Incident-as-a-Service

73% retention vs 12% is a timing problem, not a content problem.

Incident-triggered lessons arrive while attention is highest. Your team learns from real events in near real-time, not from stale annual modules.

73% vs 12% Retention
847 Organisations
18.5h Breach to Training

*6-month retention benchmark: incident-driven training (73%) compared with annual compliance training (12%) in a 2,800-employee study.

Or create a free account — no credit card required.

Latest Incident-Based Courses

Search the active catalogue and launch immediately from the incidents most relevant to your teams.

556 courses available

Available Now

N.S. Power says meters are back online after last year's hack broke communications - CBC Defence Masterclass

Scenario-led awareness training based on a real-world incident timeline.

Available Now

Fake Zoom, Teams Invites Drop Malware Using Compromised Certificates - Hackread

Built for ['Security Analyst: To deepen threat hunting skills and learn to detect sophisticated social engineering and certificate-based attacks within their SIEM and EDR tools.', 'IT Administrator: To understand the infrastructure hardening required to prevent misuse of collaboration tools and implement certificate authority security controls.', 'CISO / Risk Manager: To gain insights for board-level reporting on this threat vector, manage third-party and supply chain risks, and ensure compliance controls are effectively mapped and tested.'].

Available Now

Cancer Center Research Study Hack Affects 1.2M - GovInfoSecurity

Built for ['Healthcare Security Analyst: To understand the unique attack vectors and compliance pressures (like GDPR/HIPAA) in medical research environments and build targeted detection rules.', 'IT Administrator in a Research Organisation: To learn how to harden research IT infrastructure, implement segmentation, and manage third-party vendor risks that could expose sensitive study data.', 'CISO/Compliance Officer: To develop board-level communication strategies for cyber risk in critical sectors and map incident response controls to frameworks like NIST CSF and NIS2 for regulatory reporting.'].

Available Now

Star Citizen developer draws ire over delayed data breach disclosure - Computing

Built for ['Security Analyst: To learn how to detect data exfiltration patterns and understand the escalation path for confirmed breaches, improving their monitoring and initial response capabilities.', 'Data Protection Officer / Compliance Manager: To gain practical insight into the operational requirements of breach notification laws like GDPR and NIS2, enabling them to better audit organisational readiness and guide response procedures.', 'IT Administrator / System Engineer: To understand the infrastructure misconfigurations and access control weaknesses that often lead to data breaches, empowering them to implement stronger preventative controls in their environment.'].

Available Now

New LexisNexis Data Breach Confirmed After Hackers Leak Files - SecurityWeek

Built for ['Security Analyst: Will benefit by learning specific Indicators of Compromise (IoCs) and SIEM detection rules to identify data exfiltration attempts early.', 'IT Administrator / System Engineer: Will gain practical knowledge on hardening authentication systems and implementing network segmentation to limit lateral movement and data access.', "Compliance Officer / Data Protection Officer: Will learn how to map the incident's lessons to key requirements of GDPR, NIS2, and SOC 2, strengthening audit readiness and vendor risk assessments."].

Available Now

149 Hacktivist DDoS Attacks Hit 110 Organizations in 16 Countries After Middle East Conflict

Built for ['SOC Analyst: To learn specific detection rules and response procedures for high-volume DDoS attacks and hacktivist campaign indicators.', 'Network Security Engineer: To implement infrastructure hardening, DDoS mitigation techniques, and network segmentation strategies covered in the course.', 'CISO/Risk Manager: To understand the threat landscape, communicate risk to leadership, and map organisational controls to compliance frameworks like NIS2 and DORA.'].

