Incident-as-a-Service
73% retention vs 12% is a timing problem, not a content problem.
Incident-triggered lessons arrive while attention is highest. Your team learns from real events in near real-time, not from stale annual modules.
*6-month retention benchmark: incident-driven training (73%) compared with annual compliance training (12%) in a 2,800-employee study.
Or create a free account — no credit card required.
Latest Incident-Based Courses
Search the active catalogue and launch immediately from the incidents most relevant to your teams.
556 courses available
Hackers Leveraging Multiple AI Services to Compromise 600+ FortiGate Devices
Built for ['Network Security Engineer: Will benefit by learning to harden FortiGate and similar devices against the specific AI-driven exploitation techniques demonstrated in the incident.', 'SOC Analyst: Will gain critical skills in crafting and tuning SIEM detection rules to identify the early indicators of compromise associated with this type of automated, large-scale breach campaign.', 'IT Administrator/Manager: Will learn essential infrastructure hardening and access control measures to prevent initial compromise and understand board-level communication strategies for post-incident reporting.'].
New ClickFix Attack Targets Crypto Wallets and 25+ Browsers with Infostealer - Hackread
Built for ['Security Analyst: Will benefit by learning to craft specific detection rules for infostealer activity and understanding the forensic artefacts left by the ClickFix attack.', 'Incident Responder: Will gain a ready-made playbook and practical skills for containing and eradicating this specific threat, improving response times and effectiveness.', 'IT Administrator: Will learn critical infrastructure hardening techniques, such as application control and patch management policies, to prevent similar breaches in their environment.'].
Critical Infrastructure Under Pressure as AI Threats Grow and Global Enforcement Responds
Built for ['Security Analyst: To deepen their ability to detect and investigate data exfiltration attempts using real-world indicators and SIEM strategies.', "IT Administrator / System Engineer: To learn infrastructure hardening techniques, such as network segmentation and access control, directly informed by the incident's attack vectors.", 'CISO / Security Manager: To develop board-level communication strategies and integrate incident response playbooks with compliance requirements like NIS2 and GDPR.'].
Ukrainian hackers uncover how Russian drone operators are using Belarus
Built for ['Threat Intelligence Analyst: They will benefit by learning how to trace and attribute complex campaigns that cross national borders and leverage third-party infrastructure, enhancing their analytical tradecraft.', 'Security Operations Centre (SOC) Analyst: They will gain practical skills in writing and tuning SIEM detection rules for this specific attack pattern, improving their ability to identify similar covert operations early.', 'Chief Information Security Officer (CISO): They will learn how to communicate the business and geopolitical risks of such attacks to the board, and how to map defensive measures to compliance requirements like NIS2 and DORA.'].
Compromised npm package silently installs OpenClaw on developer machines
Built for ['Application Security Engineer: To understand how to secure CI/CD pipelines and implement software bill of materials (SBOM) to prevent dependency poisoning.', 'Security Operations Centre (SOC) Analyst: To learn specific detection rules for identifying malicious activity originating from trusted development tools and packages.', 'Chief Information Security Officer (CISO): To gain strategic insight into supply chain risk management and communicate effectively with the board on mitigating this emerging threat vector.'].
Loan applications, drivers licences, personal data of 440k Aussies exposed after hacker hits ...
Built for ['Security Analysts: Will benefit by learning to craft specific detection rules and analyse IoCs from a real data breach, enhancing their threat-hunting capabilities.', 'IT Administrators & System Engineers: Will gain critical knowledge on infrastructure hardening, access control implementation, and network segmentation to prevent similar intrusion and data exfiltration.', 'Compliance & Risk Officers: Will learn to map the technical and procedural failures of the incident to key requirements of GDPR, NIST CSF, and ISO 27001, strengthening audit and reporting processes.'].
Deutsche Bahn hit by major DDoS attack disrupting services | SC Media
Built for ['Network Security Engineer: To design and implement effective DDoS mitigation architectures and traffic filtering rules.', 'Security Operations Centre (SOC) Analyst: To improve detection and response procedures for volumetric attacks, reducing mean time to recovery.', 'IT Infrastructure Manager: To understand the business impact of DDoS attacks and justify investments in resilience and redundancy for critical services.'].
UMMC closes clinics amid ransomware attack - TechTarget
Built for ['Security Analyst: Will benefit by learning to identify ransomware IOCs and craft specific SIEM detection rules to catch similar attacks early.', 'IT Administrator/Systems Engineer: Will gain practical skills for hardening authentication systems, implementing network segmentation, and applying zero trust principles to protect critical clinical and administrative systems.', 'CISO/Risk & Compliance Manager: Will learn to communicate cyber risk to leadership, integrate incident response with compliance obligations (like GDPR and NIS2), and build a stronger organisational security culture.'].
