Incident-as-a-Service
73% retention vs 12% is a timing problem, not a content problem.
Incident-triggered lessons arrive while attention is highest. Your team learns from real events in near real-time, not from stale annual modules.
*6-month retention benchmark: incident-driven training (73%) compared with annual compliance training (12%) in a 2,800-employee study.
Or create a free account — no credit card required.
Latest Incident-Based Courses
Search the active catalogue and launch immediately from the incidents most relevant to your teams.
556 courses available
Dutch telco refuses to pay ransom, hackers to publish customer data - Techzine Global
Built for ['Security Analyst: Will benefit by learning to identify early indicators of ransomware campaigns and how to craft effective SIEM detection rules based on real-world tactics.', "Incident Response Manager: Will gain critical insights into managing a 'refuse-to-pay' ransomware scenario, including stakeholder communication and executing a compliant response playbook.", 'CISO/IT Director: Will learn to articulate the business and legal risks of data extortion to the board, and how to align security controls with frameworks like DORA and NIS2 for regulatory compliance.'].
Cisco Patches Catalyst SD-WAN Zero-Day Exploited by Highly Sophisticated Hackers
Built for ['Network Security Engineer: They will benefit by learning how to harden SD-WAN deployments and implement detection mechanisms for infrastructure-level attacks.', 'SOC Analyst: They will gain critical skills in recognising Indicators of Compromise (IoCs) and crafting SIEM detection rules specific to sophisticated network device exploitation.', 'Cybersecurity Manager/CISO: They will learn to communicate risk to leadership, integrate lessons into vendor risk management programmes, and align controls with compliance requirements like NIS2 and DORA.'].
China-linked hackers used Google Sheets to spy on telecoms and governments across 42 countries
Built for ['Security Analyst: To learn specific detection rules for cloud-based C2 traffic and analyse IOCs from a real-world espionage campaign.', 'IT Administrator: To understand how to harden cloud application configurations and implement access controls to prevent abuse of legitimate services.', 'GRC Consultant: To map the technical controls and response procedures from this incident to compliance requirements like NIS2 and GDPR for client advisories.'].
Microsoft Warns Developers of Fake Next.js Job Repos Delivering In-Memory Malware
Built for ['Security Analysts/SOC Engineers: To build detection rules for in-memory malware and understand the indicators of compromise specific to software supply chain attacks.', 'DevSecOps Engineers & Application Security Specialists: To learn how to harden development pipelines, vet third-party dependencies, and implement controls against poisoned repositories.', 'IT Administrators & Infrastructure Engineers: To implement network and endpoint defences that mitigate the lateral movement and persistence mechanisms used by such malware.'].
Google GTIG disrupted China-linked APT UNC2814 halting attacks on 53 orgs in 42 countries
Built for ['Threat Intelligence Analyst: To deepen understanding of APT campaign analysis, attribution techniques, and how to operationalise intelligence for proactive defence.', 'Security Operations Centre (SOC) Analyst: To learn specific detection strategies and Indicators of Compromise (IoCs) from a real campaign, enhancing their ability to identify and respond to similar attacks.', 'Chief Information Security Officer (CISO): To gain strategic insights into communicating APT risks to the board, managing vendor risks in a supply-chain attack context, and aligning incident response with compliance mandates like NIS2 and DORA.'].
Rethinking Security in the AI Era with the Agentic SOC - Cybersecurity Insiders
Built for ['Security Analyst: Will gain practical skills in detecting and analysing the specific tactics, techniques, and procedures (TTPs) used in the featured attack, directly enhancing their threat-hunting capabilities.', "SOC Manager/Engineer: Will learn to architect and tune detection logic for an 'Agentic SOC', improving their team's operational efficiency and response times against automated threats.", 'CISO/Compliance Officer: Will benefit from the clear mapping of defensive controls to regulatory frameworks like DORA and NIS2, aiding in risk communication and audit preparedness.'].
New UAC-0050 social engineering campaign discovered | SC Media
Built for ['Security Analyst: To develop advanced detection capabilities for social engineering lures and understand the technical indicators left by credential harvesting campaigns.', 'IT Administrator: To learn how to harden authentication systems and implement technical controls that mitigate the impact of successful social engineering attempts.', 'CISO/Security Manager: To gain strategic insight into building a human-centric security culture and communicating the business risk of social engineering to leadership and the board.'].
