Incident-as-a-Service
73% retention vs 12% is a timing problem, not a content problem.
Incident-triggered lessons arrive while attention is highest. Your team learns from real events in near real-time, not from stale annual modules.
*6-month retention benchmark: incident-driven training (73%) compared with annual compliance training (12%) in a 2,800-employee study.
Or create a free account — no credit card required.
Latest Incident-Based Courses
Search the active catalogue and launch immediately from the incidents most relevant to your teams.
556 courses available
When dating apps get hacked, your private life goes public Defence Masterclass
Scenario-led awareness training based on a real-world incident timeline.
SolarWinds WHD zero-days from January are under attack Defence Masterclass
Scenario-led awareness training based on a real-world incident timeline.
Warlock Gang Breaches SmarterTools Via SmarterMail Bugs Defence Masterclass
Scenario-led awareness training based on a real-world incident timeline.
DKnife targets network gateways in long running AitM campaign Defence Masterclass
Scenario-led awareness training based on a real-world incident timeline.
Russia Hacked the Polish Electricity Grid. Now What? - BankInfoSecurity Defence Masterclass
Scenario-led awareness training based on a real-world incident timeline.
EnCase Driver Weaponized as EDR Killers Persist - Dark Reading Defence Masterclass
Scenario-led awareness training based on a real-world incident timeline.
Substack Discloses Security Incident After Hacker Leaks Data - SecurityWeek Defence Masterclass
Scenario-led awareness training based on a real-world incident timeline.
Chinese Hackers Hijack Notepad++ Updates for 6 Months Defence Masterclass
Scenario-led awareness training based on a real-world incident timeline.
Iran-Linked RedKitten Cyber Campaign Targets Human Rights NGOs and Activists Defence Masterclass
Scenario-led awareness training based on a real-world incident timeline.
UAT-8099 Exploits IIS Servers Using Web Shell Attacks - Cyber Press Defence Masterclass
Scenario-led awareness training based on a real-world incident timeline.
Suntory Data Breach Defence Masterclass
Scenario-led awareness training based on a real-world incident timeline.
Marquis confirms data breach, point finger of blame at SonicWall firewall - TechRadar Defence Masterclass
Scenario-led awareness training based on a real-world incident timeline.
Who Operates the Badbox 2.0 Botnet? Defence Masterclass
Scenario-led awareness training based on a real-world incident timeline.
Bumble, Panera Bread, CrunchBase, Match Hit by Cyberattacks - Bloomberg Defence Masterclass
Scenario-led awareness training based on a real-world incident timeline.
Diese Unternehmen hat es schon erwischt Defence Masterclass
Scenario-led awareness training based on a real-world incident timeline.
ManoMano data breach: massive DIY chain incident impacts 38 million customers
Built for ['Security Analyst: To develop advanced detection strategies and analyse Indicators of Compromise (IoCs) specific to credential theft and data exfiltration patterns.', 'IT Administrator: To learn infrastructure hardening techniques, including access control and network segmentation, to prevent initial access and lateral movement.', 'Compliance Officer: To understand how technical incidents map to regulatory obligations under GDPR, NIS2, and other frameworks, enabling better risk reporting and control justification.'].
Cyber-Attack to Burglary: The Surprising Impact of the FFTir breach - Infosecurity Magazine
Built for ['Identity and access management teams', 'Security professionals implementing MFA', 'IT administrators managing authentication systems'].
January 2026 Healthcare Data Breach Report - The HIPAA Journal
Built for ['Healthcare IT Security Analysts: They will benefit by gaining direct insight into threats targeting Protected Health Information (PHI) and learning controls specific to HIPAA and related healthcare compliance mandates.', 'Information Security Officers: They will learn how to communicate the business impact of data breaches to leadership and how to align technical defences with organisational risk management and frameworks like NIST CSF and ISO 27001.', 'GRC (Governance, Risk, and Compliance) Consultants: They will gain a practical understanding of how technical incidents map to control failures in major frameworks (GDPR, SOC 2, NIS2), enabling them to provide more value-driven advice to clients.'].
Weak security habits of U.S. consumers make mobile devices a prime target for China's cyberattacks
Built for ['Security Analyst / SOC Analyst: To develop advanced detection capabilities for mobile-initiated attacks and user behaviour analytics, enabling earlier identification of compromised credentials or devices.', 'IT Administrator / Endpoint Engineer: To learn practical infrastructure hardening techniques for mobile device management (MDM), network access control, and authentication systems to mitigate this specific threat vector.', 'GRC (Governance, Risk, Compliance) Professional: To understand how this attack type maps to key controls in major frameworks (like NIST CSF and GDPR) and to effectively communicate technical risks to leadership in the context of regulatory requirements.'].
