Incident-as-a-Service

73% retention vs 12% is a timing problem, not a content problem.

Incident-triggered lessons arrive while attention is highest. Your team learns from real events in near real-time, not from stale annual modules.

73% vs 12% Retention
847 Organisations
18.5h Breach to Training

*6-month retention benchmark: incident-driven training (73%) compared with annual compliance training (12%) in a 2,800-employee study.

Or create a free account — no credit card required.

Latest Incident-Based Courses

Search the active catalogue and launch immediately from the incidents most relevant to your teams.

556 courses available

Available Now

600+ FortiGate Devices Hacked by AI-Armed Amateur

Built for ['Network Security Engineer: To understand the specific vulnerabilities and hardening techniques for FortiGate and similar perimeter devices, directly applying lessons to protect critical infrastructure.', 'Security Operations Centre (SOC) Analyst: To learn the specific Indicators of Compromise (IoCs) and detection strategies for this ransomware campaign, enabling faster and more accurate threat identification.', 'IT Administrator/Manager: To implement the defensive controls and organisational policies covered in the course, reducing the attack surface and improving overall security posture against ransomware.'].

Available Now

Largest Data Breach in U.S. History As Ransomware Group Stolen 8 TB of Data

Built for ['Security Analyst: Will benefit by learning to craft specific detection rules for data exfiltration and analyse the technical indicators from a real-world mega-breach.', 'Incident Response Manager: Will gain critical insights into building and testing playbooks for large-scale data breach scenarios, improving organisational readiness and response times.', 'IT Administrator / System Engineer: Will learn infrastructure hardening techniques, such as network segmentation and access control, directly informed by the attack vectors used in the incident.'].

Available Now

CSA Tax Data Breach Investigation - Strauss Borrelli PLLC

Built for ['Security Analyst: To develop advanced detection strategies for data exfiltration and learn to create actionable threat intelligence from breach reports.', 'IT Administrator / System Engineer: To understand infrastructure hardening techniques, including access control and network segmentation, to prevent unauthorised data access.', 'Compliance Officer / Risk Manager: To learn how to map specific breach scenarios to control requirements in frameworks like GDPR and NIST CSF for effective audit and reporting.'].

Available Now

Spain arrests suspected hacktivists for DDoSing govt sites - BleepingComputer

Built for ['Security Analyst: To develop advanced skills in detecting DDoS traffic patterns and implementing real-time mitigation strategies within a SIEM.', 'Network Administrator: To learn infrastructure hardening techniques, including rate limiting, web application firewall (WAF) configuration, and network segmentation to defend against volumetric and application-layer DDoS attacks.', 'Compliance Officer: To understand how DDoS incidents impact regulatory obligations under NIS2, DORA, and ISO 27001, and to map defensive controls to specific framework requirements.'].

Available Now

Iran's MuddyWater Targets Orgs With Fresh Malware as Tensions Mount

Built for ['Security Analyst: To gain deep technical insight into APT malware behaviour and improve threat detection capabilities.', 'Incident Responder: To develop and refine playbooks for responding to sophisticated, multi-stage malware infections.', 'CISO/ Security Manager: To understand the strategic risk and compliance implications of nation-state threats for board-level reporting and control prioritisation.'].

Available Now

APT28 Targeted European Entities Using Webhook-Based Macro Malware

Built for ['Security Analyst: Will benefit by learning to craft specific SIEM detection rules for webhook-based malware and macro abuse, directly improving threat hunting capabilities.', 'Incident Responder: Will gain from the detailed playbook development and forensic analysis lessons, enabling faster and more effective containment and eradication of similar incidents.', 'IT Security Administrator: Will learn practical infrastructure hardening techniques, such as disabling dangerous macros and implementing application allow-listing, to prevent initial infection.'].

Available Now

Bumble failed to protect user data in ShinyHunters hack, class action suit claims - Mashable

Built for ['Security Analyst: To develop advanced detection rules for credential-based attacks and data exfiltration, directly applicable to monitoring cloud and application environments.', 'IT Administrator: To learn infrastructure hardening techniques, specifically around authentication and access control, to prevent unauthorised access to sensitive databases.', 'Data Protection Officer / Compliance Manager: To understand how technical security failures map to regulatory obligations under GDPR and other frameworks, improving audit and reporting processes.'].