Google catches China exploiting its Sheets to launch cyber attacks on US Orgs
Built for ['Cloud Security Analyst: Will benefit by learning to detect anomalous behaviour within sanctioned SaaS applications like Google Workspace, moving beyond traditional infrastructure monitoring.', 'SOC Analyst (Tier 2/3): Will gain critical skills in hunting for IOCs related to living-off-the-land attacks in cloud services and implementing new SIEM detection rules.', 'Information Security Manager / CISO: Will learn to communicate the business risk of SaaS-based attacks to leadership and align defensive controls with organisational compliance objectives (NIST CSF, ISO 27001).'].
Who Operates the Badbox 2.0 Botnet?
Built for ['Security Analyst: To develop advanced detection rules for SIEM/EDR platforms and gain hands-on experience with botnet-related IoCs.', 'IT Administrator: To understand how to harden network infrastructure against device-based threats and implement effective segmentation controls.', 'CISO/Risk Manager: To learn how to frame the business impact of such breaches for board-level communication and map controls to key compliance frameworks like NIS2 and GDPR.'].
Ransomware Attack Traced Back to January 2026 | Social Security & Medical Data Compromised
Built for ['Security Analyst: Will benefit by learning specific detection rules for data exfiltration patterns and how to analyse IoCs from a real breach to improve monitoring efficacy.', 'Incident Response Manager: Will gain from developing and testing detailed playbooks for data breach scenarios, ensuring a coordinated and legally compliant response to ransomware and data theft.', 'IT Administrator / System Engineer: Will learn infrastructure hardening techniques, such as network segmentation and access control, crucial for preventing lateral movement and limiting data exposure during an attack.'].
Adelup: GovGuam recovers $1.6M stolen in cyber attack that targeted Judiciary, DOA | News
Built for ['Security Analyst: Will benefit by learning to identify the specific IoCs and TTPs used in this data breach to enhance monitoring and detection rules in their SIEM/EDR platforms.', 'IT Administrator: Will gain practical knowledge on hardening authentication systems, implementing network segmentation, and applying principle of least privilege to prevent lateral movement observed in the attack.', "Compliance Officer: Will learn how to map the incident's lessons and subsequent controls to key compliance requirements (GDPR, NIS2, SOC 2), strengthening audit readiness and regulatory alignment."].
Clalit probes suspected cyberattack after Iranian-linked hackers leak patient files
Built for ['Healthcare Security Analyst: To understand the specific threats to patient data and learn tailored detection and response strategies for the healthcare environment.', 'Incident Response Manager: To develop and refine playbooks for responding to data breach incidents involving nation-state actors and sensitive data leaks.', 'IT Compliance Officer: To map the technical controls and response actions from this incident to key compliance requirements like GDPR, NIS2, and HIPAA.'].
Medical Device Maker Reports Data Theft Hack to SEC
Built for ['Security Analyst: They will benefit by learning to craft specific SIEM detection rules and analyse IoCs from a real healthcare data breach, directly improving their threat hunting capabilities.', 'IT Administrator in Healthcare/Manufacturing: They will gain critical insights into hardening network infrastructure and implementing access controls to protect sensitive data and connected devices, which is central to their role.', 'Compliance Officer: This course will help them map technical incidents to regulatory requirements like GDPR and SEC rules, enabling more accurate risk assessments and reporting to leadership.'].
China-linked hackers breach dozens of telecoms, government agencies
Built for ['Security Analyst: To deepen threat hunting skills and learn to create specific detection rules for state-sponsored data breach campaigns.', 'IT Administrator / Network Engineer: To understand how to harden infrastructure, implement network segmentation, and manage access controls to prevent lateral movement observed in the incident.', 'Compliance Officer / Risk Manager: To map the technical details of the attack to regulatory requirements (e.g., NIS2, GDPR) and build a compelling business case for security investments.'].
