Group Purchasing
Group Purchasing
AI-FOCUSEDBETA

SEC546: Securing Agentic AI

SEC546Cloud Security
  • 5 Days (Instructor-Led)
  • 30 Hours (Self-Paced)
Course authored by:
Viswanath (Vis) Chirravuri
Viswanath (Vis) Chirravuri
SEC546
Course authored by:
Viswanath (Vis) Chirravuri
Viswanath (Vis) Chirravuri
  • 30 CPEs

    Apply your credits to renew your certifications

  • Advanced Skill Level

    Course material is geared for cyber security professionals with hands-on experience

  • 19 Hands-On Lab(s)

    Apply what you learn with hands-on exercises and labs

Learn to secure autonomous AI agents with the controls, guardrails, and defenses needed for real-world deployment.

Course Overview

Want to be the first to know when SEC546 beta registration opens? Complete the interest form to receive updates on beta registration, full release date, training events, OnDemand availability, and more. Be among the first to experience the only SANS course built end-to-end for securing agentic AI.

Interest Form

SEC546 equips defenders to secure modern AI agents across their full autonomy lifecycle, from input to inter-agent communication, against risks that traditional controls were never built to stop. Students enforce strong boundaries, resist prompt injection, apply secure design patterns, protect memory, and govern runtime behavior. They defend MCP and tool execution, secure desktop, browser, and multi-agent environments, and contain unsafe agent actions through hands-on, live-fire defense.  

What You'll Learn

  • Model agentic AI threats, trust boundaries, and core attack surfaces.
  • Enforce secure input, output, identity, and permission boundaries.
  • Defend against prompt injection, context poisoning, and tool tampering.
  • Harden agent memory, runtime operations, and rogue agent containment.
  • Secure MCP flows, tool execution, desktop agents, and dependencies.
  • Protect multi-agent, browser, and computer-use agent ecosystems.
  • Apply cyber-physical safeguards through hands-on live-fire defense exercises.

Business Takeaways

  • Reduce enterprise risk from autonomous agents, tools, and connected systems.
  • Establish enforceable guardrails for agent actions, data, and permissions.
  • Improve resilience against prompt injection and agent-driven compromise paths.
  • Strengthen governance for agent memory, runtime behavior, and oversight.
  • Secure desktop, browser, and multi-agent workflows at scale.
  • Prepare teams to contain rogue agents and limit operational blast radius.
  • Build confidence for safer adoption of agentic AI in production.

Course Syllabus

Explore the course syllabus below to view the full range of topics covered in SEC546: Securing Agentic AI.

Section 1Foundations of Agentic AI Security

Section 1 builds the foundation for defending agentic AI by helping students understand the risk landscape, establish trusted boundaries, resist prompt injection, apply secure design patterns, and enforce strong identity and least-privilege controls. It equips defenders to secure agents before they act.

Topics covered

  • 1.0 Introduction to Agentic AI, Risks, Threat Model
  • 1.1 Enforcing Input and Output Boundaries
  • 1.2 Defending Against Prompt Injection
  • 1.3 Secure Agent Development Patterns
  • 1.4 Agent Identity, Permissions, and Least Agency

Labs

  • Lab 1.1: Hardening with NeMo Guardrails
  • Lab 1.2: Agent Goal Integrity Controls
  • Lab 1.3: Build Secure Agent Chain
  • Lab 1.4: Privilege Scoping & Identity Controls

Section 2Agent Operations, Hardening, and MCP Defense

Section 2 moves from foundational controls to hardening production agentic AI systems at enterprise scale. Participants will secure persistent agent memory against poisoning, detect and safely terminate rogue agents, enforce runtime governance policies on live agent actions, and deploy defensive gateways that govern how agents reach external tools, data, and services.

Topics covered

  • 2.1 Securing Agent Memory and Context Stores
  • 2.2 Detecting, Containing, and Isolating Rogue Agents
  • 2.3 Observability, Governance, and Continuous Defense
  • 2.4 MCP Gateway Defense and Policy

Labs

  • Lab 2.1 Memory Integrity Controls
  • Lab 2.2 Safe Agent Termination
  • Lab 2.3 Runtime Governance and Policy Enforcement
  • Lab 2.4 Deploying Defensive MCP Gateway

Section 3Secure MCP, Desktop Agents and Runtime Defenses

Section 3 hardens the building blocks agents depend on at runtime, including MCP data flows and desktop agent environments. Participants will detect context poisoning and tool response tampering, sandbox tool execution paths, secure desktop agents such as OpenCode, and validate the provenance of dependencies, skills, and prompts.

Topics covered

  • 3.1 MCP Data Integrity & Context Security
  • 3.2 Agent Tool Execution Sandboxing
  • 3.3 Securing Desktop Agents
  • 3.4 Agent Supply Chain & AIBOM Defense

Labs

  • Lab 3.1 Detecting Context Poisoning and Tool Response Tampering
  • Lab 3.2 Tool Sandbox and Egress Controls
  • Lab 3.3 Securing OpenCode Agents
  • Lab 3.4 Dependency, Skill and Prompt Provenance

Section 4Multi-Agent, Browser and Computer-Use Agent Security

Section 4 defends the runtime ecosystem where agents communicate with peers, drive browsers and operating systems, and delegate authority. Participants build verifiable trust chains between agents, sandbox browser and computer-use actions with Cua, scope delegated authorization across agent-to-agent handoffs, and prevent task data from crossing tenant boundaries.

Topics covered

  • 4.1 Multi-Agent A2A Protocol Defense
  • 4.2 Securing Browser & Computer-Use Agents
  • 4.3 Delegated Agent Authorization Defense
  • 4.4 Cross-Agent Data Leakage Defense

Labs

  • Lab 4.1 A2A Trust Chain Controls
  • Lab 4.2 Cua Action Sandboxing
  • Lab 4.3 Token Exchange and Scoping Controls
  • Lab 4.4 Task Contamination Isolation Controls

Section 5Cyber-Physical Agent Security & Emerging Frontiers

Section 5 establishes strict fail-safe mechanisms for agents that act on the physical world or hardware devices, then present the current frontier of agentic security defenses with confidential computing. The day closes with a comprehensive live-fire defense exercise that requires participants to apply every defensive technique from the week against a multi-stage compromise of a production-grade autonomous system.

Topics covered

  • 5.1 Physical-World Agent Safety
  • 5.2 Emerging Agentic Security Topics
  • 5.3 Agent Defense Capstone

Labs

  • Lab 5.1 Robotic and IoT Kill-Switch Controls
  • Lab 5.2 Confidential Agent Execution and Attestation
  • Lab 5.3 Live Defense Operations CTF

Things You Need To Know

We're updating our course schedule - please check back later.

Benefits of Learning with SANS

Bryan Simon: Teacher Standing Next to Smartboard and Explaining Concept

Get feedback from the world’s best cybersecurity experts and instructors

OnDemand Mobile App

Choose how you want to learn - online, on demand, or at our live in-person training events

Close Up of Woman Holding a Pen and Documents

Get access to our range of industry-leading courses and resources