Available Now

Conduent Data Breach Exposes Millions Across States - Grand Pinnacle Tribune

Built for ['Security Analyst: To gain practical skills in detecting data exfiltration patterns and analysing breach indicators from a real-world case.', 'IT Administrator/Engineer: To learn infrastructure hardening techniques, such as network segmentation and access control, specifically to prevent unauthorised data access.', 'Compliance & Risk Officer: To understand how to map incident response controls to regulatory requirements like GDPR and NIS2, particularly for third-party risk scenarios.'].

Available Now

Russian-speaking hackers used gen AI tools to compromise 600 firewalls, Amazon says

Built for ['Network Security Engineer: To understand the specific firewall exploitation techniques and implement hardening measures to defend network perimeters against AI-driven attacks.', 'Security Operations Centre (SOC) Analyst: To learn the detection signatures and behavioural analytics needed to identify similar AI-facilitated credential attacks and unauthorised firewall access in SIEM logs.', "IT Risk & Compliance Officer: To map the incident's lessons to control requirements in frameworks like NIS2, DORA, and ISO 27001, strengthening the organisation's regulatory posture."].

Available Now

Hackers demand $1.5 million to not leak data on top Vegas hotel - TechRadar

Built for ['Security Analyst: To deepen their understanding of attack methodologies and improve their ability to craft detection rules and analyse IoCs from real-world breaches.', 'IT Administrator / System Engineer: To learn infrastructure hardening techniques, such as network segmentation and access control, directly applicable to securing critical hospitality or corporate environments.', 'Compliance Officer / Risk Manager: To understand how specific technical incidents map to regulatory requirements (like GDPR for data leakage), enabling better risk assessment and control alignment.'].

Available Now

Here's how much money you could get in the settlement of Norton Healthcare's data breach

Built for ['Security Analyst: To deepen their ability to detect data exfiltration patterns and analyse breach indicators within SIEM and endpoint tools.', 'IT Administrator/Engineer: To learn infrastructure hardening techniques, such as access control and network segmentation, crucial for preventing lateral movement after an initial breach.', 'Data Protection Officer/Compliance Manager: To understand how technical failures lead to regulatory penalties and how to map controls to frameworks like GDPR and NIST CSF for demonstrating compliance.'].

Available Now

Days after ransomware attack, UMMC clinics remain closed as emergency rooms rely on ...

Built for ['Security Analyst: To gain deep, practical insights into detecting and analysing data breach patterns, and to build effective SIEM detection rules.', 'IT Administrator: To understand how to harden infrastructure, implement network segmentation, and apply access controls to prevent lateral movement post-breach.', 'CISO / Security Manager: To develop board-level communication strategies, integrate incident response with compliance frameworks, and manage organisational risk posture.'].

Available Now

French government systems hacked - over 1.2 million private financial accounts hit

Built for ['Security Analyst: Will benefit by learning to craft specific detection rules and analyse indicators of compromise from a real-world government breach.', 'IT Administrator (Government/Finance): Will gain critical insights into hardening authentication systems and implementing network segmentation to protect citizen financial data.', 'Compliance Officer: Will learn to map incident response activities and technical controls to frameworks like GDPR, NIS2, and DORA to demonstrate regulatory adherence.'].

Available Now

Romanian Hacker Pleads Guilty to Selling Access to US State Network - SecurityWeek

Built for ['Security Analyst: Will benefit by learning to craft specific detection rules for credential misuse and unauthorised access patterns observed in the case study.', 'Network/Systems Administrator: Will gain critical skills in implementing access controls, network segmentation, and authentication hardening to prevent similar breaches.', "IT Risk & Compliance Officer: Will learn to map the incident's lessons and resulting security controls directly to evidence requirements for frameworks like NIST CSF, ISO 27001, and GDPR."].

Available Now

Leading Semiconductor Supplier Advantest Hit by Ransomware Attack

Built for ['Security Analyst: To develop advanced detection rules and analyse IOCs from a real-world data breach scenario.', 'IT Administrator/Engineer: To learn infrastructure hardening techniques, including network segmentation and access controls, to prevent lateral movement post-breach.', 'CISO/Risk Manager: To understand board-level communication strategies, vendor risk management, and how to map incident response to compliance frameworks like NIS2 and GDPR.'].

