Build the security team your AI transformation needs.
AI rollouts are outpacing your defenders' skills. DORA and the EU AI Act both demand demonstrable evidence of competence, not just licence seats. We build the workforce that delivers both.
Security leaders do not buy training. They buy capability.
AI shifts attack surfaces faster than point-in-time training and one-off assessments can follow. Four points where classic training planning tears:
AI systems evolve faster than individual standard trainings.
Instead of static training material, we focus on up-to-date, freshly created weekly topics around current CVEs.
New AI attack surfaces demand new skills
Prompt injection, agent misuse and model exfiltration are in no syllabus older than a year.
DORA/TLPT requires demonstrable competence
Not just the tester - the defending team must be able to evidence its own capability too.
Specialist AI security talent is hard to hire and to keep
Your existing team already knows your systems and priorities - a faster route than the market.
Who this programme is built for
We work where competence is not just useful but has to be evidenced.
Regulated financial institutions (DACH)
Banks, insurers and payment providers with 500 to 5,000 staff that must evidence testers and defenders for TLPT.
DORA, BAIT/VAIT
Critical infrastructure and industrials
Energy, transport and manufacturing with converging IT and OT, 250 to 3,000 staff.
NIS2, BSI IT-Grundschutz
Tech and AI product companies
Software and AI product teams with 100 to 1,500 staff shipping AI features and passing customer security reviews.
EU AI Act, ISO 27001
Public sector and state-linked operators
Agencies, municipal utilities and state-linked entities in Germany and the Gulf.
BSI IT-Grundschutz, NESA/TDRA
MSSPs and system integrators
Providers with 50 to 500 staff that need certified pentesters in house to bid for tenders.
Tender requirements
Role-based capability tracks
AI Red Team · OSAI
Who: For teams tasked with attacking AI systems, models and agent pipelines ahead of rollout.
Outcome: A defensible testing methodology for prompt injection, model exfiltration and agent misuse.
Enterprise Pentest · OSCP + OSEP
Who: For your core offensive team testing internal and external infrastructure under realistic conditions.
Outcome: Demonstrable enterprise-grade tradecraft - from initial access through Active Directory compromise.
Web & AppSec · OSWE
Who: For engineering and appsec roles that need to combine code review with web exploitation.
Outcome: The ability to find complex business-logic flaws in your own code before an attacker does.
Defensive Analyse & IR · OSDA + OSIR
Who: For SOC and IR teams who need to detect and contain attacks, not just triage alerts.
Outcome: Detection and response capability that can actually be tested and documented in a TLPT context.
Junior Baseline · CyberCore SEC-100
Who: For early-career and lateral hires who need a solid security baseline before specialising.
Outcome: A common foundation that all other tracks can build on.
How offensive thinking makes every security team better
AI risk cuts across the responsibilities of several security functions. A shared understanding of how attackers approach systems changes daily work in each of these roles, not only in the offensive team.
Red and purple team
Extends testing into AI-enabled applications and makes it clear to the defending side how an attack on those systems actually unfolds.
SOC team
Looks past the single alert to the attacker behaviour behind it, and carries more context into the investigation.
Blue team and incident response
Anticipates how an attacker adapts and moves as an incident develops, instead of only reacting to the last known step.
Security engineering and architecture
Considers attack paths while systems are being designed and controls can still be changed, not first at acceptance testing.
IT and infrastructure
Understands how weaknesses in the underlying environment expose AI-enabled systems and open new paths into the organisation.
The result is a shared picture of how AI systems can be attacked - and what each team can concretely do to reduce that risk.
Build AI red teaming capability in house
The AI Red Teaming Upskill Program is a structured path toward the AI Red Team Operator role: guided learning, hands-on practice and six stages that build on each other. AI security does not stop at the model - the application layer, APIs, cloud, containers and identity systems are all part of the assessment surface around any AI deployment. We deliver the programme through Learn Enterprise, map the stages onto your roles and guide progress with active practitioners.
