New programme

    AI Agents for Cyber Defense

    Hands-on training for security teams

    Attackers already use AI. At the same time, the rest of your organisation is building agents that need identities, access and privileges. Both land on the security team's desk. In this programme your people build agents for defensive work, learn how agents are attacked, and leave with principles for governing agents as identities.

    Two jobs at once

    Licence training for Copilot and similar tools teaches people to use the tool. It rarely teaches a SOC analyst to build an agent that triages alerts with a clear approval point. And it doesn't answer who owns an agent, which identity it runs as, and who reviews its permissions.

    This programme is built for exactly that gap.

    Three tracks: Build, Protect and Govern

    Build

    Participants scope a task from their own work, build an agent for it, test it, and set the points where a human approves.

    Protect

    When the agent is the attack surface: prompt injection, data leakage through context, over-privileged agents and third-party connectors. Plus zero-day readiness with AI as support.

    Govern

    Agents as identities: owner, identity, least privilege, access reviews, logging and lifecycle.

    What participants take home

    An agent they built, tested and set approval points on, for a task from their own work.

    The Agent Canvas for security: six questions that decide whether a task is fit for an agent. They can use it on every agent they build next.

    Knowledge of how agents are attacked, so the agents they build are harder to misuse.

    Hands-on experience with local open-source models running in your own environment, so sensitive logs and data never leave the building.

    A personal Top 3 of tasks where an agent can take load off, and a plan for the first 30 days.

    What the security team gets

    Prototypes on your own cases in SOC, IAM and incident response.

    A first set of principles for agent identities: owner, permissions, access reviews and lifecycle.

    A first draft of readiness for the first 24 hours of a zero-day incident.

    Documented upskilling you can point to in your NIS2 and AI Act Article 4 work.

    A follow-up after 30 days on which agents are in use and what is blocking.

    Use cases from security operations

    SOC: alert triage and enrichment, shift handover summaries, draft KQL and Sigma queries.

    Identity and IAM: access review preparation, explaining SoD conflicts, triage of access requests.

    PAM: summaries of privileged sessions and anomalies in break-glass account use.

    Incident response: timelines from logs and tickets, draft communications, runbook assistant.

    Vulnerability management: triage of advisories against your own asset inventory and suggested priorities.

    GRC and compliance: knowledge agent over policies and controls, mapping to NIS2, ISO 27001 or DORA, audit evidence.

    All exercises run on synthetic data. A human always approves.

    Packages

    Kickstart

    Duration
    Half day, 3.5 hours
    Hands-on
    First agent on a shared case
    Protect and Govern
    Short introduction

    Agents for Your Business Defense

    Duration
    Full day
    Hands-on
    Agents on three cases from your work
    Protect and Govern
    Compact module on risks and zero-day

    Bootcamp

    Duration
    Two days
    Hands-on
    Own agent on a case from own work
    Protect and Govern
    Full blocks with tabletop exercise, hands-on with a local LLM for logs and principles for agent identities

    All packages are for teams of up to 20 participants. We agree the price in a short call based on package and team size.

    Preparation with needs assessment, synthetic datasets and tool testing, plus a follow-up after 30 days, is included in every package.

    Who is it for?

    • SOC and monitoring.
    • Identity, IAM and PAM.
    • Incident response and vulnerability management.
    • GRC, compliance and the CISO office.

    Participants need to know their own work. Coding is not a prerequisite.

    Safe by design, in your own tools

    We work in the tools you already have: Microsoft 365 Copilot, Copilot Studio, an internal platform on Azure OpenAI, ChatGPT Enterprise, Claude or Gemini. Exercises run on synthetic data built for you during preparation. Real identity, access and log data is not used in the training. For sensitive logs we show local open-weight models that run inside your own environment.

    The rules are already set

    The Danish NIS2 Act took effect on 1 July 2025 and places responsibility for cyber security with management, including training requirements. Since 2 February 2025, AI Act Article 4 has required organisations to take measures to ensure, to their best extent, a sufficient level of AI literacy among staff working with AI. This programme gives you documented upskilling for the group carrying the heaviest responsibility.

    Local open-source models

    Some data must never leave the building. That's why you learn to run open-weight models locally and use them to analyse security logs. We look at which models and tools exist, where they are strong and where they fail. In the Bootcamp, participants run a local model themselves on synthetic logs. In the other packages we show it as a demo, and hands-on can be added as an option.

    What participants say

    "Stefano's infectious enthusiasm brought the teaching to life. The hands-on approach worked perfectly; I got to try many AI tools and now feel ready to use them in practice."

    "Great that we got to try so many different tools in a short time. The Miro board is a treasure trove of information that I keep coming back to."

    "I didn't have much experience with AI, but the course was accessible and educational. The informal atmosphere made it safe to ask questions and experiment."

    "Good balance between presentations and exercises. Stefano is dynamic and engaged, and his deep knowledge of AI products clearly shows in the teaching."

    "Really good and exciting exercises with relevant real-world cases that showed how AI is actually used in other Danish companies. Super inspiring!"

    "Fun to try vibe coding! The course gave me a broad overview of AI tools and how they connect. I quickly started feeling like I could do something."

    "Stefano's huge preparation work shines through. Plenty of material and hints for further study – I have resources to dive deeper on my own."

    "The ethics debate was an important and welcome element. The course isn't just about tools, but also about responsible use of AI in practice."

    "Having the class in Danish and in a small group created a great atmosphere. You could talk together and get feedback on the exercises. It was really valuable."

    "Nice amount of breaks and good time management. No stress. The structure of prompts, context and RAG was explained clearly and practically applicable."

    "Lovable and synthetic personas were an eye-opener! The course gave inspiration about new apps and tools I didn't know. Stefano's energy level keeps your attention the whole way!"

    "Good perspectives on how we'll work with AI products going forward. The consistent structure following the product development cycle made good sense."

    "Claude impressed me! The explanation of differences between similar tools like relay.app vs n8n was super useful. Expanded my horizon significantly."

    "Super hands-on with the tools – we sat and worked with the tools ourselves during the course. The helpful prompts made it possible to see the potential right away."

    "Learning how to learn with AI was a gamechanger. Real world examples and best practices mean I can now continue my development on my own."

    "The importance of spending time on role and context was clearly explained. Now I understand why my prompts didn't work before. It's worth its weight in gold!"

    "Good references to academic literature and further reading. The course doesn't just give skills, but also a foundation to keep learning afterwards."

    "The strong emphasis on practical work suited me perfectly. Less talk, more doing, and Stefano was always ready to help when we got stuck."

    "Many different scenarios were covered, so you could see AI applied broadly. It gave me courage to experiment with the tools in my own daily life. Great experience!"

    "Insight into different types of AI products: text, PowerPoint and much more. I left the course with concrete ideas for how I can improve the quality of my work."

    Your trainer

    Stefano Vincenti led the team behind the MitID app at Nets (Nexi Group), Denmark's national digital identity, and spent three years at Saxo Bank helping launch a secure hybrid cloud. He teaches AI agents at the IT University of Copenhagen and DIS and has hands-on admin experience with Microsoft Agent 365, Power Apps and Copilot Studio.

    After the programme

    Many teams want to go further. Add-ons include an Agent Governance Sprint, advisory on Agent 365 and Entra Agent ID setup, a tabletop exercise for leadership, a leadership briefing on AI in the threat landscape and hands-on with local open-source models.

    Frequently asked questions

    Ready to put agents on your security team's side?

    Book a 30-minute call about your team, your tools and the package that fits.

    Book a call