Cohort open · Free to learn · Certificate on completion

Learn cybersecurity.

Twelve modules. Twelve hours. Real 2026 case files, animated explainers, studio-narrated lessons, scenario quizzes that refuse to be guessed and a rapid-fire arcade game in every module. Built for people who defend phones, wallets, teams and networks — Africa-first examples, global standards.

12 modules12 hrs guided study36 scenario questions12 arcade quiz games0 tuition to learnKES 2,500 certificate & final exam
Cisco-style structure

Short self-paced modules with objectives, hands-on “Try it” activities, per-module knowledge checks and a shareable completion credential.

SANS-style depth

Practitioner writing, real incident tradecraft, and scenario questions that test judgement — not memorised definitions.

IBM-style assessment

A summative final exam across all modules with an 80% pass mark, plus a breach-case capstone, before the certificate is issued.

0 of 12 modules complete
Module 01 · ~60 min · Threat landscape

How attackers actually think

Before the tools, before the malware, there is a decision chain. This module reads that chain out loud — using real incidents from 2026 — so you can see exactly where it bends and where it breaks.

VUNVAULT studio narration · ~3 min · embedded in this file — plays anywhere, no audio folder needed.
  • By the end of this module you can…
  • Walk the five steps of an intrusion kill chain in plain language.
  • Explain why edge devices — not employee laptops — are attacked first in 2026.
  • Describe how automation and AI compressed attack timelines from weeks to hours.
  • Map one real 2026 incident onto the kill chain, step by step.

1.1 The chain, not the “hack”

Pop culture shows intrusions as a single dramatic “hack.” Reality is a checklist of small wins: reconnaissance (what can I learn publicly?), initial access (a password, a flaw, a person), execution (run my code), persistence (survive reboots and password resets), then lateral movement and the objective — money, data, or disruption. Defenders win by making any one link expensive enough that the attacker quits and picks an easier target.

In September 2026, Palo Alto Networks’ Unit 42 published an incident report that should reset your mental clock: an adversary used autonomous AI agents to compromise an enterprise network in under ten hours, chaining more than fifty MITRE ATT&CK techniques in automated loops — without a single zero-day. Internal reconnaissance, secret-hunting in code repositories, master-credential harvesting from a secrets manager: all known techniques, executed at machine speed. The lesson is not “AI is scary.” The lesson is: your detection and response timeline is now the product.

RECON ACCESS EXECUTE PERSIST OBJECTIVE
FIG 1.1 — The kill chain. Every defence you will learn in this course exists to break one of these arrows.

1.2 Why the edge gets hit first

Ask an attacker to rank targets and they will rank them by reachability × privilege × how nobody watches it. That is why September 2026 filled with VPN and management-platform incidents: SonicWall’s SMA1000 appliances were hit by two chained zero-days — a CVSS 10.0 pre-authentication flaw plus a command-injection flaw — handing attackers control of the box that controls an organisation’s entire remote workforce. N-able’s N-central, the console MSPs use to manage hundreds of client networks, needed its fourth emergency hotfix in five weeks, one of them a 10.0 pre-auth RCE.

Notice what these targets have in common: they sit at the perimeter, they hold privileged keys by design, and they get a fraction of the monitoring that laptops and identities get. An employee laptop has EDR, MFA and a nervous user. A VPN appliance has a firmware version and an open port. In 2026, the perimeter did not disappear — it concentrated, into a few dozen always-on boxes that attackers notice before you do.

Case file · Sep 2026

Ten hours, fifty techniques, zero zero-days

Unit 42’s report describes autonomous AI agents running reconnaissance, secret discovery and credential harvesting in automated execution loops. No novel exploits — just known techniques at a speed no human SOC triage queue was designed for. When you read “under ten hours,” read it as: the first hour of your response is the whole battle.

1.3 The economics of “you”

Most attacks on ordinary people are commodity: automated, mass-distributed, and cheap. Breached password corpora feed credential-stuffing bots; phishing kits are rented; residential proxy pools make password spraying look like normal traffic — Datadog researchers tracked low-and-low-slow spraying against AWS root accounts across 150+ organisations, deliberately paced to slip under lockout thresholds. Nobody hand-picked you; a list did.

That is oddly good news. Commodity attacks quit when cost rises: a unique password kills stuffing, phishing-resistant MFA kills most proxy kits, and a two-minute report to your bank or IT team kills the follow-on fraud. Your job in this course is not to become unbeatable — it is to become the expensive target, and to be fast and loud when something slips through.

Try it · 10 min

Map your own kill chain

Pick one service you rely on (email, mobile money, work VPN). Write five lines: what recon exists about you there (public email? phone number?), the most likely initial access (reused password? SIM swap?), what execution would look like, how an attacker would persist, and the objective. Keep it — Module 12 will make you defend every line.

kill chaininitial accesslateral movementpersistencecommodity exploitationMITRE ATT&CK

1.4 Motive: who attacks, and what they want

Defence gets sharper when you name the attacker’s appetite. Financial criminals want speed and volume: mobile-money fraud rings, SIM-swap syndicates, ransomware operators who treat your outage as their invoice. Spies want patience and position: the Fire Ant router tunnels were quiet by design because stolen tomorrow beats noise today. Hacktivists and insiders want messages or revenge, and accept clumsier methods. Most individuals and small businesses face the first group almost exclusively — commodity crime, automated and indifferent.

That indifference is your leverage. A financial attacker optimises for the cheapest viable victim; every control in this course raises your price tag. Motive also tells you what to protect first: if the appetite is money, guard the payment paths and recovery channels; if it is position, guard the edge devices and admin paths. When you know what they want, you finally know what you should defend — and what you can stop losing sleep over.

Drill · 5 min

Motive scan

Take the three assets from your Module 2 risk table. For each, write one line: most likely motive (money, access, embarrassment, espionage) and most likely actor type (commodity criminal, scammer who knows you, insider, stranger). Compare: does your current effort match the motive, or is it guarding the wrong door?

Knowledge check · Module 1

1. The Unit 42 intrusion finished in under ten hours using no zero-days. Which conclusion is most defensible?

2. A resource-limited attacker wants initial access to a mid-sized company. Based on 2026 incident patterns, the most reliable target is…

3. Why do spraying campaigns use residential proxies and deliberately slow login attempts?

🕹 Security Arcade · Module 01

Six rapid-fire questions · 15 seconds each · three lives · streak bonus up to +50 per answer. A perfect run scores 900 pts. Your best is saved in this browser.

Module 02 · ~60 min · Mental models

The CIA triad, risk, and staying sane

Three letters carry the whole profession: confidentiality, integrity, availability. Once you can sort any incident into those buckets — and name the asset, threat, vulnerability and control in play — security stops feeling like folklore and starts feeling like engineering.

VUNVAULT studio narration · ~3 min · embedded in this file — plays anywhere, no audio folder needed.
  • By the end of this module you can…
  • Classify any incident’s primary impact as confidentiality, integrity or availability.
  • Use the asset–threat–vulnerability–risk vocabulary without hand-waving.
  • Explain defence in depth and “assume breach” using a real 2026 example.
  • Write a three-line personal risk statement (asset, threat, control).

2.1 CIA, with receipts

Confidentiality is about secrets staying secret: when Dropbox disclosed that ~5,000 accounts were accessed through a Lenovo ID single-sign-on verification weakness, attackers read and downloaded users’ files — a confidentiality failure. Integrity is about things being what they claim to be: the JFrog Artifactory auth-bypass (CVE-2026-82329) mattered because an attacker with admin tokens could replace trusted packages with backdoored ones — poisoning what every downstream build trusts. Vercel’s CEO called it an “RCE bomb” for exactly this reason.

Availability is about things working when needed: the Cisco Nexus 9000 flaw (CVE-2026-20212) could crash the switch’s S1HAL process and reload the device — a data-centre outage from a single crafted packet — and ransomware’s whole business model is availability held hostage. Most real incidents hit two or three pillars at once; your job is to name the primary loss, because that tells you which control would have mattered most.

