How attackers actually think
Before the tools, before the malware, there is a decision chain. This module reads that chain out loud — using real incidents from 2026 — so you can see exactly where it bends and where it breaks.
- By the end of this module you can…
- Walk the five steps of an intrusion kill chain in plain language.
- Explain why edge devices — not employee laptops — are attacked first in 2026.
- Describe how automation and AI compressed attack timelines from weeks to hours.
- Map one real 2026 incident onto the kill chain, step by step.
1.1 The chain, not the “hack”
Pop culture shows intrusions as a single dramatic “hack.” Reality is a checklist of small wins: reconnaissance (what can I learn publicly?), initial access (a password, a flaw, a person), execution (run my code), persistence (survive reboots and password resets), then lateral movement and the objective — money, data, or disruption. Defenders win by making any one link expensive enough that the attacker quits and picks an easier target.
In September 2026, Palo Alto Networks’ Unit 42 published an incident report that should reset your mental clock: an adversary used autonomous AI agents to compromise an enterprise network in under ten hours, chaining more than fifty MITRE ATT&CK techniques in automated loops — without a single zero-day. Internal reconnaissance, secret-hunting in code repositories, master-credential harvesting from a secrets manager: all known techniques, executed at machine speed. The lesson is not “AI is scary.” The lesson is: your detection and response timeline is now the product.
1.2 Why the edge gets hit first
Ask an attacker to rank targets and they will rank them by reachability × privilege × how nobody watches it. That is why September 2026 filled with VPN and management-platform incidents: SonicWall’s SMA1000 appliances were hit by two chained zero-days — a CVSS 10.0 pre-authentication flaw plus a command-injection flaw — handing attackers control of the box that controls an organisation’s entire remote workforce. N-able’s N-central, the console MSPs use to manage hundreds of client networks, needed its fourth emergency hotfix in five weeks, one of them a 10.0 pre-auth RCE.
Notice what these targets have in common: they sit at the perimeter, they hold privileged keys by design, and they get a fraction of the monitoring that laptops and identities get. An employee laptop has EDR, MFA and a nervous user. A VPN appliance has a firmware version and an open port. In 2026, the perimeter did not disappear — it concentrated, into a few dozen always-on boxes that attackers notice before you do.
Ten hours, fifty techniques, zero zero-days
Unit 42’s report describes autonomous AI agents running reconnaissance, secret discovery and credential harvesting in automated execution loops. No novel exploits — just known techniques at a speed no human SOC triage queue was designed for. When you read “under ten hours,” read it as: the first hour of your response is the whole battle.
1.3 The economics of “you”
Most attacks on ordinary people are commodity: automated, mass-distributed, and cheap. Breached password corpora feed credential-stuffing bots; phishing kits are rented; residential proxy pools make password spraying look like normal traffic — Datadog researchers tracked low-and-low-slow spraying against AWS root accounts across 150+ organisations, deliberately paced to slip under lockout thresholds. Nobody hand-picked you; a list did.
That is oddly good news. Commodity attacks quit when cost rises: a unique password kills stuffing, phishing-resistant MFA kills most proxy kits, and a two-minute report to your bank or IT team kills the follow-on fraud. Your job in this course is not to become unbeatable — it is to become the expensive target, and to be fast and loud when something slips through.
Map your own kill chain
Pick one service you rely on (email, mobile money, work VPN). Write five lines: what recon exists about you there (public email? phone number?), the most likely initial access (reused password? SIM swap?), what execution would look like, how an attacker would persist, and the objective. Keep it — Module 12 will make you defend every line.
1.4 Motive: who attacks, and what they want
Defence gets sharper when you name the attacker’s appetite. Financial criminals want speed and volume: mobile-money fraud rings, SIM-swap syndicates, ransomware operators who treat your outage as their invoice. Spies want patience and position: the Fire Ant router tunnels were quiet by design because stolen tomorrow beats noise today. Hacktivists and insiders want messages or revenge, and accept clumsier methods. Most individuals and small businesses face the first group almost exclusively — commodity crime, automated and indifferent.
That indifference is your leverage. A financial attacker optimises for the cheapest viable victim; every control in this course raises your price tag. Motive also tells you what to protect first: if the appetite is money, guard the payment paths and recovery channels; if it is position, guard the edge devices and admin paths. When you know what they want, you finally know what you should defend — and what you can stop losing sleep over.
Motive scan
Take the three assets from your Module 2 risk table. For each, write one line: most likely motive (money, access, embarrassment, espionage) and most likely actor type (commodity criminal, scammer who knows you, insider, stranger). Compare: does your current effort match the motive, or is it guarding the wrong door?
Knowledge check · Module 1
1. The Unit 42 intrusion finished in under ten hours using no zero-days. Which conclusion is most defensible?
Correct: B. The report describes 50+ known ATT&CK techniques run in automated loops — fundamentals and response speed were the failure points, not exotic exploits.
2. A resource-limited attacker wants initial access to a mid-sized company. Based on 2026 incident patterns, the most reliable target is…
Correct: B. Edge appliances are reachable, privileged and under-monitored — the SonicWall and N-able incidents show exactly this preference.
3. Why do spraying campaigns use residential proxies and deliberately slow login attempts?
Correct: B. Low-and-slow pacing from residential IPs defeats threshold-based lockouts and reputation blocks; it does not itself defeat MFA.
🕹 Security Arcade · Module 01
Six rapid-fire questions · 15 seconds each · three lives · streak bonus up to +50 per answer. A perfect run scores 900 pts. Your best is saved in this browser.
The CIA triad, risk, and staying sane
Three letters carry the whole profession: confidentiality, integrity, availability. Once you can sort any incident into those buckets — and name the asset, threat, vulnerability and control in play — security stops feeling like folklore and starts feeling like engineering.
- By the end of this module you can…
- Classify any incident’s primary impact as confidentiality, integrity or availability.
- Use the asset–threat–vulnerability–risk vocabulary without hand-waving.
- Explain defence in depth and “assume breach” using a real 2026 example.
- Write a three-line personal risk statement (asset, threat, control).
2.1 CIA, with receipts
Confidentiality is about secrets staying secret: when Dropbox disclosed that ~5,000 accounts were accessed through a Lenovo ID single-sign-on verification weakness, attackers read and downloaded users’ files — a confidentiality failure. Integrity is about things being what they claim to be: the JFrog Artifactory auth-bypass (CVE-2026-82329) mattered because an attacker with admin tokens could replace trusted packages with backdoored ones — poisoning what every downstream build trusts. Vercel’s CEO called it an “RCE bomb” for exactly this reason.
Availability is about things working when needed: the Cisco Nexus 9000 flaw (CVE-2026-20212) could crash the switch’s S1HAL process and reload the device — a data-centre outage from a single crafted packet — and ransomware’s whole business model is availability held hostage. Most real incidents hit two or three pillars at once; your job is to name the primary loss, because that tells you which control would have mattered most.
2.2 Asset → threat → vulnerability → risk
Security speaks one grammar: an asset (something you value), a threat (something that can harm it), a vulnerability (a weakness the threat can use), and risk (how likely × how bad). A control reduces likelihood, impact, or both. Make it local: your asset is your mobile-money line; the threat is SIM-swap fraud; the vulnerability is weak identity proofing at the telco plus SMS-based codes; the risk is drained savings in an hour; controls are a porting PIN/line lock, moving MFA off SMS, and balance alerts.
This grammar also exposes lazy thinking. “We need AI security” is not a risk statement. “Our finance team’s approval workflow (asset) can be spoofed by WhatsApp impersonation (threat) because vendor bank-detail changes are never verified out-of-band (vulnerability), risking six-figure misdirected payments (impact)” — that is a risk statement, and it already contains its own control.
