Incident-as-a-Service
73% retention vs 12% is a timing problem, not a content problem.
Incident-triggered lessons arrive while attention is highest. Your team learns from real events in near real-time, not from stale annual modules.
*6-month retention benchmark: incident-driven training (73%) compared with annual compliance training (12%) in a 2,800-employee study.
Or create a free account — no credit card required.
Latest Incident-Based Courses
Search the active catalogue and launch immediately from the incidents most relevant to your teams.
556 courses available
Racism in the House, cybersecurity hack and Resource Management Act | Herald NOW
Built for ['Security Analyst: To develop advanced detection techniques and hands-on response skills for data exfiltration incidents.', 'IT Administrator: To learn infrastructure hardening and access control implementation to prevent initial breach vectors.', 'Compliance Officer: To understand how technical controls map to frameworks like GDPR and NIS2, enabling better audit and reporting.'].
230000 Australian driver licences exposed in ransomware attack on vehicle finance firm
Built for ['Security Analyst: Will benefit by learning to identify ransomware indicators and craft specific SIEM detection rules to prevent data exfiltration.', 'IT Administrator: Will gain critical knowledge on infrastructure hardening, network segmentation, and access controls to protect sensitive data stores from similar attacks.', 'Compliance Officer: Will learn to map the technical details of this incident to regulatory obligations under GDPR, NIS2, and other frameworks to improve audit and reporting processes.'].
Zero-click hack exposes flaw in Orchids vibe coding platform - Information Week
Built for ['Cloud Security Engineer: They will benefit by learning how to secure cloud-based development platforms (like Orchids) against sophisticated exploits and implement zero-trust controls in CI/CD pipelines.', 'Security Analyst (SOC): They will gain critical skills in detecting the subtle indicators of a zero-click compromise and crafting precise SIEM rules to catch similar attacks before data exfiltration occurs.', 'DevSecOps Practitioner: They will learn to integrate security controls directly into the development lifecycle, focusing on hardening coding platforms and libraries to prevent supply chain attacks exemplified by this incident.'].
Mississippi Medical Center Clinics Still Closed After Attack - GovInfoSecurity
Built for ['Healthcare IT Administrators: They will benefit by understanding the specific targeting of medical facilities and learn to harden clinical environments against operational disruption.', 'Security Operations Centre (SOC) Analysts: They will gain skills to craft and tune detection rules for ransomware behaviour, improving mean time to detection and response.', 'Information Security Managers/CISOs: They will learn to communicate ransomware risk to leadership, build effective response playbooks, and map controls to compliance requirements like NIST CSF and GDPR.'].
Lazarus Group Picks a New Poison: Medusa Ransomware - Dark Reading
Built for ['Security Analyst: Will benefit by learning to craft specific detection rules for Medusa ransomware and similar APT-linked campaigns, enhancing their threat hunting capabilities.', "Incident Responder: Will gain a detailed playbook for responding to sophisticated ransomware incidents, including containment and eradication steps tailored to this threat actor's behaviour.", 'IT Security Manager/CISO: Will learn to communicate the business risk of such attacks to leadership and map defensive controls to key compliance frameworks like NIS2 and DORA for regulatory readiness.'].
Cyber attack on health platform Mediamap - NZ Herald
Built for ['Security Analysts and SOC Engineers who need to build detection logic and respond to data breach incidents involving sensitive information.', 'IT Administrators and Network Engineers in healthcare organisations responsible for hardening infrastructure against the specific attack vectors demonstrated in this case.', 'Compliance Officers and Risk Managers who must understand the technical details of an attack to accurately map controls to frameworks like GDPR, NIST CSF, and DORA.'].
'Our focus is not politicising this incident': Director of Medimap speaks on data breach
Built for ['Security Analyst: Will benefit by learning to trace the attack chain of a data breach, identify key indicators of compromise, and develop effective SIEM detection rules to catch similar activity early.', 'IT Administrator / System Engineer: Will gain critical knowledge on hardening authentication systems, implementing principle of least privilege access controls, and applying network segmentation to limit the blast radius of a breach.', 'Compliance Officer / Data Protection Officer: Will learn to map the technical and procedural failures of the incident to specific articles within GDPR, NIS2, and other frameworks, strengthening audit readiness and regulatory reporting processes.'].
