AI Security & Governance — Secure MCP Development, Prompt Injection, and OWASP for LLMs

You have Cowork deployed and now you're staring at the question: who's going to approve this, how will we audit it, what if someone exploits it? WS3 gives you answers grounded in concrete demonstrations.
Who It's For
Companies that already have Cowork (or Copilot) connected to a system and now need to make security and governance decisions. Ideal group of 8–15 people:
- Security architects — approve MCP connectors.
- CIO / CTO — the governance document will need support from leadership.
- Compliance or governance lead (banking, telco, public sector).
- Developers who will write custom MCP servers — for the afternoon Track 2.
- Internal auditor or DPO, if GDPR is in play.
What You Walk Away With
- Concrete prompt injection demos in multiple forms — you'll set them up and try them yourself.
- An audit process design for your organization — who approves, what's logged, how you handle an incident.
- Your own secure MCP server (Track 2) — a working prototype with authentication, scope restriction, logging.
- A governance document template — 1–3 pages, the kind people will actually read.
- A risk map mapped to OWASP Top 10 for LLM and MCP specifics (tool poisoning, scope creep).
What Happens
Morning (everyone together):
- Risk demos that show why this matters. Prompt injection via email, image, PDF, GitHub issue.
- OWASP Top 10 for LLM + MCP-specific risks.
- Practical exercise: attack an MCP server and see from the inside what you need to watch.
- Exercise: design an audit process for your company.
Afternoon (two parallel tracks):
- Track 1 (governance): how to structure agentic infrastructure, draft the governance document, and define the incident process.
- Track 2 (development): MCP anatomy, writing your own secure MCP server with authentication, scope restriction, logging, and rate limiting.
Closing: Track 1 presents governance, Track 2 presents the MCP server, and we discuss how they work together.
Details
- Format: on-demand, delivered for one company at a time. Public dates announced ad hoc.
- Max participants: 15
- Location: Applifting Meetup Space, Prague — Karlín. Private on-site runs possible.
- Price: 16,000 CZK / participant (ex-VAT)
How It Fits
WS3 follows WS2 (Cowork & Internal Infrastructure). Without practical Cowork / MCP experience, WS3 is too abstract. After WS3, companies often move on to a systematic rollout: MCP Gateway Enterprise.
Want this training for your team?
Want to stay one step ahead?
Don't miss our best insights. No spam, just practical analyses, invitations to exclusive events, and podcast summaries delivered straight to your inbox.