{"product_id":"ai-risk-assurance-for-the-gcc-hands-on-red-teaming-risk-quantification-regulator-ready-governance","title":"AI Risk Assurance for the GCC: Hands-On Red-Teaming, Risk Quantification,Regulator-Ready Governance","description":"\u003cp\u003e\u003cstrong\u003eName of Training:\u003c\/strong\u003e AI Risk Assurance for the GCC Hands-On Red-Teaming, Risk Quantification, Regulator-Ready Governance\u003cbr\u003e\u003cstrong\u003eTrainer:\u003c\/strong\u003e Satinder Sandhu\u003cbr\u003e\u003cstrong\u003eDates:\u003c\/strong\u003e November 08-10, 2026\u003cbr\u003e\u003cstrong\u003eTime:\u003c\/strong\u003e 9:00 am - 5:00 pm\u003cbr\u003e\u003cstrong\u003eVenue:\u003c\/strong\u003e Exhibition World Bahrain\u003cbr\u003e\u003cstrong\u003eCost:\u003c\/strong\u003e 1200 BHD\u003c\/p\u003e\n\u003cp\u003e\u003cspan style=\"color: rgb(224, 21, 21);\"\u003e\u003cstrong\u003eImportant Note:\u003c\/strong\u003e This training is exclusively available to \u003cstrong\u003egovernment entities and participants from GCC countries\u003c\/strong\u003e.\u003c\/span\u003e\u003c\/p\u003e\n\u003ch2\u003e1. Short Summary\u003c\/h2\u003e\n\u003cp\u003eAI is being deployed across GCC banks, government, and enterprises faster than security and risk teams can keep up. This three-day course teaches both technical practitioners and risk\/governance managers how to test AI systems for real attacks, translate findings into quantified business risk, and produce the regulator-ready evidence packs that SDAIA, SAMA, CBB, CBUAE, DIFC, and the upcoming Bahrain AI Regulation Law expect — working side-by-side on the same live labs.\u003c\/p\u003e\n\u003ch2\u003e2. Course Description\u003c\/h2\u003e\n\u003cp\u003eMost AI security courses are built for offensive specialists, leaving the people who actually own AI risk inside GCC organizations — CISOs, AI risk officers, GRC managers, internal auditors, and mid-career security practitioners — without a practical entry point. This course closes that gap.\u003c\/p\u003e\n\u003cp\u003eAcross three days, students work in mixed pairs (one technically-leaning, one governance-leaning, by design) on a live, instructor-built lab environment of vulnerable AI applications, including a RAG-based financial advisor, an MCP-connected tool-using agent, and an Arabic-language customer service agent.\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eDay 1 teaches the most common AI attack patterns (prompt injection, indirect injection, RAG poisoning, agent tool abuse) using guided, step-by-step labs — no prior offensive security experience required.\u003c\/li\u003e\n\u003cli\u003eDay 2 teaches students how to convert each attack finding into a defensible dollar-value loss estimate using a simplified FAIR-style method, and how to design controls that are actually testable rather than aspirational.\u003c\/li\u003e\n\u003cli\u003eDay 3 maps everything to the GCC regulatory stack — SDAIA AI Ethics Principles and Generative AI Guidelines, UAE AI Charter and PDPL, DIFC Regulation 10, Bahrain's draft AI Regulation Law, Qatar Central Bank AI Guidelines, ISO\/IEC 42001, and NIST AI RMF — and culminates in a capstone where each pair produces a complete regulator-ready evidence pack for a fictional GCC bank deploying an Arabic AI agent. Students leave with the lab access (30 days), all templates, and a methodology they can apply to a real production AI system the Monday after the course.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch2\u003e3. Course Outline\u003c\/h2\u003e\n\u003ch3\u003eDay 1\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.1\u003c\/strong\u003e Welcome, lab access setup, partner pairing (technical + governance pairs). Why GCC AI deployments are different: the regulatory landscape, the buyer urgency, and the threat model. No-laptop-needed framing module designed so even the least technical student is grounded before the first lab.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.2\u003c\/strong\u003e The AI attack landscape, in plain language. OWASP LLM Top 10 (2026) and OWASP Agentic AI Top 10 walked through with one live demonstration per category. Governance students learn what each attack type means for risk; technical students learn the mechanics.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.3 Guided Lab 1:\u003c\/strong\u003e Prompt injection and jailbreaks against the lab's financial advisor agent. Step-by-step instructions provided. Pairs work together technical student executes, governance student documents the finding using the standardized template.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.4 Guided Lab 2:\u003c\/strong\u003e System prompt extraction and instruction leakage. Pairs swap roles governance student executes the (very simple) attack, technical student documents.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.5 Guided Lab 3:\u003c\/strong\u003e Indirect prompt injection via documents and emails. This is the most important attack pattern for GCC enterprises adopting Microsoft Copilot, Google Workspace AI, and Claude\/GPT-class agents. Pairs see how a single malicious document can hijack an AI assistant.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.6 Guided Lab 4:\u003c\/strong\u003e Agent tool abuse and confused deputy. Students attack an MCP-connected agent that has access to multiple tools (file read, email send, balance lookup) and chain a low-severity prompt injection into a meaningful business impact.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.7 Guided Lab 5:\u003c\/strong\u003e Arabic and RTL-specific attacks. Cross-lingual jailbreaks, dialect-based safety bypasses, and RTL Unicode tricks against multilingual models. This module reflects original research and is the course's most distinctive regional element.