CIACON
Training

CIACON Training is more than a workshop. It's a hands-on experience built by and for cybersecurity professionals. Real techniques, real scenarios, and real-world context from practitioners who operate at the front lines every day.

From offensive tactics to defensive strategies, our trainers bring what textbooks can't — lived experience. CIACON exists to keep that knowledge flowing all year long.

// Upcoming
Enrolling Now

Next Session

FILE // 004
Open for Enrollment
04An 8-Hour Hands-On Workshop

Agentic AI & MCP Security

Building and Breaking Autonomous AI Systems

Date23 September 2026
VenuePHD House, New Delhi
Duration8 Hours
CPE Credits8 Credits
Skill LevelIntermediate
Ratio70:30 Hands-On
Enroll in Training
TrainersSmita Jha · Nagarjun Rallapalli · Yash Raj Singh
// Briefing

Artificial Intelligence is rapidly transforming from simple conversational assistants into autonomous systems capable of reasoning, planning, interacting with enterprise applications, and making decisions with minimal human intervention. While these capabilities unlock tremendous business value, they also introduce an entirely new class of security risks.

Modern AI agents can access databases, invoke APIs, interact with SaaS applications, execute workflows, communicate with other agents, and make autonomous decisions — powered by technologies such as the Model Context Protocol (MCP). With this evolution comes a rapidly expanding attack surface.

Following a 70:30 hands-on to theory ratio, participants build, attack, defend, and secure Agentic AI applications and MCP integrations through practical exercises, live demonstrations, and real-world attack scenarios. The workshop concludes with a Capture-the-Flag challenge where attendees apply the techniques learned throughout the day.

// Offense

Attack Autonomous AI Systems

  • Prompt Injection
  • Indirect Prompt Injection
  • Tool Poisoning
  • Memory Poisoning
  • Excessive Agency
  • Permission Escalation
  • Data Exfiltration
  • Business Logic Abuse
  • Supply Chain Attacks
  • MCP Abuse
// Defense

Secure AI Applications

  • AI Guardrails
  • Semantic Validation
  • Secure Prompt Engineering
  • Input & Output Validation
  • Least-Privilege Tool Access
  • Human-in-the-Loop Controls
  • Monitoring & Logging
  • Secure MCP Deployments
  • AI Red Teaming
// Course Modules
Module01

Foundations of Agentic AI

Autonomous AI SystemsPlanning & ReasoningAI MemoryTool CallingMulti-Agent SystemsEnterprise Use CasesAI Adoption Trends
Module02

Model Context Protocol (MCP)

MCP ArchitectureClientsServersHostsTool IntegrationBuilding MCP ServersEnterprise ImplementationsCommon Security Pitfalls
Module03

Security Risks in Agentic AI

Prompt InjectionIndirect Prompt InjectionTool PoisoningMalicious MCP ServersExcessive AgencyPermission CreepMemory PoisoningData ExfiltrationSupply Chain RisksOWASP Top 10 for LLM Applications
Module04

Hands-On Attack Labs

OWASP FinBotGandalf by LakeraVulnerable MCP EnvironmentsPrompt InjectionBusiness Logic AbuseUnauthorized Tool InvocationAgent HijackingTool ChainingMemory Manipulation
Module05

Defending Agentic AI

Semantic GuardrailsSecure Prompt DesignTool AuthorizationSandboxed ExecutionHuman Approval WorkflowsMonitoring & ObservabilityAI Security TestingAI Red Teaming
// Meet Your Trainers
Smita Jha
01

Smita Jha

AI Security & Application Security

Cybersecurity professional specializing in AI Security, Application Security, Secure Software Development, and Enterprise AI Risk Management. Brings practical experience in helping organizations securely adopt AI technologies while implementing secure development practices across modern cloud-native environments.

AI SecurityAppSecSecure SDLCAI Risk
Nagarjun Rallapalli
02

Nagarjun Rallapalli

Cybersecurity Consultant & Security Researcher

Expertise across Application Security, Cloud Security, DevSecOps, Offensive Security, and AI Security. Extensive experience assessing enterprise applications and securing AI-enabled systems against emerging attack vectors.

AppSecCloud SecurityDevSecOpsOffensive Security
Yash Raj Singh
03

Yash Raj Singh

AI Security Researcher & Offensive Security

Specializes in Large Language Models (LLMs), Agentic AI, Model Context Protocol (MCP), Prompt Injection, AI Red Teaming, and Secure AI System Design. Focuses on identifying and mitigating vulnerabilities in autonomous AI systems.

