Incident-as-a-Service
73% retention vs 12% is a timing problem, not a content problem.
Incident-triggered lessons arrive while attention is highest. Your team learns from real events in near real-time, not from stale annual modules.
*6-month retention benchmark: incident-driven training (73%) compared with annual compliance training (12%) in a 2,800-employee study.
Or create a free account — no credit card required.
Latest Incident-Based Courses
Search the active catalogue and launch immediately from the incidents most relevant to your teams.
556 courses available
'Damn Vulnerable' Training Apps Leave Vendors' Clouds Exposed Defence Masterclass
Built for ['Vendor risk managers assessing third-party security', 'Procurement teams evaluating supplier security', 'Security professionals managing supply chain risks', 'CISOs responsible for third-party risk management'].
Exposure Assessment Platforms Signal a Shift in Focus Defence Masterclass
Built for ['Security professionals learning from real-world breaches', 'IT teams responsible for implementing security controls', 'Business leaders making security investment decisions', 'Compliance officers requiring current, incident-driven training', 'Risk managers assessing organizational vulnerabilities'].
EU-Kommission will Huawei und ZTE aus Netzen verbannen Defence Masterclass
Built for ['Security professionals learning from real-world breaches', 'IT teams responsible for implementing security controls', 'Business leaders making security investment decisions', 'Compliance officers requiring current, incident-driven training', 'Risk managers assessing organizational vulnerabilities'].
Hacker erbeuten rund 42.000 Datensätze von Ingram Micro Defence Masterclass
Built for ['Security professionals learning from real-world breaches', 'IT teams responsible for implementing security controls', 'Business leaders making security investment decisions', 'Compliance officers requiring current, incident-driven training', 'Risk managers assessing organizational vulnerabilities'].
Contagious Interview turns VS Code into an attack vector Defence Masterclass
Built for ['Security professionals learning from real-world breaches', 'IT teams responsible for implementing security controls', 'Business leaders making security investment decisions', 'Compliance officers requiring current, incident-driven training', 'Risk managers assessing organizational vulnerabilities'].
Fiserv Seeks Exit From Credit Union Security Flaws Suit - Law360
Built for ['Vendor Risk Manager: To learn how to critically assess and contractually enforce security controls with third-party providers, directly mitigating the risks exemplified by the Fiserv case.', 'Security Operations Centre (SOC) Analyst: To gain skills in detecting anomalous behaviour stemming from compromised vendor access and writing precise SIEM detection rules for similar attack patterns.', 'IT Compliance Officer: To understand how to map incident response and vendor management controls to specific requirements in DORA, NIS2, and GDPR, strengthening audit readiness and regulatory reporting.'].
Experts Welcome Global Cybersecurity Vulnerability Enumeration Launch Defence Masterclass
Built for ['Security professionals learning from real-world breaches', 'IT teams responsible for implementing security controls', 'Business leaders making security investment decisions', 'Compliance officers requiring current, incident-driven training', 'Risk managers assessing organizational vulnerabilities'].
Dismantling Defenses: Trump 2.0 Cyber Year in Review Defence Masterclass
Built for ['Security professionals learning from real-world breaches', 'IT teams responsible for implementing security controls', 'Business leaders making security investment decisions', 'Compliance officers requiring current, incident-driven training', 'Risk managers assessing organizational vulnerabilities'].
AI-Powered Government Cyberattack: Weaponised LLMs in Nation-State Operations Defence Masterclass
Built for ['Security professionals learning from real-world breaches', 'IT teams responsible for implementing security controls', 'Business leaders making security investment decisions', 'Compliance officers requiring current, incident-driven training', 'Risk managers assessing organizational vulnerabilities'].
Patch Tuesday, January 2026 Edition Defence Masterclass
Built for ['Security professionals learning from real-world breaches', 'IT teams responsible for implementing security controls', 'Business leaders making security investment decisions', 'Compliance officers requiring current, incident-driven training', 'Risk managers assessing organizational vulnerabilities'].
Vulnerability prioritization beyond the CVSS number - CSO Online Defence Masterclass
Built for ['Security professionals learning from real-world breaches', 'IT teams responsible for implementing security controls', 'Business leaders making security investment decisions', 'Compliance officers requiring current, incident-driven training', 'Risk managers assessing organizational vulnerabilities'].
What 3PL execs must know about mandatory cyber incident reporting - The Loadstar Defence Masterclass
Built for ['Microsoft infrastructure administrators (Azure, AD, O365)', 'IT teams managing Microsoft enterprise services', 'Security professionals securing Microsoft environments', 'Cloud security engineers responsible for Azure security'].
Coupang swings to loss as data breach dents Q4; sees muted near-term growth | Reuters
Built for ['Security Analyst: Will benefit by learning to craft specific detection rules for data exfiltration and apply forensic techniques from a real-world case to improve monitoring and initial response capabilities.', "IT Administrator / System Engineer: Will gain crucial knowledge on implementing infrastructure hardening controls, such as access management and network segmentation, directly informed by the breach's attack vectors to prevent similar incidents.", 'Compliance Officer / Risk Manager: Will learn to map the technical details of the breach to specific requirements in frameworks like GDPR, NIS2, and SOC 2, enabling more effective risk assessments and audit preparations.'].
