Incident-as-a-Service
73% retention vs 12% is a timing problem, not a content problem.
Incident-triggered lessons arrive while attention is highest. Your team learns from real events in near real-time, not from stale annual modules.
*6-month retention benchmark: incident-driven training (73%) compared with annual compliance training (12%) in a 2,800-employee study.
Or create a free account — no credit card required.
Latest Incident-Based Courses
Search the active catalogue and launch immediately from the incidents most relevant to your teams.
556 courses available
N.S. Power says meters are back online after last year's hack broke communications - CBC Defence Masterclass
Scenario-led awareness training based on a real-world incident timeline.
Fake Zoom, Teams Invites Drop Malware Using Compromised Certificates - Hackread
Built for ['Security Analyst: To deepen threat hunting skills and learn to detect sophisticated social engineering and certificate-based attacks within their SIEM and EDR tools.', 'IT Administrator: To understand the infrastructure hardening required to prevent misuse of collaboration tools and implement certificate authority security controls.', 'CISO / Risk Manager: To gain insights for board-level reporting on this threat vector, manage third-party and supply chain risks, and ensure compliance controls are effectively mapped and tested.'].
Cancer Center Research Study Hack Affects 1.2M - GovInfoSecurity
Built for ['Healthcare Security Analyst: To understand the unique attack vectors and compliance pressures (like GDPR/HIPAA) in medical research environments and build targeted detection rules.', 'IT Administrator in a Research Organisation: To learn how to harden research IT infrastructure, implement segmentation, and manage third-party vendor risks that could expose sensitive study data.', 'CISO/Compliance Officer: To develop board-level communication strategies for cyber risk in critical sectors and map incident response controls to frameworks like NIST CSF and NIS2 for regulatory reporting.'].
Star Citizen developer draws ire over delayed data breach disclosure - Computing
Built for ['Security Analyst: To learn how to detect data exfiltration patterns and understand the escalation path for confirmed breaches, improving their monitoring and initial response capabilities.', 'Data Protection Officer / Compliance Manager: To gain practical insight into the operational requirements of breach notification laws like GDPR and NIS2, enabling them to better audit organisational readiness and guide response procedures.', 'IT Administrator / System Engineer: To understand the infrastructure misconfigurations and access control weaknesses that often lead to data breaches, empowering them to implement stronger preventative controls in their environment.'].
New LexisNexis Data Breach Confirmed After Hackers Leak Files - SecurityWeek
Built for ['Security Analyst: Will benefit by learning specific Indicators of Compromise (IoCs) and SIEM detection rules to identify data exfiltration attempts early.', 'IT Administrator / System Engineer: Will gain practical knowledge on hardening authentication systems and implementing network segmentation to limit lateral movement and data access.', "Compliance Officer / Data Protection Officer: Will learn how to map the incident's lessons to key requirements of GDPR, NIS2, and SOC 2, strengthening audit readiness and vendor risk assessments."].
149 Hacktivist DDoS Attacks Hit 110 Organizations in 16 Countries After Middle East Conflict
Built for ['SOC Analyst: To learn specific detection rules and response procedures for high-volume DDoS attacks and hacktivist campaign indicators.', 'Network Security Engineer: To implement infrastructure hardening, DDoS mitigation techniques, and network segmentation strategies covered in the course.', 'CISO/Risk Manager: To understand the threat landscape, communicate risk to leadership, and map organisational controls to compliance frameworks like NIS2 and DORA.'].
LexisNexis confirms data breach, says hackers hit customer and business info | TechRadar
Built for ['Security Analyst: Will benefit by learning to craft specific detection rules for data exfiltration and understanding the full attack chain to improve monitoring and threat hunting capabilities.', 'IT Administrator / System Engineer: Will gain practical knowledge on implementing infrastructure hardening controls, such as network segmentation and access management, to prevent lateral movement and data theft.', 'Compliance & Risk Manager: Will learn to map the technical details of this breach to control requirements in frameworks like GDPR and NIST CSF, enabling more effective risk assessments and audit preparations.'].
LastPass warns of spoofed alerts aimed at stealing master passwords - Security Affairs
Built for ['Security Analyst / SOC Analyst: They will benefit by learning to craft precise detection rules for credential-phishing campaigns and enhancing their incident triage and response capabilities.', 'IT Administrator / System Administrator: They will gain crucial knowledge to harden authentication systems, implement technical controls like email filtering, and contribute to organisational security awareness.', 'Information Security Manager / CISO: They will learn to communicate the business risk of such incidents to leadership, develop comprehensive defence programmes, and map controls to frameworks like NIST CSF and ISO 27001 for compliance reporting.'].
