CN-CAISE curriculum
8 modules, published in full
What each module covers, what you do in its lab, and what you can do afterwards. Nothing here is behind a form.
Module 1
The AI attack surface
- What it covers
- Where AI systems differ from the systems you already secure: the trust boundaries that moved, and the ones that were never drawn.
- Lab
- Map the attack surface of a running retrieval-augmented application.
- Afterwards
- You can describe an AI system’s trust boundaries to another engineer.
Module 2
Prompt injection and instruction hijacking
- What it covers
- Direct and indirect injection, why input validation does not solve it, and what actually reduces the risk in production.
- Lab
- Compromise a deployed assistant, then implement and test mitigations.
- Afterwards
- You can assess and harden an application against injection.
Module 3
Securing retrieval pipelines
- What it covers
- How document access controls dissolve at the context window, and how to keep authorisation intact through embedding, retrieval and generation.
- Lab
- Exfiltrate a restricted document through a RAG pipeline, then close the path.
- Afterwards
- You can design a retrieval pipeline that preserves authorisation.
Module 4
Model assets and supply chain
- What it covers
- Weights, prompts, fine-tuning data and third-party models as assets: classification, provenance, and the risks of what you did not train.
- Lab
- Audit a model supply chain and produce a risk register entry.
- Afterwards
- You can bring model assets into an existing security inventory.
Module 5
Agentic systems and privilege
- What it covers
- Tool-calling systems that act on the world, and the privilege boundaries nobody scoped for an autonomous caller.
- Lab
- Escalate privilege through an agent’s tool chain, then constrain it.
- Afterwards
- You can scope and review permissions for an agentic system.
Module 6
AI red teaming
- What it covers
- How adversarial testing of AI systems differs from a penetration test, and how to structure an exercise that produces actionable findings.
- Lab
- Run a scoped red-team exercise against a target application.
- Afterwards
- You can plan, run and report an AI red-team engagement.
Module 7
Incident response for AI systems
- What it covers
- What “compromised” means for a model-backed system, what evidence exists, and what to preserve before it is gone.
- Lab
- Tabletop exercise against a live AI-security incident scenario.
- Afterwards
- You know what to do in the first hour, and what not to destroy.
Module 8
Governance, review and reporting
- What it covers
- Bringing AI security into design review, and writing for an audience that includes people who do not build systems.
- Lab
- Review a feature specification and produce a written assessment.
- Afterwards
- You can hold the AI security position in a design review.
How you are assessed
- Continuous assessment through the labs, with feedback in the session rather than afterwards
- A final exercise: a scoped review of an AI system, written up as findings
- Assessed on judgement and reasoning, not on recall
- Certification is issued to those who meet the standard. Not everyone does — a credential everyone receives is worth nothing.
Is this the right level for you?
Five questions, about a minute, and an honest answer.