Who We Are Solutions
Human Risk AssessmentManaged Awareness 365Phish & LearnCyber CultureAI & Deepfake Awareness
How It Works Showcase Insights Contact Talk to an Expert
Close detail of a circuit board

Sample library

See the learning before you commission it.

Everything below is our own work, produced in-house, and playable right now. It is here so you can judge the standard rather than take our word for it.

05
micro-films in The Human Layer series
01
playable incident simulation, SCORM 1.2
25
minutes of decision-making, scored and reported

How we build learning

01
Behavioural brief
We start from the behaviour that has to change, not the topic that has to be covered.
02
Threat script
Written from live attack patterns, in the language your workforce actually uses.
03
Storyboard
Every beat mapped before a frame is produced. Client sign-off happens here, not at the end.
04
Production
AI-assisted film, voice and design under a fixed brand system. Days, not months.
05
Decision points
Learners choose and see consequences. No page-turning, no click-next compliance.
06
Ship & measure
SCORM 1.2 or xAPI into your LMS, scored, with the behavioural data coming back out.
A dark abstract security backdrop

Micro-film series

The Human Layer.

Sixty seconds per threat. One behaviour to change, delivered in the time someone will actually give you. Built for LMS intros, campaign drops, town halls and internal comms.

EP 01 The Human Layer, episode 1 — Fake CEO, real loss 0:60

BEC · CEO fraud

Fake CEO. Real loss.

An urgent payment request from the top of the company. Correct tone, correct signature, wrong sender.

Takeaway Verify on a second channel before money or data moves.

EP 02 The Human Layer, episode 2 — The face is fake 0:60

AI · Deepfake

The face is fake.

Synthetic video and cloned voice have moved from research demo to a working fraud tool. The call looks normal.

Takeaway A face on a screen is not identity verification.

EP 03 The Human Layer, episode 3 — One scan, account gone 0:60

Quishing · QR phishing

One scan. Account gone.

A QR code moves the attack to a personal phone, outside mail filtering, outside the managed device, outside the log.

Takeaway Treat an unexpected QR code exactly like an unexpected link.

EP 04 The Human Layer, episode 4 — One password, every door 0:60

Credential · Password spraying

One password. Every door.

Attackers do not guess one account a thousand times. They try one common password against a thousand accounts.

Takeaway Unique passphrases turn one compromise into one compromise.

EP 05 The Human Layer, episode 5 — Tired tap, total breach 0:60

MFA fatigue · Push bombing

Tired tap. Total breach.

Approval prompts at 2am until one is accepted. The control worked. The moment did not.

Takeaway Deny every prompt you did not start, then report it.

Episodes 06 – 12 in production

Vishing, shadow AI, supplier impersonation, insider mistakes and physical tailgating. Series clients get each one on release, brandable to your organisation.

Nothing loads from YouTube until you open an episode — the grid ships as static images, so the page stays fast and sets no third-party cookies on arrival.

Playable simulation

Night Shift: Containment.

A twenty-five minute cyber escape room. Five stations, a live attacker, a clock that punishes guessing. It runs in the browser and reports a score back to your LMS like any other SCORM module.

25:00

23:47 · Level 3 · badge readers offline

Night Shift:
Containment

A finance workstation has been talking to a server in another country for ninety minutes. The security team is mid-flight. You are the only person in the building.

Plays here · no login · no install

Five stations. One exit code.

Each station is a real decision an employee has to make under pressure, and each one releases one character of the exit door code. Wrong moves and hints both cost time, so the score reflects judgement rather than persistence.

Stations
Phishing & lookalike domains · passphrases & MFA fatigue · vishing & pretexting · data classification under the DPDP Act · ransomware containment
Runtime
25 minutes on the clock, roughly 30 to 40 with reading
Scoring
100 points across five stations, 70 to pass, penalties for wrong moves and hints
Standard
SCORM 1.2 — score, status, session time and suspend data. xAPI on request
Runs on
Any modern browser, desktop and tablet. No plugins, no installs, works offline once loaded
Brandable
Organisation name, scenario, timings, scoring and every puzzle sit in one config file

What we deliver

Formats, and what each one is actually for.

Most programmes fail because the format was chosen before the behaviour was defined. This is the order we recommend instead.

FormatUse it whenTypical lengthDelivery
Micro-filmYou need attention and recall across the whole workforce, fast45–90 secondsMP4, LMS, intranet, screens, Teams & Slack
SimulationThe behaviour only shows up under time pressure and ambiguity20–40 minutesSCORM 1.2 / xAPI, scored
Scenario moduleA role has specific decisions to get right — finance, HR, support10–15 minutesSCORM 1.2 / xAPI, scored
Phishing simulationYou need behavioural data, not self-reported confidenceContinuousPlatform-delivered, segmented by risk
Campaign kitThe message has to stay visible between formal trainingMonthly dropPosters, mailers, carousels, screen loops
Live workshopLeadership, finance approvers and high-risk groups need the room60–120 minutesOn-site or virtual, facilitated

Everything is produced against your brand, your systems and your real incident history. The samples on this page use our own branding because they are ours — yours would not.

A team reviewing work together

Commission the work

Want this standard, with your name on it?

Send us the behaviour you need to change and the audience it applies to. We will come back with a treatment, a timeline and a number.