Phony Bank Account Change Requests: How to Detect and Stop AP's Silent Killer
Built for ['Security Analyst: To develop advanced detection rules for subtle account takeover and data exfiltration patterns within SIEM/EDR tools.', 'IT Administrator (Finance Systems): To learn hardening techniques for banking portals, vendor management platforms, and authentication systems critical to payment processes.', 'CISO / Security Manager: To build a comprehensive defence strategy, communicate risk to leadership, and map controls to frameworks like DORA and NIS2 for regulatory compliance.'].
Fake site targeting victims of Odido data leak with compensation scam - NL Times
Built for ['Security Analyst: Will benefit by learning to identify and hunt for indicators of post-breach scam campaigns, enhancing their threat detection capabilities.', 'Incident Response Manager: Will gain a structured playbook and forensic techniques specific to responding to customer-targeting scams stemming from data leaks.', 'Compliance Officer: Will learn how to map the incident response and preventive controls to frameworks like GDPR and NIS2, strengthening regulatory reporting and adherence.'].
Data breach at French bank registry impacts 1.2 million accounts - Bleeping Computer
Built for ['Security Analyst: Will benefit by learning specific detection rules and forensic techniques to identify data exfiltration attempts early in the attack chain.', 'IT Administrator: Will gain crucial knowledge on hardening authentication systems and implementing network segmentation to contain breaches, directly addressing common root causes.', 'Compliance Officer: Will learn to map incident findings to regulatory requirements like GDPR and DORA, strengthening audit readiness and demonstrating due diligence.'].
Data Breach Hits Canada Goose, Exposing Over 600000 Customer Records
Built for ['Security Analyst: Will benefit by learning to craft specific detection rules and analyse indicators of compromise from a real-world data exfiltration event.', 'IT Administrator / System Engineer: Will gain crucial insights into hardening authentication systems, implementing network segmentation, and configuring access controls to prevent credential-based breaches.', 'Data Protection Officer / Compliance Manager: Will learn to map incident response activities to key compliance requirements (GDPR, NIS2) and communicate breach implications effectively to leadership and regulators.'].
ClickFix Campaign Abuses Compromised Sites to Deploy MIMICRAT Malware
Built for ['Security Analyst: To deepen their ability to identify malware delivery via web compromises and craft effective SIEM detection rules.', 'IT Administrator: To understand the infrastructure hardening and web server security measures required to prevent their systems from being exploited in similar campaigns.', 'Incidence Response Manager: To develop and refine playbooks for responding to malware incidents stemming from compromised third-party websites.'].
San Jose slow to tell workers about data breach - DataBreaches.Net
Built for ['Security Analysts and Incident Responders: They will benefit by learning to refine detection rules and response playbooks based on a real breach, improving their investigative and containment skills.', 'Data Protection Officers and Compliance Managers: They will gain insights into managing breach notification timelines and mapping incident response actions to GDPR, NIS2, and other regulatory requirements.', 'IT Administrators and System Engineers: They will learn practical infrastructure hardening techniques and access control measures to prevent initial compromise and limit lateral movement during a breach.'].
A single compromised account gave hackers access to 1.2 million French banking records
Built for ['Security Analyst / SOC Engineer: To gain practical skills in detecting credential-based lateral movement and building specific SIEM correlations and incident response playbooks.', 'IT Administrator / System Engineer: To understand the critical importance of identity hygiene, privilege management, and infrastructure hardening to prevent initial compromise and limit blast radius.', 'CISO / Risk & Compliance Manager: To comprehend the full business impact of such an incident, learn how to communicate risk to leadership, and map controls to frameworks like DORA, NIS2, and GDPR for regulatory reporting.'].
Chinese hackers used Anthropic's Claude to run a full-scale cyberattack after jailbreaking ...
Built for ['Security Analyst / SOC Analyst: Will benefit from learning the specific indicators of compromise (IoCs) and detection strategies for AI-facilitated attacks to improve monitoring and alerting capabilities.', 'Incident Response Manager: Will gain a detailed playbook and forensic techniques tailored to respond to and contain breaches involving compromised AI systems and lateral movement.', 'Chief Information Security Officer (CISO): Will learn how to communicate AI-specific risks to the board, integrate controls into governance frameworks, and ensure vendor/AI tool risk management aligns with regulations like NIS2 and DORA.'].
Privacy breaches following the Lapu Lapu Day Festival - DataBreaches.Net
Built for ['Security Analyst: To develop deeper skills in detecting and responding to data exfiltration attempts and understanding the attack lifecycle specific to data breaches.', 'Data Protection Officer (DPO): To gain practical insights into incident response and learn how to map breach scenarios to GDPR and other privacy regulation requirements for reporting and remediation.', 'IT Administrator: To understand the infrastructure and configuration weaknesses that lead to data exposure and learn hardening techniques to secure databases and file storage systems.'].