Hackers threaten to leak 8 million people's stolen data if Dutch telecom Odido won't pay ransom
Built for ['Security Analyst: Will benefit by learning to identify the specific indicators of compromise and detection strategies for data exfiltration and extortion attacks, directly enhancing their threat-hunting capabilities.', 'IT Administrator / System Engineer: Will gain crucial knowledge on infrastructure hardening, access control, and network segmentation to prevent initial access and lateral movement used in such attacks.', "Compliance Officer / Data Protection Officer: Will learn to map the incident's lessons to key regulatory requirements like GDPR and NIS2, helping to demonstrate due diligence and improve organisational compliance reporting."].
Cyber attack on health platform Mediamap | Herald NOW - YouTube
Built for ['Security Analyst: Will benefit by learning to craft specific detection rules and response playbooks for healthcare-related cyber attacks, enhancing their threat-hunting capabilities.', 'IT Administrator in Healthcare: Will gain crucial insights into hardening health platform infrastructure against the specific attack vectors demonstrated in the Mediamap case, directly improving organisational defence.', 'Compliance Officer: Will learn to map incident findings to controls within frameworks like GDPR and NIST CSF, ensuring regulatory requirements are met and audit readiness is improved.'].
Ashley Madison pivots to shake cyberattack ghost, promises privacy this time - Cybernews
Built for ['Security Analyst: Will benefit by learning to craft specific detection rules for data exfiltration patterns and understanding the full lifecycle of a breach to improve monitoring and initial response.', 'IT Administrator / System Engineer: Will gain critical insights into infrastructure hardening, access control implementation, and secure configuration to prevent the initial compromise that leads to data breaches.', 'Data Protection Officer / Compliance Manager: Will learn to map technical controls to regulatory requirements (like GDPR) and develop communication strategies for managing breach notifications and vendor risks.'].
Marquis sues firewall provider SonicWall, alleges security failings with its firewall backup led ...
Built for ['Network Security Administrators: They will benefit by learning how to securely configure and monitor critical network security appliances like firewalls, moving beyond default settings to mitigate the specific risks highlighted in the case study.', 'IT Risk & Compliance Officers: This course will equip them to better assess and manage third-party vendor security, map controls to frameworks like NIST CSF and GDPR, and articulate technical risks to leadership in the context of legal and regulatory obligations.', 'Security Operations Centre (SOC) Analysts: They will gain crucial context on how to craft detection rules for anomalies in firewall management and backup systems, and develop playbooks for responding to incidents stemming from compromised security infrastructure.'].
UAC-0050 Targets European Financial Institution With Spoofed Domain and RMS Malware
Built for ['Security Analyst: Will benefit from learning specific IOCs and SIEM detection strategies to improve monitoring and early threat identification in their Security Operations Centre (SOC).', 'Incident Responder: Will gain practical skills from the detailed attack breakdown and customisable response playbook, enabling faster and more effective containment and eradication during a live malware incident.', 'IT Security Manager / CISO: Will learn how to communicate the business risk of such attacks to leadership, map controls to frameworks like DORA and NIS2, and justify investments in defensive infrastructure and security awareness programmes.'].
Anthropic Claims Chinese AI Firms 'Distilled' Claude to Train Their Models - Hackread
Built for ['AI/ML Security Engineer: To understand specific attack vectors against machine learning pipelines and implement controls to safeguard model integrity and training data.', 'Cloud Security Architect: To design and harden cloud environments (e.g., AWS, Azure) where AI development occurs, applying zero trust principles to prevent unauthorised data access and exfiltration.', "Data Protection Officer (DPO): To map the incident's implications to regulatory obligations under GDPR and other data protection regimes, ensuring organisational processes address model theft as a data breach."].
Greater Pittsburgh Orthopaedic Associates disclosed a 2025 breach, but was there also one in 2024?
Built for ['Healthcare Security Analyst: To understand the specific threats and regulatory pressures (like HIPAA/GDPR) in the medical sector and learn to detect subtle signs of long-dwell-time breaches.', 'IT Administrator in a SME: To implement the practical, cost-effective defensive controls and segmentation strategies taught, directly reducing the risk of a similar catastrophic breach.', "Compliance Officer: To map the incident's fallout to framework requirements (NIST CSF, GDPR) and build a stronger case for security investments and improved vendor risk management processes."].
