SPECIALIST PROGRAM · LIVE ONLINE · ENGLISH

AI Cyber Risk, GRC & Governance

Assess cyber risks from GenAI and autonomous agents, verify controls and build an auditable governance portfolio using NIST, OWASP and evidence from realistic security scenarios.

AI proposesEvidence verifiesHumans authorize.
8 weeksProgram duration
24 sessions3 instructor-led sessions/week
2436 hours60–90 minutes/session

Who this program is for

Cyber-risk and GRC professionals, security managers, auditors, compliance teams and technical staff moving into AI security governance.

Entry requirements

Basic understanding of business risk, security controls and evidence review. No coding prerequisite; technical control demonstrations are explained through business decisions and risk scenarios.

Weekly commitment

Allow 2–4 hours each week for evidence review and portfolio assignments. Live time totals 2436 hours across 24 sessions; assignments and preparation do not count toward those hours.

Use a laptop with a current browser, spreadsheet editor and reliable internet.

WEEK-BY-WEEK CURRICULUM

Learn through security work.

Each week combines explanation, guided practice and evidence review across three sessions. The lab tasks and portfolio outputs below form the assessment trail.

WEEK 1

AI cyber-risk inventory

GenAI, RAG and agents; data flows, shadow AI, critical assets, ownership and third-party dependencies.

Lab: Use AI to draft an inventory from a fictional company pack; verify every entry against source documents.

Evidence: AI inventory and data-flow record.

WEEK 2

Threats and control mapping

OWASP GenAI/agent risks, ATT&CK/ATLAS context and NIST CSF/AI RMF mapping.

Lab: Evaluate a security copilot and customer-facing AI agent; separate documented controls from assumptions.

Evidence: Cyber-risk register and source-linked control matrix.

WEEK 3

Vendor and supply-chain assurance

Data handling, model provenance, hosting, subcontractors, access, retention and incident commitments.

Lab: Review a simulated vendor questionnaire and conflicting evidence; draft follow-up questions.

Evidence: Vendor assessment and residual-risk decision.

WEEK 4

Agent authority and human oversight

Least privilege, identity, approval rules, autonomy limits, monitoring, shutdown and AI-to-AI accountability.

Lab: Assess a proposed autonomous security workflow and set who may approve each action.

Evidence: Agent permission matrix and human-approval policy.

WEEK 5

Testing, assurance and governance evidence

AI-assisted control testing, red-team evidence, false assurance, performance thresholds and exception handling.

Lab: Review a technical test report with missing evidence and inflated success claims.

Evidence: Assurance checklist, test acceptance criteria and exceptions log.

WEEK 6

Incident and regulatory readiness

AI incident management, reporting ownership, records, legal-review triggers and jurisdiction-specific obligations. Framework mapping is not proof of legal compliance.

Lab: Run a tabletop involving a leaking AI assistant; build a defensible decision timeline.

Evidence: Incident protocol and management briefing.

WEEK 7

Cyber Range decision exercise and Emerging Threat Lab

Translate technical evidence into risk decisions; assess a newly published AI-security advisory.

Lab: Act as risk owner in a staged agent compromise and challenge unverified containment claims.

Evidence: Range decision log and emerging-threat control update.

WEEK 8

Governance capstone and oral defence

Control ownership, evidence cadence, risk acceptance, metrics and a practical implementation roadmap.

Lab: Present a security governance pack for a simulated AI deployment and defend approval conditions.

Evidence: Board-ready portfolio, action plan and individual oral review.

Tool stack: know what you will actually use.

CoverageTools and materialAccess and use
Hands-on coreSpreadsheet risk register · Approved AI assistant · NIST CSF / AI RMF · OWASP GenAI guidance · MITRE ATT&CK / ATLAS · Technical evidence packsCreate and verify risk, control and assurance records; no programming lab requirement.
Framework-basedOWASP GenAI and Agentic Security · MITRE ATT&CK/ATLAS · NIST CSF/AI RMF · NIST adversarial-ML taxonomyMap threats and controls, justify test scope and trace evidence. These are references, not software subscriptions or AI5 accreditations.
Demonstrated or evidence-ledTechnical red-team output, cloud security findings, agent traces and SOC incidentsInstructor walkthroughs or sanitized evidence packs; not every platform is a student lab.
Commercial / usage-dependentMicrosoft Security Copilot, Sentinel, Splunk, enterprise AI assistants, cloud accounts and paid model APIsHands-on access only when a suitable license, tenant and budget are confirmed. These subscriptions, credits and exams are not automatically included. Equivalent local exercises support the core learning goals.

Use only approved AI endpoints with synthetic or sanitized data. Product names describe training context, not partnerships. Tool versions and the exact lab access list are confirmed for each cohort.

ASSESS THE WORK, NOT THE PROMPT

Portfolio and employer-grade capstone

Final capstone

Deliver a cyber-governance approval pack for a simulated enterprise introducing GenAI and agents: inventory, risks, verified controls, vendor findings, incident duties, monitoring metrics, ownership and a 90-day action plan.

40% · Practical evidence

Reproducible results, source checks, tested controls and useful lab records.

