Each week combines explanation, guided practice and evidence review across three sessions. The lab tasks and portfolio outputs below form the assessment trail.
WEEK 1–2AI security foundations and evidence discipline
LLMs, retrieval, tool use and model limits in security work; data classification, secret removal, untrusted input, hallucinated indicators and reproducible verification. Refresh only the networking and scripting needed for the labs.
Lab: Set up an isolated Linux/Python lab. Compare AI-generated alert summaries with source logs and document unsupported claims.
Evidence: AI-use policy, lab baseline and evidence-checking rubric.
WEEK 3–4Security data and AI-assisted detection
Endpoint, identity, DNS and network telemetry; parsing, time zones, data quality, Python/Pandas, rule drafting and supervised anomaly detection. Precision, recall, class imbalance, drift and false positives.
Lab: Use labelled benign and suspicious records to compare a rule baseline with a small anomaly model. Verify AI-generated queries before running them.
Evidence: Versioned dataset notes, tested detection queries and a false-positive analysis.
WEEK 5–6AI-powered SOC operations
SIEM triage, alert enrichment, case management, asset context, severity, escalation and analyst handovers. Source-grounded security copilots with redacted evidence.
Lab: Investigate replayed identity and endpoint alerts using Wazuh and case worksheets; compare manual and assisted triage on the same cases.
Evidence: Triage casebook with citations, uncertainty, review time and escalation decisions.
WEEK 7–8Threat intelligence and threat hunting
ATT&CK-based hypotheses, observable validation, intelligence quality, Sigma logic, coverage gaps and evidence-led hunting. Distinguish correlation from proof.
Lab: Hunt through a controlled multi-stage intrusion dataset, validate an AI-proposed hypothesis and reject decoy indicators.
Evidence: Hunt report, tested rules and an ATT&CK coverage map.
WEEK 9–10Incident response and supervised automation
Scope, timelines, evidence integrity, containment options, recovery, communications and post-incident review. Separate read-only enrichment from actions that change systems.
Lab: Build a local enrichment workflow with an approval gate; run a ransomware-style tabletop using synthetic events, then test recovery and rollback.
Evidence: Incident timeline, approval log, response playbook and recovery checklist.
WEEK 11–12Cloud and identity security with AI
Cloud audit logs, IAM, service accounts, secrets, storage exposure, workload identity and least privilege. Validate AI-generated policy changes and infrastructure findings.
Lab: Review sample AWS/Azure policies and audit events; scan a local container and IaC sample, propose a minimal permission set and test it in a sandbox.
Evidence: Cloud risk findings, permission diff, test results and rollback plan.
WEEK 13–14GenAI and RAG application security
Prompt injection, unsafe output handling, sensitive-data exposure, retrieval access control, document poisoning, embeddings and tenant isolation. Threat models across model, application and data boundaries.
Lab: Build a small RAG assistant with synthetic documents; reproduce indirect prompt injection and cross-role retrieval failures, then apply and retest controls.
Evidence: Data-flow threat model and before/after security regression results.
WEEK 15–16AI red teaming and adversarial evaluation
Authorized test scope, threat-driven test design, garak and PyRIT, manual verification, attack-success rate and clean-task performance. Adversarial-ML concepts: poisoning, evasion, extraction and privacy attacks.
Lab: Evaluate an intentionally vulnerable local AI application with bounded probes and a benign control set. Verify findings manually and record model/settings versions.
Evidence: Reproducible red-team report with severity, evidence, fixes and residual risk.
WEEK 17–18Agentic AI and AI-to-AI security
Tool permissions, MCP trust boundaries, identity delegation, memory/context poisoning, tool-output injection and multi-agent trust. Approval gates, budgets, monitoring, containment and kill switches.
Lab: Build a restricted tool-using agent; test a malicious tool response and memory contamination. Enforce allowlists and prevent unapproved writes.
Evidence: Agent permission matrix, execution traces, denied-action tests and containment runbook.
WEEK 19–20AI cyber risk and governance
NIST CSF and AI RMF mapping, AI inventory, vendor assessment, supply chain, control ownership, risk acceptance and audit evidence. Communicate technical findings to decision makers.
Lab: Review a simulated company adopting a security copilot and customer-facing agent. Check AI-drafted controls against actual evidence.
Evidence: Risk register, control matrix, vendor review and executive decision memo.
WEEK 21–22Cyber Range and AI5 Emerging Threat Lab
Connect SOC investigation, compromised AI application, cloud identity and response decisions in one scoped exercise. Evaluate a newly documented AI-security development.
Lab: Rotate analyst, reviewer and incident commander roles through staged evidence releases; reproduce a safe emerging-threat test and validate a mitigation.
Evidence: Range case record, threat advisory, detection updates and lessons learned.
WEEK 23–24Employer-grade capstone and oral defence
Deliver an auditable security improvement for a simulated enterprise; demonstrate technical controls, trade-offs, recovery and operational handover.
Lab: Run the integrated capstone against unseen benign and adversarial cases, present it live and answer individual verification questions.
Evidence: Repository, evidence bundle, scorecard, runbooks, executive briefing and individual oral defence.