Multi-Stage "BadPaw" Malware Campaign Targets Ukraine
Built for ['Security Analyst: Will benefit by learning to craft specific detection rules for multi-stage malware and analysing its behaviour within a SIEM, enhancing their threat hunting capabilities.', 'Incident Responder: Will gain a structured playbook and forensic techniques tailored to contain and eradicate sophisticated malware infections, improving response times and effectiveness.', 'IT Security Manager/CISO: Will learn to communicate the business risk of such campaigns to leadership and map defensive controls to key compliance frameworks like NIS2 and DORA, strengthening organisational governance.'].
China's Silver Dragon Razes Governments in EU, SE Asia - Dark Reading
Built for ['Security Analyst / SOC Analyst: To learn specific detection rules for advanced persistent threats (APTs) and understand the full attack chain for better alert triage and investigation.', 'IT Administrator / System Engineer: To implement the infrastructure hardening and access control lessons directly into system and network configuration, reducing the attack surface.', 'CISO / Security Manager: To gain a strategic view of the threat landscape, develop effective incident response playbooks, and align security controls with compliance requirements for board-level reporting.'].
Madison Square Garden Data Breach Confirmed Months After Hacker Attack - OODAloop
Built for ['Security Analyst: To develop advanced detection rules for stealthy data exfiltration and learn forensic techniques for post-breach analysis.', 'Incident Response Manager: To build and refine playbooks for data breach containment, evidence preservation, and stakeholder communication, informed by a real-world case study.', 'IT & Compliance Officer: To understand how technical controls map to regulatory requirements (like GDPR and NIS2) for data protection and breach notification, ensuring organisational readiness.'].
Hack on French medical site sees over 15 million records leaked, including private health info
Built for ['Security Analyst: Will benefit by learning to craft specific SIEM detection rules and forensic techniques tailored to identifying data exfiltration patterns associated with healthcare breaches.', 'IT Administrator / System Engineer: Will gain critical knowledge on hardening web applications and databases, implementing least-privilege access models, and segmenting networks to protect sensitive health information repositories.', 'Data Protection Officer / Compliance Manager: Will learn to map incident causes to specific GDPR, NIS2, and SOC 2 control failures, enabling more effective risk assessments and board-level reporting on security posture.'].
Interplay between Iranian Targeting of IP Cameras and Physical Warfare in the Middle East
Built for ['Security Operations Centre (SOC) Analysts: They will benefit by learning to craft specific detection rules for phishing campaigns targeting IoT devices and understanding the escalation path to physical threats.', 'IT and OT Network Administrators: They will gain crucial insights into segmenting and hardening networks that contain both traditional IT and internet-connected physical devices like IP cameras.', 'Chief Information Security Officers (CISOs) and Risk Managers: They will learn how to communicate the business impact of such blended threats to leadership and map defences to compliance requirements like NIS2 and DORA.'].
Data breach at University of Hawaiʻi Cancer Center impacts 1.2 Million individuals
Built for ['Healthcare IT Security Analyst: To understand the specific regulatory (e.g., HIPAA parallels) and technical challenges of protecting patient data in academic research centres.', 'Compliance Officer: To learn how to map incident findings to control requirements in frameworks like GDPR and NIST CSF for audit and reporting purposes.', 'System Administrator in Higher Education: To implement the infrastructure hardening and access control lessons directly relevant to university network environments with diverse user populations.'].
Dark Reading Confidential: This Threat Hunter Helped Cops Bust Up An African Cybercrime Syndicate
Built for ['Threat Hunter / Security Analyst: Will gain advanced techniques for tracking persistent adversaries, analysing malware campaigns, and developing high-fidelity detection rules based on real-world indicators of compromise.', 'SOC Manager / Incident Responder: Will learn to build and refine incident response playbooks specifically for organised crime syndicates, improve triage processes, and enhance collaboration with external entities like law enforcement.', 'IT Security Manager / CISO: Will benefit from understanding the organisational and technical controls needed to mitigate such threats, and learn how to effectively communicate risk and compliance alignment to leadership and boards.'].
LexisNexis Investigates Breach, Customer Data Access - CRN
Built for ['Security Analyst: Will benefit by learning to identify specific indicators of compromise (IoCs) and craft detection rules for data exfiltration attempts.', 'IT Administrator: Will gain crucial knowledge on hardening authentication systems and implementing network segmentation to contain breaches.', 'Compliance Officer: Will learn to map incident response controls to frameworks like GDPR and NIS2 to demonstrate regulatory adherence post-incident.'].