C I A secrets stay secret things are what they claim to be works when needed
FIG 2.1 — The triad. Every control in this course defends at least one corner.

2.2 Asset → threat → vulnerability → risk

Security speaks one grammar: an asset (something you value), a threat (something that can harm it), a vulnerability (a weakness the threat can use), and risk (how likely × how bad). A control reduces likelihood, impact, or both. Make it local: your asset is your mobile-money line; the threat is SIM-swap fraud; the vulnerability is weak identity proofing at the telco plus SMS-based codes; the risk is drained savings in an hour; controls are a porting PIN/line lock, moving MFA off SMS, and balance alerts.

This grammar also exposes lazy thinking. “We need AI security” is not a risk statement. “Our finance team’s approval workflow (asset) can be spoofed by WhatsApp impersonation (threat) because vendor bank-detail changes are never verified out-of-band (vulnerability), risking six-figure misdirected payments (impact)” — that is a risk statement, and it already contains its own control.

2.3 Defence in depth, and assuming the breach

Layers fail individually; that is why there are several. The StyleSmuggler Magento zero-day is a perfect autopsy: the patching layer could not work (no patch existed; the first victim was fully patched), yet on one compromised store the implant was found within an hour — because a merchant forwarded a weird “payment transaction failed” email to their host. A human reporting layer caught what no dashboard could.

“Assume breach” is the attitude that makes layers honest: you design as if compromise will happen, so you pre-agree what detection, containment and reporting look like. It is not pessimism; it is the difference between a fire drill and a fire panic.

Case file · Sep 2026

One poisoned package, every build downstream

Integrity attacks are force multipliers: watchTowr observed attackers minting admin tokens on exposed Artifactory instances within days of disclosure. One compromised repository can ship a backdoor to every customer that trusts its packages — which is why supply-chain roles get their own module later (Module 8).

Try it · 10 min

Your 3×3 risk table

Write three rows: asset / most plausible threat / one control you already have and one you’ll add this month. Include at least one non-digital asset (your ID documents count). This table returns in Module 12 as your audit baseline.

confidentialityintegrityavailabilityrisk = likelihood × impactcontroldefence in depth

2.4 Risk treatment: the four honest choices

Once risk is named, you have exactly four moves: mitigate (add controls — MFA, backups, patching), transfer (insurance, or contractually shifting liability to a vendor), avoid (stop holding the data or running the service at all), and accept (decide, consciously and in writing, that the risk is cheaper than the fix). Every organisation does all four; mature ones know which is which. Immature ones believe a fifth option exists: “ignore, and hope nobody notices.”

What remains after treatment is residual risk — the honest baseline you live with. Vendors who promise to “eliminate risk” are selling the fifth option in a nicer font. Personal translation: you mitigate your email (manager + MFA), transfer your laptop’s loss (insurance or accepting replacement cost), avoid storing client IDs in WhatsApp chats, and accept that your public posts can be screenshotted. Naming the choice is what makes it a decision instead of an accident.

Case file · 2026

Accepted risk with an expiry date

Exchange 2016/2019 without Extended Security Updates is a textbook accepted risk — until 31 October 2026, when the acceptance silently becomes “permanently unpatchable.” Accepted risks need review dates, because the world moves while you accept.

Knowledge check · Module 2

1. An attacker silently replaces an internal build artifact with a backdoored version; nothing crashes and nothing leaks yet. The pillar primarily under attack is…

2. Ransomware encrypts a hospital’s scheduling and imaging systems; elective surgery is cancelled for a week. The primary loss is…

3. Which control most directly reduces SIM-swap risk to your mobile-money account?

🕹 Security Arcade · Module 02

Six rapid-fire questions · 15 seconds each · three lives · streak bonus up to +50 per answer. A perfect run scores 900 pts. Your best is saved in this browser.

Module 03 · ~60 min · Identity

Passwords, MFA, passkeys — and the session thieves

Identity is the new perimeter: attackers would rather log in as you than break in around you. This module builds your credential stack from the floor up — and shows the two tricks (stolen sessions, phished relays) that skip MFA entirely.

VUNVAULT studio narration · ~3 min · embedded in this file — plays anywhere, no audio folder needed.
  • By the end of this module you can…
  • Explain credential stuffing and why one reused password becomes many breaches.
  • Rank SMS OTP, TOTP and passkeys by phishing resistance, with reasons.
  • Describe how stolen session cookies bypass MFA after login.
  • Build a personal credential stack: manager + unique passphrases + passkeys.

3.1 Credentials are the new perimeter

Every breach corpus ever leaked is still for sale, and bots never sleep: credential stuffing fires your old email+password pairs at hundreds of services until something opens. Strength is irrelevant here — uniqueness is the defence. One password reused across five services means one breached forum from 2019 owns your 2026.

The practical floor in 2026: a password manager, and inside it a unique passphrase per service (four or more random words beat eight clever characters, and they’re typeable). The manager also kills the visual tell of phishing: it simply will not autofill on paypa1.com.

pwd 2nd something you know something you have
FIG 3.1 — Two factors, one door. The second factor only helps if it cannot be phished or swapped.

3.2 MFA that can be phished — and MFA that can’t

SMS codes die to SIM swaps and to real-time phishing relays that proxy your login while you type. TOTP apps beat SMS but still type into a fake site happily. Passkeys (FIDO2) are cryptographic and origin-bound: the key refuses to sign for a lookalike domain, which is why they are called phishing-resistant. Choose downward only when you must: passkey → TOTP → SMS → nothing is the wrong order.

And know MFA’s two bypasses so you respect its limits. First, session theft: after a successful login, your browser holds a session cookie — steal that (infostealer malware, or a compromised machine) and the attacker is logged in; no password, no MFA prompt. In 2026 researchers tracked info-stealers specifically harvesting authenticated AI-assistant session cookies to read corporate chat histories. Second, MFA itself can be backdoored: CISA’s Gunra ransomware advisory describes attackers editing a victim’s VDI portal so one attacker-chosen OTP always succeeded.

3.3 Your credential stack, in order

Build it like a building: manager (the floor), unique passphrases everywhere (the walls), passkeys where offered (the doors), TOTP as fallback (the spare keys), and session hygiene (the locks): sign out of shared devices, treat “stay logged in” on public machines as a donation, and when an account behaves strangely, rotate the password and revoke active sessions — rotating without revoking leaves the stolen session alive.

Case file · 2026

The cookies that bypassed MFA

Info-stealer campaigns extracted stored browser cookies for authenticated AI-assistant sessions straight from infected employee machines — no password, no MFA prompt, full conversation history including code and confidential context. MFA protects the door; it cannot protect a copied key already inside the room.

Try it · 15 min

Move your five crown jewels

Email, mobile money/bank, primary social, work account, cloud drive: give each a unique manager-generated passphrase today; enable passkeys on at least two. Then open one service’s security page and find the “active sessions / sign out everywhere” button — know where it lives before you need it.

credential stuffingTOTPpasskey / FIDO2session cookieAiTM relaysession revocation

3.4 When the account is already gone: the recovery play

Sometimes you are not preventing takeover, you are evicting someone. Act in this order: recover access through the provider’s official flow from a clean device; then immediately inspect what attackers change first — recovery email, recovery phone, added MFA devices, active sessions, forwarding rules, connected apps. Remove their footholds before celebrating; a password reset with an attacker-owned recovery address is a revolving door.

Then contain the blast: warn contacts (hijacked accounts scam your friends next), check payment methods and addresses for additions, and where money or identity is involved, file the report while timestamps are fresh. Finally, learn the structural lesson: your recovery path is part of your credential stack. An outdated backup email is a back door with your name on it — audit recovery settings with the same seriousness as passwords.

