SAN-102 · Free online · Self-paced

Data at Risk:
LLMs, AI Models & Cybersecurity

Every prompt your team sends is data leaving a boundary. SAN-102 teaches security professionals to map the full data-risk surface of AI adoption — leakage, shadow AI, provider retention, injection-driven exfiltration — and to build the controls, habits and governance that close it. Trusting the model is SAN-101’s problem. Telling it too much is this one.

2 days · 09:00–17:00 Free online · personal access link Prerequisites: working security experience On-site UK or virtual classroom

Overview

Who this course is for.

SAN-102 is for the people whose data flows through AI tools — and the people accountable when it shouldn’t have. Technical enough for practitioners, structured enough for those who govern them.

SOC Analysts & Incident Responders

You paste logs, indicators and client artefacts into AI tools daily. Learn exactly what happens to that data, which paths leak, and the handling rules that keep you effective and defensible.

Security Engineers & Architects

You deploy copilots, RAG assistants and AI-enabled tooling. Learn the architecture patterns — permission-aware retrieval, egress control, private endpoints — that make them safe to run.

Managers, DPOs & CREST Member Firms

You sign off AI use under client confidentiality duties and UK GDPR. Leave with a working governance pack: policy, DPIA skeleton, vendor due-diligence checklist and audit trail design.

Prerequisites

Working experience in a security role. No data-science background required. Concepts such as embeddings and retrieval are taught from first principles — the course’s depth is in risk and control, not model internals.

Relationship to SAN-101

SAN-102 stands alone; SAN-101 is not required. Taken together they are the complete SanRa foundation: SAN-101 covers judgement with AI in the loop, SAN-102 covers the data that flows through it. Team bookings commonly run both in the same week.

Learning Outcomes

What you will be able to do.

On completion, and evidenced through assessment, you will be able to:

Trace the complete data lifecycle of an AI interaction — prompts, context windows, retrieval, fine-tuning, provider logging and telemetry — across consumer, enterprise and local deployment tiers.
Identify and classify leakage pathways: direct prompt disclosure, shadow AI, agent tool-chains, browser extensions, over-permissioned RAG corpora and model memorisation.
Explain and demonstrate how indirect prompt injection turns retrieved content into an exfiltration channel — and apply the architectural and behavioural controls that break it.
Apply data-classification and redaction patterns to everyday analyst tasks, deciding what may leave the boundary, in what form, to which tier of model.
Evaluate AI vendors and tools with a structured due-diligence method: training-use terms, retention, subprocessors, residency, and enterprise vs. consumer API differences.
Map AI data handling to UK GDPR, the EU AI Act, ISO/IEC 42001 and ISO/IEC 27001, and produce a DPIA skeleton for a proposed AI use case.
Protect client confidentiality and evidential integrity when AI assists with security work subject to CREST member-company obligations.
Audit a realistic AI-assisted workflow, find its data risks, and deliver a prioritised remediation plan that survives management review.

Curriculum

Five modules. Two days. Every leak closed.

Each module pairs a technical mechanism with the human behaviour that makes it dangerous — because data rarely leaks through technology alone. Roughly 40% of contact time is hands-on.

Topics

  • The anatomy of an AI interaction: prompts, system prompts, context windows, retrieval augmentation, tool calls
  • Where your data goes: provider logging, retention windows, abuse-prevention review, human evaluation queues, telemetry
  • Deployment tiers and what they actually guarantee: consumer apps, enterprise APIs, private endpoints, local and open-weight models
  • Training on your data: when it happens, when it contractually cannot, and what “we don’t train on your data” does and doesn’t cover
  • Model memorisation and training-data extraction: what research has demonstrated, what it means for fine-tunes

Exercise

  • Map the journey of one real prompt (sanitised) through a consumer app, an enterprise API and a local model — identify every copy made and every party that can read it
Human factors lens: the “chat illusion” — why a private-feeling conversational interface suppresses the mental model of data leaving a boundary, and how to rebuild that boundary instinct.

