icon icon

AI Cybersecurity – Security Lab: secure AI in the organization, data protection and responsible use of GenAI tools

icon

Training process

Training needs analysis

If you have specific requirements regarding the training programme, we will carry out a training needs analysis for you. This will guide us on which aspects of the programme should receive greater emphasis, so that the training programme meets your specific needs.

What will you gain?

icon

You will spot AI risks - You will learn to separate real GenAI risks from marketing hype, so you can quickly judge when AI genuinely supports your work and when it creates unnecessary exposure for your organization.

icon

You will prevent data leaks - You will learn how to keep confidential, personal, financial, and internal business data out of public AI tools, and how to anonymize materials safely before sending them for AI analysis.

icon

You will detect new attack paths - You will understand prompt injection, jailbreaks, malicious integrations, and attacks on AI agents, making it easier for you to notice suspicious behavior and reduce the chance of serious incidents.

icon

You will write safer prompts - You will practice building prompts that produce useful results without exposing sensitive details, full documents, or client data, improving both the quality of outputs and your security posture.

icon

You will assess data faster - You will learn how to classify information before using AI and apply a simple checklist, so you can quickly decide whether a file, message, or data extract is safe to use with an AI tool.

icon

You will verify AI outputs better - You will learn how to check sources, calculations, summaries, and recommendations generated by models, so you do not base business actions on hallucinations, errors, or incomplete conclusions.

icon

You will handle compliance wisely - You will understand how the AI Act, GDPR, and internal policies affect daily AI use, helping you recognize when you should involve IT, the DPO, security teams, or legal before moving forward.

icon

You will strengthen responsible AI use - You will gain practical rules for using AI safely in communication, analysis, and automation, helping you adopt new tools effectively without lowering security standards in everyday work.

Training programme

1. Introduction to AI cybersecurity

  • what generative AI is and how it changes the way organizations work,
  • the most commonly used AI tools in the business environment,
  • differences between public AI models, company tools and solutions deployed locally,
  • why AI is becoming a new area of risk for organizations,
  • key concepts: AI model, prompt, input data, output data, hallucinations, public model, private model, integrations, AI agents,
  • the most important risk categories: cybersecurity, confidential data, intellectual property, regulatory compliance, reputation, erroneous business decisions.

2. Threats resulting from the use of generative AI tools

  • the most common threats related to the use of AI in professional work,
  • entering confidential, personal, financial and business data into AI tools,
  • the risk of unintentional disclosure of information covered by trade secret,
  • AI hallucinations and incorrect recommendations as operational risk,
  • false content generated by AI: deepfake, phishing, false documents, false instructions,
  • automatic generation of malicious code, phishing messages and manipulative messages,
  • abuses related to the use of AI by cybercriminals,
  • risks resulting from the use of unverified tools, extensions, chatbots and AI integrations,
  • examples of incidents and threat scenarios in the organization.

3. New attack vectors related to the use of AI

  • Prompt injection – what it is and why it poses a threat,
  • AI model jailbreaks and bypassing security restrictions,
  • attacks on chatbots, AI agents and systems integrated with company data,
  • manipulating the model through appropriately prepared input data,
  • data leaks through AI integrations with email, documents, CRM, ERP and knowledge bases,
  • attacks using false commands, documents and websites,
  • the risk of AI agents automatically performing actions without sufficient human oversight,
  • AI in phishing, social engineering and attacks on end users,
  • how to recognize suspicious activity and unusual responses of AI systems.

4. Protection of data and confidential information when working with AI

  • what data should not be provided to public AI tools,
  • personal data, customer data, financial data, internal documentation, passwords, tokens, source codes and contracts,
  • classification of information before using an AI tool,
  • principles of data anonymization and pseudonymization,
  • secure preparation of materials for analysis by AI,
  • working with company documents and attachments,
  • the risk of copying content from email, messengers and internal systems,
  • principles of using AI when working with customer and contractor data,
  • the user's responsibility for data provided to the model,
  • practical checklist: can I use this data in an AI tool?

5. Work hygiene with AI

  • good practices for everyday use of AI tools,
  • the principle of limited trust in results generated by AI,
  • verification of responses, sources, calculations, recommendations and summaries,
  • when AI can support work, and when it should not replace human decisions,
  • secure login, company accounts, access to tools and permission control,
  • using approved AI tools instead of random web applications,
  • the risk of using private accounts for business purposes,
  • working with AI in the model „human supervises – AI supports”,
  • limiting input data to the necessary minimum,
  • documenting the use of AI in business tasks.

6. Safe creation and use of prompts

  • what a prompt is and how it affects the quality and safety of responses,
  • elements of a safe prompt: objective, context, constraints, response format, exclusions,
  • how to write prompts without disclosing sensitive and confidential data,
  • safe replacement of real data with examples or fictitious data,
  • prompting using roles, procedures and safety principles,
  • how to ask AI for analysis without providing full documents,
  • how to limit the risk of generating false, non-compliant or risky content,
  • examples of safe and unsafe prompts,
  • exercise: improving risky prompts and creating safe versions.

7. Identification of risks related to transferring data to AI models

  • how to assess risk before using AI in a specific task,
  • risk matrix: type of data, purpose of processing, tool, user, possible consequences,
  • risks to personal data and GDPR compliance,
  • risks to trade secrets and competitive advantage,
  • risks to the security of IT systems,
  • reputational and legal risks,
  • risks related to the automation of decisions and recommendations,
  • when consultation with IT, security, the DPO or the legal department is required,
  • exercise: assessment of AI use cases in terms of risk.

8. AI Act and regulatory aspects

  • the most important assumptions of the AI Act,
  • a risk-based approach: prohibited, high-risk, limited-risk and minimal-risk systems,
  • the role of the organization as a user, deployer or provider of AI solutions,
  • the obligations of providers and entities deploying AI systems,
  • AI literacy – the obligation to develop AI competence and awareness in the organization,
  • the impact of the AI Act on organizations, IT departments, compliance, HR, security and data management,
  • transparency in the use of AI and informing users about interaction with AI systems,
  • the importance of documenting AI applications, risk assessment and human oversight,
  • the relationship of the AI Act to GDPR, cybersecurity, data protection and internal organizational policies,
  • the practical consequences of the regulations for the everyday use of generative AI tools.

9. Building an AI culture in the organization

  • what responsible AI usage culture is,
  • the role of employees, managers, the IT department, security, HR and compliance,
  • creating rules for the use of AI tools in the organization,
  • AI policy: what it should regulate and how to communicate it,
  • standards for approving AI tools and integration with company systems,
  • rules for the use of AI in communication, data analysis, content creation and work automation,
  • development of AI competencies in the organization,
  • building awareness of risks and good practices,
  • responding to AI-related incidents,
  • how to encourage the use of AI without lowering the level of security.

What are the prerequisites for participating in the training?

icon

Basic office workflow - You should be comfortable using email, documents, spreadsheets, and workplace messengers, because the training links AI risks directly to everyday tasks in a business environment.

icon

Awareness of company data - You should understand which information in your work is confidential, personal, or business sensitive, so you can judge what data must never be shared with AI tools.

icon

Core cyber hygiene - You should know basic safe practices for accounts, passwords, attachments, and websites, because the training expands these habits specifically for generative AI use.

icon

Readiness for case analysis - You should be ready to review AI use cases and assess their impact on work and data, since the training includes exercises on risk, prompting, and user decisions.