Available Now

LexisNexis confirms data breach, says hackers hit customer and business info | TechRadar

Built for ['Security Analyst: Will benefit by learning to craft specific detection rules for data exfiltration and understanding the full attack chain to improve monitoring and threat hunting capabilities.', 'IT Administrator / System Engineer: Will gain practical knowledge on implementing infrastructure hardening controls, such as network segmentation and access management, to prevent lateral movement and data theft.', 'Compliance & Risk Manager: Will learn to map the technical details of this breach to control requirements in frameworks like GDPR and NIST CSF, enabling more effective risk assessments and audit preparations.'].

Available Now

LastPass warns of spoofed alerts aimed at stealing master passwords - Security Affairs

Built for ['Security Analyst / SOC Analyst: They will benefit by learning to craft precise detection rules for credential-phishing campaigns and enhancing their incident triage and response capabilities.', 'IT Administrator / System Administrator: They will gain crucial knowledge to harden authentication systems, implement technical controls like email filtering, and contribute to organisational security awareness.', 'Information Security Manager / CISO: They will learn to communicate the business risk of such incidents to leadership, develop comprehensive defence programmes, and map controls to frameworks like NIST CSF and ISO 27001 for compliance reporting.'].

Available Now

Multi-Stage "BadPaw" Malware Campaign Targets Ukraine

Built for ['Security Analyst: Will benefit by learning to craft specific detection rules for multi-stage malware and analysing its behaviour within a SIEM, enhancing their threat hunting capabilities.', 'Incident Responder: Will gain a structured playbook and forensic techniques tailored to contain and eradicate sophisticated malware infections, improving response times and effectiveness.', 'IT Security Manager/CISO: Will learn to communicate the business risk of such campaigns to leadership and map defensive controls to key compliance frameworks like NIS2 and DORA, strengthening organisational governance.'].

Available Now

China's Silver Dragon Razes Governments in EU, SE Asia - Dark Reading

Built for ['Security Analyst / SOC Analyst: To learn specific detection rules for advanced persistent threats (APTs) and understand the full attack chain for better alert triage and investigation.', 'IT Administrator / System Engineer: To implement the infrastructure hardening and access control lessons directly into system and network configuration, reducing the attack surface.', 'CISO / Security Manager: To gain a strategic view of the threat landscape, develop effective incident response playbooks, and align security controls with compliance requirements for board-level reporting.'].

Available Now

Madison Square Garden Data Breach Confirmed Months After Hacker Attack - OODAloop

Built for ['Security Analyst: To develop advanced detection rules for stealthy data exfiltration and learn forensic techniques for post-breach analysis.', 'Incident Response Manager: To build and refine playbooks for data breach containment, evidence preservation, and stakeholder communication, informed by a real-world case study.', 'IT & Compliance Officer: To understand how technical controls map to regulatory requirements (like GDPR and NIS2) for data protection and breach notification, ensuring organisational readiness.'].

Available Now

Hack on French medical site sees over 15 million records leaked, including private health info

Built for ['Security Analyst: Will benefit by learning to craft specific SIEM detection rules and forensic techniques tailored to identifying data exfiltration patterns associated with healthcare breaches.', 'IT Administrator / System Engineer: Will gain critical knowledge on hardening web applications and databases, implementing least-privilege access models, and segmenting networks to protect sensitive health information repositories.', 'Data Protection Officer / Compliance Manager: Will learn to map incident causes to specific GDPR, NIS2, and SOC 2 control failures, enabling more effective risk assessments and board-level reporting on security posture.'].

Available Now

Interplay between Iranian Targeting of IP Cameras and Physical Warfare in the Middle East

Built for ['Security Operations Centre (SOC) Analysts: They will benefit by learning to craft specific detection rules for phishing campaigns targeting IoT devices and understanding the escalation path to physical threats.', 'IT and OT Network Administrators: They will gain crucial insights into segmenting and hardening networks that contain both traditional IT and internet-connected physical devices like IP cameras.', 'Chief Information Security Officers (CISOs) and Risk Managers: They will learn how to communicate the business impact of such blended threats to leadership and map defences to compliance requirements like NIS2 and DORA.'].

