Incident-as-a-Service

73% retention vs 12% is a timing problem, not a content problem.

Incident-triggered lessons arrive while attention is highest. Your team learns from real events in near real-time, not from stale annual modules.

73% vs 12% Retention
847 Organisations
18.5h Breach to Training

*6-month retention benchmark: incident-driven training (73%) compared with annual compliance training (12%) in a 2,800-employee study.

Or create a free account — no credit card required.

Latest Incident-Based Courses

Search the active catalogue and launch immediately from the incidents most relevant to your teams.

556 courses available

Available Now

Hackers Leveraging Multiple AI Services to Compromise 600+ FortiGate Devices

Built for ['Network Security Engineer: Will benefit by learning to harden FortiGate and similar devices against the specific AI-driven exploitation techniques demonstrated in the incident.', 'SOC Analyst: Will gain critical skills in crafting and tuning SIEM detection rules to identify the early indicators of compromise associated with this type of automated, large-scale breach campaign.', 'IT Administrator/Manager: Will learn essential infrastructure hardening and access control measures to prevent initial compromise and understand board-level communication strategies for post-incident reporting.'].

Available Now

New ClickFix Attack Targets Crypto Wallets and 25+ Browsers with Infostealer - Hackread

Built for ['Security Analyst: Will benefit by learning to craft specific detection rules for infostealer activity and understanding the forensic artefacts left by the ClickFix attack.', 'Incident Responder: Will gain a ready-made playbook and practical skills for containing and eradicating this specific threat, improving response times and effectiveness.', 'IT Administrator: Will learn critical infrastructure hardening techniques, such as application control and patch management policies, to prevent similar breaches in their environment.'].

Available Now

Critical Infrastructure Under Pressure as AI Threats Grow and Global Enforcement Responds

Built for ['Security Analyst: To deepen their ability to detect and investigate data exfiltration attempts using real-world indicators and SIEM strategies.', "IT Administrator / System Engineer: To learn infrastructure hardening techniques, such as network segmentation and access control, directly informed by the incident's attack vectors.", 'CISO / Security Manager: To develop board-level communication strategies and integrate incident response playbooks with compliance requirements like NIS2 and GDPR.'].

Available Now

Ukrainian hackers uncover how Russian drone operators are using Belarus

Built for ['Threat Intelligence Analyst: They will benefit by learning how to trace and attribute complex campaigns that cross national borders and leverage third-party infrastructure, enhancing their analytical tradecraft.', 'Security Operations Centre (SOC) Analyst: They will gain practical skills in writing and tuning SIEM detection rules for this specific attack pattern, improving their ability to identify similar covert operations early.', 'Chief Information Security Officer (CISO): They will learn how to communicate the business and geopolitical risks of such attacks to the board, and how to map defensive measures to compliance requirements like NIS2 and DORA.'].

Available Now

Compromised npm package silently installs OpenClaw on developer machines

Built for ['Application Security Engineer: To understand how to secure CI/CD pipelines and implement software bill of materials (SBOM) to prevent dependency poisoning.', 'Security Operations Centre (SOC) Analyst: To learn specific detection rules for identifying malicious activity originating from trusted development tools and packages.', 'Chief Information Security Officer (CISO): To gain strategic insight into supply chain risk management and communicate effectively with the board on mitigating this emerging threat vector.'].

Available Now

Loan applications, drivers licences, personal data of 440k Aussies exposed after hacker hits ...

Built for ['Security Analysts: Will benefit by learning to craft specific detection rules and analyse IoCs from a real data breach, enhancing their threat-hunting capabilities.', 'IT Administrators & System Engineers: Will gain critical knowledge on infrastructure hardening, access control implementation, and network segmentation to prevent similar intrusion and data exfiltration.', 'Compliance & Risk Officers: Will learn to map the technical and procedural failures of the incident to key requirements of GDPR, NIST CSF, and ISO 27001, strengthening audit and reporting processes.'].

