From AI Security Foundations to Responsible AI Governance: Taking on EC-Council’s C|RAGE
Our Cyber Security Expert, Phil Chapman's take on this new EC-Council certification
Continuing my journey in the world of AI Security, last week I completed one of EC-Council’s newer AI-focused certifications: C|RAGE – Responsible AI, Governance and Ethics.
This certification is designed for professionals who already have a solid grounding in AI technologies and cybersecurity. Building on that foundation, it dives deeper into the governance, risk, compliance, regulatory, and ethical considerations surrounding AI, with a strong focus on international frameworks, legislation, and industry standards.
What I particularly appreciated was the course’s use of real-world events, incidents, and practical scenarios to demonstrate why effective governance is becoming such a critical component of AI adoption. The examples are relevant across multiple sectors and highlight challenges that many organisations are already beginning to encounter.
I’ll be honest—some of the content covering frameworks, standards, and especially auditing was challenging. However, that was largely because these areas are relatively new to me and sit outside my primary area of cybersecurity expertise. For experienced information security professionals, that challenge is exactly what makes the course valuable. It provides a fantastic opportunity to develop new skills and knowledge that can be applied both strategically and operationally when implementing governance and security controls for AI systems.
One of my favourite areas of the course was the focus on ethical responsibilities in AI. It offered valuable insight into some of the complex issues organisations face when deploying AI technologies and reinforced the importance of balancing innovation with accountability.
Having a strong understanding of areas such as risk management, incident response, business continuity, and disaster recovery proved extremely beneficial throughout the course. Previous certifications, including EC-Council AI Essentials and CompTIA SecAI+, also provided excellent foundational knowledge that made the learning journey easier and more rewarding.
For anyone considering more advanced AI governance and security pathways, this course also complements specialist certifications such as ISACA’s AAISM™ (Advanced in AI Security Management™) and AAIR™ (Advanced in AI Risk™), alongside established credentials such as CISM®, CRISC®, and CISA®.
As for the exam—be prepared. All 100 questions were scenario-based, requiring careful reading and a strong understanding of the concepts covered throughout the course. There were no surprises, but the questions were designed to test your ability to apply knowledge in realistic situations rather than simply recall facts. Challenging? Absolutely. Worthwhile? Definitely.
Overall, I highly recommend taking a look at C|RAGE if you're interested in developing your AI governance, risk, compliance, and ethics expertise. As AI continues to become embedded within organisations, dedicated AI security and governance knowledge will only become more important.
Perhaps it's time to tackle your inner RAGE?!