Every major training provider now teaches analysts to use AI. Almost none teach them to think with it — to calibrate trust, resist automation bias, and keep their tradecraft sharp while machines draft the first answer. That is the gap SanRa was built to close.
Market Whitespace
The AI-era security training market has split into crowded lanes — tool training, offensive AI, and defending AI platforms. The fourth quadrant, the one that decides whether the first three actually work under pressure, sits empty. It is the human layer.
Prompting copilots, automating workflows, building with LLMs and agents. Useful, but commoditising fast and vendor-driven.
Occupied by: global training majors, tool vendors
Offensive AI tradecraft, LLM application security, AI-driven detection engineering and data-science-for-security bootcamps.
Occupied by: established certification bodies
Protecting models, pipelines and AI deployments; governance frameworks and compliance for AI platforms.
Occupied by: cloud & AI platform providers
Calibrated trust, automation bias, vigilance, skill maintenance and verification discipline for analysts with AI in the loop. The layer that determines whether every other investment pays off.
Owner: SanRa — a Human Factors company for the AI Age
The Curriculum
SAN-101 trains the analyst’s judgement when AI is in the loop. SAN-102 protects the data that AI touches. Together they cover the two failure modes of AI-era security work: trusting the model too much, and telling it too much.
SAN-101 Flagship
Work with AI systems without surrendering judgement to them — calibrated trust, automation-bias resistance, durable tradecraft and accountable, auditable AI-assisted decisions.
SAN-102 New
Map and close the data-risk surface of AI adoption — leakage into prompts, shadow AI, provider retention, RAG over-permissioning, injection-driven exfiltration and the controls that actually stop them.
One personal access link unlocks the full catalogue. No password. No payment.
Get free access link →The SanRa Difference
Aviation learned it in the 1970s; medicine learned it in the 1990s. Security operations is learning it now: when automation does the first pass, the human becomes the last line of defence — and the least engineered one.
Analysts learn structured verification protocols — when to trust AI output, when to challenge it, and how to document the challenge — replacing vibes with procedure.
Techniques drawn from aviation and process-control research to counter automation bias, alert fatigue and the out-of-the-loop performance problem in AI-assisted triage.
Deliberate-practice regimes and “AI-shadow” drills that keep CREST-relevant tradecraft sharp, so analysts retain the ability to work when the model is wrong — or offline.
CREST Alignment
SAN-101 is engineered to sit alongside the CREST certification ladder. Course content is mapped to CREST Practitioner Security Analyst (CPSA) and CREST Registered Penetration Tester (CRT) syllabus domains. This free online edition is for individual learning and is not a formal accreditation or CPD product.
Scenario practice and reporting discipline that reinforce CPSA/CRT examination domains — with the AI-era threat knowledge those syllabi increasingly assume.
Self-paced modules and a knowledge check you can take free online now — without claiming CPD or third-party accreditation credits.
A defensible answer to the board question: “Our analysts use AI — who verified the output?” Assessment records map directly to ISO/IEC 42001 competence clauses.
Cohorts run monthly, on-site across the UK or in our virtual classroom. Prefer instructor-led delivery for your team? Email us after you try the free online edition.
Start free online →