Available Now

Deutsche Bahn hit by major DDoS attack disrupting services | SC Media

Built for ['Network Security Engineer: To design and implement effective DDoS mitigation architectures and traffic filtering rules.', 'Security Operations Centre (SOC) Analyst: To improve detection and response procedures for volumetric attacks, reducing mean time to recovery.', 'IT Infrastructure Manager: To understand the business impact of DDoS attacks and justify investments in resilience and redundancy for critical services.'].

Available Now

UMMC closes clinics amid ransomware attack - TechTarget

Built for ['Security Analyst: Will benefit by learning to identify ransomware IOCs and craft specific SIEM detection rules to catch similar attacks early.', 'IT Administrator/Systems Engineer: Will gain practical skills for hardening authentication systems, implementing network segmentation, and applying zero trust principles to protect critical clinical and administrative systems.', 'CISO/Risk & Compliance Manager: Will learn to communicate cyber risk to leadership, integrate incident response with compliance obligations (like GDPR and NIS2), and build a stronger organisational security culture.'].

Available Now

Phony Bank Account Change Requests: How to Detect and Stop AP's Silent Killer

Built for ['Security Analyst: To develop advanced detection rules for subtle account takeover and data exfiltration patterns within SIEM/EDR tools.', 'IT Administrator (Finance Systems): To learn hardening techniques for banking portals, vendor management platforms, and authentication systems critical to payment processes.', 'CISO / Security Manager: To build a comprehensive defence strategy, communicate risk to leadership, and map controls to frameworks like DORA and NIS2 for regulatory compliance.'].

Available Now

Fake site targeting victims of Odido data leak with compensation scam - NL Times

Built for ['Security Analyst: Will benefit by learning to identify and hunt for indicators of post-breach scam campaigns, enhancing their threat detection capabilities.', 'Incident Response Manager: Will gain a structured playbook and forensic techniques specific to responding to customer-targeting scams stemming from data leaks.', 'Compliance Officer: Will learn how to map the incident response and preventive controls to frameworks like GDPR and NIS2, strengthening regulatory reporting and adherence.'].

Available Now

Data breach at French bank registry impacts 1.2 million accounts - Bleeping Computer

Built for ['Security Analyst: Will benefit by learning specific detection rules and forensic techniques to identify data exfiltration attempts early in the attack chain.', 'IT Administrator: Will gain crucial knowledge on hardening authentication systems and implementing network segmentation to contain breaches, directly addressing common root causes.', 'Compliance Officer: Will learn to map incident findings to regulatory requirements like GDPR and DORA, strengthening audit readiness and demonstrating due diligence.'].

Available Now

Data Breach Hits Canada Goose, Exposing Over 600000 Customer Records

Built for ['Security Analyst: Will benefit by learning to craft specific detection rules and analyse indicators of compromise from a real-world data exfiltration event.', 'IT Administrator / System Engineer: Will gain crucial insights into hardening authentication systems, implementing network segmentation, and configuring access controls to prevent credential-based breaches.', 'Data Protection Officer / Compliance Manager: Will learn to map incident response activities to key compliance requirements (GDPR, NIS2) and communicate breach implications effectively to leadership and regulators.'].

Available Now

ClickFix Campaign Abuses Compromised Sites to Deploy MIMICRAT Malware

Built for ['Security Analyst: To deepen their ability to identify malware delivery via web compromises and craft effective SIEM detection rules.', 'IT Administrator: To understand the infrastructure hardening and web server security measures required to prevent their systems from being exploited in similar campaigns.', 'Incidence Response Manager: To develop and refine playbooks for responding to malware incidents stemming from compromised third-party websites.'].

Available Now

San Jose slow to tell workers about data breach - DataBreaches.Net

Built for ['Security Analysts and Incident Responders: They will benefit by learning to refine detection rules and response playbooks based on a real breach, improving their investigative and containment skills.', 'Data Protection Officers and Compliance Managers: They will gain insights into managing breach notification timelines and mapping incident response actions to GDPR, NIS2, and other regulatory requirements.', 'IT Administrators and System Engineers: They will learn practical infrastructure hardening techniques and access control measures to prevent initial compromise and limit lateral movement during a breach.'].

