AI for Cybersecurity is one of six short AI courses I bought from ISC2 in May 2026, and at $96 it is the bundle’s best treatment of the threat model. The first third walks the AI development lifecycle in detail, with analogies to traditional software engineering methodologies – because fundamentally an AI project is still a software engineering project, with the same methodologies applied differently. The second half is the attacks-and-mitigations section, and it is the most useful piece of content across the entire bundle: many attacks I had not seen before, others I had picked up only in pieces from following the field and now had explained properly, with pointers to live external resources that get updated as new attack surfaces emerge. Like the rest of the bundle, it predates the agentic wave and shows it. Even so, this is the one to take if you want a working threat model for AI systems.

What It Covers

The AI development lifecycle is about a third of the course, and unusually thorough. The framing is the right one: AI is still a software engineering project, so traditional methodologies still apply – just differently. What is unusual is the genuine attention paid to the end-of-life phase. End of life is the part of the lifecycle that software engineering chronically underestimates, and AI makes it worse. The vast training datasets must be safeguarded during use, and then disposed of securely when the project ends. The deployed model itself must be continuously monitored and updated to stay relevant as the underlying data shifts. And running underneath the whole section is a flat, honest admission: many of the traditional risk-mitigation techniques in software development do not apply cleanly to AI, and the right way to manage AI risk is, bluntly, not yet known. That is a refreshing thing to hear in a $96 course.

The rest is AI attacks and mitigations, and it is the single most useful piece of any of the six courses. Many of these attacks were new to me. Others I had absorbed in pieces from paying attention to the field, and the course gave a better and more thorough explanation than I had assembled on my own. The references to detailed external resources – the kind that will be updated as new attacks are discovered – are the right design choice for a course that knows it cannot keep up with the field on its own. The examples covered obvious attacks against running systems, such as direct and indirect prompt injection, the less obvious ones such as model inversion, and even attacks relevant to building models like data poisoning.

The visible gap is agentic AI. The attack section does not cover the threats specific to agents – prompt-injection cascades, tool-use abuse, the expanded surface area of a model that can act – in any depth. That is the part of the threat model moving fastest right now, and a course written before the agentic wave will miss it. Take it knowing the agentic class of threats is the sequel this course has not yet been updated to cover.

Verdict

Four stars. The lifecycle section is the most honest in the bundle about what is known and what is not. The attack section is the best single piece of content across all six courses, both for the breadth of what it covers and for the resource pointers that will outlast the course itself. The agentic gap is real but consistent with the rest of the bundle, and it does not undermine the value of what is there. If you take only one of the six on the cybersecurity side, take this one. The $96 buys you the working threat model – something the rest of the bundle approaches sideways at best.


Part of The ISC2 AI Course Bundle . More from the bundle: The Evolving Cybersecurity Workforce · Foundations of AI · Aligning with Global AI Regulations · AI Security: Managing Overconfidence · Planning for Secure by Design AI