Programme Content
2 weeks 6 hrs Self-paced + live
Python for security automation | ML workflow integration | Wireshark Nmap Burp Suite Kali Linux Cloud setup (AWS / Azure / GCP) | MITRE ATT&CK introduction
2. Cybersecurity Foundations, Threat Modelling, and Threat Landscape3 weeks 9 hrs
STRIDE threat modelling | MITRE ATT&CK deep-dive | Penetration testing CVSS 4.0 | OWASP Top 10 API security | Identity attacks: OAuth, JWT, SAML | India threat landscape: APTs, UPI fraud | Vulnerability management
In this module you will
Produce a STRIDE threat model for a BFSI or enterprise SaaS application with assets, trust boundaries, and abuse cases
Conduct a scoped penetration test with CVSS 4.0 scoring and ATT&CK technique mapping
Deliver a prioritised top-5 remediation roadmap with implementation effort estimates
5 weeks 15 hrs
ML for threat detection: malware, phishing, fraud | Security-grade model evaluation | Sigma rule authoring + ATT&CK mapping | SIEM with Elastic Stack | Detection-as-code SOAR playbooks | MLOps: experiment tracking, model registry
In this module you will
Build a production-ready security classifier (malware or fraud) with documented threshold trade-offs and model card
Write 5 validated Sigma detection rules with ATT&CK technique mapping, unit tests, and tuning evidence
Build a SIEM dashboard in Elastic Stack with log ingestion, correlation, and severity scoring
5 weeks 15 hrs
Adversarial ML: evasion, poisoning, extraction | OWASP LLM Top 10 (2025) | LLM red teaming: PyRIT Garak PromptBench | Secure RAG pipelines | Multimodal jailbreaks | MCP prompt injection | Memory poisoning | Tool-calling exploitation | Model hub supply chain attacks
In this module you will
Execute an end-to-end LLM red team engagement with PyRIT, Garak, and PromptBench producing quantified metrics
Reproduce at least 2 of the 5 frontier agentic AI attack surfaces in a controlled lab environment
Build a repeatable evaluation harness measuring before/after robustness delta
4 weeks 12 hrs
DevSecOps + MLSecOps pipelines | ModelScan Sigstore AI-BOM | Policy-as-code (OPA) Runtime detection (Falco) | DPDP Rules 2025 artifacts | SEBI CSCRF 2024 audit format | RBI Master Directions 2024
In this module you will
Implement a DevSecOps + MLSecOps pipeline with OPA policy-as-code, Falco runtime detection, Sigstore signing, and AI-BOM generation
Produce auditor-ready DPDP Rules 2025 artifacts: breach notification workflow, Consent Manager integration, Data Fiduciary checklist
Map security controls to SEBI CSCRF 2024 structured audit format with RE classification tier assignment
4 weeks 12 hrs
NIST AI RMF ISO/IEC 42001 | EU AI Act phased enforcement | FAIR risk quantification + Monte Carlo | Board-level executive communication | AI ethics: bias, dual-use, explainability | Post-quantum readiness: NIST PQC standards
In this module you will
Apply NIST AI RMF and ISO/IEC 42001 to produce governance workflow artifacts and map EU AI Act risk tiers
Quantify cyber risk using FAIR methodology with Monte Carlo simulation and present as a board-level executive narrative
Produce an EU AI Act risk classification memo with GPAI obligation checklist for an India-facing MNC
3 weeks 9 hrs
Production-grade AI security solution | IIT Delhi faculty evaluation panel | IEEE-format technical report (8-12 pages) | Campus Immersion at IIT Delhi campus
The capstone projects are indicative and may be modified to suit the requirements of the programme and the batch at the discretion of the Programme Coordinator.