Drill · 10 min

Recovery-path audit

Open security settings on your email and your money app. Check: recovery email current? recovery phone current? any MFA devices or sessions you don’t recognise? any mail-forwarding rules you didn’t create? Fix or remove everything unexpected, and write the date beside each account in your manager.

Knowledge check · Module 3

1. A user with strong TOTP MFA is taken over without the MFA ever being broken. Most likely mechanism?

2. Which factor best resists a real-time adversary-in-the-middle phishing proxy?

3. Why is password reuse catastrophic even when the reused password is long and “strong”?

🕹 Security Arcade · Module 03

Six rapid-fire questions · 15 seconds each · three lives · streak bonus up to +50 per answer. A perfect run scores 900 pts. Your best is saved in this browser.

Module 04 · ~60 min · Social engineering

Phishing defence for the WhatsApp era

The most exploited vulnerability in 2026 is still a person trying to be helpful, fast, or polite. This module replaces “don’t click links” with a working method: recognise the pressure, verify out-of-band, and make reporting a reflex instead of a confession.

VUNVAULT studio narration · ~3 min · embedded in this file — plays anywhere, no audio folder needed.
  • By the end of this module you can…
  • Name the four pressure levers every social-engineering lure pulls.
  • Apply an out-of-band verification habit to payment and credential changes.
  • Spot channel-hopping and tech-support-scam patterns (Quick Assist, refunds).
  • Execute the first five minutes after a suspected click, in order.

4.1 Anatomy of a lure

Every social-engineering message, in any channel, pulls some combination of four levers: urgency (“within 24 hours”), authority (“CEO”, “bank fraud desk”, “Geek Squad refunds”), fear or greed (“failed transfer”, “you won”), and effort-minimisation (“just click to confirm”, “just run Quick Assist so I can fix it”). The 2026 twist is channel diversity: email for the office, SMS and WhatsApp for the wallet, voice calls for the anxious — and remote-support tools as the payload, as Huntress documented with rogue ScreenConnect installs seeded by Quick Assist tech-support scams and fake refund lures.

Notice what the levers attack: not your intelligence, your context. You are tired, mid-task, polite, or scared of looking silly. That is why the defence is procedural, not personal: a habit that runs even when you are tired.

urgency · authority fear/greed · easy path the hook is the pressure, not the link
FIG 4.1 — The payload changes (link, file, call-back, remote tool); the four levers never do.

4.2 The verification habit that ends most fraud

One habit beats a thousand warnings: verify out-of-band. Any request to change payment details, reset credentials, or grant remote access gets confirmed through a channel the message did not provide — the number on your card, the contact in your contract, walking over to the desk. Business-email-compensation fraud collapses against it; so does the “new WhatsApp number” CEO scam. Second habit: channel-hopping is a red flag. “Email me on WhatsApp” / “call this number” exists to escape the channel your organisation monitors.

Third: treat unexpected remote-access requests as hostile by default. Nobody legitimate needs you to run Quick Assist or install a remote client to “fix” a refund. In the ScreenConnect worm incidents, the initial accesses were exactly this: a support scam, a phishing MSI, a fake Geek Squad refund form.

4.3 The first five minutes after a click

Order matters more than speed: stop (do not type anything more), disconnect the trust, not the evidence — on a credential phish, change the password from a different device and revoke active sessions; on a file/executable, isolate the machine from the network but keep it powered on for forensics; report to bank/IT/telecom with screenshots; warn your contacts if identity or email is involved so the follow-on scam fails. Then breathe: reporting fast is a win, and organisations that punish reporters train their staff to hide breaches instead.

Remember the StyleSmuggler merchant: the fastest detection in that incident was a forwarded “weird email.” Your report is not an admission — it is a sensor.

Case file · Aug–Sep 2026

“Let me help you fix that refund”

Huntress traced three unrelated intrusions to the same social shape: a victim persuaded to run a remote-support tool or open a “refund” lure, deploying rogue ScreenConnect clients that then spread worm-like to whoever connected next — including help-desk technicians arriving to help. Kindness, weaponised; verification, absent.

Try it · 10 min

Run a two-person drill

Take a real scam SMS you’ve received. With one family member or colleague, rehearse: read it aloud, name which of the four levers it pulls, then perform the out-of-band check together (find the official number independently). Finish by agreeing one code word that means “verify me, I might be impersonated.”

phishingvishing / smishingpretextingout-of-band verificationchannel-hoppingtech-support scam

4.4 The AI era of lures: when your eyes can’t verify

2026 social engineering stopped asking you to spot bad grammar. Voice-cloned “family emergency” calls, deepfake video of executives approving payments, and phishing emails written fluently by language models have moved verification out of the realm of perception: you cannot out-see or out-hear these lures, and trying to is a trap. Police agencies across several continents have warned about clone-voice calls pressing for instant money — the constant tells are urgency, secrecy (“don’t tell anyone”), and resistance to a call-back.

So the defence becomes purely procedural, which is good news: procedures don’t care how realistic the lie is. Pre-agreed code words for family and finance; mandatory out-of-band call-backs for any payment or credential change; a standing rule that urgency plus secrecy equals verification, every time, no exceptions for rank or emotion. The lie gets better; the procedure doesn’t need to.

Case file · pattern of 2026

“Mum, it’s me — my phone died”

Clone-voice calls impersonating relatives in trouble follow one script: distress, a new number, pressure to pay now, and anger at any hesitation. Families who survive it intact have one habit: a code word asked calmly before any money moves. Fifteen seconds of awkwardness beats a lifetime of regret.

Knowledge check · Module 4

1. An SMS from your “bank” asks you to call the number in the message about a failed transfer. Best next action?

2. A “CEO” messages from a new WhatsApp number requesting an urgent supplier bank-detail change. The single strongest control is…

3. An employee reports within two minutes that they entered credentials on a phishing page. The best first organisational response is…

🕹 Security Arcade · Module 04

Six rapid-fire questions · 15 seconds each · three lives · streak bonus up to +50 per answer. A perfect run scores 900 pts. Your best is saved in this browser.

Module 05 · ~60 min · Endpoints

Devices: the computers you actually own

Your phone is your bank, your ID wallet and your office. This module hardens the endpoints you personally control — and explains what “EDR”, “MDM” and “sideloading” mean when a company asks to put them on your machine.

VUNVAULT studio narration · ~3 min · embedded in this file — plays anywhere, no audio folder needed.
  • By the end of this module you can…
  • Explain why updates are a security control, and set a personal patch rule.
  • Distinguish antivirus, EDR and MDM — and what each can and cannot see.
  • Describe how signed-but-malicious apps and AV exclusions defeat “trust”.
  • Run a 10-minute phone hardening pass (SIM PIN, 2FA, sources, updates).

5.1 Updates are a security feature, not a nuisance

Every patch is a public confession of a flaw — and attackers read confessions faster than defenders deploy them. The September 2026 Exchange story is the archetype: fix shipped 11 August, working exploit code public by 27 August, and Shadowserver still counted 21,899 exposed unpatched servers on 1 September. Patch latency is the exploit window.

Your personal rule should be boring and absolute: OS and browser updates within 72 hours when rated critical (Chrome’s actively-exploited V8 zero-day, CVE-2026-85046, was fixed by an emergency update — the sixth Chrome zero-day of 2026), everything else within two weeks, auto-update on for apps wherever offered. And remember the uncomfortable footnote: sometimes the security product itself is the surface — Microsoft spent September racing to patch “ShieldBreak”, a privilege-escalation flaw in Defender’s own malware engine with a public PoC since August.

you → lock+encryption → updates → EDR/AV → network layers fail individually — that’s why plural
FIG 5.1 — Endpoint defence in depth. The innermost layer (lock + encryption) is the one thieves meet first.

5.2 AV, EDR, MDM — the alphabet, decoded

Antivirus matches known bad files. EDR (endpoint detection & response) watches behaviour — process trees, odd PowerShell, credential access — and lets a SOC respond. MDM (mobile device management) is the enrolment layer: enforced encryption, patch policy, remote wipe for company data. When an employer asks to enrol your personal phone, the honest question is what can they see and what can they wipe — usually work-profile data, not your photos, but ask in writing.