The six stages
- Stage 1
Foundations of cybersecurity and computing
- Stage 2
Offensive security plus web and API attacks
- Stage 3
Cloud, containers and modern infrastructure
- Stage 4
Red team operations: Active Directory lateral movement and evasion
- Stage 5
LLM red teaming
- Stage 6
Advanced AI red teaming
How the programme is run
Assess existing skills
A placement assessment establishes current competency and the right starting stage. Earlier stages covering already demonstrated skills can be tested out of.
Follow a role-aligned path
Modules and hands-on labs per stage, from foundations through to advanced AI red teaming - assigned along the role rather than as an open catalogue.
Validate readiness to advance
An optional four-hour stage assessment verifies the acquired skills. From a 70% objective score the next stage is cleared. The final stage closes with Synthetic Siege, an AI-300 challenge lab.
Track development across the programme
Progress per stage plus an overall completion figure across learning content and assessments - reported at aggregated team level on request.
The programme can be completed without a separate certification exam - the associated AI-300 certification stays optional for people who want to pursue it. OffSec designed the same stage-based model as a repeatable pattern that can cover further roles and technical domains over time.
What security leaders get out of it
Your own pipeline of AI security talent
Instead of only hiring externally: identify suitable people, develop them through a structured progression and prepare them for more specialised AI security responsibilities. OffSec's premise for the programme is that the specialist talent pool is limited and hiring alone does not scale.
Budget lands at the right level
Every person starts where the material is actually demanding for them. Experienced practitioners do not repeat foundations, less experienced people get the preparation they need before advanced content.
One standard across all teams
The stages form a common competency frame on the way to the AI Red Team Operator role. Managers assess readiness against the same standard instead of maintaining a separate development plan per person.
Measure skills, not course completion
Hands-on labs and objective-based assessments say more than a completion rate. What gets reported is what someone demonstrated in practice, not how many videos were watched.
Four steps from diagnosis to evidence
Workforce assessment
We map roles, existing certifications and your AI transformation roadmap against the actual threat picture.
Licence allocation via Learn Enterprise
OffSec Learn Enterprise seats are allocated across the capability tracks - centrally managed, invoiced in EUR.
Practitioner-led guidance
Active pentesters and trainers track progress, answer questions grounded in real engagements, and keep the team moving.
Optional TIBER-EU/DORA validation
A validation engagement measures whether your team's capability actually changed - not just whether exams were passed.
The same firm that tests your defences trains your defenders.
EUR invoicing from a German GmbH
Buying direct from OffSec typically runs on a US credit card. We provide German-law contracting, VAT treatment and a DPA.
Delivery presence: DACH, Dubai, Reykjavík
Points of contact in your timezone and language, not a ticketing portal.
The business case for your budget approval.
Two pages: cost per seat and per track, mapping to DORA, NIS2, the EU AI Act and IT-Grundschutz, plus a realistic timeline. Ready to forward without rewriting anything.
Development is a retention argument too
The budget does not only offset recruiting cost. Visibly investing in skills gives strong people a reason to stay and a path into in-demand roles, with recognised certifications as milestones along the way.
Invest in the team you already have
Your people already know your systems, processes and priorities. Structured hands-on development turns that knowledge into offensive capability that stays inside the business, instead of dependence on scarce specialist hires.
"We don't separate offensive and defensive thinking when we train analysts. We're building full spectrum defenders who understand both sides of the attack."
Klaus Wunder, Principal Cyber Defense Analyst at SecuInfra - our blue team partner in the Red Blue Alliance. The quote is from the case study published by OffSec on how SecuInfra develops analysts, from career changers through to AI security topics.
"We already have a training budget with a generic vendor."
This is not video courses with a completion rate. It is hands-on labs along real attack paths, plus certifications that hold up in a TLPT context.
"Certificates do not prove day-to-day skill."
Which is why we track continuous progress through pins, path badges and an optional validation engagement instead of one exam at year end.