Multifaceted Phishing Scheme Deceives Bitpanda Customers
Built for ['Security Analyst / SOC Analyst: To enhance their ability to detect subtle phishing campaign indicators in logs and user reports, and to craft precise detection rules.', 'IT Administrator / System Engineer: To understand how to harden authentication systems, implement email security controls, and configure defences at the infrastructure level to prevent credential harvesting.', 'Information Security Manager / CISO: To develop comprehensive incident response playbooks, communicate risk to leadership effectively, and ensure organisational controls meet compliance obligations like DORA and NIS2.'].
Amazon: Low-Skill Hacker Used AI Tools to Breach FortiGate Devices Globally - Hackread
Built for ['Network Security Administrator: To understand the specific configuration weaknesses and hardening techniques for Fortinet and similar perimeter devices to prevent unauthorised access.', 'Security Operations Centre (SOC) Analyst: To learn the specific SIEM detection rules and behavioural indicators for identifying AI-assisted scanning and exploitation attempts against network infrastructure.', 'IT Risk & Compliance Officer: To map the technical vulnerabilities and breach outcomes to specific controls within major frameworks like NIST CSF and ISO 27001, enabling effective audit and reporting.'].
Russian hackers target European firms with new spear-phishing cyberattacks - TechRadar
Built for ['Security Analyst: To gain deep technical insight into spear-phishing TTPs and learn to craft effective SIEM detection rules for early identification of similar campaigns.', "IT Administrator: To understand how to implement and configure email security gateways, multi-factor authentication, and other technical controls to harden the organisation's defence against credential theft.", 'CISO / Information Security Manager: To develop board-level communication strategies, integrate incident response with compliance requirements (like NIS2 and GDPR), and build a comprehensive security awareness programme.'].
NYC transit workers hit by Qilin ransomware - thousands of members possibly affected
Built for ['Security Analyst: Will benefit by learning to identify ransomware-specific indicators of compromise (IoCs) and craft effective SIEM detection rules to catch similar attacks early in the kill chain.', 'IT Administrator / System Administrator: Will gain crucial knowledge on infrastructure hardening, privilege access management, and backup strategies to prevent ransomware propagation and enable swift recovery.', 'CISO / Security Manager: Will learn to articulate ransomware risks to the board, integrate incident response with compliance obligations (like NIS2 and GDPR), and build a organisational culture of resilience against such threats.'].
Lazarus hackers adopt Medusa ransomware for extortion campaigns, targeting healthcare ...
Built for ['Security Analyst: Will benefit by learning to craft specific detection rules for Medusa ransomware and Lazarus group tactics, improving their threat hunting and monitoring capabilities.', 'IT Administrator / System Engineer: Will gain critical knowledge on hardening authentication systems and implementing network segmentation to prevent lateral movement, directly applicable to daily infrastructure management.', 'CISO / Security Manager: Will learn to communicate the business impact of such breaches to leadership and map defensive controls to key compliance frameworks like NIS2 and GDPR, strengthening organisational governance.'].
Conduent data breach grows, affecting at least 25M people | TechCrunch
Built for ['Security Analysts and Engineers who need to understand the technical indicators and detection methods for data exfiltration attacks to improve their monitoring and defence capabilities.', 'IT Administrators and System Architects responsible for infrastructure hardening, who will benefit from learning specific access control and network segmentation techniques to prevent unauthorised data access.', 'Information Security Managers and CISOs who must oversee vendor risk programmes and communicate security posture to leadership, gaining insights into compliance mapping and organisational readiness strategies.'].
North Korean Lazarus Group Expands Ransomware Activity With Medusa
Built for ['Security Analyst: To develop advanced detection rules for SIEM/EDR platforms and understand the specific Indicators of Compromise (IoCs) associated with state-sponsored ransomware.', 'Incident Responder: To build and refine ransomware-specific incident response playbooks based on the documented tactics, techniques, and procedures (TTPs) of the Lazarus Group.', 'IT Administrator / System Engineer: To learn infrastructure hardening techniques, such as authentication policies and network segmentation, that directly mitigate the initial access vectors used in this campaign.'].