20% · Scenario decisions

Range performance, uncertainty, approval boundaries and communication.

40% · Capstone & defence

Working or auditable deliverables, unseen test cases, handover and individual explanation.

Completion standard: 70% overall, all mandatory submissions and a pass on evidence verification and authorization controls. Unsafe unapproved actions or fabricated evidence must be corrected and reassessed. AI assistance must be disclosed; copied model output without verification is not accepted as proof.

Technical scorecards include false positives, detection or attack-success measures, clean-task performance and reproducibility. Governance scorecards check evidence completeness, control ownership, risk decisions and traceability. An attractive report alone does not meet the standard.

PRACTISE THE WHOLE DECISION

Cyber Range: investigate, verify, respond.

The Cyber Range is a sequence of isolated training scenarios using local applications, synthetic company records and replayed security events. Technical routes test controls; the governance route reviews the evidence and authorizes decisions in tabletop exercises.

Investigate

Work with incomplete evidence, noisy alerts and an AI system that can make mistakes. Record hypotheses and competing explanations.

Verify

Reproduce findings, test benign controls and keep source references, timestamps, configuration and version records.

Respond

Request approval for changes, test containment and rollback, then explain remaining risk in an operational handover.

All testing stays within authorized training targets. No live third-party attacks or real customer secrets. Hosted range subscriptions and continuous access are not assumed; confirm the cohort’s delivery and access arrangements before enrolment.

BUILT TO KEEP LEARNING

AI5 Emerging Threat Lab

Each cohort examines a recent AI-security advisory or research finding within its scheduled lab time. Learners check the source, assess relevance, reproduce a safe bounded example where feasible, test a mitigation and add an evidence-backed advisory to their portfolio.

Topics may include new agent protocols, AI-to-AI trust failures, memory poisoning, impersonation, autonomous tool misuse or changes in defensive models. This prepares learners for increasingly capable AI without speculative claims about AGI. The lab refreshes case material while preserving the program’s core learning outcomes and hours.

Live Online. Built for professional teams worldwide.

English-language live instruction, practical assignments and individual review. International learners should share their country and time zone so admissions can confirm a suitable cohort, local class times and daylight-saving changes before enrolment. Three sessions per week; generally 60–90 minutes each.

AI5 also serves learners in India and Delhi NCR. These programs are listed as Live Online; any on-site company delivery requires a separate agreed scope. Ask for batch dates, fees, applicable taxes, payment currency and international payment instructions. No batch date or commercial-tool access is promised until confirmed.

Companies can request a private cohort around approved tools, sanitized scenarios, team roles and measurable acceptance criteria. Discuss company training.

Questions before you join

How is this different from a conventional cybersecurity course?

AI-assisted security work and the security of AI systems are the starting point. Every workflow requires evidence checks, explicit authority and measurable tests. Conventional foundations are prerequisites or targeted refreshers, rather than the main curriculum.

How many live sessions and hours are included?

8 weeks × 3 sessions = 24 live sessions. At 60–90 minutes each, that is 24–36 instructor-led hours. Independent assignments are additional.

Do I need coding or cybersecurity experience?

Basic understanding of business risk, security controls and evidence review. No coding prerequisite; technical control demonstrations are explained through business decisions and risk scenarios.

Are paid tools, exams or professional certifications included?

Do not assume a commercial subscription, cloud credit, vendor exam, external certification or CPE entitlement is included. Core practical work uses local/open tools and synthetic evidence where possible. Ask admissions for a written list of any batch-specific access costs and completion documentation.

Can international learners and company teams join?

Yes, through Live Online training in English, subject to a suitable confirmed cohort. Share your time zone and objectives. Companies may request a private cohort with agreed tools and sanitized scenarios.

Does the program guarantee a job or a secure AI system?

No. The assessed output is a portfolio of verified workflows and control evidence. Hiring and production security depend on experience, the environment and ongoing review; a course or scanner cannot guarantee either.

CURRICULUM REFERENCES

Work from current security guidance.

Source pages checked September 2026. Each cohort records the editions, tool versions and advisories used in its lab briefs. Framework use does not imply accreditation, partnership or endorsement.

OWASP GenAI Security Project
GenAI application risks and control guidance.

OWASP Agentic Security Initiative
Agent trust boundaries, identity, tools and memory risks.

MITRE ATT&CK
Threat behaviours, hunting hypotheses and detection coverage.

MITRE ATLAS
Adversarial threats to AI systems.

NIST Cybersecurity Framework
Cybersecurity outcomes and control ownership.

NIST AI Risk Management Framework
AI risk management and evidence review.

NIST Adversarial Machine Learning taxonomy
Attack and mitigation terminology.

Discuss your fit, fees and next batch.

Tell us your experience and time zone. We will use those details to discuss a suitable cohort and confirm access requirements.

Cybersecurity course enquiry

By requesting details, you agree to be contacted about this enquiry. Please do not include confidential company data. Privacy policy

Compare the other routes.

Return to Applied AI for Cybersecurity

Call now1800 1020 418WAGet details
CallWhatsAppFees & syllabus