2.3 Defence in depth, and assuming the breach
Layers fail individually; that is why there are several. The StyleSmuggler Magento zero-day is a perfect autopsy: the patching layer could not work (no patch existed; the first victim was fully patched), yet on one compromised store the implant was found within an hour — because a merchant forwarded a weird “payment transaction failed” email to their host. A human reporting layer caught what no dashboard could.
“Assume breach” is the attitude that makes layers honest: you design as if compromise will happen, so you pre-agree what detection, containment and reporting look like. It is not pessimism; it is the difference between a fire drill and a fire panic.
One poisoned package, every build downstream
Integrity attacks are force multipliers: watchTowr observed attackers minting admin tokens on exposed Artifactory instances within days of disclosure. One compromised repository can ship a backdoor to every customer that trusts its packages — which is why supply-chain roles get their own module later (Module 8).
Your 3×3 risk table
Write three rows: asset / most plausible threat / one control you already have and one you’ll add this month. Include at least one non-digital asset (your ID documents count). This table returns in Module 12 as your audit baseline.
2.4 Risk treatment: the four honest choices
Once risk is named, you have exactly four moves: mitigate (add controls — MFA, backups, patching), transfer (insurance, or contractually shifting liability to a vendor), avoid (stop holding the data or running the service at all), and accept (decide, consciously and in writing, that the risk is cheaper than the fix). Every organisation does all four; mature ones know which is which. Immature ones believe a fifth option exists: “ignore, and hope nobody notices.”
What remains after treatment is residual risk — the honest baseline you live with. Vendors who promise to “eliminate risk” are selling the fifth option in a nicer font. Personal translation: you mitigate your email (manager + MFA), transfer your laptop’s loss (insurance or accepting replacement cost), avoid storing client IDs in WhatsApp chats, and accept that your public posts can be screenshotted. Naming the choice is what makes it a decision instead of an accident.
Accepted risk with an expiry date
Exchange 2016/2019 without Extended Security Updates is a textbook accepted risk — until 31 October 2026, when the acceptance silently becomes “permanently unpatchable.” Accepted risks need review dates, because the world moves while you accept.
Knowledge check · Module 2
1. An attacker silently replaces an internal build artifact with a backdoored version; nothing crashes and nothing leaks yet. The pillar primarily under attack is…
Correct: B. Trust in the artifact is broken even before anyone runs it; that is an integrity attack.
2. Ransomware encrypts a hospital’s scheduling and imaging systems; elective surgery is cancelled for a week. The primary loss is…
Correct: C. Modified files are an integrity symptom, but the scenario’s defining harm — services unavailable — is availability. (Exfiltration, if proven, would add confidentiality.)
3. Which control most directly reduces SIM-swap risk to your mobile-money account?
Correct: B. The attack targets number ownership and SMS codes; a porting PIN blocks the swap and non-SMS MFA removes the payoff.
🕹 Security Arcade · Module 02
Six rapid-fire questions · 15 seconds each · three lives · streak bonus up to +50 per answer. A perfect run scores 900 pts. Your best is saved in this browser.
Passwords, MFA, passkeys — and the session thieves
Identity is the new perimeter: attackers would rather log in as you than break in around you. This module builds your credential stack from the floor up — and shows the two tricks (stolen sessions, phished relays) that skip MFA entirely.
- By the end of this module you can…
- Explain credential stuffing and why one reused password becomes many breaches.
- Rank SMS OTP, TOTP and passkeys by phishing resistance, with reasons.
- Describe how stolen session cookies bypass MFA after login.
- Build a personal credential stack: manager + unique passphrases + passkeys.
3.1 Credentials are the new perimeter
Every breach corpus ever leaked is still for sale, and bots never sleep: credential stuffing fires your old email+password pairs at hundreds of services until something opens. Strength is irrelevant here — uniqueness is the defence. One password reused across five services means one breached forum from 2019 owns your 2026.
The practical floor in 2026: a password manager, and inside it a unique passphrase per service (four or more random words beat eight clever characters, and they’re typeable). The manager also kills the visual tell of phishing: it simply will not autofill on paypa1.com.
3.2 MFA that can be phished — and MFA that can’t
SMS codes die to SIM swaps and to real-time phishing relays that proxy your login while you type. TOTP apps beat SMS but still type into a fake site happily. Passkeys (FIDO2) are cryptographic and origin-bound: the key refuses to sign for a lookalike domain, which is why they are called phishing-resistant. Choose downward only when you must: passkey → TOTP → SMS → nothing is the wrong order.
And know MFA’s two bypasses so you respect its limits. First, session theft: after a successful login, your browser holds a session cookie — steal that (infostealer malware, or a compromised machine) and the attacker is logged in; no password, no MFA prompt. In 2026 researchers tracked info-stealers specifically harvesting authenticated AI-assistant session cookies to read corporate chat histories. Second, MFA itself can be backdoored: CISA’s Gunra ransomware advisory describes attackers editing a victim’s VDI portal so one attacker-chosen OTP always succeeded.
3.3 Your credential stack, in order
Build it like a building: manager (the floor), unique passphrases everywhere (the walls), passkeys where offered (the doors), TOTP as fallback (the spare keys), and session hygiene (the locks): sign out of shared devices, treat “stay logged in” on public machines as a donation, and when an account behaves strangely, rotate the password and revoke active sessions — rotating without revoking leaves the stolen session alive.
The cookies that bypassed MFA
Info-stealer campaigns extracted stored browser cookies for authenticated AI-assistant sessions straight from infected employee machines — no password, no MFA prompt, full conversation history including code and confidential context. MFA protects the door; it cannot protect a copied key already inside the room.
Move your five crown jewels
Email, mobile money/bank, primary social, work account, cloud drive: give each a unique manager-generated passphrase today; enable passkeys on at least two. Then open one service’s security page and find the “active sessions / sign out everywhere” button — know where it lives before you need it.
3.4 When the account is already gone: the recovery play
Sometimes you are not preventing takeover, you are evicting someone. Act in this order: recover access through the provider’s official flow from a clean device; then immediately inspect what attackers change first — recovery email, recovery phone, added MFA devices, active sessions, forwarding rules, connected apps. Remove their footholds before celebrating; a password reset with an attacker-owned recovery address is a revolving door.
Then contain the blast: warn contacts (hijacked accounts scam your friends next), check payment methods and addresses for additions, and where money or identity is involved, file the report while timestamps are fresh. Finally, learn the structural lesson: your recovery path is part of your credential stack. An outdated backup email is a back door with your name on it — audit recovery settings with the same seriousness as passwords.
Recovery-path audit
Open security settings on your email and your money app. Check: recovery email current? recovery phone current? any MFA devices or sessions you don’t recognise? any mail-forwarding rules you didn’t create? Fix or remove everything unexpected, and write the date beside each account in your manager.
Knowledge check · Module 3
1. A user with strong TOTP MFA is taken over without the MFA ever being broken. Most likely mechanism?
Correct: B. Sessions are post-authentication; presenting a valid cookie skips the login (and MFA) entirely.
2. Which factor best resists a real-time adversary-in-the-middle phishing proxy?
Correct: C. Passkeys sign per-origin; a proxy on a lookalike domain cannot obtain a valid assertion, while codes typed into a relay work fine for the attacker.
3. Why is password reuse catastrophic even when the reused password is long and “strong”?
Correct: B. Strength defends against guessing; reuse defeats you via other people’s breaches. Uniqueness is the property that matters here.
🕹 Security Arcade · Module 03
Six rapid-fire questions · 15 seconds each · three lives · streak bonus up to +50 per answer. A perfect run scores 900 pts. Your best is saved in this browser.
Phishing defence for the WhatsApp era
The most exploited vulnerability in 2026 is still a person trying to be helpful, fast, or polite. This module replaces “don’t click links” with a working method: recognise the pressure, verify out-of-band, and make reporting a reflex instead of a confession.
