Incident-as-a-Service
73% retention vs 12% is a timing problem, not a content problem.
Incident-triggered lessons arrive while attention is highest. Your team learns from real events in near real-time, not from stale annual modules.
*6-month retention benchmark: incident-driven training (73%) compared with annual compliance training (12%) in a 2,800-employee study.
Or create a free account — no credit card required.
Latest Incident-Based Courses
Search the active catalogue and launch immediately from the incidents most relevant to your teams.
556 courses available
Betterment - 1,435,174 breached accounts
Built for ['Security Operations Centre (SOC) analysts who need to recognise and respond to data breach indicators effectively', 'Chief Information Security Officers (CISOs) requiring strategic insights for preventing similar incidents and communicating risks to executive leadership', 'IT administrators and infrastructure teams responsible for implementing hardening controls and maintaining secure data handling practices'].
Data Protection Failures on Moldovan Portals Leave Citizens at Risk - DataBreaches.Net
Built for ['Security Operations Centre (SOC) Analysts who need to recognise data breach patterns and implement effective detection strategies for similar incidents', 'Data Protection Officers and Compliance Managers who must ensure organisational adherence to GDPR, DORA, and other regulatory frameworks whilst building robust breach response capabilities', 'IT Security Managers and CISOs who require comprehensive understanding of data breach attack vectors to make informed decisions about security investments and policy development'].
Texas sues TP-Link alleging Chinese government access to its devices - teiss
Built for ['Chief Information Security Officers (CISOs) and security managers who need to assess and mitigate supply chain risks whilst communicating threats to executive leadership', 'Threat intelligence analysts and SOC managers seeking to detect state-sponsored surveillance activities and develop effective monitoring strategies for networking infrastructure', 'Compliance and risk management professionals responsible for vendor due diligence, regulatory compliance, and implementing supply chain security frameworks across their organisations'].
ClickFix Campaign Uses Homebrew Installer To Spread Cuckoo Stealer On macOS
Built for ['Security Operations Centre (SOC) Analysts who need to detect and respond to stealer malware campaigns targeting macOS environments', 'Incident Response Specialists seeking practical playbooks for data breach incidents involving credential theft and information stealing', 'Chief Information Security Officers (CISOs) requiring strategic understanding of supply chain attacks and their impact on organisational risk posture'].
118 people press charges over data leak from lab behind cervical cancer screening
Built for ['Healthcare Security Officers who need to protect patient data and comply with healthcare-specific regulations whilst defending against ransomware targeting medical facilities', 'Corporate Security Analysts responsible for threat detection and incident response who require practical experience with ransomware investigation techniques and containment strategies', 'Compliance Managers ensuring adherence to GDPR, SOC 2, and healthcare regulations who must understand how security incidents impact regulatory requirements and breach notification obligations'].
Three Healthcare Providers Affected by Ransomware Attacks - The HIPAA Journal
Built for ['Security Operations Centre (SOC) analysts who need to recognise and respond to ransomware indicators in real-time monitoring environments', 'Healthcare IT managers and compliance officers who must ensure HIPAA compliance whilst defending against sophisticated ransomware campaigns', 'Chief Information Security Officers (CISOs) and security leaders who require strategic understanding of ransomware threats for board-level communication and budget justification'].
CRESCENTHARVEST Campaign Targets Iran Protest Supporters With RAT Malware
Built for ['Security Operations Centre (SOC) Analysts who need to detect and respond to RAT malware infections and improve their threat hunting capabilities', 'Incident Response Managers who must develop playbooks and coordinate response efforts for politically motivated malware campaigns', 'Chief Information Security Officers (CISOs) who need to understand emerging threats, communicate risks to leadership, and implement strategic defences against targeted attacks'].
More data released in NZ law firm hack - Lawyers Weekly
Built for ['Chief Information Security Officers (CISOs) and security managers seeking to strengthen organisational defences against advanced persistent threats and improve incident response capabilities', 'Security analysts and SOC team members who need hands-on experience with threat detection, SIEM rule development, and forensic analysis of real-world cyberattacks', 'IT administrators and compliance officers responsible for implementing security controls and ensuring regulatory compliance across multiple frameworks whilst managing vendor and third-party risks'].
Notepad++ declares hardened update process 'effectively unexploitable'
Built for ["Chief Information Security Officers (CISOs) seeking to enhance their organisation's software supply chain risk management capabilities and board-level communication skills", 'Security Analysts and SOC Teams who need to detect and respond to software supply chain compromise attempts and implement effective monitoring strategies', 'IT Risk Managers and Third-Party Risk Specialists responsible for evaluating vendor security practices and managing software procurement security requirements'].
A Chinese hack exposes data of 5000 Italian counterterrorism officers
Built for ['Security Operations Centre (SOC) Analysts who need to enhance their detection capabilities for advanced persistent threats and nation-state attacks targeting sensitive data repositories', 'Chief Information Security Officers (CISOs) and security managers who must communicate breach risks to executive leadership and develop strategic defence programmes against sophisticated adversaries', 'Incident Response Team Members and digital forensics specialists who require deep understanding of data exfiltration techniques and evidence collection procedures for similar attacks'].
Spanish police arrest hacker who booked luxury hotels for one cent | News | kten.com
Built for ['Security Analysts responsible for monitoring and detecting payment fraud who need to understand advanced booking system exploitation techniques', 'Fraud Prevention Specialists who require deeper technical knowledge of how cybercriminals bypass payment validation controls', 'E-commerce Security Teams protecting online booking platforms who need practical guidance on implementing defensive measures against pricing manipulation attacks'].