Available Now

PayPal confirms data breach — user info may have been exposed for 6 months - TechRadar

Built for ['Security Analyst: Will benefit by learning to craft specific SIEM detection rules and analyse IoCs from a real-world data breach to improve monitoring efficacy.', 'IT Administrator: Will gain crucial knowledge on implementing infrastructure hardening controls, such as network segmentation and access management, to prevent initial compromise and lateral movement.', 'Compliance Officer: Will learn to map the technical details of the breach to specific articles in GDPR, NIS2, and other frameworks, strengthening audit and reporting processes.'].

Available Now

Hacker stiehlt Daten von Tausenden RTL-Mitarbeitern

Built for ['Security Analyst: Will benefit by learning to craft specific detection rules and response playbooks based on a real data exfiltration attack, directly improving their threat-hunting capabilities.', 'IT Administrator: Will gain crucial insights into infrastructure hardening, particularly around authentication and access controls, to prevent initial access and lateral movement by attackers.', 'Compliance Officer / DPO: Will learn to map the technical details of the incident to regulatory requirements like GDPR and NIS2, enabling more effective risk assessments and reporting to leadership.'].

Available Now

Mississippi Hospital System Closes All Clinics After Ransomware Attack - SecurityWeek

Built for ['Healthcare IT Administrators: They will benefit by understanding the specific attack vectors that target medical systems and learn to harden clinical network infrastructure against operational disruption.', 'Security Operations Centre (SOC) Analysts: They will gain critical insight into the indicators of compromise and attack patterns of healthcare ransomware, enabling faster and more accurate detection and triage.', 'Compliance Officers (HIPAA, GDPR): They will learn to map the technical and organisational failures in the incident to specific regulatory requirements, strengthening their audit and risk management programmes.'].

Available Now

University of Mississippi Medical Center Still Offline After Ransomware Attack

Built for ['Security Analyst: To deepen technical investigation skills for ransomware indicators and improve SIEM detection rule creation.', 'IT Administrator: To learn infrastructure hardening techniques, such as network segmentation and access control, directly applicable to preventing initial compromise.', 'CISO/IT Manager: To gain strategic insights for board-level communication, vendor risk management, and integrating technical controls with compliance frameworks like NIS2 and GDPR.'].

Available Now

MuddyWater Targets MENA Organizations with GhostFetch, CHAR, and HTTP_VIP

Built for ["Security Operations Centre (SOC) Analyst: To gain deep insight into MuddyWater's tactics for creating more effective detection rules and improving triage accuracy.", 'Incident Response Manager: To develop and refine playbooks specifically for multi-stage cyberattacks involving living-off-the-land binaries (LOLBins) and script-based payloads.', 'IT Security Manager / CISO: To understand the strategic implications of the attack, communicate risk to leadership, and align defensive investments with compliance requirements like NIS2 and GDPR.'].

Available Now

Silver Fox APT Deploys DLL Sideloading and BYOVD in Advanced Malware Campaign

Built for ['Security Analyst: To gain deep technical insight into advanced malware tradecraft and build effective SIEM/EDR detection rules for sideloading and driver-based attacks.', 'Incident Responder: To develop and refine playbooks for investigating and containing sophisticated malware incidents that leverage BYOVD and living-off-the-land techniques.', 'IT Security Manager/CISO: To understand the organisational risk and compliance implications, enabling better vendor risk management, board communication, and control investment aligned with frameworks like NIS2 and DORA.'].

Available Now

The Philippine military said the country continues to face escalating cybersecurity threats ...

Built for ['Security Analysts and SOC Engineers who need to improve detection capabilities and response playbooks for advanced cyberattacks.', 'IT Administrators and Network Engineers responsible for implementing defensive controls and hardening infrastructure against the specific tactics used in this incident.', 'CISOs and Risk Managers who must understand the threat landscape to justify security investments, manage vendor risk, and ensure alignment with frameworks like NIST CSF and GDPR.'].

