Training
Security knowledge that sticks — hands-on with your team's real stack instead of slide battles with sample projects.
Topics
DevSecOps & CI/CD
DevSecOps fundamentals for development teams and secure CI/CD pipelines — from the first commit to deployment.
Supply chain & containers
Supply chain security with dependencies, signatures and provenance, plus container and Kubernetes security.
AI in everyday development
The safe use of AI tools in everyday development — from coding agents to MCP.
How a workshop works
Content is tailored to your team and skill level in advance. From half a day to several days, remote or on site.
We work on your infrastructure and your pipelines — hands-on instead of slide battles with sample projects.
What we build in the workshop, you can keep using the next day. The knowledge stays with your team.
Got a topic and a date in mind?
We sort out the rest directly.
Send me a short note on what your team wants to learn and when it suits — I will get back to you personally with a concrete proposal.
Formats
Every workshop runs on your team's real stack, not on a sample project. That is why the exact scope is settled after a short intro call.
Compact — half a day
One topic, one team, tight focus. Works as an entry point or as a refresher after an incident.
Intensive — one day
One topic in depth: understand the attack surface, secure it concretely, apply it directly in your pipeline.
Multi-day — two to three days
Several topics combined, including reworking your pipeline during the workshop itself.
Pricing and available dates on request. After the intro call you get a concrete quote — not a package price that does not fit your stack.
Who it is for
- Development teams running TYPO3, Symfony or PHP in production
- Platform and DevOps teams working with Kubernetes, AWS or their own CI/CD
- Teams bringing AI tooling into everyday development
The prerequisite is hands-on experience with your own stack. A security background is not required — that is rather the point.
What the topics cover
The modules below are the frame. Which ones we take, and how deep we go, is agreed beforehand.
DevSecOps & CI/CD
- A threat model for your pipeline: where code, secrets and artifacts actually flow
- Secrets handling and least privilege for runners and deploy tokens
- Wiring in SAST and DAST without drowning the team in findings
- Signed artifacts and traceable delivery
Supply chain & containers
- Assessing dependencies: what a CVE actually means for your operation
- Lockfiles and update strategy — patching without constant firefighting
- Hardening containers: base images, rootless, capabilities
- Kubernetes security basics: networking, RBAC, secrets
AI tooling in everyday development
- Where agents carry their weight — and where they get expensive
- Prompt injection and tool access: the new attack surface inside the editor
- Configuration and approvals: what an agent may do in your repository
- Review practice for AI-generated code
Where this comes from: I analyse incidents like these publicly and continuously on the blog, and I run the building blocks we discuss myself — see Open Source.