Available Now

Data breach at University of Hawaiʻi Cancer Center impacts 1.2 Million individuals

Built for ['Healthcare IT Security Analyst: To understand the specific regulatory (e.g., HIPAA parallels) and technical challenges of protecting patient data in academic research centres.', 'Compliance Officer: To learn how to map incident findings to control requirements in frameworks like GDPR and NIST CSF for audit and reporting purposes.', 'System Administrator in Higher Education: To implement the infrastructure hardening and access control lessons directly relevant to university network environments with diverse user populations.'].

Available Now

Dark Reading Confidential: This Threat Hunter Helped Cops Bust Up An African Cybercrime Syndicate

Built for ['Threat Hunter / Security Analyst: Will gain advanced techniques for tracking persistent adversaries, analysing malware campaigns, and developing high-fidelity detection rules based on real-world indicators of compromise.', 'SOC Manager / Incident Responder: Will learn to build and refine incident response playbooks specifically for organised crime syndicates, improve triage processes, and enhance collaboration with external entities like law enforcement.', 'IT Security Manager / CISO: Will benefit from understanding the organisational and technical controls needed to mitigate such threats, and learn how to effectively communicate risk and compliance alignment to leadership and boards.'].

Available Now

LexisNexis Investigates Breach, Customer Data Access - CRN

Built for ['Security Analyst: Will benefit by learning to identify specific indicators of compromise (IoCs) and craft detection rules for data exfiltration attempts.', 'IT Administrator: Will gain crucial knowledge on hardening authentication systems and implementing network segmentation to contain breaches.', 'Compliance Officer: Will learn to map incident response controls to frameworks like GDPR and NIS2 to demonstrate regulatory adherence post-incident.'].

Available Now

'You can't separate the physical from the cyber,' says New York's first security and ... - StateScoop

Built for ['Security professionals learning from real-world breaches', 'IT teams responsible for implementing security controls', 'Compliance officers requiring incident-driven training'].

Available Now

Iranian Use of Cybercriminal Tactics in Destructive Cyber Attacks: 2026 Updates - Halcyon

Built for ['Security professionals learning from real-world breaches', 'IT teams responsible for implementing security controls', 'Compliance officers requiring incident-driven training'].

Available Now

Hacktivists may have just cracked open ICE and exposed over 6,000 companies working ...

Built for ['Security Analyst: Will benefit by learning to craft specific detection rules for data exfiltration and understand the indicators of a hacktivist-led breach.', 'IT Administrator: Will gain crucial knowledge on hardening authentication systems and implementing network segmentation to protect sensitive data stores.', 'Compliance Officer: Will learn to map the technical controls discussed to specific requirements in GDPR, NIS2, and SOC 2, strengthening audit readiness.'].

Available Now

Ransomware is now less about malware and more about impersonation

Built for ['Security Analyst: To enhance their ability to detect subtle identity-based attacks within SIEM logs and user behaviour analytics, moving beyond signature-based malware detection.', 'Identity & Access Management (IAM) Specialist: To understand how compromised credentials are weaponised in modern ransomware campaigns and to design more resilient authentication and authorisation controls.', 'IT Administrator: To implement infrastructure hardening measures, such as network segmentation and privileged access management, that mitigate the lateral movement phase of impersonation-based breaches.'].

Available Now

Pathstone Family Office Cyberattack Threatens 641K Sensitive Files - Class Action Lawsuits

Built for ['Security Analyst: Will benefit by learning to craft specific SIEM detection rules and analyse IoCs from a real-world data breach to improve monitoring capabilities.', 'IT Administrator: Will gain practical knowledge on hardening authentication systems, implementing network segmentation, and applying access controls to prevent unauthorised data access.', 'Data Protection Officer / Compliance Manager: Will learn to map incident response activities to GDPR, NIS2, and other regulatory requirements, strengthening organisational compliance posture.'].