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.8\u003c\/strong\u003e Day 1 debrief. Pairs consolidate findings into a structured inventory.\u003c\/p\u003e\n\u003ch3\u003eDay 2\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.9\u003c\/strong\u003e The assurance gap, in plain language: why most AI red-team reports never lead to action, and what it takes to make findings stick with executives and regulators. Introduction to the AI Decision Receipt pattern.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.10 Guided Lab 6:\u003c\/strong\u003e Simplified FAIR-style loss quantification. Pairs take three findings from Day 1 and produce dollar-value loss exposure ranges using a provided spreadsheet. Governance students lead this module; technical students provide the attack-side detail.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.11 Guided Lab 7:\u003c\/strong\u003e Building a quantified AI risk register. Pairs aggregate their findings into a single board-ready view, including a simple Monte Carlo simulation (provided spreadsheet — no coding required).\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.12 Guided Lab 8:\u003c\/strong\u003e Designing testable controls. For each finding category, pairs design a control that is implementable, measurable, and re-testable. Common anti-patterns walked through with examples: aspirational policy language, untestable \"human review\" requirements, one-time assessments.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.13 Guided Lab 9:\u003c\/strong\u003e The AI Decision Firewall pattern, explained for both audiences. Technical students see a simple reference implementation; governance students learn how to specify and audit it. Pairs re-test Day 1 attacks against the hardened agent and see which controls held.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.14 Guided Lab 10:\u003c\/strong\u003e Continuous AI assurance — what \"ongoing testing\" actually means in practice, and how it integrates with the GRC, SOC, and ServiceNow workflows that already exist in most GCC enterprises.\u003c\/p\u003e\n\u003ch3\u003eDay 3\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.15\u003c\/strong\u003e The GCC regulatory landscape walkthrough: SDAIA AI Ethics Principles and Generative AI Guidelines (KSA), UAE AI Charter and PDPL, DIFC Regulation 10, ADGM ( Data Protection Regulations ) , Bahrain Personal Data Protection Law and the draft AI Regulation Law (April 2024), Qatar Central Bank AI Guidelines, ISO\/IEC 42001, and NIST AI RMF. Where they overlap, where they conflict, and what an examiner actually asks for. Designed to be useful for both technical and governance students.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.16 Guided Lab 11:\u003c\/strong\u003e Mapping Day 2 controls to the regulatory stack using a provided cross-walk matrix. Pairs identify gaps where their controls satisfy one framework but leave another exposed.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.17 Guided Lab 12:\u003c\/strong\u003e Building the regulator-ready evidence pack — adversarial test results, quantified risk register, control register, residual risk acceptance memo, and a one-page executive briefing — assembled into a single defensible artifact.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.18 Capstone briefing:\u003c\/strong\u003e Scenario: a fictional GCC bank (\"Bank Al-Khaleej\") is deploying an Arabic-language customer service agent with limited tool access to balance lookup, transaction history, and small transfers. Pairs must deliver a complete assurance package.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.19 Capstone execution:\u003c\/strong\u003e Pairs attack the live capstone agent, quantify findings, design controls, map to the regulatory stack, and produce the evidence pack. Instructor circulates for guidance throughout. Pairs that purchased the proficiency exam add-on submit their evidence packs for graded review.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.20\u003c\/strong\u003e Capstone debrief, instructor walkthrough of the reference solution, course wrap-up, and post-course resource handoff (lab access continues for 30 days, instructor follow-up available for 60 days).\u003c\/p\u003e\n\u003ch2\u003e4. Difficulty Level\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003eIntermediate\u003c\/strong\u003e - The student has education and some experience in the field and familiarity with the topic being presented. The student has foundational knowledge that the course will leverage to provide practical skills on the topic.\u003c\/p\u003e\n\u003ch2\u003e5. Suggested Prerequisites\u003c\/h2\u003e\n\u003cp\u003eThis course is designed for two complementary audiences who will work together in pairs: (a) security practitioners with 2–4 years of general cybersecurity experience (any background — pentest, SOC, GRC, audit, cloud security) and basic comfort with a Linux terminal and reading code; and (b) risk, governance, and management professionals (CISOs, AI risk officers, GRC managers, internal auditors, compliance leads) with foundational security knowledge equivalent to CISM, CRISC, ISO 27001 LA, or 3+ years in a security-adjacent role.