- By the end of this module you can…
- Name the four pressure levers every social-engineering lure pulls.
- Apply an out-of-band verification habit to payment and credential changes.
- Spot channel-hopping and tech-support-scam patterns (Quick Assist, refunds).
- Execute the first five minutes after a suspected click, in order.
4.1 Anatomy of a lure
Every social-engineering message, in any channel, pulls some combination of four levers: urgency (“within 24 hours”), authority (“CEO”, “bank fraud desk”, “Geek Squad refunds”), fear or greed (“failed transfer”, “you won”), and effort-minimisation (“just click to confirm”, “just run Quick Assist so I can fix it”). The 2026 twist is channel diversity: email for the office, SMS and WhatsApp for the wallet, voice calls for the anxious — and remote-support tools as the payload, as Huntress documented with rogue ScreenConnect installs seeded by Quick Assist tech-support scams and fake refund lures.
Notice what the levers attack: not your intelligence, your context. You are tired, mid-task, polite, or scared of looking silly. That is why the defence is procedural, not personal: a habit that runs even when you are tired.
4.2 The verification habit that ends most fraud
One habit beats a thousand warnings: verify out-of-band. Any request to change payment details, reset credentials, or grant remote access gets confirmed through a channel the message did not provide — the number on your card, the contact in your contract, walking over to the desk. Business-email-compensation fraud collapses against it; so does the “new WhatsApp number” CEO scam. Second habit: channel-hopping is a red flag. “Email me on WhatsApp” / “call this number” exists to escape the channel your organisation monitors.
Third: treat unexpected remote-access requests as hostile by default. Nobody legitimate needs you to run Quick Assist or install a remote client to “fix” a refund. In the ScreenConnect worm incidents, the initial accesses were exactly this: a support scam, a phishing MSI, a fake Geek Squad refund form.
4.3 The first five minutes after a click
Order matters more than speed: stop (do not type anything more), disconnect the trust, not the evidence — on a credential phish, change the password from a different device and revoke active sessions; on a file/executable, isolate the machine from the network but keep it powered on for forensics; report to bank/IT/telecom with screenshots; warn your contacts if identity or email is involved so the follow-on scam fails. Then breathe: reporting fast is a win, and organisations that punish reporters train their staff to hide breaches instead.
Remember the StyleSmuggler merchant: the fastest detection in that incident was a forwarded “weird email.” Your report is not an admission — it is a sensor.
“Let me help you fix that refund”
Huntress traced three unrelated intrusions to the same social shape: a victim persuaded to run a remote-support tool or open a “refund” lure, deploying rogue ScreenConnect clients that then spread worm-like to whoever connected next — including help-desk technicians arriving to help. Kindness, weaponised; verification, absent.
Run a two-person drill
Take a real scam SMS you’ve received. With one family member or colleague, rehearse: read it aloud, name which of the four levers it pulls, then perform the out-of-band check together (find the official number independently). Finish by agreeing one code word that means “verify me, I might be impersonated.”
4.4 The AI era of lures: when your eyes can’t verify
2026 social engineering stopped asking you to spot bad grammar. Voice-cloned “family emergency” calls, deepfake video of executives approving payments, and phishing emails written fluently by language models have moved verification out of the realm of perception: you cannot out-see or out-hear these lures, and trying to is a trap. Police agencies across several continents have warned about clone-voice calls pressing for instant money — the constant tells are urgency, secrecy (“don’t tell anyone”), and resistance to a call-back.
So the defence becomes purely procedural, which is good news: procedures don’t care how realistic the lie is. Pre-agreed code words for family and finance; mandatory out-of-band call-backs for any payment or credential change; a standing rule that urgency plus secrecy equals verification, every time, no exceptions for rank or emotion. The lie gets better; the procedure doesn’t need to.
“Mum, it’s me — my phone died”
Clone-voice calls impersonating relatives in trouble follow one script: distress, a new number, pressure to pay now, and anger at any hesitation. Families who survive it intact have one habit: a code word asked calmly before any money moves. Fifteen seconds of awkwardness beats a lifetime of regret.
Knowledge check · Module 4
1. An SMS from your “bank” asks you to call the number in the message about a failed transfer. Best next action?
Correct: B. Out-of-band verification uses a channel the message did not supply; the SMS number is attacker-controlled by definition.
2. A “CEO” messages from a new WhatsApp number requesting an urgent supplier bank-detail change. The single strongest control is…
Correct: B. Only a channel the attacker does not control verifies identity; moving to email still lands in attacker-controlled territory if the account is spoofed internally.
3. An employee reports within two minutes that they entered credentials on a phishing page. The best first organisational response is…
Correct: B. Speed of reporting is the asset to protect; revocation closes the window the phished credentials opened. Destroying logs destroys evidence.
🕹 Security Arcade · Module 04
Six rapid-fire questions · 15 seconds each · three lives · streak bonus up to +50 per answer. A perfect run scores 900 pts. Your best is saved in this browser.
Devices: the computers you actually own
Your phone is your bank, your ID wallet and your office. This module hardens the endpoints you personally control — and explains what “EDR”, “MDM” and “sideloading” mean when a company asks to put them on your machine.
- By the end of this module you can…
- Explain why updates are a security control, and set a personal patch rule.
- Distinguish antivirus, EDR and MDM — and what each can and cannot see.
- Describe how signed-but-malicious apps and AV exclusions defeat “trust”.
- Run a 10-minute phone hardening pass (SIM PIN, 2FA, sources, updates).
5.1 Updates are a security feature, not a nuisance
Every patch is a public confession of a flaw — and attackers read confessions faster than defenders deploy them. The September 2026 Exchange story is the archetype: fix shipped 11 August, working exploit code public by 27 August, and Shadowserver still counted 21,899 exposed unpatched servers on 1 September. Patch latency is the exploit window.
Your personal rule should be boring and absolute: OS and browser updates within 72 hours when rated critical (Chrome’s actively-exploited V8 zero-day, CVE-2026-85046, was fixed by an emergency update — the sixth Chrome zero-day of 2026), everything else within two weeks, auto-update on for apps wherever offered. And remember the uncomfortable footnote: sometimes the security product itself is the surface — Microsoft spent September racing to patch “ShieldBreak”, a privilege-escalation flaw in Defender’s own malware engine with a public PoC since August.
5.2 AV, EDR, MDM — the alphabet, decoded
Antivirus matches known bad files. EDR (endpoint detection & response) watches behaviour — process trees, odd PowerShell, credential access — and lets a SOC respond. MDM (mobile device management) is the enrolment layer: enforced encryption, patch policy, remote wipe for company data. When an employer asks to enrol your personal phone, the honest question is what can they see and what can they wipe — usually work-profile data, not your photos, but ask in writing.
And know how endpoints actually fall in 2026: not by exotic malware, but by trust misplacement. Kaspersky tracked “Silver Fox” distributing the ValleyRAT backdoor inside a genuinely signed Chinese wallpaper app — signed, because signatures prove provenance, not intent — and running it under trusted processes while victims were socially engineered into adding it to their antivirus exclusions. An exclusion is a hole you dug yourself.
5.3 The ten-minute phone hardening pass
In order of payoff: lock + encryption (biometric + strong PIN; modern phones encrypt by default — verify); SIM PIN plus a telco porting/line lock (Module 3’s SIM-swap control); app sources — store-only installs, no sideloaded APKs chasing “premium free”; messaging 2FA (WhatsApp/Telegram two-step PIN); auto-update on for OS, browser, banking apps; Find My Device on; and a permissions sweep — does the torch app really need contacts? Charge-only on strange USB ports is paranoia-lite: the realistic risk is low, the habit is free.