Available Now

LexisNexis confirms data breach as hackers leak stolen files - Bleeping Computer

Built for ['Security Analyst: To develop advanced detection rules for data exfiltration and understand the forensic artefacts left behind in such breaches.', 'IT Administrator: To learn infrastructure hardening techniques, particularly around access controls and network segmentation, to prevent unauthorised data access.', 'Compliance Officer: To map the technical details of this incident to specific articles and controls within GDPR, NIS2, and other relevant frameworks for accurate reporting and gap analysis.'].

Available Now

Hack of Cameras, AI Use: Wide Cyberattack on Iran Preceded Khamenei Assassination

Built for ['Security professionals learning from real-world breaches', 'IT teams responsible for implementing security controls', 'Compliance officers requiring incident-driven training'].

Available Now

Fake Tech Support Spam Deploys Customized Havoc C2 Across Organizations

Built for ['Security Analyst: Will benefit from learning specific IOCs and SIEM detection strategies to identify Havoc C2 activity and similar ransomware delivery mechanisms.', 'Incident Responder: Will gain practical skills for containing and eradicating this threat through detailed playbooks and forensic analysis techniques derived from the real case study.', 'IT Security Manager/CISO: Will learn to communicate risk effectively to leadership, map controls to major compliance frameworks, and implement organisational hardening measures to prevent similar breaches.'].

Available Now

Pro-Russia actors team with Iran-linked hackers in attacks

Built for ['Security Analyst: To deepen their understanding of APT campaign analysis and develop actionable SIEM detection rules for early identification of similar collaborative attacks.', 'Incident Response Manager: To build and refine incident response playbooks specifically tailored to multi-actor threat campaigns and improve coordination procedures.', "IT Administrator / System Engineer: To learn and implement the infrastructure hardening and access control measures taught in the course to directly improve their organisation's defensive posture."].

Available Now

Oracle EBS 2025 campaign impacts Madison Square Garden, sensitive data leaked

Built for ['Security Analyst: To learn specific SIEM detection rules and forensic techniques for identifying ERP-focused data exfiltration.', 'IT Administrator (ERP/Systems): To understand how to harden Oracle EBS and similar application environments against the misconfigurations and vulnerabilities exploited in this campaign.', 'CISO/Risk Manager: To gain insights into board-level communication regarding such breaches and how to map incident response to compliance requirements like GDPR and NIS2.'].

Available Now

UMMC reopens clinics shut down by ransomware attack as recovery progresses

Built for ['Security Analyst: To deepen technical analysis skills for detecting ransomware activity and utilising IoCs within their security monitoring tools.', 'IT Administrator / System Engineer: To understand infrastructure hardening techniques, such as network segmentation and access control, critical for preventing lateral movement post-breach.', 'CISO / IT Security Manager: To gain insights for board-level communication, building effective security awareness programmes, and aligning incident response with major compliance frameworks like NIS2 and GDPR.'].

Available Now

1.2 Million Affected by University of Hawaii Cancer Center Data Breach - SecurityWeek

Built for ['Security Analyst: Will benefit by learning to craft specific detection rules for unauthorised data exfiltration and understanding the forensic artefacts left behind in breach investigations.', 'IT Administrator / System Engineer: Will gain crucial insights into hardening file servers, implementing least-privilege access models, and configuring audit logging to prevent and detect similar incidents.', 'Data Protection Officer / Compliance Manager: Will learn to map incident root causes to specific GDPR, NIST CSF, and other regulatory requirements, strengthening organisational compliance posture and reporting.'].

Available Now

Pro-Iranian Actors Launch Barrage of Cyberattacks - Dark Reading

Built for ['Security Analyst: To deepen their understanding of advanced persistent threat (APT) behaviours and improve their ability to craft detection rules and analyse breaches.', 'IT Administrator: To learn infrastructure hardening techniques, such as network segmentation and access control, that directly mitigate the attack vectors used in this incident.', 'Compliance Officer: To understand how real-world attacks map to regulatory requirements like NIS2 and GDPR, enabling more effective risk management and audit preparation.'].