And know how endpoints actually fall in 2026: not by exotic malware, but by trust misplacement. Kaspersky tracked “Silver Fox” distributing the ValleyRAT backdoor inside a genuinely signed Chinese wallpaper app — signed, because signatures prove provenance, not intent — and running it under trusted processes while victims were socially engineered into adding it to their antivirus exclusions. An exclusion is a hole you dug yourself.

5.3 The ten-minute phone hardening pass

In order of payoff: lock + encryption (biometric + strong PIN; modern phones encrypt by default — verify); SIM PIN plus a telco porting/line lock (Module 3’s SIM-swap control); app sources — store-only installs, no sideloaded APKs chasing “premium free”; messaging 2FA (WhatsApp/Telegram two-step PIN); auto-update on for OS, browser, banking apps; Find My Device on; and a permissions sweep — does the torch app really need contacts? Charge-only on strange USB ports is paranoia-lite: the realistic risk is low, the habit is free.

Case file · Sep 2026

The backdoor the user whitelisted

ValleyRAT’s disguise worked because victims were coached into adding the “adware” to antivirus exclusions — then the backdoor ran under trusted process names. Signature valid, user consent obtained, AV blind. Trust is a configuration; attackers configure it too.

Try it · 10 min

Phone hardening pass

Do all five now: confirm auto-updates on; set SIM PIN; enable messaging-app two-step verification; review permissions on your three most-permissioned apps and revoke one each; confirm Find My Device and screen-lock timeout (<2 min).

EDRMDMsideloadingAV exclusionn-day vs zero-daySIM PIN

5.5 Loss, theft and the second-hand market

Devices also die socially: they get lost on matatus, stolen off tables, or sold onward. Pre-commit the sequence so panic doesn’t choose for you: remote lock first (Find My Device / Find My), then change the crown-jewel passwords from another device and revoke sessions, then telco SIM lock, then bank-app logout where offered, then remote wipe only after you’ve preserved what investigations or insurance need. Wiping is irreversible; sequence matters.

The market runs both ways. Buying used: insist on a clean factory reset in front of you, no activation locks (FRP/iCloud), and update immediately — second-hand phones often ship with ancient, exploitable builds. Selling or disposing: sign out of everything, remove SIM and SD, encrypt-then-factory-reset, and keep the receipt trail. A wiped phone with your account still signed in is not wiped; it is a donation.

Drill · 5 min

Loss-prep in five minutes

Enable remote lock/locate now if off; write your phone’s IMEI (dial *#06#) into your password manager’s secure notes; add the telco’s SIM-lock line to your IR card. Three minutes of paperwork that turns a future crisis into a checklist.

Knowledge check · Module 5

1. ValleyRAT shipped inside a genuinely code-signed app. Why doesn’t the signature make it safe?

2. A “support agent” walks a user through adding an app to the antivirus exclusion list. The exclusion matters because…

3. Which single configuration most reduces the impact of a stolen, powered-off phone?

🕹 Security Arcade · Module 05

Six rapid-fire questions · 15 seconds each · three lives · streak bonus up to +50 per answer. A perfect run scores 900 pts. Your best is saved in this browser.

Module 06 · ~60 min · Networks

Routers, Wi-Fi and the VPN truth

Your router is a computer that decides what reaches your home — and in 2026, perimeter routers were among the most-abused devices on the internet. Here’s how to own yours, survive café Wi-Fi, and know exactly what a VPN does and doesn’t do.

VUNVAULT studio narration (~3 min). Not playing? The audio/ folder is missing on this host — the built file embeds audio directly; this preview falls back to audio/m06.mp3.
  • By the end of this module you can…
  • Harden a home router: admin creds, firmware, WPA2/3, guest isolation.
  • Explain the realistic risks of public Wi-Fi and the rules that neutralise them.
  • State precisely what a VPN protects you from — and what it doesn’t.
  • Explain why unpatched routers become botnet and proxy infrastructure.

6.1 Your router is an edge device (act like it)

Everything in Module 1 about “the edge” applies to the box under your TV: always on, privileged, unwatched. September 2026 reporting on MikroTik RouterOS flaws described exactly the downstream abuse: unpatched perimeter appliances used for unauthorised config changes, packet interception, command proxies and DDoS botnets. Separately, the “Fire Ant” espionage campaign planted covert GRE tunnels inside Cisco IOS XR routers to siphon live traffic — routers as spy hardware.

The home checklist is short and unglamorous: change the factory admin password (still the #1 router failure); update firmware and enable auto-update if present; WPA2-AES or WPA3, never WEP/open; disable WPS; put IoT gadgets and guests on a guest network so a compromised bulb can’t reach your laptop; and disable remote admin from the internet unless you can explain why you need it.

device your router = your edge internet
FIG 6.1 — The shield is configuration, not hardware: admin password, firmware, WPA3, guest isolation.

6.2 Public Wi-Fi: the real risk model

HTTPS encrypts your traffic’s contents end-to-end, so the old “everyone reads your passwords at the café” story is mostly dead. The living risks are: rogue/evil-twin access points with convincing names; attacks on the unencrypted leftovers (captive portals, legacy protocols, local file sharing, printer discovery); and simple local proximity — same network means your device can be scanned and probed directly. Rules: forget networks after use, disable auto-join, keep the device firewall on, and for anything sensitive on untrusted Wi-Fi use your phone’s hotspot or a VPN.

6.3 What a VPN does — and the marketing lie

A VPN encrypts the hop between you and the VPN server and masks your traffic from the local network — genuinely valuable on hotel and café Wi-Fi, and for routing around censorship or hostile networks. It does not make you anonymous to the sites you log into (they still see your account), it does not block malware or phishing, and it does not replace device security — you are simply extending trust to the VPN provider. Choose providers like you choose banks; free VPNs are usually the product.

Case file · 2026

Tunnels inside the tunnel-makers

Fire Ant’s campaign hid GRE tunnels in router configs and exfiltrated live packet captures; MikroTik abuse turned neglected routers into proxy fleets. The pattern for defenders: inventory the routers you forgot (home, branch, SOHO), because attackers already have.

Try it · 15 min

Router audit

Log into your router (sticker or 192.168.x.1): change admin password if default; note firmware version and check for updates; confirm WPA2-AES/WPA3; disable WPS; enable guest network for IoT. Write the model + firmware date somewhere you’ll find it next quarter.

WPA3evil twinguest networkfirmwareVPN tunnelGRE tunnel

6.5 Segmenting a home network without enterprise gear

You don’t need VLANs to get most of the benefit: your router’s guest network is a segmentation tool wearing a hospitality costume. Put every IoT device — bulbs, cameras, smart plugs, the TV that argues with updates — on guest Wi-Fi with client isolation on, and keep phones and laptops on the main network. A compromised camera now sees nothing but other compromised cameras.

Three more cheap wins: turn UPnP off (it lets devices punch holes in your firewall autonomously, and malware loves it); replace remote-access port forwarding with a VPN or vendor cloud relay; and consider a filtering resolver such as Quad9 (9.9.9.9) at router level, which blocks known-malicious domains for every device at once — including the ones too old to protect themselves. Fifteen minutes of router configuration, years of quiet.

Drill · 10 min

Three router switches

In one sitting: disable UPnP; enable guest network and move IoT devices onto it; set DNS to a filtering resolver (or note it as this week’s task if your router refuses). Screenshot your settings page into your manager’s secure notes — future-you will reconfigure faster.

Knowledge check · Module 6

1. With HTTPS everywhere, what is the primary realistic risk of open café Wi-Fi?

2. On hostile hotel Wi-Fi, a reputable VPN’s main protection is…

3. Per 2026 reporting, the most common real-world fate of neglected, unpatched SOHO routers is…

🕹 Security Arcade · Module 06

Six rapid-fire questions · 15 seconds each · three lives · streak bonus up to +50 per answer. A perfect run scores 900 pts. Your best is saved in this browser.

