← All courses

Training

AI-Power in Action

AI-Power in Action

A demo-driven one-day workshop on using Generative AI, prompt engineering, and responsible AI practices to strengthen cybersecurity work.

Artificial Intelligence is no longer just a productivity tool; it is becoming part of how cybersecurity teams detect threats, investigate alerts, explain risk, write reports, and make faster decisions. At the same time, it introduces new risks such as hallucinated findings, prompt injection, sensitive data exposure, automation bias, and unsafe reliance on AI-generated conclusions.

This one-day course combines the most practical and engaging parts of the AI for Cybersecurity outline and the GenAI and Prompt Engineering outline, with a strong focus on demonstrations, guided exercises, and real-world cybersecurity workflows. The course keeps the theory light and useful, then quickly moves into how AI can support security analysts, IT teams, managers, auditors, and risk professionals in day-to-day work. The original cybersecurity outline emphasizes AI use in threat analysis, incident response, vulnerability management, responsible AI, and SOC workflows, while the GenAI outline contributes practical prompt engineering, AI productivity, AI adoption, ethics, and strategic implementation topics.

The course also reflects current concerns in the AI security space. OWASP’s 2025 work on LLM application risks highlights issues such as prompt injection, sensitive information disclosure, insecure output handling, excessive agency, and model misuse, all of which are highly relevant when AI is used in security operations. CISA also emphasizes that AI systems should be approached with secure-by-design principles, treating AI as software that must be governed, protected, and monitored rather than blindly trusted.

The instructor for this course has over 30 years of industry experience and will use real industry-demanded content instead of presenting the subject as a purely academic discussion. The training is designed to be practical, current, and highly demonstration-oriented.

Learning Outcomes

By the end of this one-day course, participants will be able to:

  • Understand the relationship between Artificial Intelligence, Machine Learning, Deep Learning, Large Language Models, and Generative AI.
  • Explain how Generative AI can support cybersecurity tasks such as alert review, log interpretation, threat intelligence summarization, incident reporting, and vulnerability communication.
  • Use practical prompt engineering techniques to produce clearer, safer, and more useful cybersecurity outputs.
  • Compare how different AI tools may respond to the same cybersecurity task.
  • Identify where AI can improve productivity, consistency, and communication in security operations.
  • Recognize major AI risks, including hallucinations, data leakage, prompt injection, automation bias, and over-reliance.
  • Apply human-in-the-loop review practices when using AI for cybersecurity decisions.
  • Design a simple AI-assisted cybersecurity workflow from alert analysis to reporting.
  • Identify realistic AI adoption opportunities for cybersecurity, IT, risk, and business teams.

Prerequisites

  • Basic familiarity with IT, cybersecurity, risk, or business operations.
  • No prior AI, machine learning, or programming experience is required.
  • An open-minded approach to using AI tools responsibly and practically.
  • A Google account or access to commonly available Generative AI tools is recommended.
  • Participants should avoid using real confidential company, customer, or security incident data during demos and exercises.

Detailed 1-Day Training Outline

1. AI, Generative AI, and Cybersecurity Fundamentals

  • What Artificial Intelligence is and is not
    • Common misconceptions about AI
    • AI as assistance rather than replacement
    • AI as decision support rather than final authority
  • Relationship between key AI concepts
    • Artificial Intelligence
    • Machine Learning
    • Deep Learning
    • Neural Networks
    • Large Language Models
    • Generative AI
    • AI agents and copilots
  • Generative AI capabilities in cybersecurity
    • Text generation
    • Summarization
    • Classification support
    • Pattern explanation
    • Report drafting
    • Policy simplification
    • Security awareness content creation
    • Decision support
  • Generative AI limitations in cybersecurity
    • Hallucinated explanations
    • Incomplete technical reasoning
    • Outdated information
    • Overconfident outputs
    • Lack of organizational context
    • Dependence on prompt quality
    • Need for human validation
  • AI in the modern cybersecurity environment
    • Faster security analysis
    • Better documentation consistency
    • Improved communication with non-technical stakeholders
    • Support for overloaded SOC and IT teams
    • Productivity gains in repetitive security tasks
    • AI-driven risks and attacker use of AI