LLM SecurityAgentic AIMCPAI Red Teaming
FILE // 004-B
Participant Brief
01

Who Should Attend

14 Roles
  • 01Security Architects
  • 02Application Security Engineers
  • 03AI Security Engineers
  • 04DevSecOps Engineers
  • 05Cloud Security Engineers
  • 06Security Consultants
  • 07Red Team Professionals
  • 08Penetration Testers
  • 09SOC Analysts
  • 10Threat Hunters
  • 11Platform Engineers
  • 12AI Engineers
  • 13Security Researchers
  • 14CISOs Evaluating AI Adoption
02

What to Bring

8 Items
  • [ ]Laptop (Windows, macOS, or Linux)
  • [ ]Minimum 8 GB RAM
  • [ ]Modern web browser (Chrome, Edge, Firefox)
  • [ ]Wi-Fi capability
  • [ ]GitHub account
  • [ ]VS Code or preferred IDE
  • [ ]Terminal / PowerShell / SSH client
  • [ ]Laptop charger
03

What's Included

13 Inclusions
  • [✓]8 Hours of instructor-led training
  • [✓]Dedicated cloud-based lab environment
  • [✓]Pre-configured Agentic AI & MCP labs
  • [✓]Hands-on exercises & live demonstrations
  • [✓]AI attack & defense playbooks
  • [✓]Course slides & training manual
  • [✓]Sample MCP servers & reference implementations
  • [✓]Capture-the-Flag (CTF) challenge
  • [✓]Official CIACON 2026 training certificate
  • [✓]8 CPE (Continuing Professional Education) credits
  • [✓]Lunch & refreshments
  • [✓]Networking with AI security professionals
  • [✓]Curated learning resources & reference material
Prerequisites

A basic understanding of application security, APIs, cloud computing and DevSecOps concepts. Python is recommended but not mandatory. No prior AI or ML experience required.

Not designed for

Absolute beginners with no cybersecurity background, attendees seeking a business or strategy-focused session, or data scientists looking for deep machine learning and model-training techniques.

Seats are limited

Build, break, and secure real-world Agentic AI systems under the guidance of experienced practitioners.

Enroll in Training
// Past Trainings

Past Sessions

FILE // 001
✓ Completed
Abraham Aranguren
01

Mobile App Attacks, By Example

Abraham ArangurenCEO, 7ASecurity

Presenting Abraham Aranguren (7ASecurity) — giving his first ever training in the subcontinent. Trainings provided by him have helped thousands of students enhance their skillset. He enlightened participants with real-world examples on Practical Mobile App Attacks.

OSCPOSCEGWAPT
DateDecember 03–06, 2020
Participants120+
LinkedIn ↗
FILE // 002
✓ Completed
Sankarraj Subramanian
02

Cyber Forensics

Sankarraj SubramanianFounder & CEO, Prompt Watch

Cyber forensics mainly focuses on analyzing encrypted data, recovering records and investigating possible security breaches. Learn the ins & outs of the topic from Mr. Sankarraj Subramanian and equip yourself with an unparalleled skillset.

GCFAGCIHCHFI
DateDecember 03–06, 2020
Participants95+
LinkedIn ↗
FILE // 003
✓ Completed
Sanjeev Multani
03

Buffer Overflows

Sanjeev MultaniCyber Security Consultant

Buffer Overflow occurs when data exceeds the storage capacity of a buffer, potentially corrupting or crashing the system. Join this extensive learning session by Mr. Sanjeev Multani and develop your expertise on this critical vulnerability class.

CEHOSCPCRTP
DateDecember 03–06, 2020
Participants85+
LinkedIn ↗
// Open Application

Call
For
Trainers

Got knowledge worth sharing? CIACON gives you the stage. Join a community of practitioners who are shaping the next generation of cybersecurity professionals — one session at a time.

01Bring your real-world experience to an engaged, technical audience
02Design your own curriculum — your expertise, your way
03Deliver immersive, hands-on learning that leaves a lasting impact
contact@ciaconference.com
// Philosophy

Our Training Ethos

Across all sessions, one principle remains constant: industry-ready security comes from learning directly from practitioners who operate at the front lines.

Our trainers are not career lecturers—they are builders, investigators, and attackers who bring real-world context into every session. This is how we ensure our conferences and trainings continue to deliver practical, relevant, and future-proof cybersecurity education.

Next Chapter

New voices. New expertise. New sessions.
Speaker announcements dropping soon.

Stay tuned

Apply to Train at CIACON

Share your expertise and shape the next generation of cybersecurity professionals

01Trainer Information

02Training Proposal

0 / 100–300 words

03Lab & Logistics

Leave blank if no preference. Most CIACON workshops run 20–50 participants.

04Experience & Credentials

List relevant certifications, awards, or industry recognition.