Module 07 · ~60 min · Privacy & data

Your data: what exists, who holds it, what the law says

Privacy is security’s quiet twin: the data that exists about you is the map attackers plan with. This module inventories that map, translates Kenya’s Data Protection Act into plain rights, and cuts your exposed surface in an afternoon.

VUNVAULT studio narration (~3 min). Not playing? The audio/ folder is missing on this host — the built file embeds audio directly; this preview falls back to audio/m07.mp3.
  • By the end of this module you can…
  • List the four places personal data leaks from (breaches, brokers, telemetry, you).
  • Summarise Kenya DPA 2019 rights: consent, access, correction, erasure, breach notice.
  • Reduce app/service data exposure with a permissions and backups pass.
  • Explain how oversharing becomes reconnaissance for account recovery attacks.

7.1 The map that already exists

Assume four copies of “you” are circulating: breach corpora (old leaks, forever for sale — check your email on a breach-lookup service today), data brokers and ad ecosystems (inferred profiles, location histories), app telemetry (contacts, photos metadata, usage), and you (posts, tags, check-ins, the school name in your bio). Scammers compose these copies: your pet’s name in a 2019 post is a password-reset answer in 2026.

Metadata deserves special suspicion: a “harmless” photo can carry GPS coordinates, device model and timestamp. Strip or disable location tagging for public posts, and remember that the audience of a “friends-only” post includes every friend’s compromised account.

consent · purpose · minimisation excess collection refused
FIG 7.1 — Data-protection law in one picture: what enters must be necessary, consented, and lockable.

7.2 Kenya’s DPA 2019, in human sentences

The Act says, in effect: your personal data may only be collected with a lawful basis (usually your informed consent), only for a stated purpose, only as much as is necessary; you may ask what is held about you, correct it, and in many cases demand deletion; and when it is breached, the holder must notify the regulator — and where the harm is real, you — without undue delay. The Office of the Data Protection Commissioner (ODPC) is your escalation route when a company stonewalls you.

Use it practically: when an app demands contacts “or you can’t continue,” that is a purpose-limitation conversation; when a company you left still emails you, that is an erasure request; when your bank breaches, notification is not a favour — it is the law.

7.3 The afternoon cleanup

Four passes, in order: breach pass (lookup your email; rotate everything listed); permissions pass (revoke contacts/location/mic from apps that don’t earn them); backup pass (enable end-to-end-encrypted cloud backups for WhatsApp and device, or accept that your “private” chats sit in someone’s cloud in plaintext); visibility pass (social: hide birthday year, old posts audit, stranger-followers prune). None of this makes you invisible; all of it makes you expensive.

Case file · Sep 2026

When someone else’s weak check becomes your open door

Dropbox’s incident: attackers abused an email-verification weakness in Lenovo ID, then Dropbox’s federated login accepted the asserted email without a second challenge — ~5,000 accounts accessed. Your data’s safety can depend on a partner company’s verification logic you have never heard of. Federated convenience is borrowed trust; inventory what is connected (Module 8).

Try it · 15 min

Breach + permissions double-pass

1) Run your primary email through a reputable breach-lookup service; change every password that appears. 2) In phone settings, sort apps by permissions; revoke one permission from each of your three greediest apps. 3) Turn on encrypted chat backups if offered.

personal datadata controllerconsentpurpose limitationright to erasuremetadata

7.4 Asking for your data: subject-access requests that work

Kenya’s Data Protection Act gives you leverage most people never use: the right to ask any organisation holding your personal data what they hold, why, and where it came from — and to request correction or erasure. A subject-access request needs no lawyer: a short email naming yourself, your identifiers (account number, phone), the request (“a copy of my personal data processed, its purposes and recipients”), and a deadline reference (“within the period prescribed by the Data Protection Act, 2019”) is legally sufficient.

Keep expectations adult: some replies are slow or evasive; that is when you escalate to the ODPC with your paper trail attached. Even never sending a request, knowing the mechanism changes how you read every “we value your privacy” banner — you now know it is a legal duty with a regulator behind it, not a favour. Privacy stops being vibes the day you write your first request.

Template · copy-edit-send

Four-line SAR email

“Dear Data Protection Officer, I am [name], account [x]/phone [y]. Under the Data Protection Act, 2019, I request: (1) confirmation of personal data you process about me; (2) a copy of that data; (3) its purposes and recipients. Please respond within the statutory period. Regards.” Save sent mail; diarise 30 days.

Knowledge check · Module 7

1. The Dropbox–Lenovo ID incident’s core lesson is…

2. Which set counts as personal data under Kenya’s DPA-style protections?

3. Why disable location metadata on publicly shared photos?

🕹 Security Arcade · Module 07

Six rapid-fire questions · 15 seconds each · three lives · streak bonus up to +50 per answer. A perfect run scores 900 pts. Your best is saved in this browser.

Module 08 · ~60 min · Cloud & third parties

Cloud accounts, SaaS and the vendors holding your keys

Most of your life runs on other people’s computers. This module teaches the shared-responsibility split, the OAuth/grant inventory nobody does, backup strategy that survives ransomware, and the vendor question that separates mature organisations from lucky ones.

VUNVAULT studio narration (~3 min). Not playing? The audio/ folder is missing on this host — the built file embeds audio directly; this preview falls back to audio/m08.mp3.
  • By the end of this module you can…
  • Explain the shared-responsibility model with one concrete example per layer.
  • Audit and revoke third-party app grants (OAuth) on your cloud accounts.
  • Design a 3-2-1 backup scheme with one immutable or offline copy.
  • Ask a vendor the four questions that expose their real security posture.

8.1 Shared responsibility, without the slide deck

The provider secures the cloud: physical datacentres, hypervisors, the fabric. You secure in the cloud: your accounts, your configurations, your data, your sharing links. Nearly every “cloud breach” headline is a your-side failure: an over-broad sharing link, a storage bucket left public, an unrevoked ex-employee grant. Default-deny is the posture: private by default, shared deliberately, reviewed quarterly.

PROVIDER: fabric, hardware, hypervisor SHARED: config baselines, logging YOU: accounts, data, grants, backups ← most breaches live here
FIG 8.1 — The layer you own is the layer that leaks. Sweep = where audit effort belongs.

8.2 Grants, integrations and the shadow perimeter

Every “Sign in with X” and every connected app is a standing permission: read my mail, post as me, see my files. Attackers love OAuth abuse because it needs no password — the token is the key. Twice a year, open your Google/Microsoft/account “third-party access” page and revoke ruthlessly; anything you don’t recognise gets evicted, not investigated. The Dropbox incident adds the federation clause: integrations can also inherit a partner’s verification weaknesses, so the inventory includes SSO links, not just apps.

8.3 Backups that survive ransomware, and exits that survive vendors

3-2-1: three copies, two media, one offsite — and in 2026, one immutable or offline, because ransomware now deletes reachable backups first. Test a restore quarterly; an untested backup is a rumour. Then the vendor exit question: if this SaaS vanished tonight, what would you get back, in what format, how fast? “Your data is yours” should be a download button, not a slogan.

And when a vendor is breached, respond like JetBrains’ customers were told to: rotate what you entrusted. JetBrains disclosed that attackers entered through its own unpatched TeamCity server (CVE-2026-63077), took a 2024 backup of its Cadence service and touched AWS credentials — users were told to revoke/rotate everything used in Cadence executions and treat those outputs as untrusted. Your vendor’s patch hygiene is your risk; the four questions: how do you patch, how fast? what do you hold about us? how would you notify us, and within how long? can we export and leave?