2. AI Tools Landscape for Cybersecurity and Productivity

  • Common Generative AI tools and platforms
    • ChatGPT
    • Gemini
    • Copilot
    • Claude
    • Perplexity
    • NotebookLM
    • Other emerging AI assistants
  • Selecting the right AI tool for the task
    • Research and explanation
    • Drafting and rewriting
    • Summarizing long documents
    • Comparing technical information
    • Creating executive summaries
    • Building checklists
    • Supporting investigation notes
    • Generating awareness materials
  • Using AI alongside cybersecurity tools
    • SIEM
    • SOAR
    • IDS and IPS
    • EDR and XDR
    • Vulnerability scanners
    • Ticketing systems
    • GRC platforms
    • Threat intelligence portals
  • Demo-focused tool usage patterns
    • Asking AI to explain an alert
    • Asking AI to summarize a log sample
    • Asking AI to convert technical details into management language
    • Asking AI to produce a checklist
    • Asking AI to compare two possible interpretations
    • Asking AI to challenge its own answer

3. Prompt Engineering for Cybersecurity Work

  • Prompt engineering fundamentals
    • Clear task definition
    • Role-based prompting
    • Context setting
    • Output format control
    • Constraints and boundaries
    • Tone and audience adjustment
    • Iterative prompting
    • Verification prompts
  • Cybersecurity prompt structure
    • Objective
    • Context
    • Data provided
    • Assumptions
    • Required output
    • Risk level
    • Audience
    • Validation requirements
  • Prompting for security analysis
    • Alert explanation prompts
    • Log review prompts
    • Threat intelligence summary prompts
    • Incident timeline prompts
    • Root cause support prompts
    • Risk impact prompts
    • Control recommendation prompts
  • Prompting for communication
    • Technical-to-non-technical translation
    • Executive summary generation
    • Incident notification drafting
    • Risk acceptance explanation
    • Audit finding clarification
    • Security awareness messaging
  • Prompting for better AI quality
    • Asking for assumptions
    • Asking for uncertainty
    • Asking for missing information
    • Asking for alternative explanations
    • Asking for validation steps
    • Asking for concise output
    • Asking for structured output
  • Prompting mistakes to avoid
    • Vague requests
    • Uploading sensitive data
    • Treating AI output as verified evidence
    • Asking for conclusions without context
    • Using AI-generated remediation without review
    • Ignoring organizational policies

4. AI for Threat Analysis and Incident Response Support

  • AI-assisted alert triage
    • Alert summarization
    • Severity explanation
    • Possible causes
    • Suggested investigation direction
    • Questions for the analyst to verify
  • AI-assisted log and event analysis
    • Log summarization
    • Pattern identification support
    • Timeline reconstruction
    • Suspicious activity explanation
    • Noise reduction support
    • Correlation support
  • AI-assisted threat intelligence interpretation
    • Summarizing threat reports
    • Extracting key indicators
    • Explaining attacker techniques
    • Mapping threats to business impact
    • Preparing analyst briefing notes
  • AI-assisted incident response documentation
    • Incident summary drafting
    • Timeline drafting
    • Impact statement drafting
    • Containment note drafting
    • Lessons learned drafting
    • Post-incident report structure
  • Communicating incidents to different audiences
    • SOC analyst summary
    • IT operations summary
    • Management summary
    • Customer-facing summary
    • Audit and compliance summary
  • Demo and hands-on activity topics
    • Writing prompts for security alert review
    • Generating an incident timeline
    • Drafting an incident response report
    • Creating an executive-level incident summary
    • Comparing AI outputs from different prompts
    • Improving weak AI responses through prompt refinement