'You can't separate the physical from the cyber,' says New York's first security and ... - StateScoop
Built for ['Security professionals learning from real-world breaches', 'IT teams responsible for implementing security controls', 'Compliance officers requiring incident-driven training'].
Iranian Use of Cybercriminal Tactics in Destructive Cyber Attacks: 2026 Updates - Halcyon
Built for ['Security professionals learning from real-world breaches', 'IT teams responsible for implementing security controls', 'Compliance officers requiring incident-driven training'].
Hacktivists may have just cracked open ICE and exposed over 6,000 companies working ...
Built for ['Security Analyst: Will benefit by learning to craft specific detection rules for data exfiltration and understand the indicators of a hacktivist-led breach.', 'IT Administrator: Will gain crucial knowledge on hardening authentication systems and implementing network segmentation to protect sensitive data stores.', 'Compliance Officer: Will learn to map the technical controls discussed to specific requirements in GDPR, NIS2, and SOC 2, strengthening audit readiness.'].
Ransomware is now less about malware and more about impersonation
Built for ['Security Analyst: To enhance their ability to detect subtle identity-based attacks within SIEM logs and user behaviour analytics, moving beyond signature-based malware detection.', 'Identity & Access Management (IAM) Specialist: To understand how compromised credentials are weaponised in modern ransomware campaigns and to design more resilient authentication and authorisation controls.', 'IT Administrator: To implement infrastructure hardening measures, such as network segmentation and privileged access management, that mitigate the lateral movement phase of impersonation-based breaches.'].
Pathstone Family Office Cyberattack Threatens 641K Sensitive Files - Class Action Lawsuits
Built for ['Security Analyst: Will benefit by learning to craft specific SIEM detection rules and analyse IoCs from a real-world data breach to improve monitoring capabilities.', 'IT Administrator: Will gain practical knowledge on hardening authentication systems, implementing network segmentation, and applying access controls to prevent unauthorised data access.', 'Data Protection Officer / Compliance Manager: Will learn to map incident response activities to GDPR, NIS2, and other regulatory requirements, strengthening organisational compliance posture.'].
LexisNexis confirms data breach as hackers leak stolen files - Bleeping Computer
Built for ['Security Analyst: To develop advanced detection rules for data exfiltration and understand the forensic artefacts left behind in such breaches.', 'IT Administrator: To learn infrastructure hardening techniques, particularly around access controls and network segmentation, to prevent unauthorised data access.', 'Compliance Officer: To map the technical details of this incident to specific articles and controls within GDPR, NIS2, and other relevant frameworks for accurate reporting and gap analysis.'].
Hack of Cameras, AI Use: Wide Cyberattack on Iran Preceded Khamenei Assassination
Built for ['Security professionals learning from real-world breaches', 'IT teams responsible for implementing security controls', 'Compliance officers requiring incident-driven training'].
Fake Tech Support Spam Deploys Customized Havoc C2 Across Organizations
Built for ['Security Analyst: Will benefit from learning specific IOCs and SIEM detection strategies to identify Havoc C2 activity and similar ransomware delivery mechanisms.', 'Incident Responder: Will gain practical skills for containing and eradicating this threat through detailed playbooks and forensic analysis techniques derived from the real case study.', 'IT Security Manager/CISO: Will learn to communicate risk effectively to leadership, map controls to major compliance frameworks, and implement organisational hardening measures to prevent similar breaches.'].
Pro-Russia actors team with Iran-linked hackers in attacks
Built for ['Security Analyst: To deepen their understanding of APT campaign analysis and develop actionable SIEM detection rules for early identification of similar collaborative attacks.', 'Incident Response Manager: To build and refine incident response playbooks specifically tailored to multi-actor threat campaigns and improve coordination procedures.', "IT Administrator / System Engineer: To learn and implement the infrastructure hardening and access control measures taught in the course to directly improve their organisation's defensive posture."].
Oracle EBS 2025 campaign impacts Madison Square Garden, sensitive data leaked
Built for ['Security Analyst: To learn specific SIEM detection rules and forensic techniques for identifying ERP-focused data exfiltration.', 'IT Administrator (ERP/Systems): To understand how to harden Oracle EBS and similar application environments against the misconfigurations and vulnerabilities exploited in this campaign.', 'CISO/Risk Manager: To gain insights into board-level communication regarding such breaches and how to map incident response to compliance requirements like GDPR and NIS2.'].