Available Now

Hackers used AI to breach more than 600 security systems in 55 countries — Amazon

Built for ['Security Analyst: Will benefit by learning to recognise the novel IoCs and detection patterns associated with AI-facilitated attacks, enhancing their monitoring and triage capabilities.', 'Cloud Security Architect: Will gain critical insights into hardening cloud identity, access, and network configurations against the automated, large-scale reconnaissance and exploitation techniques demonstrated in the incident.', 'CISO / Security Manager: Will learn to articulate the business risk of AI-powered threats, develop board-level communications, and align defensive investments with compliance frameworks like NIS2 and DORA.'].

Available Now

Hacker gained access to PayPal systems resulting in unauthorised transactions

Built for ['Security Analyst: To develop advanced detection rules and understand the forensic artefacts left by a sophisticated data breach.', 'IT Administrator: To learn infrastructure hardening techniques, particularly around authentication and access controls, to prevent initial access.', 'CISO / Risk Manager: To gain insights for board-level reporting, vendor risk management, and aligning incident response with major compliance frameworks like DORA and NIS2.'].

Available Now

Luxury hotel stays for just €0.01. Spanish police arrest hacker. - Security Affairs

Built for ['Application Security Engineer: To learn how to identify and remediate business logic flaws in web applications through specialised testing techniques.', 'Security Operations Centre (SOC) Analyst: To understand the unique indicators of compromise for logic-based fraud and develop effective SIEM detection rules for anomalous transactions.', 'IT Risk & Compliance Officer: To map the controls needed to mitigate such attacks to key frameworks like PCI DSS, GDPR, and SOC 2, ensuring regulatory adherence.'].

Available Now

Conduent data breach hits millions across multiple states | National | foxbangor.com

Built for ['Security Analyst: Will benefit by learning to craft specific detection rules and response procedures for data exfiltration events, enhancing their threat-hunting capabilities.', 'IT Administrator: Will gain crucial insights into infrastructure hardening and access control measures to prevent unauthorised data access at the system level.', 'Compliance Officer: Will learn to map incident response controls to frameworks like GDPR and NIST CSF, strengthening audit readiness and regulatory reporting.'].

Available Now

PayPal Breach, Chrome 0-Day, BeyondTrust RCE Exploit, and More - Cybersecurity News Weekly

Built for ["Security Analyst: Will benefit by learning to craft specific detection rules for complex, multi-stage data exfiltration attacks and understanding the attacker's methodology.", 'Incident Responder: Will gain practical skills for managing a breach involving multiple exploited vulnerabilities, from initial triage to containment and recovery.', 'IT & Security Manager: Will learn to communicate technical risks to leadership, map controls to compliance frameworks, and implement organisational hardening measures to prevent similar incidents.'].

Available Now

Conduent data breach hits millions across multiple states - AOL.com

Built for ['Security Analyst: Will benefit by learning to identify the specific tactics, techniques, and procedures (TTPs) used in a large-scale data breach, enabling them to fine-tune SIEM alerts and conduct more effective threat hunts.', 'IT Administrator/Engineer: Will gain practical knowledge on hardening authentication systems, implementing network segmentation, and applying zero trust principles to prevent lateral movement and data exfiltration.', 'Compliance & Risk Officer: Will learn how to map the technical failures of this incident to major regulatory frameworks like GDPR and NIS2, helping them conduct more accurate vendor risk assessments and ensure organisational controls meet compliance mandates.'].

Available Now

Hackers Hide Pulsar RAT Inside PNG Images in New NPM Supply Chain Attack - Hackread

Built for ['Security Analyst: To enhance threat hunting capabilities for detecting steganography and malicious packages within their environment.', 'DevSecOps Engineer: To implement security controls and scanning processes directly into CI/CD pipelines to prevent similar supply chain compromises.', 'IT Administrator (Infrastructure): To harden development and build servers against unauthorised code execution and data exfiltration attempts.'].

Available Now

The hospitality sector continues to be lucrative targets - DataBreaches.Net

Built for ['Security Analyst: To gain hands-on skills in detecting data exfiltration patterns and analysing breach indicators specific to high-volume transaction environments.', 'IT Administrator: To learn infrastructure hardening techniques, such as network segmentation and access control, that directly prevent the lateral movement observed in this breach.', 'Compliance Officer: To understand how the technical details of a real breach map to control requirements in frameworks like GDPR, NIS2, and SOC 2, enabling more effective audits and risk assessments.'].

