AI SECURITY WORKSHOP

Give your team AI habits that keep client data safe

A hands-on workshop for software development companies. We show real attacks on the AI tools your people open every morning, then teach the rules and habits that keep client data safe, while getting more out of AI, not less.

  • Two hours to multi-day
  • On-site or remote
  • English or Bulgarian
  • Engineers or non-technical staff
Stihia AI security workshop in progress

What your team walks away with

Not a slide deck nobody opens again. Habits, and evidence you can point at.

Awareness that sticks

Your team watches a prompt injection walk data out of a tool they used that same morning. After that, the rules stop sounding theoretical and start sounding obvious.

Rules people actually follow

Concrete practices they can apply the next day: what never goes into a prompt, which tools and MCP servers to trust, least privilege and secret handling, and habits that make AI output better, not just safer.

Evidence you can show clients

An attendance record, the materials we leave behind, and a topic list you can map to your AI policy, so the next client security review gets answers, not scrambling.

Theory, demos, hands-on practice

Every workshop moves through these three stages. How much time each one gets depends on who is in the room and how long we have.

Stage 01 Grounding

Theory

What an AI agent actually is, how agents fail, and what has already gone wrong in the real world, with documented incidents rather than hypotheticals.

  • Agents, autonomy levels, tools, and memory
  • OWASP Top 10 for Agentic Applications
  • Prompt injection, direct and indirect
  • Real incidents, real losses
Stihia workshop theory
Stage 02 Watch it break

Demos

We attack real, popular AI tools, not mock-ups. The audience follows each step of the attack so they understand where risks come from, turning abstract concepts into concrete examples.

  • Data exfiltration from a coding agent
  • Agent goal hijacking
  • Memory and context poisoning
  • System prompt leaks
Stihia workshop demo
Stage 03 Hands-on

Practice

Participants stop watching and start attacking. Everyone gets time on Stihia Zmey, a real AI agent built to be broken in a safe environment.

  • Attack a live agent, not a simulation
  • Progressively harder defences
  • Group debrief on what worked
  • A medal for the winner
Stihia workshop practice

We hack the tools your team opens every morning

Demos run against current real products. The point is not to scare anyone. It is to make the failure mode concrete enough to act on.

  • Data exfiltration: leak confidential data out of a developer's environment by confusing the agent.
  • Agent goal hijack: hide instructions in content a coding agent reads, and watch its objective change.
  • Memory poisoning: plant something in persistent memory that keeps influencing later, unrelated sessions.
  • System prompt leak: coax an assistant into revealing the instructions it was told to keep private.

The demo set is refreshed as new vulnerabilities appear, so a workshop run this quarter is not the one we ran last quarter. We can also target the specific tools your team has adopted, or your own AI product, on request.

Stihia workshop demo evidence

The part they talk about afterwards

Watching an attack is useful. Landing one yourself is what changes behaviour.

Everyone gets a turn on the agent

Stihia Zmey is a deployed AI agent with real defences and a real goal to protect. Participants have to talk their way past it. Attempts get shared, the room starts collaborating, and the concepts from the theory stage land without anyone needing to take notes.

Whoever gets furthest takes home the Stihia Zmey Slayer medal. It is a small thing that turns out to matter: medals end up on desks, and the conversation about AI security keeps going after we leave.

Play Zmey About Zmey

Stihia Zmey winner
Stihia Zmey medals

Topics we cover

We assemble each workshop from these modules. Shorter formats take the essentials, longer ones go deep, and we add modules specific to your stack or industry when it helps.

AI agents, explained

  • What separates an agent from a chatbot
  • Reasoning, tools, memory, and autonomy levels
  • Where agents already sit inside your delivery process

The threat landscape

  • OWASP Top 10 for Agentic Applications
  • Shadow AI
  • Direct and indirect prompt injection
  • The lethal trifecta: private data, untrusted content, outbound communication

What has already happened

  • Documented breaches, thefts, and destroyed data
  • The specific mistake behind each one
  • Which of them your setup is currently exposed to

Safe, effective AI use for everyone

  • What never belongs in a prompt
  • Vetting tools, MCP servers, and skills
  • Least privilege, sandboxing, and secret storage
  • Which tasks to hand to AI, and how to get output worth keeping

Secure AI development

  • Treating model inputs and outputs as untrusted
  • Input and output guardrails, and their limits
  • Logging, observability, and real-time detection
  • Design patterns that contain a compromised agent

Regulation and policy context

  • EU AI Act, GDPR, NIS2, and DORA in plain language
  • Where ISO 27001, ISO 42001, and SOC 2 touch AI use
  • How the workshop connects to your internal AI policy

Sovereignty, privacy, and local-model questions come up in almost every session; we cover them wherever they fit best for your team.

Formats

Flexible content, sized to your calendar. If none of these fits, tell us the constraint and we will shape something that does.

Two hours

Intro session

One sitting, mixed audience, the full arc: theory, a set of demos, and a short Zmey round with a medal at the end. Enough to shift how people work the following week.

Half or full day

Deep dive

More demos, far more hands-on time, and room to split into role-specific tracks: engineers going into secure design while everyone else works on daily practice.

Every 3–6 months

Recurring refresher

The AI risk landscape moves faster than a single session can cover. Each round brings new incidents, new mitigations, and new demos, so your team stays current as the tools change.

Who it is for

  • Engineers and AI builders: deeper into agent architecture, guardrails, and the design decisions that contain a compromise.
  • Leadership and compliance: the risk, regulatory, and client-trust picture, and what it implies for policy.
  • Everyone who touches AI: including non-technical staff. No prior security knowledge assumed, and no jargon left unexplained.