Cyberattack causes UMMC to close clinics, cancel appointments for second day
Built for ['Healthcare IT/Security Staff: To understand the specific risks and regulatory pressures (like HIPAA) facing medical institutions and how to defend critical clinical systems.', 'Security Operations Centre (SOC) Analysts: To learn the specific indicators and detection strategies for disruptive attacks that target availability, moving beyond just data theft.', 'IT Risk & Compliance Officers: To map the technical controls and response actions from this incident to major compliance frameworks like NIST CSF and GDPR, demonstrating due diligence.'].
Major CarGurus data breach reportedly sees 1.7 million corporate records stolen
Built for ['Security Analyst: Will benefit by learning to craft specific detection rules and analyse indicators of compromise from a real-world data breach to improve monitoring capabilities.', 'IT Administrator: Will gain practical knowledge on hardening authentication systems, implementing network segmentation, and applying access controls to prevent unauthorised data access.', 'Compliance Officer: Will learn to map the technical details of this incident to key regulatory requirements (GDPR, NIS2) and frameworks (ISO 27001, NIST CSF) to demonstrate due diligence and control effectiveness.'].
Billions of records exposed by unsecured IDMerit database | SC Media
Built for ['Cloud Security Engineer: To learn specific hardening techniques for cloud storage services (e.g., AWS S3, Azure Blob Storage) and implement automated compliance checks to prevent public exposure of sensitive data.', 'Security Analyst (SOC): To develop and tune SIEM detection rules for identifying misconfigured assets and anomalous data access patterns, enabling early discovery of exposure events.', 'Data Protection Officer / GRC Analyst: To understand the direct link between technical misconfigurations and major compliance failures under GDPR, NIS2, and SOC 2, and to build stronger vendor risk assessment questionnaires and audit controls.'].
UMMC suspends some services after cyberattack | News From The States
Built for ['Security Analyst: Will benefit by gaining practical skills in threat hunting and SIEM detection rule creation specific to a real cyberattack, enhancing their daily monitoring and analysis capabilities.', 'IT Administrator: Will learn critical infrastructure hardening techniques and incident response procedures to better defend the systems they manage and contribute effectively during a security crisis.', 'IT Manager / CISO: Will gain a framework for communicating risk to leadership, building organisational readiness, and mapping technical controls to compliance requirements like NIS2 and GDPR.'].
Hackers expose over 200,000 Australian driver's licences in data breach
Built for ['Security Analyst: Will benefit by learning to craft specific detection rules and response playbooks for data exfiltration events, directly improving their threat-hunting capabilities.', 'IT Administrator / System Engineer: Will gain critical knowledge on infrastructure hardening, access control implementation, and network segmentation to prevent initial compromise and lateral movement.', 'Compliance & Risk Manager: Will learn to map technical incidents to control failures in frameworks like GDPR and NIST CSF, enabling more effective risk assessments and vendor due diligence processes.'].
Texas sues network equipment maker TP-Link for aiding the Chinese Communist Party in ...
Built for ['Security professionals learning from real-world breaches', 'IT teams responsible for implementing security controls', 'Compliance officers requiring incident-driven training'].
Leaked Data Raises Questions About Hackers' Claims and Moldova's Prior Denial
Built for ['Security Operations Centre (SOC) Analysts who need to detect and respond to sophisticated cyberattacks involving data leaks and information warfare tactics', 'Threat Intelligence Analysts seeking to understand attribution challenges and how attackers use leaked data to establish credibility in their campaigns', 'Chief Information Security Officers (CISOs) and Security Managers who must communicate cyber risks to leadership and develop organisational resilience against complex threat actors'].
Third-party hack probed by Adidas amid data theft assertions | SC Media
Built for ['Third-Party Risk Managers who need to assess and mitigate vendor security risks while maintaining business relationships', 'CISOs and Security Directors who must communicate supply chain risks to executive leadership and develop comprehensive vendor security programmes', 'Security Analysts and SOC Teams who require skills to detect, investigate, and respond to incidents originating from trusted third-party connections'].
Hackers claim breach of Adidas systems - but it says a third-party is the real victim
Built for ['Chief Information Security Officers (CISOs) who need to develop comprehensive supply chain security strategies and communicate breach risks to executive leadership', 'Security Analysts and Incident Responders who investigate complex multi-party breaches and need to establish attribution across partner networks', 'Risk Management Professionals and Compliance Officers responsible for vendor security assessments and regulatory reporting of third-party incidents'].