Topics

  • Direct disclosure: sensitive data in prompts — client identifiers, credentials in logs, vulnerability details, personal data
  • Shadow AI: unsanctioned tools, personal accounts, browser extensions, AI features silently enabled in existing SaaS
  • Agent tool-chains: how a single instruction fans out across email, tickets, code repos and browsers — and where copies persist
  • RAG over-permissioning: assistants that retrieve documents the user could never open directly; vector-store tenancy and metadata leakage
  • Case reviews: public incidents of source-code and personal-data leakage via AI tools — anatomy and lessons

Exercise

  • Shadow-AI discovery simulation: inventory a fictional SOC’s real AI usage from network, expense and browser artefacts — then score each path’s risk
Human factors lens: shadow AI as a rational response to friction — why bans fail, and how sanctioned fast paths plus classification habits beat policy alone.

Topics

  • Direct vs. indirect prompt injection: malicious instructions smuggled in web pages, emails, tickets, documents and code the model reads
  • Exfiltration mechanics: tool-call abuse, markdown/link rendering tricks, DNS and image-beacon channels, agent-to-agent spread
  • Data poisoning and RAG poisoning: corrupting the knowledge an assistant retrieves and acts on
  • AI supply chain: models, datasets, plugins and MCP servers as attack surface
  • Defensive patterns: untrusted-content handling, least-privilege tools, egress allow-lists, human-in-the-loop gates for consequential actions

Exercise

  • Live lab: an AI SOC assistant reads a poisoned ticket and attempts to leak case data through three channels — detect, contain and re-architect the workflow until the attack fails
Human factors lens: authority by fluency — why well-formatted model output disarms the suspicion that a raw log line would trigger, and how “content is not instructions” becomes a team reflex.

Topics

  • UK GDPR and the Data Protection Act applied to AI use: lawful basis, minimisation, processor terms, international transfer, DPIAs for AI tools
  • EU AI Act awareness: what touches security teams in practice; UK regulatory direction
  • ISO/IEC 42001 (AI management systems) and ISO/IEC 27001: where AI data controls slot into an existing ISMS; NIST AI RMF as a working checklist
  • Client confidentiality under CREST member-company obligations: engagement data, report material and evidential integrity when AI assists
  • Vendor due diligence: training-use terms, retention, subprocessors, residency, incident history, enterprise vs. consumer API small print

Exercise

  • Draft a DPIA skeleton and vendor scorecard for a proposed AI deployment: “LLM assistant for incident report drafting”
Human factors lens: accountability diffusion — when “the AI did it” becomes an acceptable explanation, governance has already failed. Designing ownership that has a name on it.

Topics

  • Data classification for AI: a practical four-tier scheme (public / internal / client / evidential) mapped to allowed model tiers
  • Redaction and pseudonymisation patterns that preserve analytical value: tokenisation of identifiers, log scrubbing, safe exemplars
  • Technical controls: DLP for AI endpoints, CASB/proxy patterns, egress allow-lists, permission-aware retrieval, private endpoints and local-model options
  • The usable-policy problem: writing an AI acceptable-use policy people actually follow, with sanctioned fast paths and escalation routes
  • Monitoring and audit: logging AI usage without surveilling the workforce; evidencing compliance to clients and assessors

Capstone exercise (assessed)

  • Audit a realistic AI-assisted SOC workflow end-to-end: map every data flow, find the planted risks (shadow AI, over-permissioned RAG, injection path, unlawful transfer), and deliver a prioritised remediation plan with a one-page policy. Pass requires finding the critical risks and a plan that survives a management challenge
Human factors lens: controls people route around are controls that don’t exist — designing for the analyst on their worst, busiest day.

CREST Alignment Map

How SAN-102 maps to CREST.

SAN-102 complements — never replaces — CREST examinations. The table below shows the working alignment used in course design and reported on completion certificates.

SAN-102 Component CREST Syllabus Domain Benefit
Module 1 — AI data lifecycle CPSA: engagement awareness & information handling Sound mental model of where engagement data travels when AI tools are used
Module 2 — Leakage pathways CPSA & CRT: confidentiality & data protection duties Client and evidential data protected across the tools analysts actually use
Module 3 — Adversarial data risks CRT: methodology & current threat techniques Injection and exfiltration techniques understood, demonstrated and countered
Module 4 — Governance & law CREST code of conduct; member-company obligations AI use that stands up to client, regulator and assessor scrutiny
Module 5 — Controls & capstone CRT: reporting & client communication; quality expectations Auditable AI-assisted workflow and a remediation deliverable of engagement quality

Assessment & Certification

Assessed like the job, not like a quiz.

