Security Awareness
Training
Train employees to spot phishing, ransomware, and social engineering before a real attacker tests them.
87 interactive simulations across 11 structured courses. Free to play, no sign-up required.
Phishing & Impersonation Attacks
Callback Phishing
Spot a fake fraud alert built to make you call.
- ATT&CKT1566.004
- CIS 14.2
Phishing
Spot a phishing email before you click.
- ATT&CKT1566.002
- CIS 14.2
Vishing
Handle a realistic voice phishing call.
- ATT&CKT1566.004
- CIS 14.2
Smishing
Detect fraud hiding in your text messages.
- ATT&CKT1566.002
- CIS 14.2
Double Barrel Phishing
Spot the phone call that sets up the phishing email.
- ATT&CKT1566.002
- CIS 14.2
Business Email Compromise
Spot a wire request from a hijacked colleague's account.
- ATT&CKT1534
- CIS 14.2
Social Engineering
Recognize manipulation before you comply.
- ATT&CKT1598
- CIS 14.2
Whaling With A Deepfake
Spot an AI-generated executive on a video call.
- ATT&CKT1566.004
- CIS 14.2
Spear Phishing
Your public profile is their attack playbook.
- ATT&CKT1566.001
- CIS 14.2
QR Code Phishing (Quishing)
That QR code skips every email filter you have.
- ATT&CKT1566.002
- CIS 14.2
WhatsApp Social Engineering
Your "boss" on WhatsApp isn't your boss.
- ATT&CKT1566.003
- CIS 14.2
Tech Support Scams
That virus warning is the actual attack.
- ATT&CKT1656
- CIS 14.2
SEO Poisoning Awareness
Top search results aren't always trustworthy.
- ATT&CKT1608.006
- CIS 14.2
Invoice & Payment Fraud
Catch a fraudulent vendor invoice using the 3-way match before it reaches the payment file.
- ATT&CKT1656
- CIS 14.2
Verification Procedures
Stop a vendor banking BEC by using your authoritative directory and an out-of-band callback.
- ATT&CKT1656
- CIS 14.2
Deepfake Audio Detection
Catch an AI-cloned executive voice on the phone before the wire goes out.
- ATT&CKT1656
- CIS 14.2
Calendar Invite Scams
Catch a spoofed calendar invite before the fake meeting page harvests your credentials.
- ATT&CKT1566.002
- CIS 14.2
Device Security
Backup Best Practices
Set up backups before a crash takes your work.
- ATT&CKT1490
- CIS 11
- NIST CSFPR.DS
Encryption & Lock Discipline
Practice the habits that protect unattended devices.
- ATT&CKT1530
- CIS 3
- NIST CSFPR.DS
OS Updates & Patching Basics
See why skipping updates opens real attack paths.
- ATT&CKT1190
- CIS 7
- NIST CSFID.RA
Ransomware
Survive a ransomware attack in real time.
- ATT&CKT1486
- CIS 10
- NIST CSFPR.PS
USB Drop Attack
Think twice before plugging in that USB drive.
- ATT&CKT1091
- CIS 10
- NIST CSFPR.PS
Endpoint Patching & EDR Alerts
Know what your EDR alert means and what to do next.
- ATT&CKT1068
- CIS 7
- NIST CSFID.RA
File Extension Awareness
It looks like a PDF. It runs like malware.
- ATT&CKT1036.007
- CIS 10
- NIST CSFPR.PS
Safe Bluetooth Practices
Your headphones are broadcasting more than music.
- ATT&CKT1011
- CIS 14.8
Mobile Device Security
One fake text. Eight hours of stolen access.
- ATT&CKT1476
- CIS 4
- NIST CSFPR.PS
IoT & Smart Device Security
Your smart camera scores 28 out of 100.
- CWE-1392
- ATT&CKT1078.001
- CIS 4
- NIST CSFPR.PS
Mobile App Permissions
Name the feature each permission powers, or revoke it.
- ATT&CKT1626
- CIS 4
- NIST CSFPR.PS
Passwords & Account Security
Account Recovery Security
Defend account recovery from social engineering.
- ATT&CKT1098.005
- CIS 5
- NIST CSFPR.AA
Credential Stuffing Awareness
See how breached passwords fuel automated attacks.
- ATT&CKT1110.004
- CIS 14.3
Joiner-Mover-Leaver Awareness
A leaver's account that nobody switched off.
- ATT&CKT1078
- CIS 5
- NIST CSFPR.AA
Least Privilege Awareness
Keep access to the minimum your job requires.
