DXHEROES Logo
What We Do

/

AI Security & Governance — Secure MCP Development, Prompt Injection & OWASP for LLM

You have Cowork deployed and now you're staring at the question: who's going to approve this, how will we audit it, what if someone exploits it? WS3 gives you answers grounded in concrete demonstrations.

Who It's For

Companies that already have Cowork (or Copilot) connected to a system and now face the governance and security question. Ideal group of 8–14 people:

  • Security architects — approve MCP connectors.
  • CIO / CTO — the governance document will need management backing.
  • Compliance / governance owner (banking, telco, public sector).
  • Developers who'll write custom MCPs — for the afternoon Track 2.
  • Internal auditor or DPO, if GDPR is in play.

What You Walk Away With

  • Concrete prompt injection demos in multiple forms — you'll set them up and try them yourself.
  • An audit process design for your organization — who approves, what's logged, how you handle an incident.
  • Your own secure MCP server (Track 2) — a working prototype with authentication, scope restriction, logging.
  • A governance document template — 1–3 pages, the kind people will actually read.
  • A risk map mapped to OWASP Top 10 for LLM and MCP specifics (tool poisoning, scope creep).

What Happens

Morning (everyone together):

  • Motivational security risk demos. Prompt injection via email, image, PDF, GitHub issue.
  • OWASP Top 10 for LLM + MCP-specific risks.
  • Hands-on: attack an MCP server, see from inside what you need to watch.
  • Exercise: design an audit process for your company.

Afternoon (two parallel tracks):

  • Track 1 (governance): agentic infrastructure architecture, drafting the governance document, incident process.
  • Track 2 (development): MCP anatomy, hands-on writing your own secure MCP server with authentication, scope restriction, logging, rate limiting.

Closing: Track 1 presents governance, Track 2 presents MCP server, discussion of how it works together.

Details

  • Format: on-demand, delivered for one company at a time. Public dates announced ad hoc.
  • Location: Applifting Meetup Space, Prague — Karlín. Private on-site runs possible.
  • Price: from 90,000 CZK ex-VAT for the whole group.
  • Trainers: Jakub Vacek (security lead), Matyáš Křeček (MCP architecture), Karel Smutný (governance).

How It Fits

WS3 follows WS2 (Cowork & Internal Infrastructure). Without hands-on Cowork / MCP experience, WS3 is too abstract. After WS3, companies often move on to systematic deployment — MCP Gateway Enterprise.

Want this training for your team?

Every training is tailor-made. Tell us about your team and we'll come back with a proposal.

Want to stay one step ahead?

Don't miss our best insights. No spam, just practical analyses, invitations to exclusive events, and podcast summaries delivered straight to your inbox.