Preparing for AI Security Testing Through the OSAI
"OSAI provided me with the ability and the tools to test AI which is paramount to my team doing our job successfully and not having to hire a specialized team."
-
Industry
Technology
-
Size
Individual
-
HQ
N/A
Overview: Challenges
-
AI was becoming part of nearly every assessment, but there was no clear framework for how to test it
-
The team needed practical AI security skills without building a dedicated AI security function
-
Existing AI security guidance often felt fragmented and difficult to apply in real-world testing
Overview: Solutions
-
Participated in the OSAI Early Access Program to build AI security knowledge before it became a larger challenge
-
Used OSAI's structured approach to understand what to test, what matters, and how to assess AI systems with confidence
-
Contributed feedback that helped shape the course while developing internal AI security capabilities
Overview: Benefits
-
Greater confidence when assessing AI-enabled applications and workflows
-
A shared foundation for approaching AI security testing across the team
-
Better prepared to evaluate the growing number of AI systems entering the testing pipeline
The challenges
AI was no longer a future concern for Paul Campbell’s offensive security team at Cisco. Like at most organizations today, it was already showing up in the work.
“Everything that we get through our pipeline has some sort of an AI component to it now.”
His team was seeing AI across nearly every environment they tested, from LLMs to agentic workflows to AI-enabled product features. That changed what they needed to be ready for. They could not position themselves as a traditional infrastructure or application testing team and leave AI out of scope.
“We can’t just say we’re an infrastructure pen testing team or a pen testing team that doesn’t test AI.”
Paul’s team had different levels of experience. Some team members were brand new to penetration testing and offensive security. Others had 10 to 15 years of experience, including one senior team member with a deep background in machine learning. That range made consistency especially important.
The question was not whether one or two people could understand AI security. The question was how to give the broader team enough structure to test AI components with confidence.
Paul wanted his team to know what to assess, what mattered, and where to start. Without that, AI testing could become a checkbox exercise.
“We’ve looked at it. We don’t really know how to look at it. We’ve looked at it though and we’re good to go.”
That was the gap closed by OSAI: giving testers a clearer framework so they could stand behind their work, instead of guessing at the boundaries of an AI assessment.
"For the price, for the content, for the caliber of content, OSAI is one of the best investments you can do for your team."
The solutions
Paul joined the OSAI Early Access Program (EAP) for the AI-300 (OSAI) course because the need was already here. His team was heavily invested in AI work, and the company was heavily invested in AI work. Waiting for the space to settle was not realistic.
The EAP gave the team a way to start building AI security skills while the course was still being shaped. That mattered to Paul’s team. They were not only interested in learning from OffSec; they also wanted to contribute feedback that could improve the course for others.
“Some of my members are really excited to be able to give back and help out OffSec because you’re a respected name in the industry. And if they can help with feedback that makes the programming or course better, they feel like they’re giving back to the industry as well.”
That made Early Access more than early exposure. It gave the team a practical way to build capability and participate in the development of training they believed the industry needed.
The course also gave them something Paul felt was missing from much of the AI security space: a consolidated source of guidance.
“Most of the AI security training material out there is people saying what they think is best practice, what they think is good advice.”
For his team, OSAI created a more usable path through that uncertainty.
“It’s a nice consolidated, curated experience for learning AI security.”
Instead of having each tester decide independently what “good” AI testing should look like, the course gave the team terminology, methodology, tools, and reference points they could use in their work.
Paul’s goal was practical. He wanted team members to be able to look at an AI component and say they followed a framework, understood what they tested, and had a reason to feel confident in their assessment.
“(I want my team to be able to say) I followed this, the guidance I found in this course. From that, I’m able to feel confident that I’ve assessed this component of this product well.”
The hands-on portions gave the team a way to apply the material, and the Early Access format gave them room to provide feedback on where the experience could improve. Paul acknowledged the challenge of standardizing lab answers in a domain where multiple approaches can lead to valid outcomes and saw it as a meaningful area for the course to continue evolving.
The benefits
The clearest result was confidence.
“They’ve definitely got a lot more confidence in what they’re doing.”
That confidence mattered because AI was already entering the team’s normal testing pipeline. OSAI helped them approach AI components with a clearer sense of what to check, what techniques to use, and what “tested” should mean.
Paul saw the course as especially useful because it gave the team a shared foundation. That foundation helped less experienced testers build comfort with AI security while giving more experienced team members a common reference point.
“It’s a good way to give everyone a similar set of foundations to build off of.”
The response from the team reinforced the value of the course. Team members described the content as some of the best they had seen and appreciated how easy it was to digest and work through.
But the strongest signal came from something else.
“When my team was like, ‘Man, I wish I had more time in the training,’ that’s typically a good sign.”
Rather than struggling to complete the material, team members wanted more time with it. For Paul, that level of engagement was a strong indicator that the training was providing real value.
OSAI also helped Paul think about AI security as a team capability rather than a specialist function. He did not want AI testing to sit with a separate group. He wanted his team to be able to absorb AI testing into their existing work.
“Having the ability and the tools to test it is paramount to us doing our job successfully and not having to hire a specialized team to test just AI.”
That is the business value Paul saw in OSAI: it helped his team build AI security readiness at the team level, from a trusted source, before the need became even more urgent.
“AI is in everything. It’s going to be in everything that is built going forward in some manner, some way, shape, or form.”
The Early Access Program was only the beginning. As AI continues to appear in more of the environments his team assesses, Paul expects OSAI to remain part of their development path. Team members are planning to continue their progress through the course and pursue certification as they deepen their AI security testing capabilities.
For Paul, that makes AI security training a practical investment for teams that need to keep pace with what they are already seeing in the field.
“For the price, for the content, for the caliber of content, OSAI is one of the best investments you can do with your team.”
Why OffSec?
Security teams trust OffSec for training that goes beyond theory and focuses on practical application. OSAI brings that same approach to AI security, combining structured learning, hands-on exercises, and real-world methodologies to help learners understand what to test, how to test it, and why it matters.
Rather than piecing together guidance from scattered sources, learners gain access to a trusted framework for evaluating AI-enabled systems, understanding emerging risks, and approaching AI security assessments with greater confidence. Whether you're building foundational AI security knowledge or preparing your team to assess the growing number of AI-powered technologies entering today's environments, OSAI provides a practical path forward.
Explore OSAI and discover how OffSec is helping security professionals build the skills needed to test AI systems with confidence.