The backdoor the user whitelisted
ValleyRAT’s disguise worked because victims were coached into adding the “adware” to antivirus exclusions — then the backdoor ran under trusted process names. Signature valid, user consent obtained, AV blind. Trust is a configuration; attackers configure it too.
Phone hardening pass
Do all five now: confirm auto-updates on; set SIM PIN; enable messaging-app two-step verification; review permissions on your three most-permissioned apps and revoke one each; confirm Find My Device and screen-lock timeout (<2 min).
5.5 Loss, theft and the second-hand market
Devices also die socially: they get lost on matatus, stolen off tables, or sold onward. Pre-commit the sequence so panic doesn’t choose for you: remote lock first (Find My Device / Find My), then change the crown-jewel passwords from another device and revoke sessions, then telco SIM lock, then bank-app logout where offered, then remote wipe only after you’ve preserved what investigations or insurance need. Wiping is irreversible; sequence matters.
The market runs both ways. Buying used: insist on a clean factory reset in front of you, no activation locks (FRP/iCloud), and update immediately — second-hand phones often ship with ancient, exploitable builds. Selling or disposing: sign out of everything, remove SIM and SD, encrypt-then-factory-reset, and keep the receipt trail. A wiped phone with your account still signed in is not wiped; it is a donation.
Loss-prep in five minutes
Enable remote lock/locate now if off; write your phone’s IMEI (dial *#06#) into your password manager’s secure notes; add the telco’s SIM-lock line to your IR card. Three minutes of paperwork that turns a future crisis into a checklist.
Knowledge check · Module 5
1. ValleyRAT shipped inside a genuinely code-signed app. Why doesn’t the signature make it safe?
Correct: C. Signing attests provenance/integrity; attackers obtain and abuse real certificates, so “signed” never means “safe”.
2. A “support agent” walks a user through adding an app to the antivirus exclusion list. The exclusion matters because…
Correct: A. Exclusions tell every control to look away — the cheapest persistence trick in social engineering.
3. Which single configuration most reduces the impact of a stolen, powered-off phone?
Correct: B. Encryption turns a stolen device into a brick of ciphertext; patterns and app counts change little, and AV doesn’t protect data at rest.
🕹 Security Arcade · Module 05
Six rapid-fire questions · 15 seconds each · three lives · streak bonus up to +50 per answer. A perfect run scores 900 pts. Your best is saved in this browser.
Routers, Wi-Fi and the VPN truth
Your router is a computer that decides what reaches your home — and in 2026, perimeter routers were among the most-abused devices on the internet. Here’s how to own yours, survive café Wi-Fi, and know exactly what a VPN does and doesn’t do.
- By the end of this module you can…
- Harden a home router: admin creds, firmware, WPA2/3, guest isolation.
- Explain the realistic risks of public Wi-Fi and the rules that neutralise them.
- State precisely what a VPN protects you from — and what it doesn’t.
- Explain why unpatched routers become botnet and proxy infrastructure.
6.1 Your router is an edge device (act like it)
Everything in Module 1 about “the edge” applies to the box under your TV: always on, privileged, unwatched. September 2026 reporting on MikroTik RouterOS flaws described exactly the downstream abuse: unpatched perimeter appliances used for unauthorised config changes, packet interception, command proxies and DDoS botnets. Separately, the “Fire Ant” espionage campaign planted covert GRE tunnels inside Cisco IOS XR routers to siphon live traffic — routers as spy hardware.
The home checklist is short and unglamorous: change the factory admin password (still the #1 router failure); update firmware and enable auto-update if present; WPA2-AES or WPA3, never WEP/open; disable WPS; put IoT gadgets and guests on a guest network so a compromised bulb can’t reach your laptop; and disable remote admin from the internet unless you can explain why you need it.
6.2 Public Wi-Fi: the real risk model
HTTPS encrypts your traffic’s contents end-to-end, so the old “everyone reads your passwords at the café” story is mostly dead. The living risks are: rogue/evil-twin access points with convincing names; attacks on the unencrypted leftovers (captive portals, legacy protocols, local file sharing, printer discovery); and simple local proximity — same network means your device can be scanned and probed directly. Rules: forget networks after use, disable auto-join, keep the device firewall on, and for anything sensitive on untrusted Wi-Fi use your phone’s hotspot or a VPN.
6.3 What a VPN does — and the marketing lie
A VPN encrypts the hop between you and the VPN server and masks your traffic from the local network — genuinely valuable on hotel and café Wi-Fi, and for routing around censorship or hostile networks. It does not make you anonymous to the sites you log into (they still see your account), it does not block malware or phishing, and it does not replace device security — you are simply extending trust to the VPN provider. Choose providers like you choose banks; free VPNs are usually the product.
Tunnels inside the tunnel-makers
Fire Ant’s campaign hid GRE tunnels in router configs and exfiltrated live packet captures; MikroTik abuse turned neglected routers into proxy fleets. The pattern for defenders: inventory the routers you forgot (home, branch, SOHO), because attackers already have.
Router audit
Log into your router (sticker or 192.168.x.1): change admin password if default; note firmware version and check for updates; confirm WPA2-AES/WPA3; disable WPS; enable guest network for IoT. Write the model + firmware date somewhere you’ll find it next quarter.
6.5 Segmenting a home network without enterprise gear
You don’t need VLANs to get most of the benefit: your router’s guest network is a segmentation tool wearing a hospitality costume. Put every IoT device — bulbs, cameras, smart plugs, the TV that argues with updates — on guest Wi-Fi with client isolation on, and keep phones and laptops on the main network. A compromised camera now sees nothing but other compromised cameras.
Three more cheap wins: turn UPnP off (it lets devices punch holes in your firewall autonomously, and malware loves it); replace remote-access port forwarding with a VPN or vendor cloud relay; and consider a filtering resolver such as Quad9 (9.9.9.9) at router level, which blocks known-malicious domains for every device at once — including the ones too old to protect themselves. Fifteen minutes of router configuration, years of quiet.
Three router switches
In one sitting: disable UPnP; enable guest network and move IoT devices onto it; set DNS to a filtering resolver (or note it as this week’s task if your router refuses). Screenshot your settings page into your manager’s secure notes — future-you will reconfigure faster.
Knowledge check · Module 6
1. With HTTPS everywhere, what is the primary realistic risk of open café Wi-Fi?
Correct: B. Content is protected; position is the risk — rogue APs, local scanning and any plaintext protocol or service discovery still bite.
2. On hostile hotel Wi-Fi, a reputable VPN’s main protection is…
Correct: A. The VPN shields the local hop; logged-in sites still identify you, and malware/phishing travel fine inside the tunnel.
3. Per 2026 reporting, the most common real-world fate of neglected, unpatched SOHO routers is…
Correct: C. MikroTik abuse and IOS XR espionage both treat routers as durable, privileged footholds — quiet, reachable, and rarely logged.
🕹 Security Arcade · Module 06
Six rapid-fire questions · 15 seconds each · three lives · streak bonus up to +50 per answer. A perfect run scores 900 pts. Your best is saved in this browser.
Your data: what exists, who holds it, what the law says
Privacy is security’s quiet twin: the data that exists about you is the map attackers plan with. This module inventories that map, translates Kenya’s Data Protection Act into plain rights, and cuts your exposed surface in an afternoon.
- By the end of this module you can…
- List the four places personal data leaks from (breaches, brokers, telemetry, you).
- Summarise Kenya DPA 2019 rights: consent, access, correction, erasure, breach notice.
- Reduce app/service data exposure with a permissions and backups pass.
- Explain how oversharing becomes reconnaissance for account recovery attacks.
7.1 The map that already exists
Assume four copies of “you” are circulating: breach corpora (old leaks, forever for sale — check your email on a breach-lookup service today), data brokers and ad ecosystems (inferred profiles, location histories), app telemetry (contacts, photos metadata, usage), and you (posts, tags, check-ins, the school name in your bio). Scammers compose these copies: your pet’s name in a 2019 post is a password-reset answer in 2026.