\u003c\/p\u003e\n\u003ch2\u003e6. What Students Should Bring\u003c\/h2\u003e\n\u003cul\u003e\n\u003cli\u003eLaptop running Windows 10\/11, macOS 12+, or a recent Linux distribution\u003c\/li\u003e\n\u003cli\u003e8 GB RAM minimum (16 GB recommended)\u003c\/li\u003e\n\u003cli\u003e20 GB free disk space\u003c\/li\u003e\n\u003cli\u003eModern web browser (Chrome or Firefox)\u003c\/li\u003e\n\u003cli\u003eThe ability to install a small set of free tools provided in pre-work (a terminal client and a code editor — no Docker or local AI models required, as all heavy compute runs in the instructor-provided cloud lab). Students must be able to reach the cloud lab over standard HTTPS — corporate-locked devices that block outbound web traffic to non-approved domains may not work, and students should plan to bring a personal device if needed.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch2\u003e7. What the Trainer Will Provide\u003c\/h2\u003e\n\u003cul\u003e\n\u003cli\u003e30 days of access to the live cloud-hosted lab environment, including all vulnerable AI applications, agents, and the capstone scenario, with the ability to redeploy and re-attack at will\u003c\/li\u003e\n\u003cli\u003eA complete digital course pack including the finding inventory template, FAIR quantification spreadsheet, Monte Carlo notebook, control register template, regulatory cross-walk matrix, and evidence pack template.\u003c\/li\u003e\n\u003cli\u003eThe AI Decision Firewall reference architecture and source code.\u003c\/li\u003e\n\u003cli\u003eThe adversarial test suite as an importable evaluation harness.\u003c\/li\u003e\n\u003cli\u003eA curated reading list and the instructor's contact for follow-up questions for 60 days post-course.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch2\u003e8. Trainer(s) Bio\u003c\/h2\u003e\n\u003ch3\u003eSatinder Sandhu\u003c\/h3\u003e\n\u003cp\u003eSatinder Sandhu is a cybersecurity engineer and AI risk practitioner with over 15 years of experience delivering offensive security training, advisory, and consulting engagements across 25+ countries. He holds multiple industry certifications, including CISSP, CISM, CCSP, CEH, CHFI, CND, EC-Council Certified Trainer and ISO 27001 Lead Auditor.\u003c\/p\u003e\n\u003cp\u003eHis work spans offensive security, enterprise risk management, cloud and infrastructure security, and AI assurance, with a focus on translating technical vulnerabilities into quantified business and financial impact for executive leadership and regulators. He has supported regulated organizations across financial services, healthcare, and government, with hands-on experience implementing and assessing control frameworks and regional regulatory expectations relevant to AI systems.\u003c\/p\u003e\n\u003cp\u003eSatinder is the founder of a Toronto-based cybersecurity, privacy, and AI risk firm, Security Assured. The lab environments, risk quantification methods, and regulator-ready evidence templates used in his courses are drawn directly from real-world engagements building AI assurance capabilities for regulated enterprises—grounded in production practice rather than theory.\u003c\/p\u003e\n\u003ch2\u003e9. Registration Terms and Conditions\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003e9.1\u003c\/strong\u003e Trainings are refundable before September 21, 2026, minus a non-refundable processing fee of 100 BHD.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.2\u003c\/strong\u003e Between September 21, 2026 and October 21, 2026 partial refunds will be granted, equal to 50% of the course fee minus a processing fee of 100 BHD.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.3\u003c\/strong\u003e All trainings are non-refundable after October 21, 2026.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.4\u003c\/strong\u003e Training tickets may be transferred to another student. Please email us at \u003ca href=\"mailto:training@defcon.org\"\u003etraining@defcon.org\u003c\/a\u003e for specifics.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.5\u003c\/strong\u003e If a training does not reach the minimum registration requirement, it may be cancelled. In the event the training you choose is cancelled, you will be provided the option of receiving a full refund or transferring to another training (subject to availability).\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.6\u003c\/strong\u003e Failure to attend the training without prior written notification will be considered a no-show. No refund will be given.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.7\u003c\/strong\u003e DEF CON Training may share student contact information, including names and emails, with the course instructor(s) to facilitate sharing of pre-work and course instructions. Instructors are required to safeguard this information and provide appropriate protection so that it is kept private. Instructors may not use student information outside the delivery of this course without the permission of the student.\u003c\/p\u003e\n\u003cp\u003e\u003cspan\u003e\u003cstrong\u003e9.8\u003c\/strong\u003e By purchasing this ticket you agree to abide by the \u003c\/span\u003e\u003ca href=\"https:\/\/defcon.org\/html\/links\/dc-code-of-conduct.html\"\u003e\u003cspan\u003eDEF CON Training Code of Conduct\u003c\/span\u003e\u003c\/a\u003e\u003cspan\u003e and the registration terms and conditions listed above.\u003c\/span\u003e\u003c\/p\u003e","brand":"DEFCON MIDDLE EAST","offers":[{"title":"Course only","offer_id":49908107084019,"sku":null,"price":1200.0,"currency_code":"BHD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0841\/4815\/8707\/files\/SatinderSandhu.png?v=1786895474","url":"https:\/\/me.shop.defcon.org\/products\/ai-risk-assurance-for-the-gcc-hands-on-red-teaming-risk-quantification-regulator-ready-governance","provider":"DEF CON MIDDLE EAST","version":"1.0","type":"link"}