5. AI for Vulnerability Management and Risk Communication

  • AI-assisted vulnerability interpretation
    • CVE explanation
    • Vulnerability summary
    • Affected system context
    • Potential business impact
    • Remediation language simplification
  • AI-assisted vulnerability prioritization
    • Severity versus real-world risk
    • Asset criticality
    • Exploitability
    • Exposure
    • Compensating controls
    • Operational constraints
  • AI-assisted remediation planning
    • Patch summary
    • Mitigation options
    • Temporary controls
    • Testing considerations
    • Change management notes
  • AI-assisted risk reporting
    • Risk statement drafting
    • Risk scoring support
    • Management summary
    • Risk acceptance wording
    • Audit-ready explanation
  • Demo and hands-on activity topics
    • Summarizing a vulnerability report
    • Rewriting technical vulnerability details for management
    • Creating a remediation action checklist
    • Drafting a risk assessment summary

6. Responsible AI, Security, Ethics, and Governance

  • Responsible use of AI in cybersecurity
    • Human-in-the-loop decision-making
    • Review before action
    • Verification of AI output
    • Clear accountability
    • Documentation of AI-assisted work
  • Major risks of AI use in cybersecurity
    • Hallucinated threat explanations
    • False positives
    • False negatives
    • Automation bias
    • Sensitive data exposure
    • Inaccurate remediation advice
    • Prompt injection
    • Insecure output handling
    • Excessive trust in AI agents
  • Data protection and confidentiality
    • Sensitive security data
    • Customer data
    • Incident data
    • Logs and telemetry
    • Credentials and secrets
    • Internal policies and architecture details
  • AI governance for security teams
    • Acceptable use rules
    • Data handling rules
    • Approved tool lists
    • Review and approval process
    • Auditability
    • Model output validation
    • Escalation rules
  • Ethical and organizational considerations
    • Bias and fairness
    • Privacy concerns
    • Transparency
    • Accountability
    • Regulatory awareness
    • Employee readiness
    • Responsible adoption culture

7. AI for Security Awareness, Policy, and Documentation

  • AI-assisted security policy work
    • Drafting policy sections
    • Simplifying policy language
    • Creating procedure drafts
    • Summarizing standards and frameworks
    • Turning policy into checklists
  • AI-assisted security awareness
    • Awareness message drafting
    • Phishing education content
    • Password and MFA reminders
    • Safe AI usage guidance
    • Role-based awareness material
    • Microlearning content
  • AI-assisted documentation management
    • Summarizing long documents
    • Extracting key obligations
    • Creating FAQs
    • Creating quick-reference guides
    • Organizing security knowledge
  • Demo and hands-on activity topics
    • Creating a security awareness announcement
    • Simplifying a technical security policy
    • Creating a checklist from a security procedure
    • Drafting safe AI usage guidelines for staff

8. Building an AI-Assisted Cybersecurity Workflow

  • Designing an AI-supported workflow
    • Alert intake
    • Initial analysis
    • Context enrichment
    • Analyst review
    • Response planning
    • Documentation
    • Reporting
    • Lessons learned
  • AI in SOC and security operations
    • Improving analyst productivity
    • Reducing repetitive writing
    • Improving report consistency
    • Supporting knowledge sharing
    • Accelerating investigation notes
    • Supporting shift handover
  • Measuring AI value in cybersecurity
    • Time saved
    • Documentation quality
    • Analyst consistency
    • Faster reporting
    • Better stakeholder communication
    • Reduced manual effort
    • Improved training support
  • AI adoption planning
    • Identifying high-impact use cases
    • Starting with low-risk tasks
    • Defining safe usage boundaries
    • Training users on prompt quality
    • Establishing review checkpoints
    • Scaling responsibly
  • Final workshop activity topics
    • Designing a simple AI-assisted cybersecurity workflow
    • Defining safe and unsafe AI use cases
    • Building a practical AI adoption checklist
    • Creating a personal action plan for applying AI after the course

Disclaimer

This course outline is intended to serve as a general training guideline and may be refined, amended, reordered, expanded, or reduced by the trainer at his professional discretion. Adjustments may be made without prior notice to accommodate participant background, class progress, available tools, demonstration requirements, organizational priorities, technology changes, or other instructional considerations deemed appropriate by the trainer.

Practical, connected learning

My wider training approach brings hands-on implementation and systems thinking together, connecting technology with real operational needs.