UMMC reopens clinics shut down by ransomware attack as recovery progresses
Built for ['Security Analyst: To deepen technical analysis skills for detecting ransomware activity and utilising IoCs within their security monitoring tools.', 'IT Administrator / System Engineer: To understand infrastructure hardening techniques, such as network segmentation and access control, critical for preventing lateral movement post-breach.', 'CISO / IT Security Manager: To gain insights for board-level communication, building effective security awareness programmes, and aligning incident response with major compliance frameworks like NIS2 and GDPR.'].
1.2 Million Affected by University of Hawaii Cancer Center Data Breach - SecurityWeek
Built for ['Security Analyst: Will benefit by learning to craft specific detection rules for unauthorised data exfiltration and understanding the forensic artefacts left behind in breach investigations.', 'IT Administrator / System Engineer: Will gain crucial insights into hardening file servers, implementing least-privilege access models, and configuring audit logging to prevent and detect similar incidents.', 'Data Protection Officer / Compliance Manager: Will learn to map incident root causes to specific GDPR, NIST CSF, and other regulatory requirements, strengthening organisational compliance posture and reporting.'].
Pro-Iranian Actors Launch Barrage of Cyberattacks - Dark Reading
Built for ['Security Analyst: To deepen their understanding of advanced persistent threat (APT) behaviours and improve their ability to craft detection rules and analyse breaches.', 'IT Administrator: To learn infrastructure hardening techniques, such as network segmentation and access control, that directly mitigate the attack vectors used in this incident.', 'Compliance Officer: To understand how real-world attacks map to regulatory requirements like NIS2 and GDPR, enabling more effective risk management and audit preparation.'].
OAuth phishers make ‘check where the link points’ advice ineffective
Built for ['Security Analyst: To gain practical skills in detecting OAuth-based phishing and ransomware IOCs, and to build effective SIEM detection rules.', 'IT Administrator / Identity Manager: To learn how to harden authentication systems, implement conditional access policies, and defend against consent phishing attacks targeting their environment.', 'CISO / Risk & Compliance Manager: To understand the strategic business impact, learn how to communicate this threat to the board, and map incident response controls to mandatory compliance frameworks like NIS2 and DORA.'].
Starkiller Phishing Suite Uses AitM Reverse Proxy to Bypass Multi-Factor Authentication
Built for ['Security Analyst: To develop advanced detection rules for AitM phishing and understand the forensic artefacts left by such attacks.', 'SOC Manager: To build and refine incident response playbooks specifically for credential harvesting and session hijacking incidents.', 'IT Administrator / Identity Specialist: To implement stronger authentication controls and harden identity infrastructure against sophisticated phishing.'].
Europol's Project Compass nets 30 arrests in crackdown on “The Com” - Security Affairs
Built for ['Security Analyst: To deepen threat intelligence analysis skills and learn to create detection rules for malware and access broker activity linked to criminal forums.', 'IT Administrator: To understand the infrastructure hardening and access control measures necessary to prevent credential theft and lateral movement exploited by these groups.', 'CISO / Security Manager: To gain strategic insight for board-level reporting on cybercrime risks and to align incident response and vendor management programmes with relevant compliance frameworks like NIS2 and GDPR.'].
All data from Odido hack now online - Techzine Global
Built for ['Security Analyst: Will benefit by learning to craft specific detection rules and response playbooks for data exfiltration attacks, directly applicable to their daily monitoring duties.', 'IT Administrator: Will gain crucial knowledge on infrastructure hardening, access control implementation, and network segmentation to prevent initial compromise and lateral movement.', 'CISO / Risk Manager: Will learn to communicate the business impact of such breaches to leadership and map controls to key compliance frameworks like NIS2 and GDPR for improved governance.'].
Weekly Update: UMMC on paper backups after ransomware attack | 2 injuries spur FDA recall
Built for ['Security teams defending against ransomware attacks', 'IT professionals responsible for backup and recovery', 'Incident response teams managing ransomware incidents'].
Geo News' transmission hacked; subversive message displayed
Built for ['Security professionals learning from real-world breaches', 'IT teams responsible for implementing security controls', 'Compliance officers requiring incident-driven training'].
South Korean Police Lose Seized Crypto By Posting Password Online - DataBreaches.Net
Built for ['Identity and access management teams', 'Security professionals implementing MFA', 'IT administrators managing authentication systems'].
The 48-Hour Rule in Motion
From incident alert to deployed learning package in an average of 18.5 hours.
Train from what just happened, not what happened last year.
IntelXview gives security leaders a practical way to respond to new threat patterns with actionable learning while teams still remember why it matters.
The next breach will not wait for your annual cycle.
Launch incident-triggered training workflows now and move your awareness program from static compliance to active defense.