CompTIA Workshop - Five practical steps for securing AI implementations
How attackers target AI systems through model manipulation and RAG abuse. Five practical steps for defending them, with case studies and hands-on labs.
Session Details
We're still in the "wild, wild west" when it comes to protecting AI systems themselves. Join me as I discuss a practical 5-step framework that helps you focus on the most critical and overlooked steps. Rather than focusing on broad governance discussions or theoretical risks, we will examine case studies that demonstrate the technical controls and operational practices that cybersecurity professionals can apply immediately. Sure, you'll see some of the usual town characters and suspects when it comes to security controls. But, you'll also see a few surprises along the trail to protecting AI.
You'll see surprises because I have been gathering anecdotes, stories, and lessons from working cybersecurity professionals. So, you won't be hearing about mere theory; this will be a practical discussion.
Topics include protecting data used for training and inference, securing APIs and model access, defending against prompt injection and data leakage, validating model behavior and outputs, and improving explainability without exposing sensitive information. We will also explore how attackers target AI systems through model manipulation, retrieval-augmented generation (RAG) abuse, excessive permissions, and weaknesses in AI-enabled workflows.
This presentation will focus on ways to protect AI in a cost-friendly manner. Few organizations have unlimited budgets. So, I’ll demonstrate how cybersecurity leaders can evaluate costs when securing training data, prompts, models, APIs, orchestration layers, and the outputs these systems generate. I'll focus on hands-on examples and labs that will answer questions and also provoke discussion on how expect the unexpected and look for practical solutions.
By the end of the session, participants will be able to report back to their organizations with more confidence as they protect the most critical components of an AI implementation, understand the threats that affect each component, and apply practical controls that improve resilience without slowing innovation. Whether securing internally developed solutions or evaluating commercial AI platforms, attendees will leave with a useful foundation for building more trustworthy and defensible AI systems.
Attendees will leave with a clear understanding of:
- Critical AI infrastructure that needs to be protected.
- Practical steps involved for protecting that infrastructure.
- Specific challenges involved in protecting AI.
- How to create a prioritized list of practical steps for protecting AI.
There's More Where This Came From
Browse hundreds of sessions and build an agenda around the topics that matter to you.








