Skip to content

AI Risk Assurance for the GCC: Hands-On Red-Teaming, Risk Quantification,Regulator-Ready Governance

Description

Name of Training: AI Risk Assurance for the GCC Hands-On Red-Teaming, Risk Quantification, Regulator-Ready Governance
Trainer: Satinder Sandhu
Dates: November 08-10, 2026
Time: 9:00 am - 5:00 pm
Venue: Exhibition World Bahrain
Cost: 1200 BHD

Important Note: This training is exclusively available to government entities and participants from GCC countries.

1. Short Summary

AI is being deployed across GCC banks, government, and enterprises faster than security and risk teams can keep up. This three-day course teaches both technical practitioners and risk/governance managers how to test AI systems for real attacks, translate findings into quantified business risk, and produce the regulator-ready evidence packs that SDAIA, SAMA, CBB, CBUAE, DIFC, and the upcoming Bahrain AI Regulation Law expect — working side-by-side on the same live labs.

2. Course Description

Most AI security courses are built for offensive specialists, leaving the people who actually own AI risk inside GCC organizations — CISOs, AI risk officers, GRC managers, internal auditors, and mid-career security practitioners — without a practical entry point. This course closes that gap.

Across three days, students work in mixed pairs (one technically-leaning, one governance-leaning, by design) on a live, instructor-built lab environment of vulnerable AI applications, including a RAG-based financial advisor, an MCP-connected tool-using agent, and an Arabic-language customer service agent.

  • Day 1 teaches the most common AI attack patterns (prompt injection, indirect injection, RAG poisoning, agent tool abuse) using guided, step-by-step labs — no prior offensive security experience required.
  • Day 2 teaches students how to convert each attack finding into a defensible dollar-value loss estimate using a simplified FAIR-style method, and how to design controls that are actually testable rather than aspirational.
  • Day 3 maps everything to the GCC regulatory stack — SDAIA AI Ethics Principles and Generative AI Guidelines, UAE AI Charter and PDPL, DIFC Regulation 10, Bahrain's draft AI Regulation Law, Qatar Central Bank AI Guidelines, ISO/IEC 42001, and NIST AI RMF — and culminates in a capstone where each pair produces a complete regulator-ready evidence pack for a fictional GCC bank deploying an Arabic AI agent. Students leave with the lab access (30 days), all templates, and a methodology they can apply to a real production AI system the Monday after the course.

3. Course Outline

Day 1

3.1 Welcome, lab access setup, partner pairing (technical + governance pairs). Why GCC AI deployments are different: the regulatory landscape, the buyer urgency, and the threat model. No-laptop-needed framing module designed so even the least technical student is grounded before the first lab.

3.2 The AI attack landscape, in plain language. OWASP LLM Top 10 (2026) and OWASP Agentic AI Top 10 walked through with one live demonstration per category. Governance students learn what each attack type means for risk; technical students learn the mechanics.

3.3 Guided Lab 1: Prompt injection and jailbreaks against the lab's financial advisor agent. Step-by-step instructions provided. Pairs work together technical student executes, governance student documents the finding using the standardized template.

3.4 Guided Lab 2: System prompt extraction and instruction leakage. Pairs swap roles governance student executes the (very simple) attack, technical student documents.

3.5 Guided Lab 3: Indirect prompt injection via documents and emails. This is the most important attack pattern for GCC enterprises adopting Microsoft Copilot, Google Workspace AI, and Claude/GPT-class agents. Pairs see how a single malicious document can hijack an AI assistant.

3.6 Guided Lab 4: Agent tool abuse and confused deputy. Students attack an MCP-connected agent that has access to multiple tools (file read, email send, balance lookup) and chain a low-severity prompt injection into a meaningful business impact.

3.7 Guided Lab 5: Arabic and RTL-specific attacks. Cross-lingual jailbreaks, dialect-based safety bypasses, and RTL Unicode tricks against multilingual models. This module reflects original research and is the course's most distinctive regional element.

3.8 Day 1 debrief. Pairs consolidate findings into a structured inventory.

Day 2

3.9 The assurance gap, in plain language: why most AI red-team reports never lead to action, and what it takes to make findings stick with executives and regulators. Introduction to the AI Decision Receipt pattern.

3.10 Guided Lab 6: Simplified FAIR-style loss quantification. Pairs take three findings from Day 1 and produce dollar-value loss exposure ranges using a provided spreadsheet. Governance students lead this module; technical students provide the attack-side detail.

3.11 Guided Lab 7: Building a quantified AI risk register. Pairs aggregate their findings into a single board-ready view, including a simple Monte Carlo simulation (provided spreadsheet — no coding required).

3.12 Guided Lab 8: Designing testable controls. For each finding category, pairs design a control that is implementable, measurable, and re-testable. Common anti-patterns walked through with examples: aspirational policy language, untestable "human review" requirements, one-time assessments.

3.13 Guided Lab 9: The AI Decision Firewall pattern, explained for both audiences. Technical students see a simple reference implementation; governance students learn how to specify and audit it. Pairs re-test Day 1 attacks against the hardened agent and see which controls held.

3.14 Guided Lab 10: Continuous AI assurance — what "ongoing testing" actually means in practice, and how it integrates with the GRC, SOC, and ServiceNow workflows that already exist in most GCC enterprises.