Odido CRM Data Breach Exposes 6.2M Customer Records | eSecurity Planet Defence Masterclass
Scenario-led awareness training based on a real-world incident timeline.
New “Kurd Hackers Forum” Focuses on Middle Eastern Data Breaches and Leaks Defence Masterclass
Scenario-led awareness training based on a real-world incident timeline.
St. Paul law firm, famous for clergy sex abuse cases, snared in data breach - Star Tribune
Built for ['CISOs and Security Managers who need to develop comprehensive data breach response strategies and communicate risks effectively to executive leadership', 'Security Analysts and SOC Engineers seeking practical skills in detecting data breach indicators and implementing effective SIEM detection rules', 'IT Administrators and System Engineers responsible for hardening infrastructure and implementing preventive controls against data exfiltration'].
Nigerian man sentenced to 8 years in prison for running phony tax refund scheme
Built for ['Security Analysts who need to develop detection rules and investigate potential fraud schemes targeting personal financial information', "Compliance Officers who must ensure their organisation's data protection measures meet regulatory requirements for financial and personal data handling", 'IT Administrators responsible for implementing technical controls to prevent unauthorised access to tax and financial systems'].
Sex toys maker Tenga says hacker stole customer information - TechCrunch Defence Masterclass
Scenario-led awareness training based on a real-world incident timeline.
Critical BeyondTrust RS vulnerability exploited in active attacks Defence Masterclass
Scenario-led awareness training based on a real-world incident timeline.
South Korea fines Louis Vuitton, Christian Dior, Tiffany $25M for SaaS security failures Defence Masterclass
Scenario-led awareness training based on a real-world incident timeline.
Four new reasons why Windows LNK files cannot be trusted Defence Masterclass
Scenario-led awareness training based on a real-world incident timeline.
Critical flaw in BeyondTrust Remote Support sees early signs of exploitation Defence Masterclass
Scenario-led awareness training based on a real-world incident timeline.
Ransomware attacks increase against IT and food sectors Defence Masterclass
Scenario-led awareness training based on a real-world incident timeline.
CyberWiseCon Europe 2026 Defence Masterclass
Scenario-led awareness training based on a real-world incident timeline.
UAT-9921 Deploys VoidLink Malware to Target Technology and Financial Sectors Defence Masterclass
Scenario-led awareness training based on a real-world incident timeline.
npm’s Update to Harden Their Supply Chain, and Points to Consider Defence Masterclass
Scenario-led awareness training based on a real-world incident timeline.
Who Benefited from the Aisuru and Kimwolf Botnets? Defence Masterclass
Scenario-led awareness training based on a real-world incident timeline.
The Kimwolf Botnet is Stalking Your Local Network Defence Masterclass
Scenario-led awareness training based on a real-world incident timeline.
Notepad++ author says fixes make update mechanism ‘effectively unexploitable’
Built for ['Chief Information Security Officers (CISOs) who need strategic insight into supply chain risk management and board-level communication strategies for software security incidents', 'Security Analysts and SOC Teams who require practical skills in detecting, analysing, and responding to software supply chain attacks using SIEM platforms and threat intelligence', 'IT Administrators and System Engineers who need to implement defensive controls and hardening measures to protect against update mechanism exploitation and software-based threats'].
Threat actor posts allegedly sensitive data related to Safran Group, company denies cyberattack
Built for ['Chief Information Security Officers (CISOs) seeking to understand modern data breach attack vectors and develop comprehensive organisational response strategies', 'Security Operations Centre (SOC) analysts requiring advanced skills in data breach detection, investigation techniques, and incident response coordination', 'Data Protection Officers (DPOs) needing to align technical security controls with GDPR compliance requirements and breach notification procedures'].
Happy 16th Birthday, KrebsOnSecurity.com! Defence Masterclass
Scenario-led awareness training based on a real-world incident timeline.
Land Bank declines to confirm R50m ransom claim as cyber investigation continues - IOL Defence Masterclass
Scenario-led awareness training based on a real-world incident timeline.
Google Ties Suspected Russian Actor to CANFAIL Malware Attacks on Ukrainian Orgs Defence Masterclass
Scenario-led awareness training based on a real-world incident timeline.
San Diego Man Pleads Guilty In $42M International Tech Support Scam - Forbes Defence Masterclass
Scenario-led awareness training based on a real-world incident timeline.
Cyber Attack Rumors Swirl as NASCAR Faces $4 Million Ransom Demand - MSN Defence Masterclass
Scenario-led awareness training based on a real-world incident timeline.
Dell's Hard-Coded Flaw: A Nation-State Goldmine
Built for ['CISOs and Security Directors who need to understand supply chain risks and communicate hardware vulnerability impact to executive leadership and board members', 'Security Analysts and SOC Engineers who require advanced detection techniques for nation-state malware campaigns and supply chain compromise indicators', 'IT Risk Managers and Compliance Officers who must map hardware vulnerabilities to regulatory frameworks and develop vendor risk assessment programmes'].
Israeli Media Acknowledge Iranian Intelligence Superiority in the Digital Arena - ISNA Defence Masterclass
Scenario-led awareness training based on a real-world incident timeline.
Operation DoppelBrand Weaponizes Trusted Brands For Credential Theft Defence Masterclass
Scenario-led awareness training based on a real-world incident timeline.
The 48-Hour Rule in Motion
From incident alert to deployed learning package in an average of 18.5 hours.
Train from what just happened, not what happened last year.
IntelXview gives security leaders a practical way to respond to new threat patterns with actionable learning while teams still remember why it matters.
The next breach will not wait for your annual cycle.
Launch incident-triggered training workflows now and move your awareness program from static compliance to active defense.