Training Catalog
Official certifications, custom workshops and hands-on AI security training — delivered in a dedicated lab environment through realistic, scenario-based exercises.
Choose your learning goal
Learn how to assess, govern and secure AI responsibly
Build the confidence to review AI systems, design controls and produce evidence-ready outcomes for teams and stakeholders.
Explore governance programsLearn by doing with realistic labs and attack scenarios
Strengthen your practical skills in Microsoft 365, security operations and Copilot readiness through immersive exercises.
Explore hands-on programsPopular learning outcomes
Assess AI risk with confidence
Turn AI governance into a repeatable practice with practical labs, evidence collection and clear decision-making.
Secure Microsoft 365 operations
Practice the workflows, controls and investigations that modern operations teams need in real environments.
Build Copilot readiness
Prepare people and processes for safe, useful and governed Copilot adoption through realistic scenarios.
Custom lab environment
Every training runs in a dedicated, isolated lab tailored to your context — a safe place to explore, break things and practise on realistic systems.
Scenario-based & CTF-style learning
You learn by doing. Realistic scenarios and Capture-the-Flag style challenges turn theory into practical, lasting skills.
Customized & Immersive Training
Immersive, AI-powered training on AI and security
A fully customised AI-and-security training journey where your teams learn on realistic scenarios built around your own environment.
- Tailored scenarios generated for your systems, roles and threat context
- Learn by doing — hands-on exercises, not passive presentations
- AI & security focus — responsible AI, governance, secure adoption
- Adaptable depth — from executives to technical teams
- Repeatable and updatable as tools and risks evolve
Sample scenario: securing a Copilot rollout for a 500-person organisation
- Map where Copilot can surface sensitive data across SharePoint, Teams and email
- Design and apply governance guardrails with Purview and sensitivity labels
- Run a hands-on lab where teams test prompts, oversharing and mitigations
- Leave with a repeatable checklist and an updatable training pack
Official CompTIA Certifications
CompTIA Security+ (official)
The industry-standard foundation in cybersecurity — threats, architecture, operations and governance — with official courseware, hands-on labs and exam preparation.
CompTIA SecAI+ (official)
CompTIA's certification for securing AI systems — official training, hands-on labs and exam preparation to validate your AI security skills.
Official Microsoft Certifications
Microsoft AB-730 (official)
Official Microsoft AB-730 preparation with practical labs, role-based scenarios and exam-focused coaching for your team.
Microsoft AB-731 (official)
Official Microsoft AB-731 preparation with guided labs and real-world exercises to build confidence before the exam.
Microsoft AB-100 (official)
Official Microsoft AB-100 training that blends architecture guidance, hands-on practice and targeted exam preparation.
Microsoft GH-300 Copilot (official)
Official Microsoft GH-300 Copilot preparation focused on practical scenarios, governance and operational readiness.
Need help choosing the right certification track for your team?
Book a 20-minute fit callAI Security & Governance
AI Security and Assurance in Practice
How to review AI systems, risks, controls and evidence
A two-day, no-code training that gives governance and risk teams a practical method to assess AI systems with confidence.
A repeatable five-step method — classify the architecture, build the system map, place controls and collect evidence, analyse threats and mitigations, then write the audit report and action plan.
Uses NIST AI RMF, OWASP for LLMs, MITRE ATLAS, GDPR and the EU AI Act as practical reference points — no need to memorise the frameworks.
View audience details
- Internal and external auditors
- Risk, governance and compliance professionals
- Data-protection, privacy and responsible AI teams
- Business managers and AI system owners
- Procurement and third-party risk professionals
- IT, security and architecture professionals seeking an assurance perspective
Ideal for mixed groups of technical and non-technical participants.
View lab outcomes
- Map an AI system: users, data, components and trust boundaries
- Recognise security, privacy, fairness and governance risks
- Evaluate controls and audit evidence across the AI lifecycle
- Observe live control-failure demonstrations in the lab
- Produce a concise AI Security & Governance Assessment with remediation priorities
View programme details
Day 1 — Understand the system
Why AI security differs from traditional application security, classifying six common AI architectures, and building a full system map covering users, data, identity, components, information flows and trust boundaries — with live demonstrations of access-control and retrieved-content failures.
Day 2 — Assess and act
Privacy, governance and EU regulation (GDPR and the EU AI Act), threat assessment with NIST AI RMF, MITRE ATLAS and OWASP, AI-assisted threat mapping and audit-report drafting, then a critical review and a practical 30-day action plan.
Final deliverable
Working from the Contoso HR Assistant case study, participants produce a one-page AI Security Assessment covering the business purpose, architecture and trust boundaries, priority risks, controls and evidence, framework references, residual risk and a 30-day action plan.
Want this delivered for your leadership and governance stakeholders?
