Every prompt your team sends is data leaving a boundary. SAN-102 teaches security professionals to map the full data-risk surface of AI adoption — leakage, shadow AI, provider retention, injection-driven exfiltration — and to build the controls, habits and governance that close it. Trusting the model is SAN-101’s problem. Telling it too much is this one.
Overview
SAN-102 is for the people whose data flows through AI tools — and the people accountable when it shouldn’t have. Technical enough for practitioners, structured enough for those who govern them.
You paste logs, indicators and client artefacts into AI tools daily. Learn exactly what happens to that data, which paths leak, and the handling rules that keep you effective and defensible.
You deploy copilots, RAG assistants and AI-enabled tooling. Learn the architecture patterns — permission-aware retrieval, egress control, private endpoints — that make them safe to run.
You sign off AI use under client confidentiality duties and UK GDPR. Leave with a working governance pack: policy, DPIA skeleton, vendor due-diligence checklist and audit trail design.
Working experience in a security role. No data-science background required. Concepts such as embeddings and retrieval are taught from first principles — the course’s depth is in risk and control, not model internals.
SAN-102 stands alone; SAN-101 is not required. Taken together they are the complete SanRa foundation: SAN-101 covers judgement with AI in the loop, SAN-102 covers the data that flows through it. Team bookings commonly run both in the same week.
Learning Outcomes
On completion, and evidenced through assessment, you will be able to:
Curriculum
Each module pairs a technical mechanism with the human behaviour that makes it dangerous — because data rarely leaks through technology alone. Roughly 40% of contact time is hands-on.
CREST Alignment Map
SAN-102 complements — never replaces — CREST examinations. The table below shows the working alignment used in course design and reported on completion certificates.
| SAN-102 Component | CREST Syllabus Domain | Benefit |
|---|---|---|
| Module 1 — AI data lifecycle | CPSA: engagement awareness & information handling | Sound mental model of where engagement data travels when AI tools are used |
| Module 2 — Leakage pathways | CPSA & CRT: confidentiality & data protection duties | Client and evidential data protected across the tools analysts actually use |
| Module 3 — Adversarial data risks | CRT: methodology & current threat techniques | Injection and exfiltration techniques understood, demonstrated and countered |
| Module 4 — Governance & law | CREST code of conduct; member-company obligations | AI use that stands up to client, regulator and assessor scrutiny |
| Module 5 — Controls & capstone | CRT: reporting & client communication; quality expectations | Auditable AI-assisted workflow and a remediation deliverable of engagement quality |
Assessment & Certification
Certification is earned, not attended. Both components must be passed; one resit of the knowledge check is included.
The Day 2 workflow audit is graded against a published rubric: risks found vs. planted, quality of the data-flow map, and the prioritisation and defensibility of the remediation plan. Pass mark: 70%.
25 scenario-based questions covering all five modules, taken in the training environment. Pass mark: 70%. Questions rotate between cohorts.
Digital certificate of completion with unique verification ID, This free edition is learning content only. It is not CPD-accredited and not (ISC)² accredited.
Try It Now
Four real questions from the SAN-102 item bank. Answer to see the marking logic.
Q1.An analyst pastes a client’s subnet ranges and three vulnerability descriptions into a consumer LLM app to speed up report drafting. The primary problem is:
Accuracy is a SAN-101 problem; this is a custody problem. Consumer-tier apps may log, retain, human-review and train on prompts, and nothing is anonymised automatically. The fix is a sanctioned enterprise/local path plus redaction — not slower reporting. (Module 2)
Q2.Your AI SOC assistant summarises incoming tickets. A ticket contains hidden instructions telling the assistant to forward case details to an external address. This is:
Indirect prompt injection is the defining adversarial data risk of tool-connected AI: the model cannot distinguish instructions from content it was asked to read. Defence is architectural (constrain tools and egress) plus behavioural (verify consequential actions), not “better prompting.” (Module 3)
Q3.A RAG assistant deployed over the company document store answers a junior analyst with content from HR disciplinary files. The most likely root cause is:
The assistant retrieved what its service account could read, not what the user may see. Permission-aware retrieval — enforcing source-system ACLs at query time — is the control. This is the most common real-world RAG data failure. (Module 2 & 5)
Q4.Under UK GDPR, sending personal data to a third-party AI API for processing is lawful when:
Compliance is a set of verifiable conditions, not a vendor claim. Lawful basis, minimisation, Article 28 processor terms, transfer mechanism and DPIA are the working checklist — Module 4 builds one live in class. (Module 4)
FAQs
Either works — they are independent. If your team’s AI use is already widespread and touches client or personal data, start with SAN-102 to close the data risks, then SAN-101 for the judgement layer. Most team bookings run both in the same week at a combined rate.
Practitioner-level. You will work a live injection lab and a shadow-AI discovery exercise, but no programming is required. Concepts like embeddings, retrieval and context windows are taught from first principles — the depth is in risk, control and governance.
No. SanRa is vendor-neutral. The due-diligence method taught in Module 4 lets you score any vendor — consumer, enterprise or open-weight — against training-use terms, retention, residency and subprocessor risk.
The worked frameworks are UK GDPR, the Data Protection Act and EU AI Act awareness, mapped to ISO/IEC 42001 and 27001. The control patterns transfer; the statutory detail is UK/EU-focused. This course is training, not legal advice.
Yes — private cohorts (8–16) can run against a sanitised model of your actual AI stack, so the capstone audit rehearses your real workflows. Deliverables include your team’s draft AI acceptable-use policy and data-classification scheme.
Public cohort places and private team rates are quoted on enquiry. Pricing includes two delivery days, all materials, the assessment, one knowledge-check resit, The online edition is free for now. Instructor-led team delivery can be quoted separately.
Get a personal access link that unlocks both SanRa courses. Work through five modules and take the knowledge check — no password and no payment.
Get free access link →Want instructor-led delivery for a team? Email ibrahim.mukherjee@icloud.com.