CompTIA Workshop - Five practical steps for securing AI implementations

James Stanger
2026-10-14 11:10 am
2026-10-14 12:40 pm
Workshop Room 4 - Room 101

How attackers target AI systems through model manipulation and RAG abuse. Five practical steps for defending them, with case studies and hands-on labs.

Prerequisite: None, other than a good working knowledge of essential cybersecurity concepts and best practices.

Session Details

We're still in the "wild, wild west" when it comes to protecting AI systems themselves. Join me as I discuss a practical 5-step framework that helps you focus on the most critical and overlooked steps. Rather than focusing on broad governance discussions or theoretical risks, we will examine case studies that demonstrate the technical controls and operational practices that cybersecurity professionals can apply immediately. Sure, you'll see some of the usual town characters and suspects when it comes to security controls. But, you'll also see a few surprises along the trail to protecting AI.

You'll see surprises because I have been gathering anecdotes, stories, and lessons from working cybersecurity professionals. So, you won't be hearing about mere theory; this will be a practical discussion.

Topics include protecting data used for training and inference, securing APIs and model access, defending against prompt injection and data leakage, validating model behavior and outputs, and improving explainability without exposing sensitive information. We will also explore how attackers target AI systems through model manipulation, retrieval-augmented generation (RAG) abuse, excessive permissions, and weaknesses in AI-enabled workflows.

This presentation will focus on ways to protect AI in a cost-friendly manner. Few organizations have unlimited budgets. So, I’ll demonstrate how cybersecurity leaders can evaluate costs when securing training data, prompts, models, APIs, orchestration layers, and the outputs these systems generate. I'll focus on hands-on examples and labs that will answer questions and also provoke discussion on how expect the unexpected and look for practical solutions.

By the end of the session, participants will be able to report back to their organizations with more confidence as they protect the most critical components of an AI implementation, understand the threats that affect each component, and apply practical controls that improve resilience without slowing innovation. Whether securing internally developed solutions or evaluating commercial AI platforms, attendees will leave with a useful foundation for building more trustworthy and defensible AI systems.

Attendees will leave with a clear understanding of:

  • Critical AI infrastructure that needs to be protected.
  • Practical steps involved for protecting that infrastructure.
  • Specific challenges involved in protecting AI.
  • How to create a prioritized list of practical steps for protecting AI.

There's More Where This Came From

Browse hundreds of sessions and build an agenda around the topics that matter to you.

Speaker in a grey suit presenting at a lectern on stage
Woman being interviewed with a Ticker microphone on the expo floor
Audience members smiling and taking photos on their phones during a session
Speaker presenting on stage against a blue and pink backdrop
Attendees wearing CyberCon headphones listening during a session
Panellists seated in white armchairs on stage during a conference discussion
Keynote speaker presenting on stage with a title slide behind him
Speaker addressing the audience with a microphone as a colleague looks on