Case file · Aug–Sep 2026

The vendor that told everyone to patch — except itself

JetBrains disclosed CVE-2026-63077 on 27 July, warned customers, and was itself breached through an unpatched instance from 8–24 August. The irony is the lesson: supplier security claims age like fish. Verify with questions, contracts and rotation drills — not brochures.

Try it · 15 min

Grant purge + backup proof

Open third-party access on your two biggest cloud accounts; revoke at least three stale grants. Then locate your most important document’s backup: when was it last copied, where does it live, and could you restore it tonight? If any answer is “unsure,” that’s this month’s project.

shared responsibilityOAuth granttoken abuse3-2-1 backupsimmutable copyvendor exit plan

8.4 SaaS sprawl: the accounts you forgot are still holding you

Every trial signup, quiz site and dead startup that ever took your email is a standing copy of some version of you — password hashes from 2014, phone numbers from 2018, ID scans from that one KYC form. Breach after breach is simply these forgotten warehouses leaking on schedule. Your password manager’s full account list is therefore not a convenience feature; it is your personal asset register, and the dormant entries are your unmapped attack surface.

Run the sprawl purge twice a year: for each dormant account, decide delete or defend — delete with the provider’s closure flow (or erasure request when they stall), or defend with a unique password and MFA if it still earns its place. For new signups, consider purpose aliases: a dedicated email for financial life, one for shopping, one for experiments. Sprawl is how one 2019 forum breach becomes a 2026 takeover; registries are how it doesn’t.

Drill · 15 min

Count your warehouses

Open your manager, count total accounts, then flag every account untouched in 12+ months. This month: close three of them properly (delete, not abandon). Record the count; watch it fall each half-year. Fewer warehouses, fewer leaks with your name on them.

Knowledge check · Module 8

1. After the JetBrains Cadence disclosure, the most important action for affected users was…

2. In the shared-responsibility model, which item is normally YOUR side?

3. Why keep one immutable or offline backup copy?

🕹 Security Arcade · Module 08

Six rapid-fire questions · 15 seconds each · three lives · streak bonus up to +50 per answer. A perfect run scores 900 pts. Your best is saved in this browser.

Module 09 · ~60 min · Vulnerabilities

CVEs, CVSS and the patching economy

“Critical vulnerability” is a headline; CVE-2026-20212 (CVSS 9.8, AV:N/AC:L/PR:N/UI:N) is a sentence you can actually act on. This module teaches you to read advisories like an analyst — and to understand why patching alone never finishes the job.

VUNVAULT studio narration (~3 min). Not playing? The audio/ folder is missing on this host — the built file embeds audio directly; this preview falls back to audio/m09.mp3.
  • By the end of this module you can…
  • Decode a CVE entry: identifier, CVSS vector, affected versions, workaround vs fix.
  • Explain why reachability and chaining outrank raw CVSS in prioritisation.
  • Describe the KEV catalogue and what listing changes operationally.
  • Explain “fully patched but compromised” using StyleSmuggler.

9.1 Reading an advisory like an analyst

Every advisory answers five questions: what (CVE id + weakness class), how bad (CVSS — note the vector: network? complexity? privileges? user interaction?), who is affected (exact versions/PIDs), is it exploited (KEV listing, vendor PSIRT language), and what now (fixed release vs workaround). Cisco’s September advisory is a clean specimen: CVE-2026-20212, CVSS 9.8, vector AV:N/AC:L/PR:N/UI:N — reachable over the network, easy, no credentials, no click — because TCP ports 43210/43211 sat open in the default VRF; fix = upgraded NX-OS; workaround = iACLs blocking those ports.

Two reading habits separate pros from panic: CVSS is severity, not risk — a 9.8 buried in a sealed management VLAN loses to a 7.5 facing the internet with no auth; and “workaround” is not “fix” — it is a bridge you pay tolls on until the real release lands.

disclosed patched deployed exposure clock
FIG 9.1 — The window that matters is between “disclosed” and “deployed.” Attackers watch the same belt.

9.2 The exposure economy

Disclosure starts a race both sides can see. Shadowserver’s internet-wide scans flagged 21,899 Exchange servers still unpatched against CVE-2026-62911 three weeks after the fix — the same count attackers use as a shopping list. End-of-support makes it structural: Exchange 2016/2019 fixes ride on paid Extended Security Updates that end 31 October 2026, after which “unpatched” becomes permanent. And “it’s internal only” is a topology hope, not a control: Cisco’s own advisory notes a switch needn’t face the internet if a compromised segment can reach it.

Prioritisation, then, is exposure math: KEV-listed or actively exploited → now; internet-reachable unauthenticated RCE → this week; everything else on SLA. KEV (CISA’s Known Exploited Vulnerabilities catalogue) is the profession’s agreement to stop debating scores once real exploitation exists — SonicWall’s chained SMA1000 flaws landed there within days of disclosure.

9.3 Chains, and the patched-but-compromised paradox

Attackers compose flaws the way chefs compose flavours: SonicWall’s 10.0 pre-auth SSRF bought privileged reach; the 7.8 command injection cashed it in — individually “just” two CVEs, together an unauthenticated takeover. Which brings us to the paradox every practitioner must internalise: patch status does not equal safety. StyleSmuggler’s first victim ran the highest patch level available with a clean patch report — and was compromised by a flaw no vendor had described yet. Vulnerability management is therefore three jobs, not one: inventory (you cannot patch what you forgot), exposure reduction (disable GraphQL, block ports, segment), and detection (for the flaw with no CVE yet).

Case file · Sep 2026

Two open ports, root on the switch

Cisco found CVE-2026-20212 itself, while closing a support ticket — a reminder that criticals often surface quietly. The ports (43210/43211) were open by default. Default configurations are the attacker’s standing invitation; your job is to rescind it.

Try it · 15 min

Decode one real advisory

Open any current vendor advisory (Cisco PSIRT, SAP notes, or a KEV entry). Extract five fields: CVE, CVSS vector, affected versions, exploitation status, fix vs workaround. Write a three-line summary a manager could act on. If your three lines change a decision, you’ve learned the module.

CVECVSS vectorKEV catalogueexploit chainworkaround ≠ fixexposure window

9.4 A personal vulnerability-management loop

Organisations run vulnerability management as a discipline; you can run a credible solo version in twenty monthly minutes. Keep a tiny register — a notes-app table: asset / version / update channel / last checked — covering phone, laptop, router, TV/IoT oddities, and your five crown-jewel services. Each month walk it: OS and browser updates applied? router firmware current? any service shouting about a breach? Any “critical” headline touching your assets gets the 72-hour rule from Module 9’s SLAs.

The register’s real power is memory: “last checked” columns turn guilt into schedule, and the asset list kills the classic personal-security failure — forgetting the device in the drawer that still receives your OTPs. Pair the loop with the quarterly rituals from Module 12 and you have, in miniature, exactly what auditors look for in organisations: inventory, cadence, evidence.

Template · start now

Your first register row-set

Create the table with five rows today (phone, laptop, router, money app, email). Fill versions roughly, set “last checked = today,” and add a monthly calendar repeat named “Vuln loop.” Imperfect data entered today beats perfect data imagined next month.

Knowledge check · Module 9

1. Flaw A: CVSS 9.8, reachable only from a sealed management VLAN. Flaw B: CVSS 7.5, internet-facing, unauthenticated. With limited patch capacity this week, you fix…

2. A vulnerability appears in CISA’s KEV catalogue. Operationally, this means…

3. StyleSmuggler compromised a store running the highest available patch level with a clean patch report. The defensible conclusion is…

🕹 Security Arcade · Module 09

Six rapid-fire questions · 15 seconds each · three lives · streak bonus up to +50 per answer. A perfect run scores 900 pts. Your best is saved in this browser.

Module 10 · ~60 min · Incident response

The first hour: your personal incident playbook

Unit 42’s ten-hour breach and your drained mobile-money account run on the same clock: the first hour decides the outcome. This module gives you containment orders, evidence habits and reporting routes — for work incidents and for the ones that hit your own wallet.

