Agentic governance, guardrails and security (tech)
Code: ENG-005 | Track: technical | Duration: 3 hr
Securing autonomous systems: threat landscape, enforceable controls, red-teaming and incident response.
Context
Security and engineering teams hardening agents that act on the firm's behalf.
Who it's for
Security and engineering teams
What you'll leave with
- Evaluate agent risks and implement security guardrails.
- Design enforceable controls for actions and permissions.
- Conduct red-teaming and incident response.
Prerequisites
- Familiarity with your agent stack; a vulnerable sandbox agent is provided for red-teaming
Format
- Remote
Agenda
- The agentic threat and risk landscape - mapping attack surfaces across models, tools, data and orchestration, including prompt injection variants.
- Guardrails - layered defences - the difference between probabilistic prompt advice and hard environmental controls, tracked through a live injection walkthrough.
- Permissioning, authority and human oversight - least privilege, separating reasoning from authority, and event-driven oversight with last-line controls.
- Hands-on red-teaming an agent - attacking a deliberately vulnerable agent through manipulated documents, privilege escalation and exfiltration paths.
- Observability, audit and incident response - governance telemetry, anomaly detection and managing halt, escalate and abstain states.
- Governance frameworks and production readiness - translating policy into enforceable controls, risk tiering and the regulatory direction of travel.
Session details
- Total time: 3 hours (including one short break)
- Participants: Up to 15
- Delivery: Remote or in person (UK; other locations by arrangement)
- What you leave with: An attack-surface map, a control checklist and an incident-response starter