Public Sector

We've had the pleasure of working with UK and overseas central and local government departments, including Healthcare (NHS and Foundation Trusts), Defence, Education (Universities and colleges), many of the main Civil Service departments, Emergency Services; also public-owned corporations including the BBC, Bank of England, Ordnance Survey, and regulatory bodies such as Ofgem.

We are registered on Crown Commercial Service’s (CCS) Dynamic Purchasing System (RM6219 Training and Learning) and also with numerous tender portals such as Ariba, Coupa and Delta E-Sourcing.

Read more...

Graduate Training Schemes

Framework Training has a strong track record of providing a solid introduction into the working world for technical graduates across myriad industries. We provide the opportunity to learn and gain valuable hands-on experience in a supportive, friendly and sociable training environment.

Attract & retain the brightest new starters

We know it is vital for our clients to invest in the future of their talented grads; not only to provide them with high-quality, professional training essential for their roles, but to embed them within the organisation’s culture and guide them on the right path to a successful career.

After all, your new hires could well be the next leaders and their creative ideas and unique insights are invaluable to your business.

Read more ...

Learning & Development

Our unique portfolio of high-quality technical courses and training programmes are industry-respected. They’re carefully designed so that delegates can seamlessly apply what they’ve learnt back in the workplace. Our team of domain experts, trainers, and support teams know our field — and all things tech — inside out, and we work hard to keep ourselves up to speed with the latest innovations. 

We’re proud to develop and deliver innovative learning solutions that actually work and make a tangible difference to your people and your business, driving through positive lasting change. Our training courses and programmes are human-centred. Everything we do is underpinned by our commitment to continuous improvement and learning and generally making things much better.

Read more...

Corporate & Volume Pricing

Whether you are looking to book multiple places on public scheduled courses (attended remotely or in our training centres in London) or planning private courses for a team within your organisation, we will be happy to discuss preferential pricing which maximise your staff education budget.

Enquire today about:

  • Training programme pricing models  

  • Multi-course voucher schemes

Read more...

Custom Learning Paths

We understand that your team training needs don't always fit into a "one size fits all" mould, and we're very happy to explore ways in which we can tailor a bespoke learning path to fit your learning needs.

Find out about how we can customise everything from short overviews, intensive workshops, and wider training programmes that give you coverage of the most relevant topics based on what your staff need to excel in their roles.

Read more...

Securing LLMs: A Hands-On Guide to the OWASP LLM Top Ten

This one-day, hands-on course provides a practical deep dive into the OWASP LLM Top Ten vulnerabilities. Learn how to identify, exploit, and mitigate the most critical risks in large language model applications, with a focus on the issues most relevant to developers and product teams.

Book now

About the course

AI-powered applications bring new security challenges. In this intensive course, participants will move beyond theory and gain practical experience with the most significant vulnerabilities affecting Large Language Models (LLMs).

Through a series of hands-on labs, you will explore and mitigate the Top Ten vulnerabilities identified by OWASP, focusing on the five that pose the greatest risks in real-world deployments. The remaining five will be covered through guided demonstrations and case studies, ensuring complete coverage without sacrificing lab depth.

You will leave with a practical toolkit for building more secure and resilient LLM-powered systems.

Instructor-led online and in-house face-to-face options are available - as part of a wider customised training programme, or as a standalone workshop, on-site at your offices or at one of many flexible meeting spaces in the UK and around the World.

  • By the end of this course, attendees will be able to:

    • Understand all ten OWASP LLM vulnerabilities
    • Gain practical experience exploiting and mitigating the five most critical risks
    • Learn to assess your own LLM-driven systems for weaknesses
    • Build a security toolkit and mitigation strategies to apply immediately
  • This course is designed for:

    • Developers incorporating LLMs into products

    • Security professionals responsible for testing or securing AI systems

    • Technical project managers overseeing LLM-driven applications

  • Delegates will benefit from this course most if they have

    • A foundational understanding of web development and programming concepts

    • Basic familiarity with API interactions (e.g. using curl or Python requests)

    We can customise the training to match your team's experience and needs though - with more time and coverage of fundamentals for new developers, for instance.

  • This LLM OWASP top ten course is available for private / custom delivery for your team - as an in-house face-to-face workshop at your location of choice, or as online instructor-led training via MS Teams (or your own preferred platform).

    Get in touch to find out how we can deliver tailored training which focuses on your project requirements and learning goals.

  • Input & Output Vulnerabilities (Deep-Dive Labs)

    • LLM01: Prompt Injection: * Mastering Direct (jailbreaking) and Indirect injections.

      • Lab: Bypassing a secure chat application to extract system instructions.

    • LLM02: Insecure Output Handling: * How unvalidated LLM output leads to XSS, CSRF, or SSRF in downstream systems.

      • Lab: Crafting prompts that trigger unintended code execution in the UI.

    Data & Model Integrity (Deep-Dive Labs)

    • LLM03: Training Data Poisoning: * Risks of tampered datasets creating "backdoors" or biased behavior.

      • Lab: Identifying subtle poisoning in a sample sentiment analysis model.

    • LLM04: Model Denial of Service (DoS): * Exploiting resource-heavy operations to degrade service and drive up costs.

      • Lab: Crafting recursive or context-heavy prompts to exhaust model tokens.

    • LLM05: Supply Chain Vulnerabilities: * The risks of 3rd-party models, plugins, and "poisoned" libraries.

      • Lab: Auditing an AI project manifest for insecure dependencies and compromised weights.

    Information & Agency Risks (Guided Analysis)

    • LLM06: Sensitive Information Disclosure: * Preventing the LLM from leaking PII or proprietary data in its responses.

      • Strategy: Implementing robust output filters and "scrubbing" techniques.

    • LLM07: Insecure Plugin Design: * When plugins accept untrusted inputs or lack sufficient access control.

      • Case Study: Analyzing a remote code execution (RCE) via a malicious plugin payload.

    • LLM08: Excessive Agency: * The dangers of giving AI "Agents" too much autonomy or high-privilege permissions.

      • Strategy: Implementing the "human-in-the-loop" pattern and the principle of least privilege.

    User & Model Protection (Strategic Overview)

    • LLM09: Overreliance: * Risks of "hallucinations" and the failure to critically assess LLM outputs.

      • Discussion: Designing UIs that encourage user verification and fact-checking.

    • LLM10: Model Theft: * Protecting proprietary models and weights from unauthorized access or exfiltration.

      • Strategy: Hardening infrastructure and implementing rate-limiting for model-querying APIs.

    Building a Secure AI Lifecycle

    • The AI Red Teaming Process: How to continuously test your LLM implementation.

    • Guardrails & Filters: Introduction to open-source and cloud-native safety tools (e.g., NeMo Guardrails, Azure AI Content Safety).

    • Compliance & Governance: Aligning your AI security with emerging standards and local regulations.

Trusted by

University of Glasgow logo/crest IBM company logo Amadeus Services company logo

Public Courses Dates and Rates

Standard duration: 2 days

June 22nd, 2026 - £1295
September 28th, 2026 - £1295
December 14th, 2026 - £1295

All prices are excluding VAT.

If our published dates don't work for you, please get in touch - we are happy to explore scheduling additional courses.

Book now

Secure or reserve a space on a public scheduled course date.

Course enquiry

Send us a no-obligation enquiry about this course

Choose how you first heard about Framework Training.

Related courses