Metadata deserves special suspicion: a “harmless” photo can carry GPS coordinates, device model and timestamp. Strip or disable location tagging for public posts, and remember that the audience of a “friends-only” post includes every friend’s compromised account.
7.2 Kenya’s DPA 2019, in human sentences
The Act says, in effect: your personal data may only be collected with a lawful basis (usually your informed consent), only for a stated purpose, only as much as is necessary; you may ask what is held about you, correct it, and in many cases demand deletion; and when it is breached, the holder must notify the regulator — and where the harm is real, you — without undue delay. The Office of the Data Protection Commissioner (ODPC) is your escalation route when a company stonewalls you.
Use it practically: when an app demands contacts “or you can’t continue,” that is a purpose-limitation conversation; when a company you left still emails you, that is an erasure request; when your bank breaches, notification is not a favour — it is the law.
7.3 The afternoon cleanup
Four passes, in order: breach pass (lookup your email; rotate everything listed); permissions pass (revoke contacts/location/mic from apps that don’t earn them); backup pass (enable end-to-end-encrypted cloud backups for WhatsApp and device, or accept that your “private” chats sit in someone’s cloud in plaintext); visibility pass (social: hide birthday year, old posts audit, stranger-followers prune). None of this makes you invisible; all of it makes you expensive.
When someone else’s weak check becomes your open door
Dropbox’s incident: attackers abused an email-verification weakness in Lenovo ID, then Dropbox’s federated login accepted the asserted email without a second challenge — ~5,000 accounts accessed. Your data’s safety can depend on a partner company’s verification logic you have never heard of. Federated convenience is borrowed trust; inventory what is connected (Module 8).
Breach + permissions double-pass
1) Run your primary email through a reputable breach-lookup service; change every password that appears. 2) In phone settings, sort apps by permissions; revoke one permission from each of your three greediest apps. 3) Turn on encrypted chat backups if offered.
7.4 Asking for your data: subject-access requests that work
Kenya’s Data Protection Act gives you leverage most people never use: the right to ask any organisation holding your personal data what they hold, why, and where it came from — and to request correction or erasure. A subject-access request needs no lawyer: a short email naming yourself, your identifiers (account number, phone), the request (“a copy of my personal data processed, its purposes and recipients”), and a deadline reference (“within the period prescribed by the Data Protection Act, 2019”) is legally sufficient.
Keep expectations adult: some replies are slow or evasive; that is when you escalate to the ODPC with your paper trail attached. Even never sending a request, knowing the mechanism changes how you read every “we value your privacy” banner — you now know it is a legal duty with a regulator behind it, not a favour. Privacy stops being vibes the day you write your first request.
Four-line SAR email
“Dear Data Protection Officer, I am [name], account [x]/phone [y]. Under the Data Protection Act, 2019, I request: (1) confirmation of personal data you process about me; (2) a copy of that data; (3) its purposes and recipients. Please respond within the statutory period. Regards.” Save sent mail; diarise 30 days.
Knowledge check · Module 7
1. The Dropbox–Lenovo ID incident’s core lesson is…
Correct: C. Dropbox trusted an assertion produced by Lenovo ID’s flawed email verification; owning an inbox address was treated as proving identity.
2. Which set counts as personal data under Kenya’s DPA-style protections?
Correct: D. Personal data is anything relating to an identified or identifiable person, including technical identifiers and inferred/located activity.
3. Why disable location metadata on publicly shared photos?
Correct: A. Embedded coordinates plus timestamps are free reconnaissance for stalking, burglary timing and social-engineering prep.
🕹 Security Arcade · Module 07
Six rapid-fire questions · 15 seconds each · three lives · streak bonus up to +50 per answer. A perfect run scores 900 pts. Your best is saved in this browser.
Cloud accounts, SaaS and the vendors holding your keys
Most of your life runs on other people’s computers. This module teaches the shared-responsibility split, the OAuth/grant inventory nobody does, backup strategy that survives ransomware, and the vendor question that separates mature organisations from lucky ones.
- By the end of this module you can…
- Explain the shared-responsibility model with one concrete example per layer.
- Audit and revoke third-party app grants (OAuth) on your cloud accounts.
- Design a 3-2-1 backup scheme with one immutable or offline copy.
- Ask a vendor the four questions that expose their real security posture.
8.1 Shared responsibility, without the slide deck
The provider secures the cloud: physical datacentres, hypervisors, the fabric. You secure in the cloud: your accounts, your configurations, your data, your sharing links. Nearly every “cloud breach” headline is a your-side failure: an over-broad sharing link, a storage bucket left public, an unrevoked ex-employee grant. Default-deny is the posture: private by default, shared deliberately, reviewed quarterly.
8.2 Grants, integrations and the shadow perimeter
Every “Sign in with X” and every connected app is a standing permission: read my mail, post as me, see my files. Attackers love OAuth abuse because it needs no password — the token is the key. Twice a year, open your Google/Microsoft/account “third-party access” page and revoke ruthlessly; anything you don’t recognise gets evicted, not investigated. The Dropbox incident adds the federation clause: integrations can also inherit a partner’s verification weaknesses, so the inventory includes SSO links, not just apps.
8.3 Backups that survive ransomware, and exits that survive vendors
3-2-1: three copies, two media, one offsite — and in 2026, one immutable or offline, because ransomware now deletes reachable backups first. Test a restore quarterly; an untested backup is a rumour. Then the vendor exit question: if this SaaS vanished tonight, what would you get back, in what format, how fast? “Your data is yours” should be a download button, not a slogan.
And when a vendor is breached, respond like JetBrains’ customers were told to: rotate what you entrusted. JetBrains disclosed that attackers entered through its own unpatched TeamCity server (CVE-2026-63077), took a 2024 backup of its Cadence service and touched AWS credentials — users were told to revoke/rotate everything used in Cadence executions and treat those outputs as untrusted. Your vendor’s patch hygiene is your risk; the four questions: how do you patch, how fast? what do you hold about us? how would you notify us, and within how long? can we export and leave?
The vendor that told everyone to patch — except itself
JetBrains disclosed CVE-2026-63077 on 27 July, warned customers, and was itself breached through an unpatched instance from 8–24 August. The irony is the lesson: supplier security claims age like fish. Verify with questions, contracts and rotation drills — not brochures.
Grant purge + backup proof
Open third-party access on your two biggest cloud accounts; revoke at least three stale grants. Then locate your most important document’s backup: when was it last copied, where does it live, and could you restore it tonight? If any answer is “unsure,” that’s this month’s project.
8.4 SaaS sprawl: the accounts you forgot are still holding you
Every trial signup, quiz site and dead startup that ever took your email is a standing copy of some version of you — password hashes from 2014, phone numbers from 2018, ID scans from that one KYC form. Breach after breach is simply these forgotten warehouses leaking on schedule. Your password manager’s full account list is therefore not a convenience feature; it is your personal asset register, and the dormant entries are your unmapped attack surface.
Run the sprawl purge twice a year: for each dormant account, decide delete or defend — delete with the provider’s closure flow (or erasure request when they stall), or defend with a unique password and MFA if it still earns its place. For new signups, consider purpose aliases: a dedicated email for financial life, one for shopping, one for experiments. Sprawl is how one 2019 forum breach becomes a 2026 takeover; registries are how it doesn’t.
Count your warehouses
Open your manager, count total accounts, then flag every account untouched in 12+ months. This month: close three of them properly (delete, not abandon). Record the count; watch it fall each half-year. Fewer warehouses, fewer leaks with your name on them.
Knowledge check · Module 8
1. After the JetBrains Cadence disclosure, the most important action for affected users was…
Correct: B. Compromise of the execution environment means anything presented to it is assumed taken; rotation closes the reuse path while scope is still unknown.
