About this interactive
What you're doing: running a security awareness program rather than sitting through one. Harbor Ridge Medical Group is a fictional clinic group with 420 staff, 240 of whom have no work email, and an awareness program that until now was a single annual slide deck with a 96% completion rate and nothing to show for it. You take it over and walk it through all four stages of the training life cycle — Develop, Deliver, Test, Monitor — making eight decisions along the way, each revealed with the reasoning and with the reason the other three options fall short. Why it matters: almost everything that makes an awareness program work or fail is a program-design decision rather than a fact about phishing. A policy that was published but never communicated will not be followed. A perfectly delivered email reaches the half of this workforce that has email. A simulation nobody can fail measures nothing, and a 96% completion rate is not awareness. The stage most programs never reach is the last one, and it is the one that closes the loop: monitoring exists to change what you develop next. How to use it: at each stage, ask who the decision is actually about before you look at the options — the whole organization, or one person. Several items turn on that difference, and several wrong answers are the right idea aimed at the wrong population. Watch for the options that are genuinely half right: threat intelligence really is an input, credential theft really is the most severe outcome, and a wave of pretext phone calls really is an incident. Each of those is true, and none of them is the answer.
About TechKnowSurge
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →