CREST-Aligned Training · Cybersecurity Analysts · AI Age

Train the analyst,
not just the tool.

Every major training provider now teaches analysts to use AI. Almost none teach them to think with it — to calibrate trust, resist automation bias, and keep their tradecraft sharp while machines draft the first answer. That is the gap SanRa was built to close.

2 days instructor-led Free online self-paced edition Knowledge check included On-site or virtual delivery

Market Whitespace

The gap nobody is teaching.

The AI-era security training market has split into crowded lanes — tool training, offensive AI, and defending AI platforms. The fourth quadrant, the one that decides whether the first three actually work under pressure, sits empty. It is the human layer.

Crowded

“Using AI” — tool training

Prompting copilots, automating workflows, building with LLMs and agents. Useful, but commoditising fast and vendor-driven.

Occupied by: global training majors, tool vendors

Crowded

AI for offensive & defensive security

Offensive AI tradecraft, LLM application security, AI-driven detection engineering and data-science-for-security bootcamps.

Occupied by: established certification bodies

Crowded

Securing AI systems

Protecting models, pipelines and AI deployments; governance frameworks and compliance for AI platforms.

Occupied by: cloud & AI platform providers

Open — SanRa’s Ground

Thinking with AI — the human layer

Calibrated trust, automation bias, vigilance, skill maintenance and verification discipline for analysts with AI in the loop. The layer that determines whether every other investment pays off.

Owner: SanRa — a Human Factors company for the AI Age

The Curriculum

Two courses. One discipline.

SAN-101 trains the analyst’s judgement when AI is in the loop. SAN-102 protects the data that AI touches. Together they cover the two failure modes of AI-era security work: trusting the model too much, and telling it too much.

SAN-101 Flagship

Thinking with AI: Human Factors for the AI-Augmented Analyst

Work with AI systems without surrendering judgement to them — calibrated trust, automation-bias resistance, durable tradecraft and accountable, auditable AI-assisted decisions.

  • 01 The AI-Shaped Threat Landscape
  • 02 AI in the Analyst’s Toolkit — Power & Failure Modes
  • 03 Calibrated Trust: Automation Bias & Vigilance
  • 04 Skill Maintenance in an AI-First SOC
  • 05 Governance, Accountability & Capstone Exercise
Free online 5 modules Knowledge check
SAN-101 overview →

SAN-102 New

Data at Risk: LLMs, AI Models & Cybersecurity

Map and close the data-risk surface of AI adoption — leakage into prompts, shadow AI, provider retention, RAG over-permissioning, injection-driven exfiltration and the controls that actually stop them.

  • 01 How AI Models Handle Your Data
  • 02 Leakage Pathways: Prompts, Shadow AI & RAG
  • 03 Adversarial Data Risks: Injection & Exfiltration
  • 04 Governance, Law & Client Confidentiality
  • 05 Controls, Architecture & Capstone Audit
Free online 5 modules Knowledge check
SAN-102 overview →

Start both courses free online.

One personal access link unlocks the full catalogue. No password. No payment.

Get free access link →

The SanRa Difference

Human factors is not a soft skill.
It is the control surface.

Aviation learned it in the 1970s; medicine learned it in the 1990s. Security operations is learning it now: when automation does the first pass, the human becomes the last line of defence — and the least engineered one.

Calibrated Trust

Analysts learn structured verification protocols — when to trust AI output, when to challenge it, and how to document the challenge — replacing vibes with procedure.

Vigilance Under Automation

Techniques drawn from aviation and process-control research to counter automation bias, alert fatigue and the out-of-the-loop performance problem in AI-assisted triage.

Skills That Survive AI

Deliberate-practice regimes and “AI-shadow” drills that keep CREST-relevant tradecraft sharp, so analysts retain the ability to work when the model is wrong — or offline.

CREST Alignment

Built on the CREST pathway.

SAN-101 is engineered to sit alongside the CREST certification ladder. Course content is mapped to CREST Practitioner Security Analyst (CPSA) and CREST Registered Penetration Tester (CRT) syllabus domains. This free online edition is for individual learning and is not a formal accreditation or CPD product.

For CREST Candidates

Scenario practice and reporting discipline that reinforce CPSA/CRT examination domains — with the AI-era threat knowledge those syllabi increasingly assume.

For practitioners

Self-paced modules and a knowledge check you can take free online now — without claiming CPD or third-party accreditation credits.

For Employers

A defensible answer to the board question: “Our analysts use AI — who verified the output?” Assessment records map directly to ISO/IEC 42001 competence clauses.

Your analysts already use AI.
Train them to out-think it.

Cohorts run monthly, on-site across the UK or in our virtual classroom. Prefer instructor-led delivery for your team? Email us after you try the free online edition.

Start free online →