Training Catalog
Official certifications, custom workshops and hands-on AI security training — delivered in a dedicated lab environment through realistic, scenario-based exercises.
Custom lab environment
Every training runs in a dedicated, isolated lab tailored to your context — a safe place to explore, break things and practise on realistic systems.
Scenario-based & CTF-style learning
You learn by doing. Realistic scenarios and Capture-the-Flag style challenges turn theory into practical, lasting skills.
Customized & Immersive Training
Immersive, AI-powered training on AI and security
Beyond standard courses, I design fully customised, scenario-based training that uses AI to generate realistic, immersive exercises tailored to your environment, roles and risks. Your teams learn AI and security by doing — through scenarios built around your real context, not generic slides.
- Tailored scenarios generated for your systems, roles and threat context
- Learn by doing — hands-on exercises, not passive presentations
- AI & security focus — responsible AI, governance, secure adoption
- Adaptable depth — from executives to technical teams
- Repeatable and updatable as tools and risks evolve
Sample scenario: securing a Copilot rollout for a 500-person organisation
- Map where Copilot can surface sensitive data across SharePoint, Teams and email
- Design and apply governance guardrails with Purview and sensitivity labels
- Run a hands-on lab where teams test prompts, oversharing and mitigations
- Leave with a repeatable checklist and an updatable training pack
Official CompTIA Certifications
CompTIA Security+ (official)
The industry-standard foundation in cybersecurity — threats, architecture, operations and governance — with official courseware, hands-on labs and exam preparation.
CompTIA SecAI+ (official)
CompTIA's certification for securing AI systems — official training, hands-on labs and exam preparation to validate your AI security skills.
AI Security & Governance
AI Security and Assurance in Practice
How to review AI systems, risks, controls and evidence
A practical, two-day course on AI security, governance and assurance for professionals who review, approve or assess AI systems — no coding required. Everything is practised in a hands-on lab, built around a realistic HR-assistant case study.
A repeatable five-step method — classify the architecture, build the system map, place controls and collect evidence, analyse threats and mitigations, then write the audit report and action plan.
Uses NIST AI RMF, OWASP for LLMs, MITRE ATLAS, GDPR and the EU AI Act as practical reference points — no need to memorise the frameworks.
Who should attend
- Internal and external auditors
- Risk, governance and compliance professionals
- Data-protection, privacy and responsible AI teams
- Business managers and AI system owners
- Procurement and third-party risk professionals
- IT, security and architecture professionals seeking an assurance perspective
Ideal for mixed groups of technical and non-technical participants.
What you'll be able to do
- Map an AI system: users, data, components and trust boundaries
- Recognise security, privacy, fairness and governance risks
- Evaluate controls and audit evidence across the AI lifecycle
- Observe live control-failure demonstrations in the lab
- Produce a concise AI Security & Governance Assessment with remediation priorities
Programme at a glance
Day 1 — Understand the system
Why AI security differs from traditional application security, classifying six common AI architectures, and building a full system map covering users, data, identity, components, information flows and trust boundaries — with live demonstrations of access-control and retrieved-content failures.
Day 2 — Assess and act
Privacy, governance and EU regulation (GDPR and the EU AI Act), threat assessment with NIST AI RMF, MITRE ATLAS and OWASP, AI-assisted threat mapping and audit-report drafting, then a critical review and a practical 30-day action plan.
Final deliverable
Working from the Contoso HR Assistant case study, participants produce a one-page AI Security Assessment covering the business purpose, architecture and trust boundaries, priority risks, controls and evidence, framework references, residual risk and a 30-day action plan.
Microsoft 365 Scenario-Based Workshops
Microsoft 365 in Action: A Day in the Life of an IT Manager
Microsoft 365 administration & operations — learn by running a real tenant
A lab-first, scenario-based workshop: you take on the role of the IT Manager at Contoso and work through 70+ guided, hands-on exercises connected by one continuous storyline — onboarding, securing and governing a brand-new department from the ground up.
Every lab is triggered by a realistic business event — an HR request, a manager needing autonomy, a CISO policy requirement or an urgent support ticket. You configure the solution in a live Microsoft 365 environment, then sign in as the manager and employee to prove it works.