- ATT&CKT1078
- CIS 6
- NIST CSFPR.AA
MFA Setup & Best Practices
Set up multi-factor authentication the right way.
- ATT&CKT1621
- CIS 6
- NIST CSFPR.AA
MFA Fatigue Attack
Your phone buzzes for the thirtieth time. Then a Slack message says approve.
- ATT&CKT1621
- CIS 6
- NIST CSFPR.AA
Password Manager Habits
Build strong habits with your password manager.
- ATT&CKT1555.005
- CIS 14.3
Privileged Access Basics
Learn why admin accounts need special handling.
- ATT&CKT1078
- CIS 6
- NIST CSFPR.AA
Web & Browser Safety
HTTPS & Website Security
Learn why the padlock icon is not proof of safety.
- ATT&CKT1557
- CIS 9
- NIST CSFPR.PS
Safe Browsing & Downloads
Spot malicious downloads before they run.
- ATT&CKT1189
- CIS 9
- NIST CSFPR.PS
Typosquatting Awareness
Catch the domain tricks attackers use against you.
- ATT&CKT1583.001
- CIS 9
- NIST CSFPR.PS
Browser Autofill Risks
Hidden fields silently steal your autofilled data.
- ATT&CKT1555.003
- CIS 9
- NIST CSFPR.PS
Browser Extension Safety
That helpful extension might be stealing everything.
- ATT&CKT1176
- CIS 9
- NIST CSFPR.PS
Browser Notification Abuse
That CAPTCHA was a trap for push spam.
- ATT&CKT1204.001
- CIS 9
- NIST CSFPR.PS
Incident Reporting
Safe Communication & Sharing
Cloud Sharing Controls
Audit who can see your shared files right now.
- CWE-732
- ATT&CKT1530
- CIS 3
- NIST CSFPR.DS
Guest Access Management
Control what external users can reach and for how long.
- ATT&CKT1078
- CIS 5
- NIST CSFPR.AA
Secure Messaging Practices
Stop sensitive data from leaking through chat apps.
- ATT&CKT1552.008
- CIS 14.4
Social Media Policy
Learn what not to post on corporate accounts.
- CIS 14.1
Social Media Oversharing
See how attackers exploit your public profiles.
- ATT&CKT1589
- CIS 14.5
Third-Party App OAuth Risks
Check what you gave permission to access.
- ATT&CKT1528
- CIS 15
- NIST CSFGV.SC
Secure Online Meetings
Spot the drop-in attendee, remove them, lock the meeting, file the report.
- ATT&CKT1656
- CIS 14.2
Security Policies & Your Role
Audit Mindset Basics
Think like an auditor to find compliance gaps.
- CIS 14.2
Audit Portal Training
Navigate GRC portals and submit audit evidence.
- CIS 14.6
Employee Security Responsibilities
Know your personal security duties at work.
- CIS 14.1
ISMS Policy Awareness
Connect ISO 27001 policies to your daily work.
- CIS 14.1
Internet & Email Acceptable Use
Stay within corporate internet and email policies.
- CIS 14.1
Protecting Sensitive Information
Data Classification Basics
Label data correctly by sensitivity level.
- CIS 3
- NIST CSFPR.DS
Identity Theft Prevention
Spot identity theft tactics targeting employees.
- ATT&CKT1566.004
- CIS 14.2
Secure Sharing Practices
Share files safely without creating security gaps.
- CWE-732
- CIS 3
- NIST CSFPR.DS
Data Leakage
Stop sensitive data from leaving your org.
- CWE-200
- CIS 14.5
Log Sensitivity Awareness
Production logs hold things you would never email out.
- CWE-532
- CIS 8
- NIST CSFPR.PS
Metadata Awareness
A black rectangle over text does not remove the text.
- CWE-212
- CIS 14.4
Safe GenAI Usage
Use generative AI without leaking sensitive client data.
- OWASP LLMLLM02:2025
- EU AI ActArt. 4
- CIS 14.4
Workplace Security
Insider Threat (Intentional)
Recognize the warning signs of a malicious insider.
- ATT&CKT1052
- CIS 3
- NIST CSFPR.DS
Shadow IT Awareness
Find out what happens when teams use unapproved apps.
- CIS 2
- NIST CSFID.AM
Image-Based Attacks (Stegosploit)
That image file might be carrying more than pixels.
- ATT&CKT1027.003
- CIS 10
- NIST CSFPR.PS
Insider Threat (Accidental)
One wrong attachment. Confidential data in the wrong inbox.