Iran-Linked Group Claims Hack of Israel's Largest Healthcare Network - Caspianpost.com
Built for ['Security Analyst: To gain practical skills in detecting and analysing data breach patterns using real-world indicators of compromise and SIEM strategies.', 'IT Administrator/Network Engineer: To learn infrastructure hardening techniques, such as network segmentation and access control, directly applicable to defending against credential-based attacks and lateral movement.', 'CISO/Risk Manager: To understand the strategic implications, board-level communication tactics, and compliance mapping required to justify investments and improve organisational resilience following a major breach.'].
Autonomous Endpoint Management Isn't Just Efficiency, It's a Security Imperative - Hackread
Built for ['Security Operations Centre (SOC) Analysts - They will benefit by learning to craft precise detection rules for anomalous administrative tool behaviour and integrating these threats into their incident response playbooks.', 'IT Infrastructure and Endpoint Administrators - They will gain critical insight into securing the management tools they use daily, understanding how misconfigurations can be exploited, and implementing hardening measures aligned with zero trust.', 'Cybersecurity Compliance Officers - They will learn to map the technical controls and processes discussed directly to evidence requirements for frameworks like NIST CSF, ISO 27001, and GDPR, strengthening audit readiness.'].
PowerSchool, Chicago Public Schools to settle student data privacy lawsuit for $17 million
Built for ['Data Protection Officer (DPO): To understand the specific legal and regulatory fallout from a student data breach, including GDPR and FERPA implications, and to strengthen vendor risk management programmes.', 'Security Analyst: To gain hands-on skills in detecting data exfiltration patterns and developing SIEM rules and incident response playbooks based on a real-world case study.', 'IT Administrator in Education: To learn infrastructure hardening techniques specific to protecting student information systems (SIS) and implementing access controls in a highly sensitive environment.'].
Court to hear motions relating to HSE cyber victims - RTE
Built for ['Security Analyst: Will benefit by learning to craft specific detection rules and response playbooks for ransomware and disruptive attacks, directly improving their threat-hunting capabilities.', 'IT Administrator (Healthcare/Public Sector): Will gain crucial insights into hardening infrastructure against the specific tactics used in the HSE attack, with a focus on maintaining service availability under duress.', 'Compliance & Risk Officer: Will learn to map incident lessons to control requirements in frameworks like NIS2 and GDPR, strengthening audit readiness and regulatory reporting processes.'].
Hacker Used Anthropic's Claude to Steal Sensitive Mexican Data - Bloomberg.com
Built for ['Security Analysts and SOC Engineers: They will benefit by learning to craft specific detection rules for AI-augmented social engineering and data exfiltration, enhancing their threat-hunting capabilities.', "Incident Response Managers: They will gain a ready-made playbook and forensic analysis techniques tailored to breaches involving AI tools, improving their team's response efficacy and evidence collection.", 'Information Security Officers (CISOs/ISOs): They will learn to communicate AI-specific risks to leadership, map controls to key compliance frameworks, and strengthen organisational policies around third-party AI usage.'].
CarGurus data breach affects 12.5 million accounts - TechCrunch
Built for ['Security Analyst: Will benefit by learning to craft specific detection rules and analyse indicators of compromise from a real-world data breach to improve monitoring efficacy.', 'IT Administrator: Will gain practical knowledge on implementing infrastructure hardening controls, such as authentication and network segmentation, to prevent unauthorised data access.', "Compliance Officer: Will learn to map the incident's technical and procedural failures to major compliance frameworks like GDPR and NIST CSF, strengthening audit and reporting processes."].
Cyberattack on Russian Military Targets Hundreds of Devices, Exposing Key Military Data
Built for ['Security Analyst: Will benefit by learning to craft specific detection rules and analyse IoCs from a real-world data breach to improve monitoring and threat hunting capabilities.', 'IT Administrator: Will gain crucial knowledge on implementing the defensive controls and hardening techniques (like network segmentation) that could have prevented the widespread device compromise seen in the incident.', 'CISO/ Security Manager: Will learn to communicate risk effectively to leadership, integrate lessons into organisational policy, and map response actions to major compliance frameworks like NIS2 and GDPR.'].
SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks
Built for ['Security Analyst / SOC Analyst: To develop advanced detection rules for social engineering lures and improve incident triage and response procedures for vishing incidents.', 'IT Help Desk Manager / Administrator: To understand the specific tactics used against help desk functions, implement verification protocols, and train staff to recognise and resist social engineering attempts.', 'Information Security Manager / CISO: To assess organisational vulnerability to similar campaigns, justify security awareness investments to leadership, and ensure controls map to key compliance obligations like NIS2 and GDPR.'].