Risky Bulletin: Russian man investigated for extorting Conti ransomware group
Built for ['Security Analyst: To deepen their ability to detect data exfiltration patterns and analyse breach indicators from real-world cases.', 'Incident Response Manager: To develop and refine playbooks for responding to data breaches involving insider threats or compromised third-party data.', 'IT & Compliance Officer: To understand how technical breaches map to regulatory obligations under GDPR, NIS2, and other frameworks, enabling better risk reporting and control implementation.'].
Coupang's 2025 cyberattack dents Q4 profits (CPNG:NYSE) | Seeking Alpha
Built for ['Security Analysts and Engineers who need to understand the specific tactics, techniques, and procedures (TTPs) used in this breach to improve their monitoring and detection strategies.', 'Incident Responders and SOC team members who will benefit from building and practising response playbooks based on a real incident timeline and impact analysis.', 'IT Risk and Compliance Officers who must map the security failures and subsequent controls to major regulatory frameworks like GDPR, NIS2, and SOC 2 to demonstrate due diligence and compliance.'].
Bumble Faces Lawsuit Over Alleged Preventable Cyberattack - The National Law Review
Built for ['Security Analyst: Will benefit by learning specific detection rules for data exfiltration and how to conduct thorough incident analysis to support legal and compliance requirements.', 'IT Administrator / System Engineer: Will gain critical knowledge on implementing hardening controls, segmentation, and access management to prevent the initial access and lateral movement common in data breaches.', 'Compliance Officer / Risk Manager: Will learn how to map technical incidents to regulatory obligations (like GDPR and NIS2) and build a stronger case for security investments based on legal precedents from real lawsuits.'].
Unsecured Elasticsearch database leaks Dungeon Crusher players' purchase data | brief
Built for ['Cloud Security Engineer: To learn practical techniques for hardening database-as-a-service (DBaaS) configurations and implementing automated compliance checks.', 'Security Analyst (SOC): To develop detection strategies for identifying exposed databases and understand the forensics of a data leak incident for improved response.', 'IT Administrator / DevOps Engineer: To gain critical knowledge on securing development and test environments, preventing similar misconfigurations from reaching production.'].
Wynn Resorts confirms breach, believes data deletion claims | brief | SC Media
Built for ['Security Analysts who need to understand the technical indicators and detection methods for data exfiltration and destruction attacks.', 'Incident Response Managers who must develop and refine playbooks for handling data breach scenarios, including stakeholder communication.', 'IT Administrators and System Engineers responsible for implementing the infrastructure hardening and access controls that prevent initial access in such breaches.'].
Marquis v. SonicWall Lawsuit Ups the Breach Blame Game
Built for ['Security Analysts and Engineers: They will benefit by learning to detect and respond to the specific attack vectors used in this breach, and by gaining access to ready-to-deploy detection rules and hardening guides.', 'IT Risk and Compliance Managers: They will gain critical insights into mapping security controls to frameworks like NIST CSF and GDPR, and learn how to structure vendor contracts and assessments to mitigate legal liability.', 'CISOs and Security Leaders: They will learn effective strategies for board-level communication on vendor risk, and how to build an organisational security culture that prioritises due diligence and documented defence.'].
Cyberattack Prompts Two Federal Lawsuits Against Wynn Resorts - Hotel Online
Built for ['Security Analyst: To deepen their understanding of data breach indicators and enhance SIEM detection capabilities for early warning.', 'IT Administrator: To learn infrastructure hardening techniques, particularly around access controls and network segmentation, to prevent lateral movement post-breach.', 'Compliance Officer / DPO: To map real-world breach scenarios to regulatory requirements like GDPR and NIS2, improving audit readiness and reporting procedures.'].
Olympique Marseille Cyberattack 2026: Club Confirms Attempted Website Breach Amid ...
Built for ['Security Analyst: Will benefit by learning to craft specific detection rules for web application attacks and enhance their incident triage skills using a real case study.', 'IT Administrator: Will gain crucial knowledge on hardening web servers, implementing strict access controls, and applying network segmentation to protect critical assets from similar breaches.', 'Compliance Officer: Will learn to map the technical details of a data breach incident to key requirements of frameworks like GDPR and NIS2, improving audit and reporting processes.'].
Figure Lending Facing Class Action Lawsuit Over February 2026 Data Breach
Built for ['Security Analyst: Will benefit by learning to craft specific detection rules and analyse indicators of compromise from a real data breach to improve monitoring capabilities.', 'IT Administrator / System Engineer: Will gain crucial knowledge on implementing infrastructure hardening controls, such as authentication and network segmentation, to prevent unauthorised data access.', "Compliance & Risk Officer: Will learn to map the incident's technical details to regulatory requirements (GDPR, NIS2) and articulate security gaps to leadership in the context of legal and financial risk."].
