Build it.
Deploy a training bank to the cloud and build a pipeline that checks what you ship.
CYBER AGOGE / LIVE DEVSECOPS & AI SECURITY BOOTCAMP
Six weeks of live training in code, cloud, pipelines and AI security. Build a portfolio. Take the CDAISP practical exam. Show employers what you can do.
21 September 2026 · £599, exam included
New to tech or already in the industry? There’s a route for you.
Student messages, reviews and live sessions from previous Cyber Agoge bootcamps.
Original screenshots from previous bootcamps. Individual experiences vary. These are not CDAISP exam results.
THE WORK BEHIND THE CONFIDENCE
Deploy a training bank to the cloud and build a pipeline that checks what you ship.
Find weaknesses in applications and AI systems. Apply controls and test your fixes.
Leave with four portfolio projects, then demonstrate your skills in the CDAISP practical exam.
CYBER AGOGE / CYBER CHARLIE
Learn live with Cyber Charlie (Charlie Banyard), an active CISO. Breakout rooms matched to your level, and feedback on the work you make. You learn alongside other people, with an instructor in the room.
Begin with a live setup evening. Build through the six weeks. Continue with six months of mentorship in small, booked clinics.
See what you’ll learn →
A TASTE OF WHAT YOU’LL LEARN
Try four everyday security decisions in our practice company. We’ll guide you through what helps and why. No experience needed to explore.
YOUR SKILLS / CONNECTED
Explore the six skill areas you’ll bring together—and the applications, cloud infrastructure, pipelines and AI systems they help you protect.
Tap a skill to see what it helps you do.
See how you build these skills →Was: the security architect and the GRC analyst. Now: yours. Think like a CISO, build like an engineer. Get the keys to FinTrust, map every way in, and start working the way security engineers actually work — protected branches, review as a control, secrets that never touch the repo. Your first pipeline is scanning every push by Wednesday. Then risk, NIST and ISO 27001 done on a live system instead of a slide. Hands on: GitHub, Cursor with AI assistance, Claude Code, Gitleaks, Semgrep, GitHub Actions, Draw.io, Jira You walk out with: your own FinTrust repo with a live pipeline · an attack-surface map · a risk assessment
Was: the cloud engineer. Now: yours. Ship a bank to AWS without becoming a headline. No long-lived keys. Logging and threat detection on before anything else. Containers behind a load balancer nobody can reach. Then all of it as code — Terraform, scanned before it applies, deployed from GitHub with no credentials stored anywhere. Includes the skill every engineer needs now: find what the AI got wrong in the Terraform it wrote for you. Hands on: AWS (Identity Center, ECS Fargate, CloudTrail, GuardDuty, WAF, Security Hub), Terraform, Trivy, Checkov You walk out with: Portfolio Project 1 — a secure cloud deployment, fully as code
Was: the DevOps engineer. Now: yours. The DevSecOps pipeline, end to end — the thing every job advert asks for and almost no course actually builds. Harden the image, scan it, generate its software bill of materials, sign it. Wire in static analysis, dependency scanning, dynamic testing and secrets scanning, with gates that kill the build the moment something critical lands, and a pipeline locked down so it can't be turned against you. Hands on: Docker, Trivy, Syft, cosign, Semgrep, Dependabot, OWASP ZAP, GitHub Actions You walk out with: Portfolio Project 2 — a secured pipeline you can put in front of a hiring manager
Was: the pen tester and the AppSec engineer. Now: yours. Break the bank. Then design it so you can't. Injection, broken access control, cross-site scripting, server-side request forgery — find each in FinTrust, exploit it, fix it, prove the fix with a test. Then run the workshop real security teams run: threat-model the bank, including the AI assistant it's about to launch, and turn it into a backlog engineers will actually work. Hands on: OWASP Top 10 2025, OWASP API Top 10, OWASP ZAP, Burp Suite, STRIDE, MITRE ATT&CK You walk out with: Portfolio Project 3 — a threat model with a prioritised security backlog
Was: the person who "does the AI stuff". Now: yours — and nobody else teaches it like this. Poison the model. Hijack the assistant. Then defend both. Inside FinTrust's AI: the fraud model, the data it learns from, the warehouse it lives in and the customer assistant running on an LLM. Poison the training data and watch fraud sail through. Prompt-inject the assistant into leaking accounts and moving money. Then build the defences and test them with the same automated red-team tooling the industry now uses. Hands on: Python and Colab, Hugging Face, Snowflake, the Anthropic and OpenAI APIs, a vector store, promptfoo and garak, OWASP LLM Top 10 2026, MITRE ATLAS You walk out with: a red-team findings log on a real LLM application — and the AI Security Engineer endorsement on your credential
Was: the SOC analyst and the compliance manager. Now: the parts of those jobs that survive automation — yours. Secure the agents. Catch the attacker in the logs. Prove it to the regulator. FinTrust has an AI agent reconciling payments with real tools and real permissions: give it too much power, exploit it, then lock it down with scoped tools, allow-lists, a human in the loop and a full audit trail — using n8n and Claude Code with MCP as live targets. Turn CloudTrail and GuardDuty into alerts, run an incident, and build the evidence pack NIST AI RMF, ISO 42001 and the EU AI Act actually require. Then a scored Red vs Blue on the bank you've spent six weeks defending. Hands on: n8n, Claude Code and MCP, guardrail frameworks, OWASP Agentic Top 10, CloudTrail and GuardDuty, NIST SP 800-61 You walk out with: Portfolio Project 4 — an AI security assessment with an assurance evidence pack
The CDAISP exam. Forty-eight hours on your own seeded copy of FinTrust with problems nobody has seen. Six tasks: threat-model the new feature, fix the infrastructure, find and fix the vulnerabilities, gate the pipeline, red-team the assistant, write the detection and the evidence. A pull request, a findings report written to a commercial template, and a fifteen-minute viva to defend it. Pass, and you're a Certified DevSecOps & AI Security Practitioner — public verification page, LinkedIn badge, and a report you can show anyone.
