IT Defense 2027 > Artificial Intelligence and IT Security
en de

Artificial Intelligence and IT Security

Artificial Intelligence and IT Security – from Risk Assessment to AI Policy

Instructor: Felix Friedberger

Duration: 1 Day – January 26, 2027

Content:
This one-day seminar covers the IT security aspects of using AI systems in enterprises – with the aim to equip you with the knowledge necessary to make informed IT governance decisions and create your own AI policy.

AI and AI-based tools have quickly found their way into nearly every area of the company: developers use coding assistants, specialist departments use chatbots and Office integrations, sensitive data is made searchable using AI, and more and more often AI features are built into existing products or AI-based applications are bought. Understanding these use cases, assessing their risks realistically and transferring them into robust regulations poses a challenge for security executives. Without a basic understanding of the underlying technology – from LLM hosting providers to tool usage and the typical attack surface – neither the requests of individual employees nor the purchase of entire products can be evaluated appropriately.

At the beginning of the seminar, we will teach you the technical fundamentals required for reliable risk assessment: tokenization and inference, the path of data from the tool through the API to the model, the concept of MCP, agents and tool usage, and the OWASP LLM Top 10 as an evaluation framework. Simple examples are used to show where data can leak, how tool calls can be malicious and what impact traditional attacks like prompt injection can have.

Based on this, we will look at the different use cases and their respective risks: the private and often unnoticed use of public AI services (“shadow AI”), using AI applications on workstations and their extensive user context permissions, the special risks with developer tools like coding agents, and creating in-house AI applications with RAG, identity and permission questions. We will also categorize publicly accessible AI applications and the relevant legal conditions, in particular the EU AI Act and data protection issues. The scenarios are explained using concrete examples and demonstrations.

Finally, we will combine the things we have learned and translate them into practical governance by jointly working on typical example cases from everyday business situations – but now with the knowledge gained in the seminar.

After the seminar, participants will not only know how AI systems technically work in general as well as the attack surface and data protection risks they entail, but also how to evaluate their employees’ requests for AI usage and develop an acceptable AI policy for their company.

Topic areas:

  • Fundamentals: tokenization, interference, data chain, data retention policies, MCP/tool usage and the OWASP LLM Top 10 as an evaluation framework
  • Shadow AI and private use: risks of private AI accounts, Office and Teams integration, discovery methods and prompt injection
  • AI on workstations: desktop applications, Office integration, browser agents and their permissions, data leakage in the user context
  • Developers and coding agents: loss of secrets and data, misconfiguration, risks of skills and agents, opt-in/opt-out during training, open weight models, routing via hyperscaler vs. third parties
  • In-house AI applications: RAG, identity and permission models, hosting of models, logging and model supply chain
  • Public AI applications and legal requirements: jailbreaking and reputational risks, EU AI Act, GDPR-relevant aspects

Target group:
CISOs, IT managers and security executives who want to understand how AI is used in their company and the risks this entails, as well as how to control these risks using an AI policy

Requirement:
Basic IT knowledge; a basic understanding of AI, e.g., using ChatGPT or the like, is an advantage

You will get a certificate after having completed the training.

This training is held in German.

Price: € 1.100

Date
January 26, 2027

Location
Scandic Frankfurt Hafenpark
Eytelweinstraße 1
Frankfurt am Main
Tel.: +49 69 219 777 0