Generative AI: cyber risks and best practices

Generative artificial intelligence is transforming business practices, but rapid adoption brings new cybersecurity risks. This training helps employees, IT leaders and CISOs understand threats linked to generative AI (ChatGPT, Copilot, Gemini, Claude...) and adopt best practices to protect company data while benefiting from the productivity gains these technologies offer.

Programme

Day 1 — Understanding risks linked to generative AI

Morning (9:00 – 12:30)

Understanding how generative AI works

  • Differences between generative AI and traditional AI
  • Overview of the main LLMs
  • How a prompt works
  • How an AI produces a response
  • Model limitations

Professional use cases

  • Writing
  • Document research
  • Software development
  • User support
  • Document analysis
  • Business assistance

Cyber risks

  • Leakage of confidential information
  • Exposure of sensitive data
  • Shadow AI
  • Hallucinations
  • Disinformation
  • Poor user practices

Afternoon (14:00 – 17:30)

Attacks against AI

  • Prompt Injection
  • Jailbreak
  • Data Leakage
  • Supply Chain
  • Data theft
  • Prompt Leakage

Hands-on workshop

  • Analysis of several real scenarios
  • An employee pastes a customer database into ChatGPT
  • Development of a script containing secrets
  • Analysis of a confidential contract
  • Creation of an HR document
  • Risk identification and definition of protection measures

Day 2 — Securing AI usage

Morning

Governance

  • AI usage policy
  • Data classification
  • Roles and responsibilities
  • Use-case validation

Best practices

  • Which documents can be shared?
  • How to anonymise data
  • Best practices for writing prompts
  • Verifying responses
  • Employee awareness

Afternoon

Compliance

  • GDPR
  • AI Act
  • ISO 27001
  • ISO 42001
  • AI charter

Workshop

  • Creating an AI policy
  • Creating a user charter
  • Creating an AI risk matrix
  • Creating an awareness plan

Skills acquired

  • Identify risks linked to generative AI
  • Use AI securely
  • Detect dangerous usage
  • Implement governance rules
  • Raise awareness among users

General information

€4,500 excl. VAT

Objective

Train participants to use generative AI in a secure, responsible way that meets the company's security requirements.

Target audience

Employees, managers, CIOs, CISOs, business leaders, IT teams

Level

Beginner / Intermediate

Duration

2 days

This training is delivered in partnership with Académie Cyber, a certified organisation. It is Qualiopi-certified and CPF-eligible.

Qualiopi certification
Mon Compte Formation
Contact us

Other training courses offered by De Shagan Network

  • Cyber incident management and first response

    A cyberattack can have serious consequences. This course enables IT teams and SOC analysts to react quickly.

    Audience

    IT teams, SOC, system administrators

    Level

    Intermediate / Advanced

    Duration

    2 days

    Discover this course
  • Application security and DevSecOps

    A simple bug can be an entry point for a cyberattack. Ensure your developers apply OWASP Top 10 best practices.

    Audience

    Developers, DevOps, IT teams

    Level

    Intermediate / Advanced

    Duration

    2 days

    Discover this course
  • Cloud environment security (AWS, Azure, Google Cloud)

    Cloud solutions (AWS, Azure, Google Cloud...) open the door to many cyber risks. Protect your business from data leaks or API attacks.

    Audience

    IT teams, cloud architects, DevOps

    Level

    Intermediate

    Duration

    1 day

    Discover this course
  • OWASP Top 10 for LLM Applications

    Identify the main vulnerabilities in language-model-based applications and learn how to secure your AI architectures, agents, and RAG systems.

    Audience

    Developers, architects, DevSecOps, AppSec, CISOs

    Level

    Intermediate / Advanced

    Duration

    2 days

    Discover this course