2. In the shared-responsibility model, which item is normally YOUR side?
Correct: C. Providers own the cloud’s substrate; customers own what their accounts, configs and links expose.
3. Why keep one immutable or offline backup copy?
Correct: A. If every backup is writable from the compromised environment, “backup” is just the attacker’s second encryption target.
🕹 Security Arcade · Module 08
Six rapid-fire questions · 15 seconds each · three lives · streak bonus up to +50 per answer. A perfect run scores 900 pts. Your best is saved in this browser.
CVEs, CVSS and the patching economy
“Critical vulnerability” is a headline; CVE-2026-20212 (CVSS 9.8, AV:N/AC:L/PR:N/UI:N) is a sentence you can actually act on. This module teaches you to read advisories like an analyst — and to understand why patching alone never finishes the job.
- By the end of this module you can…
- Decode a CVE entry: identifier, CVSS vector, affected versions, workaround vs fix.
- Explain why reachability and chaining outrank raw CVSS in prioritisation.
- Describe the KEV catalogue and what listing changes operationally.
- Explain “fully patched but compromised” using StyleSmuggler.
9.1 Reading an advisory like an analyst
Every advisory answers five questions: what (CVE id + weakness class), how bad (CVSS — note the vector: network? complexity? privileges? user interaction?), who is affected (exact versions/PIDs), is it exploited (KEV listing, vendor PSIRT language), and what now (fixed release vs workaround). Cisco’s September advisory is a clean specimen: CVE-2026-20212, CVSS 9.8, vector AV:N/AC:L/PR:N/UI:N — reachable over the network, easy, no credentials, no click — because TCP ports 43210/43211 sat open in the default VRF; fix = upgraded NX-OS; workaround = iACLs blocking those ports.
Two reading habits separate pros from panic: CVSS is severity, not risk — a 9.8 buried in a sealed management VLAN loses to a 7.5 facing the internet with no auth; and “workaround” is not “fix” — it is a bridge you pay tolls on until the real release lands.
9.2 The exposure economy
Disclosure starts a race both sides can see. Shadowserver’s internet-wide scans flagged 21,899 Exchange servers still unpatched against CVE-2026-62911 three weeks after the fix — the same count attackers use as a shopping list. End-of-support makes it structural: Exchange 2016/2019 fixes ride on paid Extended Security Updates that end 31 October 2026, after which “unpatched” becomes permanent. And “it’s internal only” is a topology hope, not a control: Cisco’s own advisory notes a switch needn’t face the internet if a compromised segment can reach it.
Prioritisation, then, is exposure math: KEV-listed or actively exploited → now; internet-reachable unauthenticated RCE → this week; everything else on SLA. KEV (CISA’s Known Exploited Vulnerabilities catalogue) is the profession’s agreement to stop debating scores once real exploitation exists — SonicWall’s chained SMA1000 flaws landed there within days of disclosure.
9.3 Chains, and the patched-but-compromised paradox
Attackers compose flaws the way chefs compose flavours: SonicWall’s 10.0 pre-auth SSRF bought privileged reach; the 7.8 command injection cashed it in — individually “just” two CVEs, together an unauthenticated takeover. Which brings us to the paradox every practitioner must internalise: patch status does not equal safety. StyleSmuggler’s first victim ran the highest patch level available with a clean patch report — and was compromised by a flaw no vendor had described yet. Vulnerability management is therefore three jobs, not one: inventory (you cannot patch what you forgot), exposure reduction (disable GraphQL, block ports, segment), and detection (for the flaw with no CVE yet).
Two open ports, root on the switch
Cisco found CVE-2026-20212 itself, while closing a support ticket — a reminder that criticals often surface quietly. The ports (43210/43211) were open by default. Default configurations are the attacker’s standing invitation; your job is to rescind it.
Decode one real advisory
Open any current vendor advisory (Cisco PSIRT, SAP notes, or a KEV entry). Extract five fields: CVE, CVSS vector, affected versions, exploitation status, fix vs workaround. Write a three-line summary a manager could act on. If your three lines change a decision, you’ve learned the module.
9.4 A personal vulnerability-management loop
Organisations run vulnerability management as a discipline; you can run a credible solo version in twenty monthly minutes. Keep a tiny register — a notes-app table: asset / version / update channel / last checked — covering phone, laptop, router, TV/IoT oddities, and your five crown-jewel services. Each month walk it: OS and browser updates applied? router firmware current? any service shouting about a breach? Any “critical” headline touching your assets gets the 72-hour rule from Module 9’s SLAs.
The register’s real power is memory: “last checked” columns turn guilt into schedule, and the asset list kills the classic personal-security failure — forgetting the device in the drawer that still receives your OTPs. Pair the loop with the quarterly rituals from Module 12 and you have, in miniature, exactly what auditors look for in organisations: inventory, cadence, evidence.
Your first register row-set
Create the table with five rows today (phone, laptop, router, money app, email). Fill versions roughly, set “last checked = today,” and add a monthly calendar repeat named “Vuln loop.” Imperfect data entered today beats perfect data imagined next month.
Knowledge check · Module 9
1. Flaw A: CVSS 9.8, reachable only from a sealed management VLAN. Flaw B: CVSS 7.5, internet-facing, unauthenticated. With limited patch capacity this week, you fix…
Correct: B. CVSS measures intrinsic severity; risk multiplies it by exposure. An unreachable 9.8 is a scheduled task; a reachable 7.5 is an incident waiting.
2. A vulnerability appears in CISA’s KEV catalogue. Operationally, this means…
Correct: C. KEV records observed exploitation; that evidence outweighs theoretical scoring in prioritisation.
3. StyleSmuggler compromised a store running the highest available patch level with a clean patch report. The defensible conclusion is…
Correct: A. Patching defends the known; zero-days are the unknown — layers two and three (exposure, detection) exist precisely for them.
🕹 Security Arcade · Module 09
Six rapid-fire questions · 15 seconds each · three lives · streak bonus up to +50 per answer. A perfect run scores 900 pts. Your best is saved in this browser.
The first hour: your personal incident playbook
Unit 42’s ten-hour breach and your drained mobile-money account run on the same clock: the first hour decides the outcome. This module gives you containment orders, evidence habits and reporting routes — for work incidents and for the ones that hit your own wallet.
- By the end of this module you can…
- Execute correct first actions for credential phish, device malware and bank fraud — in order.
- Preserve evidence without playing forensic hero.
- Name the reporting routes for personal and organisational incidents (incl. Kenya).
- Explain why post-incident resets include MFA seeds and sessions, not just passwords.
10.1 Detect without destroying
Detection signals are usually mundane: a bank SMS you didn’t trigger, a “password changed” mail you didn’t request, a device that’s hot and slow at 3am, colleagues receiving strange messages “from you,” a supplier invoice with new bank details. The first discipline: stop feeding the incident — no more typing, no more clicking — and the second: don’t destroy evidence. Reformatting the laptop feels like cleanup and is, forensically, arson. Screenshots, timestamps, message headers and the powered-on machine are your case file.
10.2 Containment orders, by scenario
Credential phish: change the password from a different, clean device, then revoke active sessions and tokens — rotating without revoking leaves the attacker’s session sipping coffee in your account. Device malware/ransomware: disconnect network (Wi-Fi off, cable out) but keep power on; do not wipe; hand to IT/forensics. Bank or mobile-money fraud: call the fraud line from a known number, request hold/reversal windows, change credentials from clean device, then written report. SIM-swap signs (signal dead + reset SMS elsewhere): telco line lock immediately, then every SMS-dependent MFA moves to app/passkey.
At work, the same shapes scale: isolate, preserve, escalate with a timeline attached. Speed beats completeness in the first report; completeness beats poetry in the second.