Available Now

A single compromised account gave hackers access to 1.2 million French banking records

Built for ['Security Analyst / SOC Engineer: To gain practical skills in detecting credential-based lateral movement and building specific SIEM correlations and incident response playbooks.', 'IT Administrator / System Engineer: To understand the critical importance of identity hygiene, privilege management, and infrastructure hardening to prevent initial compromise and limit blast radius.', 'CISO / Risk & Compliance Manager: To comprehend the full business impact of such an incident, learn how to communicate risk to leadership, and map controls to frameworks like DORA, NIS2, and GDPR for regulatory reporting.'].

Available Now

Chinese hackers used Anthropic's Claude to run a full-scale cyberattack after jailbreaking ...

Built for ['Security Analyst / SOC Analyst: Will benefit from learning the specific indicators of compromise (IoCs) and detection strategies for AI-facilitated attacks to improve monitoring and alerting capabilities.', 'Incident Response Manager: Will gain a detailed playbook and forensic techniques tailored to respond to and contain breaches involving compromised AI systems and lateral movement.', 'Chief Information Security Officer (CISO): Will learn how to communicate AI-specific risks to the board, integrate controls into governance frameworks, and ensure vendor/AI tool risk management aligns with regulations like NIS2 and DORA.'].

Available Now

Privacy breaches following the Lapu Lapu Day Festival - DataBreaches.Net

Built for ['Security Analyst: To develop deeper skills in detecting and responding to data exfiltration attempts and understanding the attack lifecycle specific to data breaches.', 'Data Protection Officer (DPO): To gain practical insights into incident response and learn how to map breach scenarios to GDPR and other privacy regulation requirements for reporting and remediation.', 'IT Administrator: To understand the infrastructure and configuration weaknesses that lead to data exposure and learn hardening techniques to secure databases and file storage systems.'].

Available Now

Cyberattack causes UMMC to close clinics, cancel appointments for second day

Built for ['Healthcare IT/Security Staff: To understand the specific risks and regulatory pressures (like HIPAA) facing medical institutions and how to defend critical clinical systems.', 'Security Operations Centre (SOC) Analysts: To learn the specific indicators and detection strategies for disruptive attacks that target availability, moving beyond just data theft.', 'IT Risk & Compliance Officers: To map the technical controls and response actions from this incident to major compliance frameworks like NIST CSF and GDPR, demonstrating due diligence.'].

Available Now

Major CarGurus data breach reportedly sees 1.7 million corporate records stolen

Built for ['Security Analyst: Will benefit by learning to craft specific detection rules and analyse indicators of compromise from a real-world data breach to improve monitoring capabilities.', 'IT Administrator: Will gain practical knowledge on hardening authentication systems, implementing network segmentation, and applying access controls to prevent unauthorised data access.', 'Compliance Officer: Will learn to map the technical details of this incident to key regulatory requirements (GDPR, NIS2) and frameworks (ISO 27001, NIST CSF) to demonstrate due diligence and control effectiveness.'].

Available Now

Billions of records exposed by unsecured IDMerit database | SC Media

Built for ['Cloud Security Engineer: To learn specific hardening techniques for cloud storage services (e.g., AWS S3, Azure Blob Storage) and implement automated compliance checks to prevent public exposure of sensitive data.', 'Security Analyst (SOC): To develop and tune SIEM detection rules for identifying misconfigured assets and anomalous data access patterns, enabling early discovery of exposure events.', 'Data Protection Officer / GRC Analyst: To understand the direct link between technical misconfigurations and major compliance failures under GDPR, NIS2, and SOC 2, and to build stronger vendor risk assessment questionnaires and audit controls.'].