Coupang braces for increased competition amid fallout from South Korea data breach
Built for ['Security Analyst: Will benefit by learning specific detection rules and IOCs to hunt for similar breach activity in their environment.', 'IT Administrator: Will gain practical knowledge on implementing infrastructure hardening controls like network segmentation and access management to prevent initial access.', "Compliance Officer: Will learn how to map the incident's lessons to control requirements in frameworks like GDPR and NIST CSF to demonstrate regulatory diligence."].
Cisco says hackers have been exploiting a critical bug to break into big customer networks ...
Built for ['Network Security Engineer: To understand the specific exploitation techniques against network devices and learn how to harden Cisco and similar infrastructure against such attacks.', 'Security Operations Centre (SOC) Analyst: To develop and implement precise detection rules for identifying exploitation attempts and subsequent lateral movement within a compromised network.', 'Chief Information Security Officer (CISO): To gain strategic insights for communicating risk to the board, managing vendor patching programmes, and aligning defences with major compliance frameworks like NIS2 and DORA.'].
Hacking group begins leaking customer data in Dutch telecom Odido hack - Reuters
Built for ['Security Analyst: To gain practical skills in detecting the specific tactics, techniques, and procedures (TTPs) used in data exfiltration attacks and to build effective SIEM detection rules.', 'IT Administrator / System Engineer: To learn infrastructure hardening techniques, such as network segmentation and access control, that could prevent initial compromise and lateral movement seen in the Odido attack.', 'Compliance & Risk Officer: To understand how technical incidents like this map to regulatory obligations under GDPR, NIS2, and DORA, enabling more accurate risk assessments and control implementations.'].
Jamaat claimed ameer's X account hacked nine hours after post, only after public outrage: BNP Defence Masterclass
Scenario-led awareness training based on a real-world incident timeline.
Jamaat claims amir's X account hacked after post targeting women - Jagonews24.com Defence Masterclass
Scenario-led awareness training based on a real-world incident timeline.
South Korea faces increased US investor legal action over Coupang breach probe Defence Masterclass
Scenario-led awareness training based on a real-world incident timeline.
Notepad++ says Chinese government hackers hijacked its software updates for months Defence Masterclass
Scenario-led awareness training based on a real-world incident timeline.
Dutch telecom Odido hacked, 6 million accounts affected - Reuters Defence Masterclass
Scenario-led awareness training based on a real-world incident timeline.
ApolloMD reveals that 626540 patients were affected by May, 2025 cyberattack Defence Masterclass
Scenario-led awareness training based on a real-world incident timeline.
Jamaat alleges hacking of ameer's X account originated from govt sources Defence Masterclass
Scenario-led awareness training based on a real-world incident timeline.
Dutch telecom Odido hacked, 6 million accounts affected Defence Masterclass
Scenario-led awareness training based on a real-world incident timeline.
Wynn hit with more class-action lawsuits after data breach - Las Vegas News
Built for ['Security Analyst: To develop advanced detection rules and understand the full lifecycle of a data breach for faster containment.', 'IT Administrator: To learn infrastructure hardening techniques and access control measures that directly prevent unauthorised data exfiltration.', 'Data Protection Officer / Compliance Manager: To map incident response actions to GDPR, NIS2, and other regulatory requirements, managing legal and reporting obligations.'].
Hackers abused Cisco SD-WAN zero-day since 2023 to gain full admin control
Built for ['Network Security Engineer: To understand the specific exploitation techniques against SD-WAN platforms and learn how to harden network device configurations and segmentation.', 'SOC Analyst (Tier 2/3): To develop advanced detection strategies for identifying anomalous administrative activity and lateral movement stemming from compromised network controllers.', 'IT Infrastructure Manager: To gain insights into vendor risk management, patch prioritisation, and implementing defensive architectural controls like Zero Trust to mitigate such infrastructure attacks.'].
Google Disrupts ‘Prolific’ and ‘Elusive’ China-Linked Global Hacking Campaign
Built for ['Security Operations Centre (SOC) Analyst: To enhance their ability to detect subtle indicators of a sophisticated, low-and-slow attack within their environment using advanced SIEM queries and endpoint data.', 'Incident Response Manager: To develop and refine playbooks specifically for handling prolonged, stealthy intrusions involving compromised credentials and custom malware, ensuring a coordinated response.', 'Information Security Officer: To understand the strategic implications of state-sponsored threats, communicate risk to leadership effectively, and align defensive investments with frameworks like NIST CSF and ISO 27001.'].
The 48-Hour Rule in Motion
From incident alert to deployed learning package in an average of 18.5 hours.
Train from what just happened, not what happened last year.
IntelXview gives security leaders a practical way to respond to new threat patterns with actionable learning while teams still remember why it matters.
The next breach will not wait for your annual cycle.
Launch incident-triggered training workflows now and move your awareness program from static compliance to active defense.