Available Now

Quatro líderes do Anonymous detidos por ciberataques a organismos públicos em Espanha

Built for ['Security Analyst: To deepen their understanding of hacktivist tactics and improve threat hunting and SIEM detection rule creation for similar campaigns.', 'IT Administrator/Network Engineer: To learn infrastructure hardening techniques, such as network segmentation and access control, directly informed by the attack vectors used in the incident.', 'Compliance & Risk Officer: To map the technical details of a real cyberattack to control requirements in frameworks like NIS2 and GDPR, enabling more effective risk assessments and audit preparations.'].

Available Now

UAE foils organised cyber attacks targeting digital infrastructure, vital sectors - Geo News

Built for ['Security Analyst: To gain practical skills in detecting and responding to sophisticated data breach campaigns using real-world indicators and SIEM strategies.', 'IT Infrastructure Administrator: To learn how to harden critical digital infrastructure against organised attacks through network segmentation and zero trust principles.', 'Compliance Officer / CISO: To understand how to map incident response controls to frameworks like NIS2 and DORA, and effectively communicate cyber risk to leadership.'].

Available Now

Morocco's Social Security Database Hacked: A Major Cyberattack - The Detroit Bureau

Built for ['Security Analyst: To deepen their understanding of attack patterns against databases and learn to craft specific detection rules for their SIEM.', 'IT Administrator/Systems Engineer: To implement the infrastructure hardening and access control lessons directly into their system configuration and management practices.', "GRC (Governance, Risk, Compliance) Consultant: To map the incident's failures and the course's prescribed controls to specific requirements within frameworks like NIS2, GDPR, and ISO 27001 for client advisement."].

Available Now

Stor kæde hacket: Dine data kan være i fare - Pensionist

Built for ['Security Analyst: Will benefit by learning specific Indicators of Compromise (IoCs) and SIEM detection strategies to identify similar attacks in their environment early.', 'IT Administrator / System Engineer: Will gain practical skills for infrastructure hardening, implementing network segmentation, and applying zero trust principles to prevent lateral movement.', "Compliance & Risk Officer: Will learn to map the incident's lessons to major regulatory frameworks like GDPR, NIS2, and DORA, strengthening audit readiness and vendor risk management programmes."].

Available Now

ATM machines under attack! FBI reveals shocking $20 million hack - Techlusive

Built for ['Financial Institution Security Analyst: To understand the specific attack vectors against ATM networks and learn to deploy detection rules for similar malware campaigns within their transaction monitoring systems.', 'Critical Infrastructure IT Administrator: To gain insights into hardening networked physical devices like ATMs and point-of-sale systems against unauthorised access and malware installation.', 'Cybersecurity Compliance Officer: To map the technical controls and response procedures from this incident directly to regulatory requirements under DORA, NIS2, and PCI-DSS, strengthening audit readiness.'].

Available Now

Rockstar beefs up security after hacking attempts with drones and fake badges by GTA 6 fans

Built for ['Security Operations Centre (SOC) Analysts: They will benefit by learning to correlate digital alerts with physical security events, enhancing their threat detection and triage capabilities.', 'Physical Security Managers: They will gain crucial insight into how physical breaches (e.g., fake badges) can enable cyberattacks, fostering better collaboration with IT security teams.', 'IT Security Administrators: They will learn to harden authentication systems and implement network segmentation to defend against the initial access techniques demonstrated in the incident.'].

Why Security Teams Choose the 48-Hour Rule

Every section below maps to one operational advantage in Incident-as-a-Service delivery.

Timing as a retention lever

Content arrives while urgency is still high, which dramatically increases recall and response quality.

Breach-to-training pipeline

Detection, analysis, course build, and review are operationalized into one repeatable release loop.

Measured outcomes

Retention, engagement, and deployment speed are tracked so security leaders can report impact, not activity.

Role-targeted relevance

Lessons are tuned to functions and threat exposure, reducing wasted modules and improving behavior change.

The 48-Hour Rule in Motion

From incident alert to deployed learning package in an average of 18.5 hours.

Train from what just happened, not what happened last year.

IntelXview gives security leaders a practical way to respond to new threat patterns with actionable learning while teams still remember why it matters.

The next breach will not wait for your annual cycle.

Launch incident-triggered training workflows now and move your awareness program from static compliance to active defense.