Before it all: one live setup evening the weekend before Week 1, so everyone starts Monday with the bank running on their own laptop. No pre-work. No homework before you've met a person.
MORE THAN SIX WEEKS OF LESSONS
Twelve live sessions, a setup evening, matched breakout rooms and every recording.
Four portfolio projects, feedback against published rubrics, and your own training environment.
The CDAISP exam and viva, one free retake, and six months of mentorship clinics.
CDAISP — Certified DevSecOps & AI Security Practitioner. One hands-on exam. Two badges: CDAISP, and the AI Security Engineer endorsement earned in Weeks 5–6. Published blueprint, pass marks and retake policy. Mapped to OWASP Top 10 2025, OWASP LLM Top 10 2026, NIST SSDF and NIST AI RMF. Valid three years, kept live with CPD. Verified at a public URL.
First exam window: 16–27 November 2026.
You don't watch this bootcamp. You work at a bank.
Day one, you join FinTrust Bank as its newest security engineer and inherit a real, broken system: a web app you can inject, a cloud account with the keys left out, a pipeline that ships anything, and an AI assistant that will move money if you ask it nicely. Twelve live nights later you've secured all of it, attacked all of it, and written the evidence a regulator would ask for. Then you sit the exam and walk out CDAISP-certified.
Every session: thirty minutes from an active CISO, forty-five minutes in a breakout room with your hands on the stack, thirty minutes pulling apart what you built. You break things before you defend them. You leave with proof, not a PDF.
Eighty-eight per cent of organisations now run generative AI. Documented AI incidents rose 55% last year. The first AI-orchestrated espionage campaign ran 80–90% of the attack through an AI agent. And only 22% of organisations test their AI adversarially — in the UK, just 24% of businesses adopting AI have any security process for it at all. The world has never needed AI security engineers more. It has almost none: 41% of the profession call AI the critical skill, 59% report critical skills gaps, and the "AI Security Engineer" adverts ask for years of experience nobody entering has. That's the gap this bootcamp exists to close — and the reason five security jobs are collapsing into one.
Sources: Stanford HAI 2026 AI Index (Apr 2026); Anthropic (Nov 2025); IBM Cost of a Data Breach 2025; UK Cyber Security Breaches Survey 2025/26 (Apr 2026); ISC2 Workforce Study 2025 (Dec 2025).
Live, and mostly you. Most bootcamps hand you a Discord server and forty hours of video you'll never finish. Here, most of every session is you doing the work, in a room of five, with a task card and a clock. The room you land in is matched to a five-minute check at the start and resets every session — nobody's bored, nobody's left behind.
Break it before you defend it. Every module starts with you as the attacker. That's how real security engineers learn, and it's why our graduates can talk about it in interviews.
Backed by a real AI security company. The FinTrust training bank, the labs and the tooling come from DevSecAI, an active security consultancy. You practise on Arko, the platform its engineers work with. The strongest graduates go into DevSecAI's hiring pool. This isn't a course written about the industry. It's built inside it.
Proof, not a PDF. Four portfolio projects marked against published rubrics. A practical exam on your own bank. A credential with a public verification page. Work a hiring manager can click on.
Career-changers. No technical background needed. The setup evening and the beginner room in Weeks 1–2 take you from zero, live, with a person in the room.
Developers and builders. You ship code, and more of it is written by AI every week. Learn to review what your AI writes, secure what you deploy, and defend the LLM features you're bolting on.
Security professionals — SOC, GRC, pen-testing, IT security. Your job is merging into this one. Skip the basics, take the Stretch tasks, earn CPD, and add the two skills every security advert now asks for.
Twelve live sessions with an active CISO opening and closing every one · a live breakout room every session, matched to your level · the setup evening · a monthly in-person Lab Day in Canary Wharf · four portfolio projects marked to published rubrics · the CDAISP exam and viva, with one free retake · six months of mentorship in small, booked clinics · every recording and session pack · the student portal · your private cohort Slack · a route into DevSecAI's hiring pool for the strongest graduates.
A FEW THINGS YOU MIGHT BE WONDERING
Yes. The live setup evening and beginner rooms in Weeks 1–2 support people without a technical background. The exam standard is the same for both routes.
Choose the experienced route. Build on your existing skills with stretch tasks and the shared work in cloud, pipelines and AI security.
Twelve live sessions, the setup evening, recordings and session packs, four marked portfolio projects, the CDAISP exam and viva, one free retake, and six months of mentorship clinics.
No. CDAISP requires passing the practical assessment. The exam has a 48-hour window and includes a pull request, findings report and 15-minute viva.
Monday 21 September 2026. Enrolment closes Sunday 20 September at 23:59 UK time. The first exam window is 16–27 November 2026.
Monday and Wednesday, 19:30–21:30 UK time, over six weeks. Begin with a live setup evening before Week 1.
Recordings and session packs are included, so you can revisit the teaching. The live sessions give you the chance to ask questions and practise with your group.
Allow four hours for the live sessions each week, plus time to practise and complete your projects. Your own study time will depend on your starting point and pace.
Use Student login in the navigation to reach the existing Cyber Agoge portal. If you need help with access or joining instructions, email charlie@cyberagoge.com.
Payment options are shown by Squarespace and Stan at checkout. Review the available plans and provider terms before purchasing.
THE SEPTEMBER COHORT
Six weeks live. Four portfolio projects. One practical exam.
Starts Monday 21 September 2026 · 12 seats
Pay in full or see the available payment options at checkout.
Secure my seat ↗Questions before you enrol? Get in touch →