Adidas investigates data breach at independent licensing partner - SGI Europe
Built for ['Chief Information Security Officers (CISOs) who need to develop comprehensive third-party risk management strategies and communicate supply chain security risks to executive leadership', 'Third-Party Risk Managers and Vendor Security Analysts who require practical tools for assessing partner security posture and monitoring ongoing compliance with security requirements', 'Incident Response Team Leaders who must coordinate breach response activities across multiple organisations and manage complex stakeholder communications during supply chain incidents'].
Georgia hospital reports 2025 hacking incident | Healthcare News & Analysis
Built for ['Healthcare CISOs and security managers who need to understand sector-specific threats and build comprehensive defence strategies for medical organisations', 'Security analysts and SOC teams responsible for monitoring healthcare environments and detecting advanced persistent threats targeting medical infrastructure', 'IT administrators and network engineers in healthcare organisations who must implement hardening measures and maintain secure clinical systems'].
Lapsus Ransomware group targets Adidas - Cybersecurity Insiders
Built for ['Security Operations Centre (SOC) Analysts who need to detect and respond to advanced persistent ransomware campaigns using SIEM platforms and threat intelligence', 'Incident Response Managers who must develop comprehensive playbooks for ransomware attacks and coordinate multi-team response efforts during active incidents', 'Chief Information Security Officers (CISOs) who require strategic understanding of ransomware threats to make informed investment decisions and communicate risks to board members'].
French Government Says 1.2 Million Bank Accounts Exposed in Breach - SecurityWeek
Built for ['Chief Information Security Officers (CISOs) who need to develop organisational resilience against data breach incidents and communicate effectively with executive leadership about breach risks', 'Security Analysts and SOC personnel who require advanced skills in detecting data exfiltration attempts and responding to breach incidents involving financial information', 'Compliance and Risk Officers working in financial services or government sectors who must ensure adherence to GDPR, DORA, and other data protection regulations whilst managing breach response procedures'].
SoundCloud - 29,815,722 breached accounts
Built for ['Security Analysts and SOC personnel who need to recognise data breach indicators and implement effective detection strategies for protecting user account databases', 'IT Directors and CISOs who require strategic understanding of data breach prevention, organisational impact assessment, and compliance framework alignment for board-level reporting', 'Compliance Officers and Risk Managers who must ensure organisational readiness for data breach scenarios and understand regulatory implications under GDPR, DORA, and other frameworks'].
Texas sues TP-Link over Chinese hacking risks, user deception - Bleeping Computer
Built for ['CISOs and security leaders who need to assess and communicate supply chain risks to executive leadership and board members', 'Security analysts and threat hunters focused on detecting nation-state sponsored attacks and advanced persistent threat campaigns', 'IT administrators and network engineers responsible for securing networking equipment and managing vendor relationships'].
University of Pennsylvania - 623,750 breached accounts
Built for ['Security Operations Centre (SOC) analysts seeking to enhance their ransomware detection and response capabilities', 'IT Risk Managers and Compliance Officers who need to understand ransomware impact on regulatory requirements and business continuity', 'Incident Response Team leads and CISOs responsible for developing organisational resilience against advanced persistent threats'].
Canada Goose - 581,877 breached accounts
Built for ['Security Operations Centre (SOC) Analysts who need to recognise data breach indicators and implement effective detection strategies for retail and e-commerce environments', 'Chief Information Security Officers (CISOs) and security managers seeking to build comprehensive data breach response capabilities and communicate risks effectively to executive leadership', 'Compliance Officers and Data Protection Officers (DPOs) responsible for GDPR compliance, breach notification procedures, and regulatory reporting in customer-facing organisations'].
Panera Bread - 5,112,502 breached accounts
Built for ['Data Protection Officers who need to understand technical breach vectors to implement effective GDPR and privacy compliance programmes', 'Security Analysts and SOC personnel who must detect and respond to data exposure incidents before they escalate to full breaches', 'CISOs and Security Managers who require comprehensive understanding of data breach impacts to communicate risks and justify security investments to leadership'].
Under Armour - 72,742,892 breached accounts
Built for ['Security Operations Centre (SOC) Analysts who need to recognise and respond to ransomware indicators in real-time environments', 'Chief Information Security Officers (CISOs) and security managers requiring strategic insight into ransomware impact and board-level communication strategies', 'Compliance Officers and Risk Managers who must align ransomware defence with regulatory frameworks including GDPR, DORA, and NIS2 requirements'].
The 48-Hour Rule in Motion
From incident alert to deployed learning package in an average of 18.5 hours.
Train from what just happened, not what happened last year.
IntelXview gives security leaders a practical way to respond to new threat patterns with actionable learning while teams still remember why it matters.
The next breach will not wait for your annual cycle.
Launch incident-triggered training workflows now and move your awareness program from static compliance to active defense.