Book a 20-minute fit callMicrosoft 365 Scenario-Based Workshops
Microsoft 365 in Action: A Day in the Life of an IT Manager
Microsoft 365 administration & operations — learn by running a real tenant
A hands-on Microsoft 365 operations workshop where your team builds and secures a tenant through one realistic end-to-end storyline.
Every lab is triggered by a realistic business event — an HR request, a manager needing autonomy, a CISO policy requirement or an urgent support ticket. You configure the solution in a live Microsoft 365 environment, then sign in as the manager and employee to prove it works.
View audience details
- IT administrators and IT managers responsible for Microsoft 365 operations
- Identity, security and collaboration administrators
- Systems engineers moving from on-premises to Microsoft Entra and cloud services
- Consultants and support professionals who provision, delegate and secure Microsoft 365 workloads
Prerequisites: working knowledge of Microsoft 365 admin portals and basic identity/MFA concepts. PowerShell and Conditional Access exposure helpful but not required.
View lab outcomes
- Just-in-time admin access with Microsoft Entra PIM and Access Packages
- Delegated administration with custom roles and Administrative Units
- Tested Conditional Access with named locations, Terms of Use and authentication strengths
- A secure SharePoint onboarding site with sensitivity labels and governed Teams policies
- Hardened Exchange Online, Microsoft 365, Office and Edge policies
- Entra ID Governance access packages, lifecycle workflows and access reviews
- Microsoft Intune device configuration, compliance and enrollment
View programme details
Day 1 — Identity, privilege & delegation
Build the identity foundation in a security-first tenant with no standing admin rights: activate access via PIM and Access Packages, provision users and guests, and create custom roles and Administrative Units for least-privilege delegation.
Day 2 — Securing access, applications & collaboration
Configure and test Conditional Access with What If and Report-Only, integrate enterprise apps with self-service and approval, and stand up secure SharePoint and Teams collaboration.
Day 3 — Messaging, hardening, governance & endpoints
Secure Exchange Online messaging, harden tenant and app policies, automate governance with access packages and reviews, and configure Microsoft Intune — then consolidate a repeatable operational playbook.
What you'll take away
A repeatable, security-first playbook for onboarding and governing a Microsoft 365 department — plus the practical judgment to know why and when each control should be applied.
Need a practitioner-focused track with hands-on labs for your operations teams?
Book a 20-minute fit callMicrosoft 365 Under Attack: A Security Analyst Investigation
Microsoft 365 security administrator & analyst — investigate a full attack chain
A realistic incident-driven workshop where analysts investigate a full Microsoft 365 attack chain and deliver an executive-ready security briefing.
The focus is evidence, decision-making and CISO-ready recommendations. A guiding principle runs throughout: prove what is connected and what is separate — distinguishing exposure from interaction, interaction from compromise, and alerts from confirmed data loss.
View audience details
- Security analysts and SOC team members
- Microsoft 365 security administrators and identity or security engineers
- Incident responders and threat hunters new to the Microsoft 365 security stack
- IT professionals moving into detection, response and evidence-based reporting
Prerequisites: working knowledge of Microsoft 365 admin portals and core security concepts. Defender and Conditional Access exposure helpful but not required.
View lab outcomes
- Security posture recon with Secure Score and Threat Analytics
- A phishing campaign with Defender for Office 365 — scope and containment
- Suspicious sign-ins and TAP/MFA recovery abuse — compromise vs attempt
- A risky OAuth consent grant and application persistence
- Device-trust abuse and SharePoint Finance data access
- Cloud exfiltration and Endpoint DLP response
- RDP access and endpoint persistence in Defender for Endpoint
- The CISO briefing — turning evidence into an executive incident story
View programme details
Day 1 — Identity, access & posture foundations
Onboard the analyst identity, learn the Zero Trust investigation model, and assess the tenant's posture with Secure Score and Threat Analytics — completing the first posture-review challenge.
Day 2 — Identity & application attack paths
Follow the incident from phishing into identity and application abuse: investigate the campaign, suspicious sign-ins and recovery abuse, and a risky OAuth consent grant, then review the controls that reduce each risk.
Day 3 — Data, endpoint & executive briefing
Trace device-trust abuse and Finance data access, sensitive-data movement through Endpoint DLP, and RDP-based endpoint persistence with Defender for Endpoint — then consolidate everything into the final CISO incident briefing.
What you'll take away
The ability to investigate a full Microsoft 365 attack chain across identity, applications, data and endpoints; to separate confirmed facts from assumptions; to recommend controls that reduce recurrence without blocking the business; and to brief leadership with clear, prioritized, evidence-based conclusions.
Hands-on Security Workshops
Capture the Flag (CTF) Security Workshop
A team-based, scenario-driven workshop in a custom lab: solve realistic Capture-the-Flag challenges to build practical security instincts and hands-on skills. Difficulty and scenarios are tailored to your team and objectives.
Every course is tailored — durations, depth and scenarios are adapted to your needs.
Back to home