10.3 Report routes, and the resets people forget
Personal incidents in Kenya have real doors: your bank’s fraud desk and the payments-reversal process, telco fraud lines, the DCI Cybercrime Unit for criminal matters, the ODPC when your personal data is breached by an organisation, and CERT.ke / CAK context for service-level incidents. Organisational incidents follow your IR procedure (Module 11) and statutory clocks — GDPR’s 72 hours, Kenya DPA’s notification duty.
Post-incident, reset what the attacker touched, not just what they typed: passwords, active sessions, OAuth grants, API keys — and MFA enrolments. CISA’s Gunra ransomware advisory describes attackers editing a victim’s VDI portal so an attacker-chosen OTP always succeeded: if MFA itself was tampered with, “we changed the password” is a lullaby. Re-enrol MFA from scratch, and review MFA method downgrade history where logs allow.
The OTP that always said yes
Gunra actors modified authentication portal files so one chosen OTP always passed — MFA as a backdoor, not a wall. Their toolkit also stole session cookies and dumped credentials from stores. Moral: post-incident, audit the authentication path itself, or you reinstall trust into a rigged lock.
Write your IR card
Five lines, wallet or notes app: bank fraud number (from card, not inbox); telco line-lock route; work IT/SOC contact; where your password manager emergency kit lives; your family/code-word verification phrase. Test one line tonight by actually finding the number.
10.4 Helping someone else through their incident
Sooner or later the phone rings: a parent scammed, a colleague phished, a friend locked out of mobile money. Your job is co-regulation before containment — panic contagion causes the worst decisions (paying immediately, wiping evidence, shouting at the victim). Script your first minute: “You did the right thing telling me. We’ll handle it step by step. Don’t touch anything yet.” Then run their containment with them, out loud: clean device for rotations, session revocation, bank and telco calls, screenshots before anything is deleted.
Guard the language: “how did you fall for that?” is not analysis, it is training them to hide the next incident — the exact culture failure organisations pay millions to undo. Debrief later, kindly, as a procedure gap (“we need a code word”) rather than a character flaw (“you’re careless”). Communities that respond well to the first victim create the reporting culture that saves the second.
Family incident protocol
In your family group chat, post three lines: the code word; who calls the bank first; and the no-blame rule (“reporting fast is always right”). Pin it. The day it’s needed, nobody will remember this module — they’ll remember the pinned message.
Knowledge check · Module 10
1. A laptop shows early ransomware behaviour (files renaming, heavy disk). Best first action?
Correct: C. Isolation stops spread; power preserves memory/evidence; reformatting destroys both the case and sometimes recoverable keys.
2. Why change a phished password from a DIFFERENT device?
Correct: B. Clean-device rotation plus session revocation closes both the credential and the live-session paths.
3. After an incident where MFA may have been tampered with (Gunra-style), what must be reset beyond passwords?
Correct: A. Authentication infrastructure is part of the blast radius; re-enrol from scratch and revoke standing tokens.
🕹 Security Arcade · Module 10
Six rapid-fire questions · 15 seconds each · three lives · streak bonus up to +50 per answer. A perfect run scores 900 pts. Your best is saved in this browser.
Policies, standards, procedures — and you
Organisations defend through documents and culture; attackers exploit the gap between them. This module decodes the governance pyramid (policy → standards & guidelines → procedures), shows where your daily habits sit inside it, and makes the case that reporting culture is a control.
- By the end of this module you can…
- Distinguish policies, standards, guidelines and procedures with examples.
- Locate your daily obligations inside acceptable-use and remote-work rules.
- Explain why near-miss reporting is a detection control, not a confession.
- Draft a three-line verification rule for your team.
11.1 The governance pyramid, decoded
Policies are the broad statements of intent — “client data is handled as if it were our own crown jewels.” Standards are specific mandatory requirements for an area or technology — “MFA must be enforced on all administrative access”; guidelines are the recommended cousins (“you should prefer phishing-resistant methods”). Procedures are the step-by-step executions — the eight-move vulnerability remediation workflow, the joiners-movers-leavers checklist with its 24-hour revocation clock. Policies say why; standards say what, exactly; procedures say how, in order, by whom.
Why care if you’re not “management”? Because every audit, client questionnaire and incident post-mortem runs on this pyramid — and because the fastest way to look senior in a security conversation is to ask which layer a decision belongs to. “That’s a policy question” and “that needs a procedure” are complete, professional sentences.
11.2 Where you live in the pyramid
Your daily obligations are procedures wearing casual clothes: lock screens and clean desks (confidentiality), no shared accounts (accountability — a shared login is a shared identity, and “who did it?” becomes unanswerable), asset returns on exit, visitor escorting, and acceptable-use boundaries (company systems for company work, personal data off company devices and vice versa). Remote work extends the corporate edge into Module 6 territory: your home router is now infrastructure your employer’s data transits — which is why sane remote-work standards mandate updates, disk encryption and private networks for sensitive calls.
And the cultural clause, which no tool can replace: reporting speed is a control. The StyleSmuggler implant found within an hour was found because a merchant forwarded a weird email without feeling silly. Organisations that punish reporters train staff to hide breaches; organisations that thank them install a human sensor network for free.
11.3 When procedures meet worms
The ScreenConnect worm is a procedures autopsy: initial accesses were social (Quick Assist scam, phishing MSI, fake refund lure), but the propagation exploited a missing verification step — technicians connecting to infected hosts with no “confirm origin” gate, and file transfer left enabled. ConnectWise’s interim advice (disable file transfer until patched) is exactly what a procedure is: a written brake applied at organisational speed. Your takeaway: any tool that can move files or control screens needs a written “verify before you connect” rule — and the discipline to follow it at 4:55pm on a Friday.
The help desk as patient zero… and vector
Huntress’s three incidents shared one gap: no procedure required verifying a support session’s origin before connecting or transferring files. The malware repaid the kindness by pushing its four-stage VBScript chain onto every new connection — including the technicians’ own environments.
Draft your team’s verification rule
Three lines, plain language: (1) which requests always require out-of-band verification (payments, credentials, remote access); (2) the approved verification channel; (3) the no-blame reporting route and its SLA. Post it for comment — a rule the team edits is a rule the team obeys.
11.4 Reading a policy like an auditor (a 15-minute career skill)
Open any security policy and ask five questions: who owns it (a role, not a department mascot)? when was it reviewed (a date older than two years is decoration)? what’s in scope (people, systems, third parties — or vague “all staff” hand-waving)? how are exceptions handled (written, time-bound, approved — or silent)? and does every “must” point at a procedure that explains how? Policies failing these tests are wallpaper; policies passing them are operating systems.
This skill compounds: it is exactly what client questionnaires, ISO-style audits and interview panels probe, and it flips your relationship with rules from obedience to judgement. Practise cheaply on public documents — banks’ privacy notices, SaaS security pages — noting what’s missing. Within a month you’ll spot an unowned, unreviewed, exception-free policy in ninety seconds, and say the sentence that gets attention in any room: “which layer of the pyramid does this decision belong to?”
Audit a public policy
Pick one public policy or privacy notice you’re subject to. Score the five questions above in a notes file: owner? review date? scope? exceptions? procedure links? Write one paragraph on what’s missing. Keep it: this paragraph is a ready answer to “tell me about a time you analysed documentation” in any security interview.
Knowledge check · Module 11
1. “All remote administrative access must use multi-factor authentication; the step-by-step enrolment workflow is documented in PR-03.” The first clause and the referenced document are, respectively…
Correct: B. “Must” + specific technology requirement = standard; numbered steps with owners = procedure.
2. A colleague borrows your unlocked laptop “for five minutes” and sends an email from your account. The core security property damaged is…
Correct: C. Shared sessions destroy non-repudiation; this is why shared logins are standard-level prohibitions, not etiquette.