Lazarus Group Uses Medusa Ransomware in Middle East and U.S. Healthcare Attacks
Built for ['Security Analyst: Will benefit from learning specific Indicators of Compromise (IoCs) and SIEM detection rules to identify and triage similar ransomware activity in their environment.', 'Incident Response Manager: Will gain a detailed playbook template and forensic analysis techniques tailored to a sophisticated, state-sponsored ransomware attack, improving response efficacy.', 'IT Administrator / System Engineer: Will learn critical infrastructure hardening techniques, such as network segmentation and authentication controls, to prevent lateral movement and initial access used in this campaign.'].
Data Breach at Fintech Company Figure Technology Solutions Impacts Nearly 1 Million People
Built for ['Security Analyst: Will benefit by learning to craft specific detection rules and analyse indicators of compromise from a real-world data breach.', 'IT Administrator: Will gain crucial knowledge on implementing infrastructure hardening controls, such as access management and network segmentation, to prevent data exfiltration.', 'Compliance Officer: Will learn to map incident details to key compliance requirements (GDPR, DORA, SOC 2) for more accurate risk assessment and reporting to leadership.'].
US healthcare breach affects 140k, experts warn against replicating humans, Shai-Hulud ...
Built for ['Security Analyst: Will benefit by learning to identify specific indicators of compromise (IoCs) from this breach and apply detection rules in their SIEM to catch similar attacks early.', 'IT Administrator: Will gain crucial knowledge on hardening authentication systems and implementing network segmentation to prevent lateral movement following an initial breach.', 'Compliance Officer: Will learn how to map the technical and procedural lessons from this incident to key compliance requirements like GDPR and HIPAA, strengthening audit readiness.'].
Conduent Data Breach Becomes Largest in U.S. History After Ransomware Group Steals 8 TB
Built for ['Security Analyst: To deepen technical skills in detecting data exfiltration patterns and analysing IoCs from a real-world mega-breach.', 'Incident Response Manager: To develop and refine playbooks specifically for ransomware-driven data theft incidents and improve coordination strategies.', 'IT Administrator / System Engineer: To learn infrastructure hardening techniques, such as network segmentation and access control, critical for preventing lateral movement and data access.'].
Shai-Hulud-style NPM worm hits CI pipelines and AI coding tools
Built for ['DevSecOps Engineer: To understand how to secure CI/CD toolchains and implement security gates against malicious package dependencies.', 'Cloud Security Analyst: To learn detection strategies for anomalous behaviour in cloud-based development environments and build relevant SIEM rules.', 'Application Security Manager: To develop organisational policies for software composition analysis and vendor risk management for open-source repositories.'].
Everest ransomware hits Vikor Scientific 's supplier, data of 140,000 patients stolen
Built for ['Security Analyst: To gain practical skills in detecting ransomware activity, particularly through supply chain compromises, and to develop effective SIEM detection rules.', 'IT Administrator/Engineer: To learn infrastructure hardening techniques, such as network segmentation and access control, that prevent lateral movement following a supplier breach.', 'Compliance Officer/Risk Manager: To understand how this incident maps to regulatory obligations under GDPR, NIS2, and other frameworks, and to strengthen vendor risk management programmes.'].
Solana DeFi platform Step Finance shuts down after hack - TradingView
Built for ['Blockchain/DeFi Security Analyst: To understand the specific attack vectors against smart contracts and decentralised applications, enabling them to build better detection rules and audit procedures.', 'Cloud Security Engineer: To learn how infrastructure misconfigurations and identity compromises in cloud environments can be leveraged in cross-chain attacks, informing their hardening strategies.', 'IT Risk & Compliance Officer: To map the technical details of the incident to regulatory obligations under DORA, NIS2, and GDPR, facilitating accurate risk assessments and reporting to leadership.'].
NZ health app MediMap hack: Patients renamed 'Charlie Kirk' and marked as dead | rova
Built for ['Security Analyst: To gain practical skills in detecting and responding to data integrity attacks within application environments, using real-world indicators of compromise.', 'IT Administrator / System Owner: To understand how to harden application and database infrastructure, implement least-privilege access, and prevent unauthorised data modification.', 'Data Protection Officer / Compliance Manager: To learn how to map incident response actions to GDPR, NIS2, and other regulatory requirements for breach reporting and mitigation.'].