- CIS 14.5
Collaboration Tool Hygiene
One shortcut in a team channel. Credentials everywhere.
- CWE-522
- ATT&CKT1552.008
- CIS 14.4
Secure Document Disposal
Find out where a binned page actually ends up.
- CWE-200
- CIS 3
- NIST CSFPR.DS
Clean Desk Basics
See what a passer-by does with the notes on your desk.
- CWE-522
- CIS 14.4
Unattended Printouts
A page in the tray belongs to whoever gets there first.
- CWE-200
- CIS 3
- NIST CSFPR.DS
Printer Admin Security
The office printer still answers to admin / admin.
- CWE-1392
- ATT&CKT1078.001
- CIS 4
- NIST CSFPR.PS
Visitor Sign-in Gaps
Nobody booked him in, but he has a ten o'clock.
- ATT&CKT1656
- CIS 14.2
Unescorted Visitors
A badge gets someone in. A host keeps them accounted for.
- ATT&CKT1656
- CIS 14.2
Intercom Tailgating
A courier at the door is not an ID card.
- ATT&CKT1656
- CIS 14.2
Badge Sharing
Lend your badge and the door log still says you.
- ATT&CKT1078
- CIS 6
- NIST CSFPR.AA
Technician Impersonation
He has a toolbox, a badge and two minutes. Check anyway.
- ATT&CKT1656
- CIS 14.2
Shoulder Surfing
Your screen is readable from two metres behind you.
- ATT&CKT1005
- CIS 14.5
Unlocked Workstations
An awake screen is a signed-in session with a name on it.
- CWE-522
- ATT&CKT1078
- CIS 14.5
- NIST CSFPR.PS
Remote & Home Office Security
Working in Public Spaces
Captive Portal Phishing
More Wi-Fi time for your work password is not a deal.
- CWE-451
- ATT&CKT1056.003
- CIS 12
- NIST CSFPR.IR
Evil Twin Wi-Fi
The network's name proved nothing. Tether when unsure.
- CWE-300
- ATT&CKT1557.004
- CIS 12
- NIST CSFPR.IR
VPN on Public Wi-Fi
A VPN that drops mid-upload does not tell you. A kill switch does.
- CWE-300
- ATT&CKT1040
- CIS 12
- NIST CSFPR.IR
Tampered QR Codes
A QR code has no sender, and a sticker can replace it.
- CWE-451
- ATT&CKT1204.001
- CIS 14.2
Juice Jacking
A charging port that asks for your files is not a charger.
- ATT&CKT1533
- CIS 14.5
Eavesdropping & Device Theft
Your voice carries further than your screen.
- CIS 14.5
Frequently asked questions
Are these security awareness exercises really free?
Yes. Every security awareness exercise on this page is free to play with no sign-up required. Each runs directly in your browser as a 3D simulation.
Enterprise features like analytics dashboards, SCORM packaging for your LMS, SSO integration, and custom content are available through our paid plans.
How long does each exercise take to complete?
Most exercises take between 5 and 15 minutes. They are designed for busy schedules.
Employees can complete them between meetings or during a dedicated training block. Short, focused sessions lead to better retention than hour-long compliance modules.
Can I use these exercises for compliance training?
Yes. Our exercises map to requirements in SOC 2, ISO 27001, HIPAA, PCI DSS, NIST, and GDPR frameworks.
For compliance documentation, our enterprise plans include SCORM packages that integrate with your LMS and provide completion tracking, scores, and audit-ready reports.
What topics does the security awareness catalogue cover?
The catalogue spans 11 structured courses: Phishing and Impersonation Attacks, Device Security, Passwords and Account Security, Web Browser Safety, Incident Reporting, Safe Communication Practices, Security Policies, Protecting Sensitive Information, Workplace Security, Remote Work Security, and Working in Public Spaces.
Together they cover the full spectrum of human-layer security risks. For the AI side of the same risks, the AI at Work course covers deepfakes, cloned voices, AI-written phishing and shadow AI tools.
How is this different from video-based security training?
Video-based training is passive. Employees watch and forget. Our 3D simulations place employees inside realistic attack scenarios where they make decisions and see consequences.
Multiple studies show that active learning outperforms passive instruction in knowledge retention. Our simulation-based exercises also see 3x higher completion rates than traditional video modules.
See RansomLeak in Action
Try the free exercises or book a demo to see analytics, SCORM export, SSO, and custom content in your environment.