← All courses
$20

Sensible Security: Defending Against Agentic AI & External Threats

Defend against agentic AI and external attackers with controls that are proportionate to the risk — not fear-driven over-lockdown that strangles the business. Match the control to the risk, shrink your attack surface (including AI), get identity right for humans and agents, govern (don't ban) AI agents, defend against AI-accelerated and autonomous attackers, and design for resilience with fast detection. For security leads, SREs, and technical leaders.

"We stopped over-locking-down: right-sized controls, scoped and monitored AI agents, and a rehearsed detect-and-respond plan — secure and still able to ship"

6 Interactive Sessions

Short, interactive sessions — watch it work, steer it, then build it yourself. Go deeper anytime with the full code walkthrough.

  1. 1

    Match the control to the risk — security that doesn't strangle the business

    A control is only worth it when it removes more risk than the friction it adds — so the goal isn't maximum lockdown, it's the right controls in the right places.

  2. 2

    Know your attack surface — including AI — then shrink it

    You can't defend what you can't see — so the first, highest-leverage move is to inventory every way an outsider could reach you (now including your AI systems) and then turn off what you don't need.

  3. 3

    Identity & access — for humans and agents

    The network edge dissolved; identity is the real boundary now — so the highest-value, lowest-friction controls govern who (human or agent) can do what.

  4. 4

    Agentic AI as an attack surface — govern your agents, don't ban them

    An agentic AI takes actions on your behalf, so a tricked or misused agent can DO things, not just say them — the defense is scoped tools, a human on high-impact actions, sandboxing, treating what it reads as untrusted, and logging what it does.

  5. 5

    AI-accelerated & autonomous attackers — old attacks, new speed

    AI didn't invent new attacks — it made the old ones faster, cheaper, and more convincing. The sensible defense is the same fundamentals, run at machine speed.

  6. 6

    Assume breach — sensible defense & detection

    You won't prevent everything — especially at AI speed — so design for it: prevention lowers the odds, but resilience (limit the damage, detect fast, respond) is what keeps a break-in from becoming a breach.

Production patterns you'll master

Risk-Proportionate ControlsAttack Surface ReductionIdentity & Least PrivilegeAgentic AI DefenseAI-Era ThreatsAssume Breach & Detection

Synthetic data included

  • Control trade-offs (sensible vs theater)
  • Attack-surface checklist (incl. AI)
  • Agentic-AI guardrails
  • Incident-response quick reference

What you walk away with

Shareable portfolio

A public URL showing your module timeline, patterns mastered, and completion status.

All the code

Download everything as a ZIP — pipelines, guardrails, deployment configs. Yours forever.

Module walkthrough

Each module documented with deliverables and the production pattern you implemented.

Ready to build your sensible security: defending against agentic ai & external threats?

First course free. $20 per course after that.