IT security should be considered from the outset across architecture, development, and operations. For existing systems, the focus is on systematically identifying vulnerabilities, assessing risks, and developing appropriate measures rather than adding security only as an afterthought.
This applies to traditional web applications and APIs as well as to agentic systems and LLM-powered applications. These introduce additional attack vectors, such as prompt injection, unsafe tool interactions, and data exfiltration, placing new demands on existing security approaches.
We offer the following formats covering different aspects of IT security:
- Agentic Software Security: A two-day training on the security risks of agentic systems and LLM-based applications.
- Web Security: Designing secure web applications and avoiding common vulnerabilities.
- OWASP Top Ten in Practice: Understanding and fixing web application vulnerabilities from an attacker’s perspective.
This page brings together articles, the Security Podcast, talks, and case studies on IT security.