Who should attend
- IT administrators and IT managers responsible for Microsoft 365 operations
- Identity, security and collaboration administrators
- Systems engineers moving from on-premises to Microsoft Entra and cloud services
- Consultants and support professionals who provision, delegate and secure Microsoft 365 workloads
Prerequisites: working knowledge of Microsoft 365 admin portals and basic identity/MFA concepts. PowerShell and Conditional Access exposure helpful but not required.
What you'll build in the labs
- Just-in-time admin access with Microsoft Entra PIM and Access Packages
- Delegated administration with custom roles and Administrative Units
- Tested Conditional Access with named locations, Terms of Use and authentication strengths
- A secure SharePoint onboarding site with sensitivity labels and governed Teams policies
- Hardened Exchange Online, Microsoft 365, Office and Edge policies
- Entra ID Governance access packages, lifecycle workflows and access reviews
- Microsoft Intune device configuration, compliance and enrollment
Programme at a glance
Day 1 — Identity, privilege & delegation
Build the identity foundation in a security-first tenant with no standing admin rights: activate access via PIM and Access Packages, provision users and guests, and create custom roles and Administrative Units for least-privilege delegation.
Day 2 — Securing access, applications & collaboration
Configure and test Conditional Access with What If and Report-Only, integrate enterprise apps with self-service and approval, and stand up secure SharePoint and Teams collaboration.
Day 3 — Messaging, hardening, governance & endpoints
Secure Exchange Online messaging, harden tenant and app policies, automate governance with access packages and reviews, and configure Microsoft Intune — then consolidate a repeatable operational playbook.
What you'll take away
A repeatable, security-first playbook for onboarding and governing a Microsoft 365 department — plus the practical judgment to know why and when each control should be applied.
Microsoft 365 Under Attack: A Security Analyst Investigation
Microsoft 365 security administrator & analyst — investigate a full attack chain
A scenario-based security workshop built around one realistic, evolving incident. As a Security Analyst on the Contoso team, you investigate a connected attack chain across Microsoft 365 — from a phishing email through identity compromise, application persistence, sensitive-data access, cloud exfiltration and endpoint persistence — before delivering an executive incident briefing.
The focus is evidence, decision-making and CISO-ready recommendations. A guiding principle runs throughout: prove what is connected and what is separate — distinguishing exposure from interaction, interaction from compromise, and alerts from confirmed data loss.
Who should attend
- Security analysts and SOC team members
- Microsoft 365 security administrators and identity or security engineers
- Incident responders and threat hunters new to the Microsoft 365 security stack
- IT professionals moving into detection, response and evidence-based reporting
Prerequisites: working knowledge of Microsoft 365 admin portals and core security concepts. Defender and Conditional Access exposure helpful but not required.
What you'll investigate in the labs
- Security posture recon with Secure Score and Threat Analytics
- A phishing campaign with Defender for Office 365 — scope and containment
- Suspicious sign-ins and TAP/MFA recovery abuse — compromise vs attempt
- A risky OAuth consent grant and application persistence
- Device-trust abuse and SharePoint Finance data access
- Cloud exfiltration and Endpoint DLP response
- RDP access and endpoint persistence in Defender for Endpoint
- The CISO briefing — turning evidence into an executive incident story
Programme at a glance
Day 1 — Identity, access & posture foundations
Onboard the analyst identity, learn the Zero Trust investigation model, and assess the tenant's posture with Secure Score and Threat Analytics — completing the first posture-review challenge.
Day 2 — Identity & application attack paths
Follow the incident from phishing into identity and application abuse: investigate the campaign, suspicious sign-ins and recovery abuse, and a risky OAuth consent grant, then review the controls that reduce each risk.
Day 3 — Data, endpoint & executive briefing
Trace device-trust abuse and Finance data access, sensitive-data movement through Endpoint DLP, and RDP-based endpoint persistence with Defender for Endpoint — then consolidate everything into the final CISO incident briefing.
What you'll take away
The ability to investigate a full Microsoft 365 attack chain across identity, applications, data and endpoints; to separate confirmed facts from assumptions; to recommend controls that reduce recurrence without blocking the business; and to brief leadership with clear, prioritized, evidence-based conclusions.
Hands-on Security Workshops
Capture the Flag (CTF) Security Workshop
A team-based, scenario-driven workshop in a custom lab: solve realistic Capture-the-Flag challenges to build practical security instincts and hands-on skills. Difficulty and scenarios are tailored to your team and objectives.
Every course is tailored — durations, depth and scenarios are adapted to your needs.
Request a custom training proposal Back to home