Day 3

3.15 The GCC regulatory landscape walkthrough: SDAIA AI Ethics Principles and Generative AI Guidelines (KSA), UAE AI Charter and PDPL, DIFC Regulation 10, ADGM ( Data Protection Regulations ) , Bahrain Personal Data Protection Law and the draft AI Regulation Law (April 2024), Qatar Central Bank AI Guidelines, ISO/IEC 42001, and NIST AI RMF. Where they overlap, where they conflict, and what an examiner actually asks for. Designed to be useful for both technical and governance students.

3.16 Guided Lab 11: Mapping Day 2 controls to the regulatory stack using a provided cross-walk matrix. Pairs identify gaps where their controls satisfy one framework but leave another exposed.

3.17 Guided Lab 12: Building the regulator-ready evidence pack — adversarial test results, quantified risk register, control register, residual risk acceptance memo, and a one-page executive briefing — assembled into a single defensible artifact.

3.18 Capstone briefing: Scenario: a fictional GCC bank ("Bank Al-Khaleej") is deploying an Arabic-language customer service agent with limited tool access to balance lookup, transaction history, and small transfers. Pairs must deliver a complete assurance package.

3.19 Capstone execution: Pairs attack the live capstone agent, quantify findings, design controls, map to the regulatory stack, and produce the evidence pack. Instructor circulates for guidance throughout. Pairs that purchased the proficiency exam add-on submit their evidence packs for graded review.

3.20 Capstone debrief, instructor walkthrough of the reference solution, course wrap-up, and post-course resource handoff (lab access continues for 30 days, instructor follow-up available for 60 days).

4. Difficulty Level

Intermediate - The student has education and some experience in the field and familiarity with the topic being presented. The student has foundational knowledge that the course will leverage to provide practical skills on the topic.

5. Suggested Prerequisites

This course is designed for two complementary audiences who will work together in pairs: (a) security practitioners with 2–4 years of general cybersecurity experience (any background — pentest, SOC, GRC, audit, cloud security) and basic comfort with a Linux terminal and reading code; and (b) risk, governance, and management professionals (CISOs, AI risk officers, GRC managers, internal auditors, compliance leads) with foundational security knowledge equivalent to CISM, CRISC, ISO 27001 LA, or 3+ years in a security-adjacent role.

6. What Students Should Bring

  • Laptop running Windows 10/11, macOS 12+, or a recent Linux distribution
  • 8 GB RAM minimum (16 GB recommended)
  • 20 GB free disk space
  • Modern web browser (Chrome or Firefox)
  • The ability to install a small set of free tools provided in pre-work (a terminal client and a code editor — no Docker or local AI models required, as all heavy compute runs in the instructor-provided cloud lab). Students must be able to reach the cloud lab over standard HTTPS — corporate-locked devices that block outbound web traffic to non-approved domains may not work, and students should plan to bring a personal device if needed.

7. What the Trainer Will Provide

  • 30 days of access to the live cloud-hosted lab environment, including all vulnerable AI applications, agents, and the capstone scenario, with the ability to redeploy and re-attack at will
  • A complete digital course pack including the finding inventory template, FAIR quantification spreadsheet, Monte Carlo notebook, control register template, regulatory cross-walk matrix, and evidence pack template.
  • The AI Decision Firewall reference architecture and source code.
  • The adversarial test suite as an importable evaluation harness.
  • A curated reading list and the instructor's contact for follow-up questions for 60 days post-course.

8. Trainer(s) Bio

Satinder Sandhu

Satinder Sandhu is a cybersecurity engineer and AI risk practitioner with over 15 years of experience delivering offensive security training, advisory, and consulting engagements across 25+ countries. He holds multiple industry certifications, including CISSP, CISM, CCSP, CEH, CHFI, CND, EC-Council Certified Trainer and ISO 27001 Lead Auditor.

His work spans offensive security, enterprise risk management, cloud and infrastructure security, and AI assurance, with a focus on translating technical vulnerabilities into quantified business and financial impact for executive leadership and regulators. He has supported regulated organizations across financial services, healthcare, and government, with hands-on experience implementing and assessing control frameworks and regional regulatory expectations relevant to AI systems.

Satinder is the founder of a Toronto-based cybersecurity, privacy, and AI risk firm, Security Assured. The lab environments, risk quantification methods, and regulator-ready evidence templates used in his courses are drawn directly from real-world engagements building AI assurance capabilities for regulated enterprises—grounded in production practice rather than theory.

9. Registration Terms and Conditions

9.1 Trainings are refundable before September 21, 2026, minus a non-refundable processing fee of 100 BHD.

9.2 Between September 21, 2026 and October 21, 2026 partial refunds will be granted, equal to 50% of the course fee minus a processing fee of 100 BHD.

9.3 All trainings are non-refundable after October 21, 2026.

9.4 Training tickets may be transferred to another student. Please email us at training@defcon.org for specifics.

9.5 If a training does not reach the minimum registration requirement, it may be cancelled. In the event the training you choose is cancelled, you will be provided the option of receiving a full refund or transferring to another training (subject to availability).

9.6 Failure to attend the training without prior written notification will be considered a no-show. No refund will be given.

9.7 DEF CON Training may share student contact information, including names and emails, with the course instructor(s) to facilitate sharing of pre-work and course instructions. Instructors are required to safeguard this information and provide appropriate protection so that it is kept private. Instructors may not use student information outside the delivery of this course without the permission of the student.

9.8 By purchasing this ticket you agree to abide by the DEF CON Training Code of Conduct and the registration terms and conditions listed above.

Sale price 1,200 BD

Options
Back to top