Fortinet Patches CVE-2026-24858 After Active FortiOS SSO Exploitation Detected Defence Masterclass
Scenario-led awareness training based on a real-world incident timeline.
Melwood Data Breach Investigation - Strauss Borrelli PLLC Defence Masterclass
Scenario-led awareness training based on a real-world incident timeline.
5 Practical Ways to Use Security AI Without Losing Control - Dark Reading Defence Masterclass
Scenario-led awareness training based on a real-world incident timeline.
Fake Microsoft Teams Billing Phishing Alerts Reach 6135 Users via 12866 Emails Defence Masterclass
Scenario-led awareness training based on a real-world incident timeline.
Cyberattack on Illinois Firm Exposes Personal Data of Thousands - Binance Defence Masterclass
Scenario-led awareness training based on a real-world incident timeline.
Phishing Attack Uses Stolen Credentials to Install LogMeIn RMM for Persistent Access Defence Masterclass
Scenario-led awareness training based on a real-world incident timeline.
Over 160,000 Companies Notify Regulators of GDPR Breaches Defence Masterclass
Scenario-led awareness training based on a real-world incident timeline.
Top 10: Malware Detection Platforms - Cyber Magazine Defence Masterclass
Built for ['Security professionals learning from real-world breaches', 'IT teams responsible for implementing security controls', 'Business leaders making security investment decisions', 'Compliance officers requiring current, incident-driven training', 'Risk managers assessing organizational vulnerabilities'].
Ask the Experts: Protect your business with a robust cyber plan Defence Masterclass
Built for ['Security professionals learning from real-world breaches', 'IT teams responsible for implementing security controls', 'Business leaders making security investment decisions', 'Compliance officers requiring current, incident-driven training', 'Risk managers assessing organizational vulnerabilities'].
Backup request is actually a phishing campaign, LastPass warns Defence Masterclass
Built for ['Email security administrators and SOC analysts', 'Security awareness training managers', 'IT teams implementing email authentication (SPF, DMARC, DKIM)', 'Business leaders protecting against BEC and phishing'].
Peruvian Loan Scam Harvests Cards and PINs via Fake Applications Defence Masterclass
Built for ['Security professionals learning from real-world breaches', 'IT teams responsible for implementing security controls', 'Business leaders making security investment decisions', 'Compliance officers requiring current, incident-driven training', 'Risk managers assessing organizational vulnerabilities'].
LastPass Users Targeted With Backup-Themed Phishing Emails - SecurityWeek Defence Masterclass
Built for ['Email security administrators and SOC analysts', 'Security awareness training managers', 'IT teams implementing email authentication (SPF, DMARC, DKIM)', 'Business leaders protecting against BEC and phishing'].
Hackers leak another 1 milion lines of stolen Odido data - NL Times
Built for ['Security Analyst: To develop advanced detection rules for data exfiltration and learn forensic techniques specific to post-breach analysis.', 'IT Administrator: To understand infrastructure hardening techniques, particularly around access control and network segmentation, to prevent initial intrusion.', "Compliance Officer / DPO: To map the incident's failures and responses to specific articles within GDPR, NIS2, and other frameworks, strengthening regulatory reporting and control audits."].
Mass Spam Attacks Leverage Zendesk Instances Defence Masterclass
Built for ['Security professionals learning from real-world breaches', 'IT teams responsible for implementing security controls', 'Business leaders making security investment decisions', 'Compliance officers requiring current, incident-driven training', 'Risk managers assessing organizational vulnerabilities'].
'CrashFix' Scam Crashes Browsers, Delivers Malware Defence Masterclass
Built for ['Security professionals learning from real-world breaches', 'IT teams responsible for implementing security controls', 'Business leaders making security investment decisions', 'Compliance officers requiring current, incident-driven training', 'Risk managers assessing organizational vulnerabilities'].
A faceless hacker stole my therapy notes Defence Masterclass
Built for ['Security professionals learning from real-world breaches', 'IT teams responsible for implementing security controls', 'Business leaders making security investment decisions', 'Compliance officers requiring current, incident-driven training', 'Risk managers assessing organizational vulnerabilities'].
EU reviews cybersecurity to limit danger from high-risk suppliers Defence Masterclass
Built for ['Security professionals learning from real-world breaches', 'IT teams responsible for implementing security controls', 'Business leaders making security investment decisions', 'Compliance officers requiring current, incident-driven training', 'Risk managers assessing organizational vulnerabilities'].
The 48-Hour Rule in Motion
From incident alert to deployed learning package in an average of 18.5 hours.
Train from what just happened, not what happened last year.
IntelXview gives security leaders a practical way to respond to new threat patterns with actionable learning while teams still remember why it matters.
The next breach will not wait for your annual cycle.
Launch incident-triggered training workflows now and move your awareness program from static compliance to active defense.