VUNVAULT studio narration (~3 min). Not playing? The audio/ folder is missing on this host — the built file embeds audio directly; this preview falls back to audio/m10.mp3.
  • By the end of this module you can…
  • Execute correct first actions for credential phish, device malware and bank fraud — in order.
  • Preserve evidence without playing forensic hero.
  • Name the reporting routes for personal and organisational incidents (incl. Kenya).
  • Explain why post-incident resets include MFA seeds and sessions, not just passwords.

10.1 Detect without destroying

Detection signals are usually mundane: a bank SMS you didn’t trigger, a “password changed” mail you didn’t request, a device that’s hot and slow at 3am, colleagues receiving strange messages “from you,” a supplier invoice with new bank details. The first discipline: stop feeding the incident — no more typing, no more clicking — and the second: don’t destroy evidence. Reformatting the laptop feels like cleanup and is, forensically, arson. Screenshots, timestamps, message headers and the powered-on machine are your case file.

STOP & isolate revoke & rotate report recover & learn 0–5 min
FIG 10.1 — The first hour, in four moves. Order is the security property.

10.2 Containment orders, by scenario

Credential phish: change the password from a different, clean device, then revoke active sessions and tokens — rotating without revoking leaves the attacker’s session sipping coffee in your account. Device malware/ransomware: disconnect network (Wi-Fi off, cable out) but keep power on; do not wipe; hand to IT/forensics. Bank or mobile-money fraud: call the fraud line from a known number, request hold/reversal windows, change credentials from clean device, then written report. SIM-swap signs (signal dead + reset SMS elsewhere): telco line lock immediately, then every SMS-dependent MFA moves to app/passkey.

At work, the same shapes scale: isolate, preserve, escalate with a timeline attached. Speed beats completeness in the first report; completeness beats poetry in the second.

10.3 Report routes, and the resets people forget

Personal incidents in Kenya have real doors: your bank’s fraud desk and the payments-reversal process, telco fraud lines, the DCI Cybercrime Unit for criminal matters, the ODPC when your personal data is breached by an organisation, and CERT.ke / CAK context for service-level incidents. Organisational incidents follow your IR procedure (Module 11) and statutory clocks — GDPR’s 72 hours, Kenya DPA’s notification duty.

Post-incident, reset what the attacker touched, not just what they typed: passwords, active sessions, OAuth grants, API keys — and MFA enrolments. CISA’s Gunra ransomware advisory describes attackers editing a victim’s VDI portal so an attacker-chosen OTP always succeeded: if MFA itself was tampered with, “we changed the password” is a lullaby. Re-enrol MFA from scratch, and review MFA method downgrade history where logs allow.

Case file · 2026

The OTP that always said yes

Gunra actors modified authentication portal files so one chosen OTP always passed — MFA as a backdoor, not a wall. Their toolkit also stole session cookies and dumped credentials from stores. Moral: post-incident, audit the authentication path itself, or you reinstall trust into a rigged lock.

Try it · 10 min

Write your IR card

Five lines, wallet or notes app: bank fraud number (from card, not inbox); telco line-lock route; work IT/SOC contact; where your password manager emergency kit lives; your family/code-word verification phrase. Test one line tonight by actually finding the number.

containmenteradicationrecoveryevidence preservationsession revocationMFA re-enrolment

10.4 Helping someone else through their incident

Sooner or later the phone rings: a parent scammed, a colleague phished, a friend locked out of mobile money. Your job is co-regulation before containment — panic contagion causes the worst decisions (paying immediately, wiping evidence, shouting at the victim). Script your first minute: “You did the right thing telling me. We’ll handle it step by step. Don’t touch anything yet.” Then run their containment with them, out loud: clean device for rotations, session revocation, bank and telco calls, screenshots before anything is deleted.

Guard the language: “how did you fall for that?” is not analysis, it is training them to hide the next incident — the exact culture failure organisations pay millions to undo. Debrief later, kindly, as a procedure gap (“we need a code word”) rather than a character flaw (“you’re careless”). Communities that respond well to the first victim create the reporting culture that saves the second.

Drill · 10 min

Family incident protocol

In your family group chat, post three lines: the code word; who calls the bank first; and the no-blame rule (“reporting fast is always right”). Pin it. The day it’s needed, nobody will remember this module — they’ll remember the pinned message.

Knowledge check · Module 10

1. A laptop shows early ransomware behaviour (files renaming, heavy disk). Best first action?

2. Why change a phished password from a DIFFERENT device?

3. After an incident where MFA may have been tampered with (Gunra-style), what must be reset beyond passwords?

🕹 Security Arcade · Module 10

Six rapid-fire questions · 15 seconds each · three lives · streak bonus up to +50 per answer. A perfect run scores 900 pts. Your best is saved in this browser.

Module 11 · ~60 min · Security at work

Policies, standards, procedures — and you

Organisations defend through documents and culture; attackers exploit the gap between them. This module decodes the governance pyramid (policy → standards & guidelines → procedures), shows where your daily habits sit inside it, and makes the case that reporting culture is a control.

VUNVAULT studio narration (~3 min). Not playing? The audio/ folder is missing on this host — the built file embeds audio directly; this preview falls back to audio/m11.mp3.
  • By the end of this module you can…
  • Distinguish policies, standards, guidelines and procedures with examples.
  • Locate your daily obligations inside acceptable-use and remote-work rules.
  • Explain why near-miss reporting is a detection control, not a confession.
  • Draft a three-line verification rule for your team.

11.1 The governance pyramid, decoded

Policies are the broad statements of intent — “client data is handled as if it were our own crown jewels.” Standards are specific mandatory requirements for an area or technology — “MFA must be enforced on all administrative access”; guidelines are the recommended cousins (“you should prefer phishing-resistant methods”). Procedures are the step-by-step executions — the eight-move vulnerability remediation workflow, the joiners-movers-leavers checklist with its 24-hour revocation clock. Policies say why; standards say what, exactly; procedures say how, in order, by whom.

Why care if you’re not “management”? Because every audit, client questionnaire and incident post-mortem runs on this pyramid — and because the fastest way to look senior in a security conversation is to ask which layer a decision belongs to. “That’s a policy question” and “that needs a procedure” are complete, professional sentences.

POLICY — intent STANDARDS & GUIDELINES — requirements PROCEDURES — steps, owners, clocks why what how
FIG 11.1 — The pyramid. Contradictions flow upward for resolution; execution flows downward.

11.2 Where you live in the pyramid

Your daily obligations are procedures wearing casual clothes: lock screens and clean desks (confidentiality), no shared accounts (accountability — a shared login is a shared identity, and “who did it?” becomes unanswerable), asset returns on exit, visitor escorting, and acceptable-use boundaries (company systems for company work, personal data off company devices and vice versa). Remote work extends the corporate edge into Module 6 territory: your home router is now infrastructure your employer’s data transits — which is why sane remote-work standards mandate updates, disk encryption and private networks for sensitive calls.

And the cultural clause, which no tool can replace: reporting speed is a control. The StyleSmuggler implant found within an hour was found because a merchant forwarded a weird email without feeling silly. Organisations that punish reporters train staff to hide breaches; organisations that thank them install a human sensor network for free.

11.3 When procedures meet worms

The ScreenConnect worm is a procedures autopsy: initial accesses were social (Quick Assist scam, phishing MSI, fake refund lure), but the propagation exploited a missing verification step — technicians connecting to infected hosts with no “confirm origin” gate, and file transfer left enabled. ConnectWise’s interim advice (disable file transfer until patched) is exactly what a procedure is: a written brake applied at organisational speed. Your takeaway: any tool that can move files or control screens needs a written “verify before you connect” rule — and the discipline to follow it at 4:55pm on a Friday.

Case file · Sep 2026

The help desk as patient zero… and vector

Huntress’s three incidents shared one gap: no procedure required verifying a support session’s origin before connecting or transferring files. The malware repaid the kindness by pushing its four-stage VBScript chain onto every new connection — including the technicians’ own environments.

