethical and data protection considerations).
Extends Module 2's legal, ethical and data protection grounding into automated decision-making.
Introduces the Data (Use and Access) Act 2025 and its provisions concerning automated decision-making.
Examines the BBC's stated lawful basis of “performance of its public task” in the context of Charter-mission continuity.
Practical: Delegates redesign a BBC-shaped automated decision-making scenario against a decision-tree worksheet.
Module 17: Editorial Integrity, Transparency & the EU AI Act
Builds on: A new strand with no direct Day 1/2 precedent.
Examines the BBC's three AI principles — public interest, talent and transparency — alongside EU AI Act Article 50.
Case study: BBC's Partnership on AI synthetic-media documentary compared with its Panorama deepfake investigation.
Explores disclosure decision-making for AI-assisted content.
Practical: Delegates work through a “Would this need disclosure?” decision-flow card set.
Module 18: Secure SDLC Synthesis, Signposting & Close
Builds on: Module 7 (SSDLC models, OWASP ASVS) and Module 12 (closing structure).
Introduces OWASP AISVS as the AI-specific sibling of ASVS, extending Module 7 directly.
Maps the NCSC/CISA four-stage AI lifecycle against the SSDLC models from Module 7.
Reflects on key learnings and how to improve AI security practice within the BBC.
Signposts trusted AI-security sources and completes end-of-course feedback.
Practical: Delegates re-sort Module 13's scenario cards against SDLC gates and draft team commitments.
Who should attend
This course is designed for delegates who have already completed Days 1–2 of the Secure Web Application Development course and want to extend their existing application security knowledge into the areas of AI security, privacy and trust.
It is particularly relevant to:
-
Web and application developers
-
Software engineers
-
Application security professionals
-
Security engineers and security architects
-
DevSecOps and secure SDLC practitioners
-
Technical leads and development team leads
-
Cybersecurity professionals involved in application security
-
Architects and technical specialists working with AI-enabled applications
-
Professionals responsible for assessing or managing security risks associated with AI and LLM technologies
-
Technical and governance professionals who need to understand the security and privacy implications of introducing AI into applications
Prerequisite
This is not intended as a standalone introductory AI security course. It is a third-day top-up to the original Secure Web Application Development security course.
Delegates should therefore have completed Days 1–2 (Modules 1–12), or have equivalent knowledge and practical experience in application and web security.
The Day 3 programme deliberately builds on concepts introduced during the prerequisite course, including:
-
OWASP and common application vulnerabilities
-
Threat modelling
-
Secure Software Development Lifecycle (SSDLC)
-
OWASP ASVS
-
Security frameworks and standards
-
Application security testing
-
Data protection and security considerations
The top-up then extends these foundations into AI/LLM security, AI-specific vulnerabilities, secure AI design, privacy and automated processing, transparency, AI governance and AI-aware secure development practices.
Feedback
4.8 out of 5 average
"Our tailored course provided a well rounded introduction and also covered some intermediate level topics that we needed to know. Clive gave us some best practice ideas and tips to take away. Fast paced but the instructor never lost any of the delegates"
Brian Leek, Data Analyst, May 2022
“JBI did a great job of customizing their syllabus to suit our business needs and also bringing our team up to speed on the current best practices. Our teams varied widely in terms of experience and the Instructor handled this particularly well - very impressive”
Brian F, Team Lead, RBS, Data Analysis Course, 20 April 2022