Available Now

UMMC suspends some services after cyberattack | News From The States

Built for ['Security Analyst: Will benefit by gaining practical skills in threat hunting and SIEM detection rule creation specific to a real cyberattack, enhancing their daily monitoring and analysis capabilities.', 'IT Administrator: Will learn critical infrastructure hardening techniques and incident response procedures to better defend the systems they manage and contribute effectively during a security crisis.', 'IT Manager / CISO: Will gain a framework for communicating risk to leadership, building organisational readiness, and mapping technical controls to compliance requirements like NIS2 and GDPR.'].

Available Now

Hackers expose over 200,000 Australian driver's licences in data breach

Built for ['Security Analyst: Will benefit by learning to craft specific detection rules and response playbooks for data exfiltration events, directly improving their threat-hunting capabilities.', 'IT Administrator / System Engineer: Will gain critical knowledge on infrastructure hardening, access control implementation, and network segmentation to prevent initial compromise and lateral movement.', 'Compliance & Risk Manager: Will learn to map technical incidents to control failures in frameworks like GDPR and NIST CSF, enabling more effective risk assessments and vendor due diligence processes.'].

Available Now

Texas sues network equipment maker TP-Link for aiding the Chinese Communist Party in ...

Built for ['Security professionals learning from real-world breaches', 'IT teams responsible for implementing security controls', 'Compliance officers requiring incident-driven training'].

Available Now

Leaked Data Raises Questions About Hackers' Claims and Moldova's Prior Denial

Built for ['Security Operations Centre (SOC) Analysts who need to detect and respond to sophisticated cyberattacks involving data leaks and information warfare tactics', 'Threat Intelligence Analysts seeking to understand attribution challenges and how attackers use leaked data to establish credibility in their campaigns', 'Chief Information Security Officers (CISOs) and Security Managers who must communicate cyber risks to leadership and develop organisational resilience against complex threat actors'].

Available Now

Third-party hack probed by Adidas amid data theft assertions | SC Media

Built for ['Third-Party Risk Managers who need to assess and mitigate vendor security risks while maintaining business relationships', 'CISOs and Security Directors who must communicate supply chain risks to executive leadership and develop comprehensive vendor security programmes', 'Security Analysts and SOC Teams who require skills to detect, investigate, and respond to incidents originating from trusted third-party connections'].

Available Now

Hackers claim breach of Adidas systems - but it says a third-party is the real victim

Built for ['Chief Information Security Officers (CISOs) who need to develop comprehensive supply chain security strategies and communicate breach risks to executive leadership', 'Security Analysts and Incident Responders who investigate complex multi-party breaches and need to establish attribution across partner networks', 'Risk Management Professionals and Compliance Officers responsible for vendor security assessments and regulatory reporting of third-party incidents'].

Available Now

Adidas investigates data breach at independent licensing partner - SGI Europe

Built for ['Chief Information Security Officers (CISOs) who need to develop comprehensive third-party risk management strategies and communicate supply chain security risks to executive leadership', 'Third-Party Risk Managers and Vendor Security Analysts who require practical tools for assessing partner security posture and monitoring ongoing compliance with security requirements', 'Incident Response Team Leaders who must coordinate breach response activities across multiple organisations and manage complex stakeholder communications during supply chain incidents'].

Available Now

Georgia hospital reports 2025 hacking incident | Healthcare News & Analysis

Built for ['Healthcare CISOs and security managers who need to understand sector-specific threats and build comprehensive defence strategies for medical organisations', 'Security analysts and SOC teams responsible for monitoring healthcare environments and detecting advanced persistent threats targeting medical infrastructure', 'IT administrators and network engineers in healthcare organisations who must implement hardening measures and maintain secure clinical systems'].

Available Now

Lapsus Ransomware group targets Adidas - Cybersecurity Insiders

Built for ['Security Operations Centre (SOC) Analysts who need to detect and respond to advanced persistent ransomware campaigns using SIEM platforms and threat intelligence', 'Incident Response Managers who must develop comprehensive playbooks for ransomware attacks and coordinate multi-team response efforts during active incidents', 'Chief Information Security Officers (CISOs) who require strategic understanding of ransomware threats to make informed investment decisions and communicate risks to board members'].