Practical details

  • On-site at your office, fully remote, or hybrid
  • Delivered in English or Bulgarian
  • A single team up to a full-company session
  • Participants bring a laptop or a smartphone for the hands-on stage
  • Slides, checklists, and links shared with all attendees afterwards
  • Demos never run against your production systems

Delivered by practitioners

Sessions are led by the people who build Stihia's AI threat detection and run its security and compliance work, not by a training vendor working from someone else's material.

Ivan Danielov Ivanov

Ivan Danielov Ivanov

Data Science & Product Engineering

Ivan builds the threat detection layers behind Stihia Sense and runs the vulnerability research the demos come from, which is why the demos are current rather than recycled. He leads the theory and live hacking stages.

  • 10+ years of data science and ML engineering experience at Ethermind, SoftServe, Progress Software
  • Data for Good Bulgaria, Humans in the Loop, and other non-profit and startup work
  • MSc in Computer Science, University of Bonn, Germany
Peter Kirkov

Peter Kirkov

Cybersecurity & Compliance

Peter works across IT security, data privacy, and IT governance, and has spent years running security awareness programmes. He covers the regulatory and governance parts of the workshop: what the rules actually require of you, and how AI use changes your risk and audit position.

  • Certified Information Systems Auditor (CISA) · Lead ISO 27001 Auditor
  • Compliance, audit, and IT risk programmes across GDPR, NIS2, and ISO 27001
  • Security training and awareness programmes across finance, government, and multinational organisations

Which of them runs your session depends on the format and the room. Technical audiences lean on the research and demo side, leadership and compliance audiences on the regulatory side, and longer formats usually bring both. Meet the full team.

What teams take away from the room

In their own words: what changed for the people who sat through it.

Exceptionally useful knowledge shared by the Stihia team! Presentation was strict and covered AI dev practices + what devs should look for to detect AI vulnerabilities. What I truly loved about this workshop was not only the interesting content, but the interest of the dev team looking into trendy AI vulnerabilities and security approaches. Everybody's eyes were saying: Wow, I was thinking exactly "how actually this was made to happen" and the lectures clearly answered everything. After those 2 hours we got a networking session and many many people wanted to extend it more. Waiting for the next season after 3-4 months.
Stoyan Simov CEO, AppStreams

How we get from here to the room

Four steps, and the first one costs you just half an hour.

Step 01

Intro call

Thirty minutes. We find out which AI tools your team actually uses, who should be in the room, and what is most important to you.

Step 02

Tailoring

We pick the modules and demo targets, then agree format, length, language, and date. You see the outline and final price before anything is agreed.

Step 03

Delivery

We run the session on-site or remotely, hands-on stage included. Questions are the point, so we leave room for them.

Step 04

Follow-up

Materials and checklists go out to attendees, along with a short summary for you of what your team should change first.

Awareness is step one

A workshop changes how people behave. Written rules and a named owner are what keep it that way.

Govern

AI Policy Consulting

Internal AI policies written and actually implemented, aligned with the EU AI Act, GDPR, NIST, NIS2, DORA, ISO 27001, SOC 2, and ISO 42001.

Learn more

Sustain

Fractional Security & Compliance Officer

A named owner for AI security and compliance who keeps policy applied and answers client security reviews, without a full-time hire.

Learn more

Full Package

Enable Safe AI Development

The whole path in one engagement, for teams moving to an AI-first delivery process and wanting it governed from the start.

Learn more

Questions we get asked

Is this too technical for non-engineers?

No. The default session is built for a mixed room and assumes no security background; every term gets explained before it gets used. Depth is available when the audience is purely technical, and we agree that in advance rather than guessing on the day.

How long should we book?

Two hours covers theory, demos, and a short hands-on round, and is enough to change behaviour. Half a day or more is worth it when you want role-specific tracks, deeper dives into tools and security architectures, a longer Zmey tournament, or discussion time about your own architecture.

How often should we rerun this?

One time is enough if you want to bring basic awareness to your team. However, as the AI field changes quickly, we recommend recurring sessions. Especially if you are in a regulated industry. Ideally, every three to six months. New vulnerabilities and new tools appear constantly, and the demo set is rebuilt each round, so recurring sessions keep pace where a one-off session ages.

Do you attack anything of ours?

Not unless you explicitly ask us to and we agree scope in writing first. By default, demos run against our own sandboxed setups and publicly available tools, never your production systems or client data.

Can you use our own AI product as a demo target?

Often, yes, and it tends to be the most valuable version of the session. It needs a scoping conversation first, and depending on what we find it may make more sense as a separate piece of work than as part of a workshop.

Does remote delivery lose anything?

The demos and the hands-on stage work the same remotely. On site you get better side conversations and a livelier competition, so we suggest it when travel is practical, but remote is a real option, not a downgrade.

What do participants need to prepare?

Nothing beforehand. They need a laptop or a smartphone and a browser for the hands-on stage. No installs, no accounts, no pre-reading.

Does this help with client security questionnaires?

It gives you part of the answer: evidence that staff have been trained, on what, and when. Questionnaires usually also ask for written policy and a responsible owner, which is where policy work and a fractional officer come in.

What does it cost?

It depends on format, length, group size, and whether we travel. Tell us roughly what you have in mind on the intro call and you will get a fixed price before you commit to anything.

Stihia AI security workshop in progress

Give your team a reason to care about AI security

Start with a half-hour call. Tell us which AI tools your developers use, and we will tell you honestly whether a workshop is the right first step, or whether something else should come first.