Skip to main content

Every exercise is indexed by name, CWE, OWASP, MITRE ATT&CK, CIS, NIST CSF, GDPR and EU AI Act reference.

Try

Security Awareness
Training

Train employees to spot phishing, ransomware, and social engineering before a real attacker tests them.

87 interactive simulations across 11 structured courses. Free to play, no sign-up required.

1

Phishing & Impersonation Attacks

Callback Phishing

Spot a fake fraud alert built to make you call.

  • ATT&CKT1566.004
  • CIS 14.2
Play Exercise →

Phishing

Spot a phishing email before you click.

  • ATT&CKT1566.002
  • CIS 14.2
Play Exercise →

Vishing

Handle a realistic voice phishing call.

  • ATT&CKT1566.004
  • CIS 14.2
Play Exercise →

Smishing

Detect fraud hiding in your text messages.

  • ATT&CKT1566.002
  • CIS 14.2
Play Exercise →

Double Barrel Phishing

Spot the phone call that sets up the phishing email.

  • ATT&CKT1566.002
  • CIS 14.2
Play Exercise →

Business Email Compromise

Spot a wire request from a hijacked colleague's account.

  • ATT&CKT1534
  • CIS 14.2
Play Exercise →

Social Engineering

Recognize manipulation before you comply.

  • ATT&CKT1598
  • CIS 14.2
Play Exercise →

Whaling With A Deepfake

Spot an AI-generated executive on a video call.

  • ATT&CKT1566.004
  • CIS 14.2
Play Exercise →

Spear Phishing

Your public profile is their attack playbook.

  • ATT&CKT1566.001
  • CIS 14.2
Play Exercise →

QR Code Phishing (Quishing)

That QR code skips every email filter you have.

  • ATT&CKT1566.002
  • CIS 14.2
Play Exercise →

WhatsApp Social Engineering

Your "boss" on WhatsApp isn't your boss.

  • ATT&CKT1566.003
  • CIS 14.2
Play Exercise →

Tech Support Scams

That virus warning is the actual attack.

  • ATT&CKT1656
  • CIS 14.2
Play Exercise →

SEO Poisoning Awareness

Top search results aren't always trustworthy.

  • ATT&CKT1608.006
  • CIS 14.2
Play Exercise →

Invoice & Payment Fraud

Catch a fraudulent vendor invoice using the 3-way match before it reaches the payment file.

  • ATT&CKT1656
  • CIS 14.2
Play Exercise →

Verification Procedures

Stop a vendor banking BEC by using your authoritative directory and an out-of-band callback.

  • ATT&CKT1656
  • CIS 14.2
Play Exercise →

Deepfake Audio Detection

Catch an AI-cloned executive voice on the phone before the wire goes out.

  • ATT&CKT1656
  • CIS 14.2
Play Exercise →

Calendar Invite Scams

Catch a spoofed calendar invite before the fake meeting page harvests your credentials.

  • ATT&CKT1566.002
  • CIS 14.2
Play Exercise →
2

Device Security

3

Passwords & Account Security

4

Web & Browser Safety

5

Incident Reporting

6

Safe Communication & Sharing

7

Security Policies & Your Role

8

Protecting Sensitive Information

9

Workplace Security

Insider Threat (Intentional)

Recognize the warning signs of a malicious insider.

  • ATT&CKT1052
  • CIS 3
  • NIST CSFPR.DS
Play Exercise →

Shadow IT Awareness

Find out what happens when teams use unapproved apps.

  • CIS 2
  • NIST CSFID.AM
Play Exercise →

Image-Based Attacks (Stegosploit)

That image file might be carrying more than pixels.

  • ATT&CKT1027.003
  • CIS 10
  • NIST CSFPR.PS
Play Exercise →

Insider Threat (Accidental)

One wrong attachment. Confidential data in the wrong inbox.

  • CIS 14.5
Play Exercise →

Collaboration Tool Hygiene

One shortcut in a team channel. Credentials everywhere.

  • CWE-522
  • ATT&CKT1552.008
  • CIS 14.4
Play Exercise →

Secure Document Disposal

Find out where a binned page actually ends up.

  • CWE-200
  • CIS 3
  • NIST CSFPR.DS
Play Exercise →

Clean Desk Basics

See what a passer-by does with the notes on your desk.

  • CWE-522
  • CIS 14.4
Play Exercise →

Unattended Printouts

A page in the tray belongs to whoever gets there first.

  • CWE-200
  • CIS 3
  • NIST CSFPR.DS
Play Exercise →

Printer Admin Security

The office printer still answers to admin / admin.

  • CWE-1392
  • ATT&CKT1078.001
  • CIS 4
  • NIST CSFPR.PS
Play Exercise →

Visitor Sign-in Gaps

Nobody booked him in, but he has a ten o'clock.

  • ATT&CKT1656
  • CIS 14.2
Play Exercise →

Unescorted Visitors

A badge gets someone in. A host keeps them accounted for.

  • ATT&CKT1656
  • CIS 14.2
Play Exercise →

Intercom Tailgating

A courier at the door is not an ID card.

  • ATT&CKT1656
  • CIS 14.2
Play Exercise →

Badge Sharing

Lend your badge and the door log still says you.

  • ATT&CKT1078
  • CIS 6
  • NIST CSFPR.AA
Play Exercise →

Technician Impersonation

He has a toolbox, a badge and two minutes. Check anyway.

  • ATT&CKT1656
  • CIS 14.2
Play Exercise →

Shoulder Surfing

Your screen is readable from two metres behind you.

  • ATT&CKT1005
  • CIS 14.5
Play Exercise →

Unlocked Workstations

An awake screen is a signed-in session with a name on it.

  • CWE-522
  • ATT&CKT1078
  • CIS 14.5
  • NIST CSFPR.PS
Play Exercise →
10

Remote & Home Office Security

11

Working in Public Spaces

Frequently asked questions

Are these security awareness exercises really free?

Yes. Every security awareness exercise on this page is free to play with no sign-up required. Each runs directly in your browser as a 3D simulation.

Enterprise features like analytics dashboards, SCORM packaging for your LMS, SSO integration, and custom content are available through our paid plans.

How long does each exercise take to complete?

Most exercises take between 5 and 15 minutes. They are designed for busy schedules.

Employees can complete them between meetings or during a dedicated training block. Short, focused sessions lead to better retention than hour-long compliance modules.

Can I use these exercises for compliance training?

Yes. Our exercises map to requirements in SOC 2, ISO 27001, HIPAA, PCI DSS, NIST, and GDPR frameworks.

For compliance documentation, our enterprise plans include SCORM packages that integrate with your LMS and provide completion tracking, scores, and audit-ready reports.

What topics does the security awareness catalogue cover?

The catalogue spans 11 structured courses: Phishing and Impersonation Attacks, Device Security, Passwords and Account Security, Web Browser Safety, Incident Reporting, Safe Communication Practices, Security Policies, Protecting Sensitive Information, Workplace Security, Remote Work Security, and Working in Public Spaces.

Together they cover the full spectrum of human-layer security risks. For the AI side of the same risks, the AI at Work course covers deepfakes, cloned voices, AI-written phishing and shadow AI tools.

How is this different from video-based security training?

Video-based training is passive. Employees watch and forget. Our 3D simulations place employees inside realistic attack scenarios where they make decisions and see consequences.

Multiple studies show that active learning outperforms passive instruction in knowledge retention. Our simulation-based exercises also see 3x higher completion rates than traditional video modules.

See RansomLeak in Action

Try the free exercises or book a demo to see analytics, SCORM export, SSO, and custom content in your environment.