"Works council and procurement will have questions."
Reporting can stay aggregated at team level and individual badges remain voluntary. Contract, DPA and EUR invoicing come from a German GmbH.
Subject: Investing in our security team ahead of our next AI rollout Hi [Name], We're shipping several AI-powered systems right now, and DORA plus the EU AI Act both require demonstrable evidence that our testers and defenders are actually qualified for it. I looked into Exploit Labs' "AI Security Workforce" programme: OffSec Learn Enterprise licences as the delivery mechanism, combined with role-based capability tracks (AI red team, enterprise pentest, appsec, defensive analysis, junior baseline) and practitioner-led guidance. Billing runs in EUR from a German GmbH with proper contracting and a DPA - no need for a direct US credit-card purchase. Optionally, there's a validation engagement at the end that checks whether our team's capability actually, measurably changed. I've attached/linked the two-page CFO one-pager. Can we find some budget for a short workforce assessment call? Thanks, [Your name]
Short updates on capability tracks, DORA/EU AI Act requirements and new roles - no marketing filler.
Frequently asked questions
Is this still an OffSec training course?
Not in the classic sense anymore. OffSec Learn Enterprise licences are the delivery vehicle - what we actually deliver is building an AI-security-ready workforce: role selection, capability tracks, practitioner-led guidance and an optional engagement to validate whether capability actually changed.
How does this relate to DORA and the EU AI Act?
Both frameworks demand demonstrable evidence of competence - DORA for testers and defenders under TLPT, the EU AI Act for the people who review and operate AI systems. A licence seat alone isn't evidence. Our programme delivers role mapping, progress evidence, and - on request - independent validation.
Why not buy directly from OffSec?
You can - but buying direct typically runs on a US credit card, without German invoicing, VAT treatment or a DPA. We invoice in EUR from a German GmbH, provide German-law contracting, and guide the licences with practitioners instead of just reselling seats.
Which roles does the programme cover?
Five capability tracks: AI red team (OSAI), enterprise pentest (OSCP+OSEP), web & appsec (OSWE), defensive analysis & IR (OSDA+OSIR), and a junior baseline track (CyberCore SEC-100). We blend tracks against your actual role distribution.
How do you measure whether capability actually changed?
Optionally through a TIBER-EU/DORA validation engagement: the same practitioners who test your defences assess whether your team actually behaves differently in a realistic exercise than before the programme - not just whether exams were passed.
Where is the team that guides us based?
Delivery presence in DACH, Dubai and Reykjavík. Your points of contact are active pentesters and trainers, not sales-only staff - the same firm that tests your defences also trains your defenders.
How does the placement assessment in the Upskill Program work?
Before the first module every person takes a placement assessment. It determines the right starting stage and lets people test out of earlier stages covering skills they have already demonstrated. Experienced analysts start where the material is actually demanding for them, not at the basics.
Does the Upskill Program replace certifications?
No, it sits in front of them and alongside them. The programme builds role-relevant skills stage by stage through modules, labs and optional stage assessments. Certifications such as OSCP, OSDA or OSAI remain the external, proctored proof at the end of a specialisation - both run on the same Learn Enterprise licence.
What does the AI Red Team Operator role cover?
It assesses AI systems in the context of their environment: application layer and APIs, cloud and container infrastructure, identity and Active Directory, plus LLM-specific attacks such as prompt injection and model misuse. That is exactly what the six stages of the Upskill Program build toward, from foundations through to advanced AI red teaming.
Does the programme require a certification exam?
No. The final stage closes with Synthetic Siege, an AI-300 challenge lab that assesses practical application. That completes the programme without a separate exam. The AI-300 certification stays optional for people who want external, proctored proof.
What progress does management actually see?
Per stage: completed modules and labs, the results of the optional stage assessments (pass mark 70% objective score), and an overall completion percentage across both learning content and assessments. On request we report at aggregated team level only, so works councils and data protection can sign off.