Available Now

OAuth phishers make ‘check where the link points’ advice ineffective

Built for ['Security Analyst: To gain practical skills in detecting OAuth-based phishing and ransomware IOCs, and to build effective SIEM detection rules.', 'IT Administrator / Identity Manager: To learn how to harden authentication systems, implement conditional access policies, and defend against consent phishing attacks targeting their environment.', 'CISO / Risk & Compliance Manager: To understand the strategic business impact, learn how to communicate this threat to the board, and map incident response controls to mandatory compliance frameworks like NIS2 and DORA.'].

Available Now

Starkiller Phishing Suite Uses AitM Reverse Proxy to Bypass Multi-Factor Authentication

Built for ['Security Analyst: To develop advanced detection rules for AitM phishing and understand the forensic artefacts left by such attacks.', 'SOC Manager: To build and refine incident response playbooks specifically for credential harvesting and session hijacking incidents.', 'IT Administrator / Identity Specialist: To implement stronger authentication controls and harden identity infrastructure against sophisticated phishing.'].

Available Now

Europol's Project Compass nets 30 arrests in crackdown on “The Com” - Security Affairs

Built for ['Security Analyst: To deepen threat intelligence analysis skills and learn to create detection rules for malware and access broker activity linked to criminal forums.', 'IT Administrator: To understand the infrastructure hardening and access control measures necessary to prevent credential theft and lateral movement exploited by these groups.', 'CISO / Security Manager: To gain strategic insight for board-level reporting on cybercrime risks and to align incident response and vendor management programmes with relevant compliance frameworks like NIS2 and GDPR.'].

Available Now

All data from Odido hack now online - Techzine Global

Built for ['Security Analyst: Will benefit by learning to craft specific detection rules and response playbooks for data exfiltration attacks, directly applicable to their daily monitoring duties.', 'IT Administrator: Will gain crucial knowledge on infrastructure hardening, access control implementation, and network segmentation to prevent initial compromise and lateral movement.', 'CISO / Risk Manager: Will learn to communicate the business impact of such breaches to leadership and map controls to key compliance frameworks like NIS2 and GDPR for improved governance.'].

Available Now

Weekly Update: UMMC on paper backups after ransomware attack | 2 injuries spur FDA recall

Built for ['Security teams defending against ransomware attacks', 'IT professionals responsible for backup and recovery', 'Incident response teams managing ransomware incidents'].

Available Now

Geo News' transmission hacked; subversive message displayed

Built for ['Security professionals learning from real-world breaches', 'IT teams responsible for implementing security controls', 'Compliance officers requiring incident-driven training'].

Available Now

South Korean Police Lose Seized Crypto By Posting Password Online - DataBreaches.Net

Built for ['Identity and access management teams', 'Security professionals implementing MFA', 'IT administrators managing authentication systems'].

Why Security Teams Choose the 48-Hour Rule

Every section below maps to one operational advantage in Incident-as-a-Service delivery.

Timing as a retention lever

Content arrives while urgency is still high, which dramatically increases recall and response quality.

Breach-to-training pipeline

Detection, analysis, course build, and review are operationalized into one repeatable release loop.

Measured outcomes

Retention, engagement, and deployment speed are tracked so security leaders can report impact, not activity.

Role-targeted relevance

Lessons are tuned to functions and threat exposure, reducing wasted modules and improving behavior change.

The 48-Hour Rule in Motion

From incident alert to deployed learning package in an average of 18.5 hours.

Train from what just happened, not what happened last year.

IntelXview gives security leaders a practical way to respond to new threat patterns with actionable learning while teams still remember why it matters.

The next breach will not wait for your annual cycle.

Launch incident-triggered training workflows now and move your awareness program from static compliance to active defense.