Highlights
- Explain why autonomy, poorly defined agentic goals and ill-defined interaction can amplify security risk.
- Draw a compact agentic reference architecture and identify important Zones of Trust and delegated-authority boundaries.
- Use Secure-By-Design patterns to place deterministic gates around unsafe, excessive or irreversible actions.
- Apply agentic STRIDE and MITRE ATLAS to turn architecture weaknesses into concrete attack narratives and mitigations.
- Model observable agent skills as atomic states using CRUDE and Action.Zone.
- Build and score Deterministic-State-Transitions, calculate Path-Danger, prioritize dangerous paths and communicate residual risk.
Course Details
Module 1 — Agentic AI Foundations & Architecture — 100 minutes / 13 slides
- Why agentic systems change threat modeling: probabilistic decisions, deterministic privileges/effects and compounding errors.
- Automation vs workflows vs agents; the agentic loop; Autonomy, Goals and Interaction as risk multipliers.
- Compress the six workflow-pattern slides into structured vs dynamic patterns and their security tradeoffs.
- LETHAL TRIFECTA, unanticipated dangerous capability and direct/indirect prompt injection with follow-on actions.
- Reference architecture with input, orchestration, service/tool and output layers plus identity, authorization, telemetry and governance.
- MCP, multi-agent delegation and Zones of Trust.
- 15-minute mini-exercise: map the refund agent, mark trust crossings and place one deterministic gate.
Module 2 — Secure Design & Threat Identification — 110 minutes / 14 slides
- Secure-By-Design: least-agentic design, secure defaults and deliberate authorization.
- Actions-based least privilege, control-plane/data-plane separation, PEPs and useful HITL.
- Sandboxing, memory controls, tool governance, guardrail stack, monitoring, resilience and evidence.
- Break the LETHAL TRIFECTA architecturally rather than relying on detection alone.
- STRIDE vs MITRE ATLAS; agentic STRIDE, attack clusters and threat multipliers.
- Condensed STRIDE→ATLAS mapping and one worked poisoned-document → email-exfiltration path.
- 25-minute integrated threat exercise: one attack fragment → STRIDE → ATLAS → preventative/detective/containment controls.
Module 3 — Agentic RTMP & Guided Lab — 110 minutes / 16 slides
- Why RTMP; static vs dynamic views; short trust-zone/zone-math review.
- Agentic RTMP pipeline: State → CRUDE → Action.Zone → transitions → Path-Danger → STRIDE → controls.
- Atomic State construction and CRUDE-to-STRIDE mapping.
- Transition modeling, normal/designed (“preferred” in the uploaded source deck) path, retry/failure/escalation/rollback/stop branches.
- Transition-Score, dangerous transitions/states and Path-Danger calculation.
- Deterministic-State-Transitions with explicit warning against false precision.
- Controls on states/transitions and residual-risk documentation.
50-minute guided lab using a pre-built refund-agent architecture: 5–7 states, two paths, scoring, STRIDE/ATLAS, controls and report-out.
Who should attend
- Security architects, threat modelers and application/product security engineers.
- AI/ML architects and engineers building agents, multi-agent workflows, MCP integrations or tool-using applications.
- Red team / security testing practitioners who need design-time attack paths to drive adversarial testing.
- Risk, assurance and governance practitioners who need reviewable evidence for agentic-system decisions.
Recommended prior knowledge
Basic familiarity with security architecture or threat modeling is helpful. Deep machine-learning expertise is not required. The abridged exercises are designed around architecture and reasoning artifacts rather than coding.
Feedback
4.8 out of 5 average
"The topics (threat modelling frameworks, zones of trust, annotating your own diagrams, implementing security into Agile practices) were all well-chosen and appropriate." GL, Software Engineer, Threat Modelling, February 2021
“JBI did a great job of customizing their syllabus to suit our business needs and also bringing our team up to speed on the current best practices. Our teams varied widely in terms of experience and the Instructor handled this particularly well - very impressive”
Brian F, Team Lead, RBS, Data Analysis Course, 20 April 2022