Skip to Content
[Masterclass] From AI Sprawl to Resilient Systems: Engineering Control over AI Risk

[Masterclass] From AI Sprawl to Resilient Systems: Engineering Control over AI Risk

Tech
Location: Talonite & Electrum - 9/4/26, 9:00 AM - 9/4/26, 10:30 AM (Europe/Berlin) (1 hour 30 minutes)
Patryk Dumicz & Thomas Punz & Jõao Fernandes
Patryk Dumicz & Thomas Punz & Jõao Fernandes

Patryk Dumicz is Head of PMO & Cyber Security Portfolios at SECURNITE, where he drives the delivery of complex security and resilience programs across regulated industries. He combines a strong background in security architecture, program governance, and operational execution, ensuring that technical security controls scale across large organizations. Patryk works closely with engineering and offensive security teams to translate regulatory and strategic requirements into practical, enforceable security architectures, with a strong focus on resilience, automation, and modern threat landscapes

Thomas Punz is CEO of SECURNITE and a cybersecurity and governance expert with a strong focus on operationalizing compliance and making regulatory requirements practically actionable. With a background in Physics, IT and Governance, Risk, and Compliance (GRC), Thomas specializes in bridging the gap between strategic requirements and technical implementation. His work focuses on building resilient control systems, integrating security into software development lifecycles, and leveraging modern technologies such as AI to increase efficiency and auditability.

João Fernandes is a Cyber Security Consultant in SECURNITE’s Offensive Security team, specializing in real‑world attack simulations, red teaming, and adversary‑driven security testing. His work focuses on identifying control gaps in modern, cloud‑ and API‑driven environments, including AI‑enabled systems. João brings a hands‑on attacker’s perspective to architecture reviews and security design, helping organizations understand how emerging threats, such as prompt injection and data poisoning, can be exploited in practice, and how to mitigate them effectively at a technical level.

Modern IT and OT security requires clear control over complex, data-driven AI systems that are directly integrated into business processes. Security architects in the DACH region face the challenge of embedding resilience from the ground up as LLMs and AI services penetrate enterprises via APIs, plugins, and SaaS platforms, often bypassing traditional asset inventories and security audit pipelines. 

This masterclass provides a practical framework for operationalizing AI governance through automated trust checks. Starting with the problem of uncontrolled AI sprawl, the session takes an architectural look inside AI agents to uncover systemic vulnerabilities. In the intensive hands-on segment, participants will interact directly with an engineering harness to manually enforce external security boundaries around AI systems. In live scenarios, critical risk vectors, such as alignment bypass, runtime anomalies, and IP exfiltration are simulated and mitigated.

By directly comparing these technical safeguards with regulatory requirements, this session demonstrates how abstract compliance can be translated into a concrete, resilient AI governance program that empirically demonstrates the value of each individual control.

During the session patripants will configure and test an external protection shield (harness) to secure LLMs and agent networks in real time. They will simulate attacks directly on the system and learn how automated controls stop them.

Participants leave with:

  • A ready-to-use framework for detecting shadow AI and systematically prioritizing vulnerabilities in your infrastructure
  • A clear methodology for mapping the technical controls from the masterclass directly to regulatory requirements
  • Practical techniques for measuring control effectiveness using data-driven evidence

Ideal for:

  • Security Architects
  • Detection & Response Engineers
  • Cloud / Platform Security Engineers
  • AI / ML Engineers with Security Responsibility
  • Senior Security Engineers supporting CISOs