Malicious NuGet Packages Stole ASP.NET Data; npm Package Dropped Malware
Built for ['Security Analyst: Will benefit by learning to craft specific SIEM/SOAR detection rules for malicious package behaviour and analysing IoCs from software repositories.', 'DevSecOps Engineer: Will gain critical skills to harden CI/CD pipelines, implement software composition analysis (SCA), and enforce secure coding practices to prevent supply chain compromise.', 'CISO / Security Manager: Will learn to communicate the business risk of supply chain attacks to leadership, map controls to compliance mandates like DORA and NIS2, and build organisational readiness programmes.'].
Patient Names Changed To Charlie Kirk In Major Medical Hack In New Zealand - NDTV
Built for ['Security Analyst: Will benefit by learning specific detection rules for unauthorised data modification and how to investigate similar integrity breaches within SIEM/EDR tools.', 'IT Administrator (Healthcare): Will gain critical insights into hardening patient database access controls, implementing audit logging, and applying segmentation to protect sensitive health information.', 'Data Protection Officer / Compliance Manager: Will learn how to map this incident to key compliance requirements like GDPR and HIPAA, and develop communication strategies for regulatory reporting and patient notification.'].
Cyber attack on health platform Medimap - NZ Herald
Built for ['Security Analyst: Will benefit by learning to craft specific detection rules for web application attacks and third-party compromise, directly improving SOC monitoring capabilities.', 'IT Administrator: Will gain crucial knowledge on hardening web servers, implementing network segmentation, and managing vendor access to prevent similar infrastructure breaches.', "Compliance Officer: Will learn to map the incident's technical and procedural failures to major frameworks like GDPR and NIS2, strengthening organisational audit and compliance postures."].
Cybersecurity MediMap hack - Ryan Bridge TODAY - NZ Herald
Built for ['Security Analyst: Will benefit by learning to craft specific SIEM detection rules and analyse Indicators of Compromise (IoCs) from a real-world data breach.', 'IT Administrator: Will gain crucial knowledge on hardening authentication systems and implementing network segmentation to prevent lateral movement post-breach.', 'Compliance Officer: Will learn to map incident findings to frameworks like GDPR and NIS2 to demonstrate regulatory due diligence and improve audit readiness.'].
Hacker knackt 600 Firewalls in einem Monat – mit KI
Built for ['Security Analyst: Will benefit by learning to craft specific detection rules for AI-driven firewall attacks and understanding the attack lifecycle to improve threat hunting capabilities.', 'Network & Firewall Administrator: Will gain critical insights into hardening network perimeter devices against the specific exploitation techniques used in this campaign, directly applicable to their daily work.', 'IT Security Manager / CISO: Will learn to communicate the business risk of such attacks to leadership, map controls to compliance requirements like NIS2 and DORA, and develop organisational playbooks.'].
Wynn Resorts hit with class action lawsuit over data breach - FOX5 Vegas
Built for ['Security Analyst: Will benefit by learning to craft specific detection rules and analyse indicators of compromise from a real data breach case, directly enhancing their threat hunting capabilities.', 'IT Administrator: Will gain critical insights into infrastructure hardening, access control implementation, and network segmentation to prevent the initial access and lateral movement often seen in data breaches.', 'Compliance Officer/Risk Manager: Will learn to map the technical details of the incident to regulatory requirements (GDPR, NIS2, etc.), improving their ability to assess organisational risk and communicate effectively with technical teams.'].
Hundreds of FortiGate Firewalls Hacked in AI-Powered Attacks: AWS - OODAloop
Built for ['Network Security Engineer: To understand the specific attack vectors against FortiGate devices and learn how to harden firewall configurations and implement effective patch management cycles.', 'Security Operations Centre (SOC) Analyst: To develop and apply detection strategies for identifying anomalous behaviour on network security appliances and streamline incident response procedures for such breaches.', 'IT Administrator/Manager: To comprehend the organisational risk posed by unpatched infrastructure, improve vendor risk management practices, and communicate security priorities effectively to leadership.'].