Certification is earned, not attended. Both components must be passed; one resit of the knowledge check is included.

Capstone Audit — 60%

The Day 2 workflow audit is graded against a published rubric: risks found vs. planted, quality of the data-flow map, and the prioritisation and defensibility of the remediation plan. Pass mark: 70%.

Knowledge Check — 40%

25 scenario-based questions covering all five modules, taken in the training environment. Pass mark: 70%. Questions rotate between cohorts.

No CPD / no (ISC)² credits

Digital certificate of completion with unique verification ID, This free edition is learning content only. It is not CPD-accredited and not (ISC)² accredited.

Try It Now

Sample the knowledge check.

Four real questions from the SAN-102 item bank. Answer to see the marking logic.

Q1.An analyst pastes a client’s subnet ranges and three vulnerability descriptions into a consumer LLM app to speed up report drafting. The primary problem is:

Accuracy is a SAN-101 problem; this is a custody problem. Consumer-tier apps may log, retain, human-review and train on prompts, and nothing is anonymised automatically. The fix is a sanctioned enterprise/local path plus redaction — not slower reporting. (Module 2)

Q2.Your AI SOC assistant summarises incoming tickets. A ticket contains hidden instructions telling the assistant to forward case details to an external address. This is:

Indirect prompt injection is the defining adversarial data risk of tool-connected AI: the model cannot distinguish instructions from content it was asked to read. Defence is architectural (constrain tools and egress) plus behavioural (verify consequential actions), not “better prompting.” (Module 3)

Q3.A RAG assistant deployed over the company document store answers a junior analyst with content from HR disciplinary files. The most likely root cause is:

The assistant retrieved what its service account could read, not what the user may see. Permission-aware retrieval — enforcing source-system ACLs at query time — is the control. This is the most common real-world RAG data failure. (Module 2 & 5)

Q4.Under UK GDPR, sending personal data to a third-party AI API for processing is lawful when:

Compliance is a set of verifiable conditions, not a vendor claim. Lawful basis, minimisation, Article 28 processor terms, transfer mechanism and DPIA are the working checklist — Module 4 builds one live in class. (Module 4)

FAQs

Common questions.

Should we take SAN-101 or SAN-102 first?

Either works — they are independent. If your team’s AI use is already widespread and touches client or personal data, start with SAN-102 to close the data risks, then SAN-101 for the judgement layer. Most team bookings run both in the same week at a combined rate.

How technical is the course?

Practitioner-level. You will work a live injection lab and a shadow-AI discovery exercise, but no programming is required. Concepts like embeddings, retrieval and context windows are taught from first principles — the depth is in risk, control and governance.

Does the course recommend specific vendors or tools?

No. SanRa is vendor-neutral. The due-diligence method taught in Module 4 lets you score any vendor — consumer, enterprise or open-weight — against training-use terms, retention, residency and subprocessor risk.

Is the legal content specific to the UK?

The worked frameworks are UK GDPR, the Data Protection Act and EU AI Act awareness, mapped to ISO/IEC 42001 and 27001. The control patterns transfer; the statutory detail is UK/EU-focused. This course is training, not legal advice.

Can this be delivered inside our own environment?

Yes — private cohorts (8–16) can run against a sanitised model of your actual AI stack, so the capstone audit rehearses your real workflows. Deliverables include your team’s draft AI acceptable-use policy and data-classification scheme.

What does it cost?

Public cohort places and private team rates are quoted on enquiry. Pricing includes two delivery days, all materials, the assessment, one knowledge-check resit, The online edition is free for now. Instructor-led team delivery can be quoted separately.

Start SAN-102 free online.

Get a personal access link that unlocks both SanRa courses. Work through five modules and take the knowledge check — no password and no payment.

Get free access link →
Free for now Self-paced Not CPD / not (ISC)² accredited

Want instructor-led delivery for a team? Email ibrahim.mukherjee@icloud.com.