3. Why treat near-miss reports (clicked, noticed, reported) as a detection control?
Correct: A. The two-minute report is a sensor reading; culture determines whether the sensor stays connected.
🕹 Security Arcade · Module 11
Six rapid-fire questions · 15 seconds each · three lives · streak bonus up to +50 per answer. A perfect run scores 900 pts. Your best is saved in this browser.
The audit: defend your own kill chain
Everything converges here. You will re-open the kill-chain map from Module 1 and the risk table from Module 2, audit your real estate against a twelve-point checklist, schedule the rituals that keep it true, and choose your next step in the profession — Cisco, SANS/GIAC, IBM or the VunVault lab path.
- By the end of this module you can…
- Score your personal security estate against a twelve-point audit.
- Prioritise remediation by risk, not by anxiety.
- Install four quarterly rituals that keep the audit true.
- Map a credible certification pathway from where you stand today.
12.1 The twelve-point audit
Score each item Yes/No; every No is a scheduled task, not a shame: 1 Unique passphrases via manager on email, money, work, cloud. 2 Phishing-resistant or app MFA on those four (no SMS on money). 3 SIM PIN + telco line lock. 4 Devices encrypted, locked <2 min, Find-My on. 5 OS/browser auto-update on; critical patches <72h habit. 6 Router: admin password changed, firmware current, WPA2/3, guest net for IoT. 7 Backups 3-2-1 with one immutable/offline copy, restore tested this quarter. 8 Cloud grants purged in last 6 months; sharing links default-private. 9 Breach-lookup run; exposed passwords rotated. 10 App permissions swept; encrypted chat backups on. 11 IR card written; family code-word agreed. 12 Verification rule (Module 11) practised with at least one other human.
12.2 Rituals that keep it true
Security decays silently: grants accumulate, firmware ages, backups rot. Four quarterly rituals arrest the decay — grant purge (third-party access pages), restore test (one real file, end to end), patch & firmware day (router, IoT, neglected laptops), and access & session review (active sessions, old devices, ex-accounts). Diarise them like tax dates. Re-run the twelve-point audit twice a year; track your score as a number, because numbers move behaviour that intentions cannot.
12.3 Where you go from here
If this course landed, the profession has doors at every level: Cisco Networking Academy / Skills for All for structured, lab-heavy fundamentals and the CCST track; IBM’s Cybersecurity Analyst certificate path for a broad analyst stack with a breach-case capstone; CompTIA Security+ as the classic first credential; and when you’re ready for practitioner depth, SANS courses with GIAC certifications (SEC275/GFACT is the friendly on-ramp). Pair any of them with hands-on repetition — labs, CTFs, home-lab builds — because every one of these bodies certifies skill, and skill is a contact sport. VunVault’s own labs and this Academy’s future modules sit in the same tradition: learn by doing, then prove it under exam conditions.
Whatever you choose, keep the two sentences this course was built on: make yourself the expensive target, and be fast and loud when something slips through. Everything else is syllabus.
Ten hours versus your first hour
Unit 42’s AI-accelerated intrusion compressed fifty techniques into a working day. Your counter-compression is smaller and just as real: an IR card in your wallet, a code-word in your family, a restore tested last quarter. Speed is a prepared artefact.
Close the loop
Run the twelve-point audit honestly; schedule your four quarterly rituals in a calendar today; pick one certification pathway and write down the first concrete step (course page, exam voucher, study group). Then take the final exam — 80% to earn the certificate, exactly like the big programmes.
12.4 Staying sharp: labs, communities and the weekly hour
Knowledge decays; skill persists — but only if rehearsed. Build the cheapest lab that works: one old laptop or a free VM slot, a deliberately vulnerable practice image, and a sandboxed browser for opening suspicious things on purpose. Add one CTF or lab platform account and commit to a weekly hour: sixty minutes of hands-on repetition beats a yearly binge, because security is pattern memory and pattern memory needs spacing.
Then add people: a local community (Nairobi’s security meetups and BSides-style conferences are real and welcoming), one online forum or Discord where practitioners post write-ups, and a habit of reading one incident report a week — like the case files in this course — and summarising it in three lines of your own. Certificates open doors; the weekly hour and the write-up habit are what make you worth hiring behind the door. VunVault’s labs and future Academy modules are built to slot into exactly this rhythm.
Book the hour, join the room
Create a recurring weekly calendar slot named “Security hour” with a rotating menu (lab, CTF, write-up, audit ritual). Then join one community today — even lurk-only. Skill is a contact sport; the calendar and the room are your training partners.
Knowledge check · Module 12
1. Your audit finds: email password reused on three forums (no MFA), and mobile money protected only by SMS codes. Most defensible FIRST fix?
Correct: B. Compromised email resets everything downstream; secure the identity hub, then remove SMS-dependence and add the porting lock.
2. Which ritual directly detects accumulated third-party access risk?
Correct: C. Grants and sessions are standing permissions; only an inventory ritual sees them pile up.
3. A career-changer with this course completed asks for the best-aligned FIRST credential. Most sensible recommendation?
Correct: A. Foundations first, labs always; elite certifications assume practitioner mileage you build, not skip.
🕹 Security Arcade · Module 12
Six rapid-fire questions · 15 seconds each · three lives · streak bonus up to +50 per answer. A perfect run scores 900 pts. Your best is saved in this browser.
Final exam & certificate
Twelve scenario questions drawn across all modules, in the style of the summative assessments used by the big programmes: judgement first, memory second. Select an answer per question, then submit. 80% or better — with your certificate unlocked — issues the VUNVAULT Academy credential.
Certificate track locked
All twelve modules and their knowledge checks are free, forever. The final exam and the printable, ID-bearing certificate are the paid tier: KES 2,500 / USD 19 — one payment, lifetime attempts.
Sandbox checkout in this build: payment rails (M-Pesa Daraja / Stripe / PayPal) plug in at the marked integration points.
Final examination · select then submit
1. An intrusion harvests master credentials from a secrets manager within hours, using no zero-days. Which investment shrinks the impact window most?
Automation beats slow loops; limiting standing secrets and detecting fast is the counter to machine-speed chains.
2. Which control best detects silent tampering of build artifacts before deployment?
Integrity is proven by verification at consumption; AV sees malware, not subtle substitution.
3. A stolen session cookie is in use by an attacker. Which action actually ends that access?
Sessions live until revoked; password-only rotation leaves the cookie valid.
4. A supplier email changes bank details and says “call me on this number to confirm.” You…
Out-of-band means a channel the message did not supply; attacker-supplied numbers verify nothing.
5. Why does EDR catch “living-off-the-land” abuse that signature AV typically misses?
Legitimate tools misused have no malicious signature; behaviour is the tell.
6. The primary security benefit of a guest network is…
Segmentation limits blast radius: a compromised bulb should not reach your laptop.
7. A company that collected your phone number for delivery now wants to use it for ad targeting. Under DPA-style law it must…
Purpose limitation: data collected for one stated purpose cannot silently migrate to another.
8. Which backup property defeats “encrypt the backups first” ransomware playbooks?
Reachable backups are just the attacker’s second target; immutability breaks the chain.
9. A flaw with CVSS 6.5 enters CISA KEV while a 9.1 stays unlisted. Prioritisation?
KEV is proof of real-world abuse; that evidence reorders the queue.
10. Early ransomware behaviour on a work laptop. Forensically correct first move?
Memory and artefacts die with power-offs and reimages; isolation preserves both case and options.
11. “Revoke leaver access within 24 hours; IT executes, HR triggers, Security samples five leavers quarterly.” This document is a…
Steps, owners and clocks = procedure; the 24-hour rule it implements is the standard.
12. Which ritual detects backup rot (backups that exist but cannot restore)?
An untested backup is a rumour; only a restore proves it.