The Challenge
Most cybersecurity awareness training is theory-heavy: definitions of phishing, a checklist of red flags, a compliance quiz at the end. It rarely resembles the moment an employee actually faces a threat, at their own desk, mid-workday, with a message that looks completely ordinary until it isn't.
My Approach
Instead of describing what a threat looks like, I built narrative video scenarios that show one unfolding in a normal workday, tied to the same patterns a Microsoft Sentinel-based security operations center actually investigates. The goal was to train the instinct to pause and verify, the behavior that keeps a suspicious message from ever becoming a SOC incident in the first place.
The Solution
- Narrative, POV-driven scenarios. Each video follows an employee through a realistic workday moment, not an abstract example read off a slide.
- Realistic phishing artifacts. The scenarios use fabricated but believable phishing emails, modeled on real social-engineering patterns like fake subscription or billing confirmations designed to prompt a costly callback.
- Tied to real incident response. Scenarios are framed around how a caught-early moment differs from an escalated Sentinel alert, connecting individual judgment to the broader security operation.
See It In Action
New Security Scenario
A day-in-the-life phishing scenario built around a fake subscription-renewal email designed to prompt a panicked callback, the same social-engineering pattern that shows up in real incident reports.
Results
Reflection
Security training tends to fail for the same reason a lot of compliance training fails: it teaches recognition in the abstract instead of practicing it in context. A definition of phishing doesn't help much at 4pm when a real message looks almost right. A video scenario that makes someone feel the same hesitation they'd feel in the moment does.