Try it · 10 min

Draft your team’s verification rule

Three lines, plain language: (1) which requests always require out-of-band verification (payments, credentials, remote access); (2) the approved verification channel; (3) the no-blame reporting route and its SLA. Post it for comment — a rule the team edits is a rule the team obeys.

policystandardguidelineprocedureacceptable usereporting culture

11.4 Reading a policy like an auditor (a 15-minute career skill)

Open any security policy and ask five questions: who owns it (a role, not a department mascot)? when was it reviewed (a date older than two years is decoration)? what’s in scope (people, systems, third parties — or vague “all staff” hand-waving)? how are exceptions handled (written, time-bound, approved — or silent)? and does every “must” point at a procedure that explains how? Policies failing these tests are wallpaper; policies passing them are operating systems.

This skill compounds: it is exactly what client questionnaires, ISO-style audits and interview panels probe, and it flips your relationship with rules from obedience to judgement. Practise cheaply on public documents — banks’ privacy notices, SaaS security pages — noting what’s missing. Within a month you’ll spot an unowned, unreviewed, exception-free policy in ninety seconds, and say the sentence that gets attention in any room: “which layer of the pyramid does this decision belong to?”

Drill · 15 min

Audit a public policy

Pick one public policy or privacy notice you’re subject to. Score the five questions above in a notes file: owner? review date? scope? exceptions? procedure links? Write one paragraph on what’s missing. Keep it: this paragraph is a ready answer to “tell me about a time you analysed documentation” in any security interview.

Knowledge check · Module 11

1. “All remote administrative access must use multi-factor authentication; the step-by-step enrolment workflow is documented in PR-03.” The first clause and the referenced document are, respectively…

2. A colleague borrows your unlocked laptop “for five minutes” and sends an email from your account. The core security property damaged is…

3. Why treat near-miss reports (clicked, noticed, reported) as a detection control?

🕹 Security Arcade · Module 11

Six rapid-fire questions · 15 seconds each · three lives · streak bonus up to +50 per answer. A perfect run scores 900 pts. Your best is saved in this browser.

Module 12 · ~60 min · Capstone

The audit: defend your own kill chain

Everything converges here. You will re-open the kill-chain map from Module 1 and the risk table from Module 2, audit your real estate against a twelve-point checklist, schedule the rituals that keep it true, and choose your next step in the profession — Cisco, SANS/GIAC, IBM or the VunVault lab path.

VUNVAULT studio narration (~3 min). Not playing? The audio/ folder is missing on this host — the built file embeds audio directly; this preview falls back to audio/m12.mp3.
  • By the end of this module you can…
  • Score your personal security estate against a twelve-point audit.
  • Prioritise remediation by risk, not by anxiety.
  • Install four quarterly rituals that keep the audit true.
  • Map a credible certification pathway from where you stand today.

12.1 The twelve-point audit

Score each item Yes/No; every No is a scheduled task, not a shame: 1 Unique passphrases via manager on email, money, work, cloud. 2 Phishing-resistant or app MFA on those four (no SMS on money). 3 SIM PIN + telco line lock. 4 Devices encrypted, locked <2 min, Find-My on. 5 OS/browser auto-update on; critical patches <72h habit. 6 Router: admin password changed, firmware current, WPA2/3, guest net for IoT. 7 Backups 3-2-1 with one immutable/offline copy, restore tested this quarter. 8 Cloud grants purged in last 6 months; sharing links default-private. 9 Breach-lookup run; exposed passwords rotated. 10 App permissions swept; encrypted chat backups on. 11 IR card written; family code-word agreed. 12 Verification rule (Module 11) practised with at least one other human.

12 checks · every “no” is a scheduled task repeat quarterly →
FIG 12.1 — The shield is a habit, not a purchase. Sweep = the quarterly pass.

12.2 Rituals that keep it true

Security decays silently: grants accumulate, firmware ages, backups rot. Four quarterly rituals arrest the decay — grant purge (third-party access pages), restore test (one real file, end to end), patch & firmware day (router, IoT, neglected laptops), and access & session review (active sessions, old devices, ex-accounts). Diarise them like tax dates. Re-run the twelve-point audit twice a year; track your score as a number, because numbers move behaviour that intentions cannot.

12.3 Where you go from here

If this course landed, the profession has doors at every level: Cisco Networking Academy / Skills for All for structured, lab-heavy fundamentals and the CCST track; IBM’s Cybersecurity Analyst certificate path for a broad analyst stack with a breach-case capstone; CompTIA Security+ as the classic first credential; and when you’re ready for practitioner depth, SANS courses with GIAC certifications (SEC275/GFACT is the friendly on-ramp). Pair any of them with hands-on repetition — labs, CTFs, home-lab builds — because every one of these bodies certifies skill, and skill is a contact sport. VunVault’s own labs and this Academy’s future modules sit in the same tradition: learn by doing, then prove it under exam conditions.

Whatever you choose, keep the two sentences this course was built on: make yourself the expensive target, and be fast and loud when something slips through. Everything else is syllabus.

Capstone case · Sep 2026

Ten hours versus your first hour

Unit 42’s AI-accelerated intrusion compressed fifty techniques into a working day. Your counter-compression is smaller and just as real: an IR card in your wallet, a code-word in your family, a restore tested last quarter. Speed is a prepared artefact.

Try it · 20 min

Close the loop

Run the twelve-point audit honestly; schedule your four quarterly rituals in a calendar today; pick one certification pathway and write down the first concrete step (course page, exam voucher, study group). Then take the final exam — 80% to earn the certificate, exactly like the big programmes.

capstoneresidual risksecurity ritualscertification pathwayCPE / continuing education

12.4 Staying sharp: labs, communities and the weekly hour

Knowledge decays; skill persists — but only if rehearsed. Build the cheapest lab that works: one old laptop or a free VM slot, a deliberately vulnerable practice image, and a sandboxed browser for opening suspicious things on purpose. Add one CTF or lab platform account and commit to a weekly hour: sixty minutes of hands-on repetition beats a yearly binge, because security is pattern memory and pattern memory needs spacing.

Then add people: a local community (Nairobi’s security meetups and BSides-style conferences are real and welcoming), one online forum or Discord where practitioners post write-ups, and a habit of reading one incident report a week — like the case files in this course — and summarising it in three lines of your own. Certificates open doors; the weekly hour and the write-up habit are what make you worth hiring behind the door. VunVault’s labs and future Academy modules are built to slot into exactly this rhythm.

Drill · 10 min

Book the hour, join the room

Create a recurring weekly calendar slot named “Security hour” with a rotating menu (lab, CTF, write-up, audit ritual). Then join one community today — even lurk-only. Skill is a contact sport; the calendar and the room are your training partners.

Knowledge check · Module 12

1. Your audit finds: email password reused on three forums (no MFA), and mobile money protected only by SMS codes. Most defensible FIRST fix?

2. Which ritual directly detects accumulated third-party access risk?

3. A career-changer with this course completed asks for the best-aligned FIRST credential. Most sensible recommendation?

🕹 Security Arcade · Module 12

Six rapid-fire questions · 15 seconds each · three lives · streak bonus up to +50 per answer. A perfect run scores 900 pts. Your best is saved in this browser.

Summative assessment · 12 questions · pass mark 80%

Final exam & certificate

Twelve scenario questions drawn across all modules, in the style of the summative assessments used by the big programmes: judgement first, memory second. Select an answer per question, then submit. 80% or better — with your certificate unlocked — issues the VUNVAULT Academy credential.

Certificate track locked

All twelve modules and their knowledge checks are free, forever. The final exam and the printable, ID-bearing certificate are the paid tier: KES 2,500 / USD 19 — one payment, lifetime attempts.

Sandbox checkout in this build: payment rails (M-Pesa Daraja / Stripe / PayPal) plug in at the marked integration points.