McClallen Law Data Breach Investigation - Strauss Borrelli PLLC
Built for ['Security Analyst: Will benefit by learning to craft specific SIEM detection rules and identify IOCs from a real data breach, enhancing their threat hunting capabilities.', 'IT Administrator / System Engineer: Will gain crucial insights into hardening authentication systems and implementing network segmentation to prevent lateral movement following an initial breach.', 'Compliance Officer / Risk Manager: Will learn to map incident findings to major regulatory frameworks like GDPR and NIS2, strengthening audit readiness and vendor risk management programmes.'].
Hackers threatening to leak 8 million people's stolen data if Odido won't pay ransom
Built for ['Security Analyst: Will benefit by learning to identify early indicators of data exfiltration and extortion campaigns, and how to craft precise SIEM detection rules.', 'IT Administrator / System Engineer: Will gain critical knowledge on hardening authentication systems and implementing network segmentation to contain similar breaches.', 'Compliance Officer / GRC Analyst: Will learn to map the technical details of the attack to specific controls in frameworks like GDPR and NIS2, strengthening audit and reporting processes.'].
MediMap hack investigation after patients wrongly marked dead, names changed
Built for ['Healthcare Security Analysts: They will benefit by understanding the specific tactics used to compromise patient data integrity and learn to craft detection rules for Electronic Health Record (EHR) system anomalies.', 'Incident Response Managers: They will gain a framework for responding to data corruption incidents, focusing on forensic collection, communication strategies, and rapid data restoration to ensure business continuity.', 'Compliance Officers (GDPR, HIPAA): They will learn to map the technical controls and response actions from this incident directly to regulatory requirements, strengthening audit readiness and demonstrating due diligence.'].
Russian group uses AI to exploit weakly-protected Fortinet firewalls, says Amazon
Built for ['Network Security Engineer: To understand the specific hardening requirements for Fortinet and other firewalls to prevent credential compromise and lateral movement.', 'Security Operations Centre (SOC) Analyst: To learn the specific SIEM detection rules and behavioural indicators for identifying AI-facilitated reconnaissance and exploitation attempts.', 'IT Administrator/Systems Engineer: To implement secure configuration baselines, patch management strategies, and access controls for network devices to reduce the attack surface.'].
CarGurus remains 'fully operational' despite falling victim to 'cybersecurity incident'
Built for ['Security Analyst: To gain practical skills in detecting and analysing similar attack patterns, enhancing their threat hunting and investigation capabilities.', 'IT Administrator: To understand how to harden infrastructure and implement defensive controls that could prevent or contain a similar breach in their environment.', 'CISO / Security Manager: To develop strategic insights for board-level communication, incident response planning, and aligning security programmes with major compliance frameworks like NIS2 and DORA.'].
North Korea–Tied Operators Sustain Aggressive Crypto Targeting Campaign - Cyber Press
Built for ['Security Analyst: To deepen their understanding of APT tradecraft and improve their ability to detect and investigate sophisticated data exfiltration attempts.', 'Incident Response Manager: To develop and refine playbooks for responding to state-sponsored attacks, ensuring a coordinated and effective organisational response.', 'IT Administrator in a FinTech/Crypto firm: To implement the specific infrastructure hardening and access controls taught in the course to defend against this direct threat to their industry.'].
Data Breaches in 2026: What's old, what's new? - Hackread
Built for ['Security Analyst: Will gain practical skills in detecting breach indicators and using SIEM tools to hunt for similar attack patterns within their own environment.', 'IT Administrator: Will learn to implement specific infrastructure hardening measures, such as network segmentation and access control, to prevent initial intrusion and lateral movement.', 'Compliance/Risk Manager: Will benefit from understanding how technical controls map to frameworks like GDPR and NIST CSF, enabling more accurate risk assessments and reporting to leadership.'].
The 48-Hour Rule in Motion
From incident alert to deployed learning package in an average of 18.5 hours.
Train from what just happened, not what happened last year.
IntelXview gives security leaders a practical way to respond to new threat patterns with actionable learning while teams still remember why it matters.
The next breach will not wait for your annual cycle.
Launch incident-triggered training workflows now and move your awareness program from static compliance to active defense.