Available Now

French Government Says 1.2 Million Bank Accounts Exposed in Breach - SecurityWeek

Built for ['Chief Information Security Officers (CISOs) who need to develop organisational resilience against data breach incidents and communicate effectively with executive leadership about breach risks', 'Security Analysts and SOC personnel who require advanced skills in detecting data exfiltration attempts and responding to breach incidents involving financial information', 'Compliance and Risk Officers working in financial services or government sectors who must ensure adherence to GDPR, DORA, and other data protection regulations whilst managing breach response procedures'].

Available Now

SoundCloud - 29,815,722 breached accounts

Built for ['Security Analysts and SOC personnel who need to recognise data breach indicators and implement effective detection strategies for protecting user account databases', 'IT Directors and CISOs who require strategic understanding of data breach prevention, organisational impact assessment, and compliance framework alignment for board-level reporting', 'Compliance Officers and Risk Managers who must ensure organisational readiness for data breach scenarios and understand regulatory implications under GDPR, DORA, and other frameworks'].

Available Now

Texas sues TP-Link over Chinese hacking risks, user deception - Bleeping Computer

Built for ['CISOs and security leaders who need to assess and communicate supply chain risks to executive leadership and board members', 'Security analysts and threat hunters focused on detecting nation-state sponsored attacks and advanced persistent threat campaigns', 'IT administrators and network engineers responsible for securing networking equipment and managing vendor relationships'].

Available Now

University of Pennsylvania - 623,750 breached accounts

Built for ['Security Operations Centre (SOC) analysts seeking to enhance their ransomware detection and response capabilities', 'IT Risk Managers and Compliance Officers who need to understand ransomware impact on regulatory requirements and business continuity', 'Incident Response Team leads and CISOs responsible for developing organisational resilience against advanced persistent threats'].

Available Now

Canada Goose - 581,877 breached accounts

Built for ['Security Operations Centre (SOC) Analysts who need to recognise data breach indicators and implement effective detection strategies for retail and e-commerce environments', 'Chief Information Security Officers (CISOs) and security managers seeking to build comprehensive data breach response capabilities and communicate risks effectively to executive leadership', 'Compliance Officers and Data Protection Officers (DPOs) responsible for GDPR compliance, breach notification procedures, and regulatory reporting in customer-facing organisations'].

Available Now

Panera Bread - 5,112,502 breached accounts

Built for ['Data Protection Officers who need to understand technical breach vectors to implement effective GDPR and privacy compliance programmes', 'Security Analysts and SOC personnel who must detect and respond to data exposure incidents before they escalate to full breaches', 'CISOs and Security Managers who require comprehensive understanding of data breach impacts to communicate risks and justify security investments to leadership'].

Available Now

Under Armour - 72,742,892 breached accounts

Built for ['Security Operations Centre (SOC) Analysts who need to recognise and respond to ransomware indicators in real-time environments', 'Chief Information Security Officers (CISOs) and security managers requiring strategic insight into ransomware impact and board-level communication strategies', 'Compliance Officers and Risk Managers who must align ransomware defence with regulatory frameworks including GDPR, DORA, and NIS2 requirements'].

Why Security Teams Choose the 48-Hour Rule

Every section below maps to one operational advantage in Incident-as-a-Service delivery.

Timing as a retention lever

Content arrives while urgency is still high, which dramatically increases recall and response quality.

Breach-to-training pipeline

Detection, analysis, course build, and review are operationalized into one repeatable release loop.

Measured outcomes

Retention, engagement, and deployment speed are tracked so security leaders can report impact, not activity.

Role-targeted relevance

Lessons are tuned to functions and threat exposure, reducing wasted modules and improving behavior change.

The 48-Hour Rule in Motion

From incident alert to deployed learning package in an average of 18.5 hours.

Train from what just happened, not what happened last year.

IntelXview gives security leaders a practical way to respond to new threat patterns with actionable learning while teams still remember why it matters.

The next breach will not wait for your annual cycle.

Launch incident-triggered training workflows now and move your awareness program from static compliance to active defense.