Russia starts criminal probe of Telegram founder Pavel Durov - Risky Biz News
Built for ['Security Analyst: Will benefit by learning to craft specific detection rules for data exfiltration and insider threat patterns revealed in this case study.', 'Data Protection Officer: Will gain critical insights into managing data sovereignty risks and aligning security controls with GDPR and other data protection regulations in a high-pressure incident.', 'IT Administrator: Will learn practical infrastructure hardening techniques, such as access control and network segmentation, to prevent unauthorised data access and lateral movement.'].
Fake Zoom meeting silently installs surveillance software, says Malwarebytes
Built for ['Security Analyst: Will gain practical skills in detecting malicious activity masquerading as legitimate collaboration tool traffic and creating actionable SIEM rules.', 'IT Administrator: Will learn to implement specific hardening controls for endpoint and application security to prevent the execution of surveillance software.', 'CISO / Risk Manager: Will benefit from understanding the business impact, crafting board-level communications, and mapping response controls to key compliance frameworks like NIS2 and GDPR.'].
Hacking Group Claims Theft of 12.4 Million CarGurus Records | PYMNTS.com
Built for ['Security Analyst: Will benefit by learning to craft specific detection rules and analyse indicators of compromise from a real-world data breach, directly improving threat hunting capabilities.', 'IT Administrator / System Engineer: Will gain crucial insights into infrastructure hardening, access control implementation, and network segmentation techniques to prevent credential theft and lateral movement.', 'Compliance Officer / GRC Analyst: Will learn to map the technical details of a breach to regulatory requirements (like GDPR and NIS2), enabling more effective risk assessments and control audits.'].
Burger King France, Wendy's UK allegedly hacked, data leaked - SC Media
Built for ['Security Analyst: Will benefit from learning specific Indicators of Compromise (IoCs) and SIEM detection rules to identify similar data exfiltration attempts early.', 'IT Administrator: Will gain practical knowledge on infrastructure hardening, access control implementation, and network segmentation to prevent initial access.', 'CISO / Risk Manager: Will learn how to communicate cyber risk to leadership, manage third-party vendor risk, and map incident response to compliance requirements like GDPR and NIS2.'].
Las Vegas-based Wynn Resorts target of cybersecurity breach - 8 News NOW
Built for ['Security Analyst: To deepen their understanding of data breach indicators and enhance their SIEM detection and triage capabilities.', 'IT Administrator/Engineer: To learn infrastructure hardening techniques, such as network segmentation and access control, directly applicable to preventing credential-based breaches.', 'Compliance Officer/Risk Manager: To understand how specific breach scenarios map to regulatory requirements like GDPR and NIS2, aiding in audit preparation and risk assessment.'].
Carolina Beach to host cyber security workshop after $488K cyber attack - WWAYTV3
Built for ['Municipal IT Directors/Managers: They will benefit by understanding the specific risks to public sector infrastructure and learning how to justify security investments to council leadership using real financial impact data.', 'Security Operations Centre (SOC) Analysts: They will gain practical skills in crafting detection rules for similar attack patterns and building effective incident response playbooks for financial fraud incidents.', "Compliance Officers: They will learn to map the technical controls discussed to major compliance frameworks like NIST CSF and GDPR, strengthening their organisation's audit posture and risk management programmes."].
Trenchant Exec Who Sold His Employer's Zero-Day Exploits to Russian Buyer Sentenced to ...
Built for ['Security Operations Centre (SOC) Analysts and Managers: They will learn to tune detection systems for anomalous user behaviour and correlate events indicative of intellectual property exfiltration.', 'Chief Information Security Officers (CISOs) and Security Leads: They will gain frameworks for building a holistic insider threat programme, communicating risk to the board, and aligning controls with organisational compliance objectives.', 'IT Administrators and System Architects: They will understand how to implement technical controls like Privileged Access Management (PAM), data loss prevention, and network segmentation to limit the damage a malicious insider can cause.'].
The 48-Hour Rule in Motion
From incident alert to deployed learning package in an average of 18.5 hours.
Train from what just happened, not what happened last year.
IntelXview gives security leaders a practical way to respond to new threat patterns with actionable learning while teams still remember why it matters.
The next breach will not wait for your annual cycle.
Launch incident-triggered training workflows now and move your awareness program from static compliance to active defense.