Labs

21 hands-on labs.

Each lab gives you a real company brief, a written-artifact prompt, and an AI rubric. Free tier saves locally; Pro runs the AI review.

Risk
Beginner
35 min
Pro

Build a Risk Register

Identify, score, and record 8–12 risks for a SaaS company with remote engineers.

Open →
Risk
Beginner
40 min
Pro

Guided Risk Register — WovenCart

Build a structured 9-risk register for a mid-size D2C retailer using a guided form with 5×5 scoring and printable output.

Open →
Risk
Intermediate
30 min
Pro

Calibrate a 5×5 Scoring Matrix

Write the org-specific likelihood/impact definitions so two analysts score the same risk the same way.

Open →
Compliance
Advanced
55 min
Pro

ISO 27001 Gap Analysis

Map an existing control set to Annex A and produce a remediation roadmap.

Open →
Vendor
Intermediate
45 min
Pro

Review a Vendor SOC 2 Report

Read a SOC 2 Type II and produce a memo on what to trust, what to verify, and which exceptions matter.

Open →
Reporting
Intermediate
30 min
Pro

Write an Executive Summary

Translate a 60-page audit report into one page a CFO will actually read.

Open →
Compliance
Beginner
25 min
Pro

Design a Policy Hierarchy

Lay out policy, standards, procedures, and guidelines for an org you have to brief.

Open →
Controls
Intermediate
45 min
Pro

Build a Control Matrix

Map each Annex A or TSC criterion to the actual control, owner, test method, and frequency.

Open →
Compliance
Advanced
50 min
Pro

Plan an Internal Audit

Scope, resource, schedule, and risk-based test plan for an annual internal audit cycle.

Open →
Vendor
Beginner
25 min
Pro

Score a New Vendor

Apply a tiered vendor risk model and recommend the right level of due diligence.

Open →
Risk
Intermediate
35 min
Pro

Classify an Incident

Apply an incident severity model to a real scenario and write the customer notification.

Open →
Compliance
Advanced
50 min
Pro

GDPR DPIA Outline

Outline a Data Protection Impact Assessment for a new product feature.

Open →
Reporting
Advanced
45 min
Pro

Craft a Board Risk Update

Five slides an actual board can read at 10pm the night before.

Open →
Controls
Beginner
25 min
Pro

Evidence Checklist

Build an evidence collection checklist for a SOC 2 walkthrough.

Open →
Controls
Intermediate
30 min
Pro

Remediation Tracker

Convert an audit findings list into a tracker with priority, owner, and due date.

Open →
Reporting
Beginner
25 min
Pro

Remediation Plan Narrative

Write the half-page narrative that goes with the tracker.

Open →
Compliance
Beginner
40 min
Pro

Draft an Information Security Policy — pick AUP / IR / AC for WovenCart

Pick Acceptable Use, Incident Response, or Access Control; complete the per-type sections for WovenCart; receive an AI rubric review; print a polished policy document to record lab completion.

Open →
Compliance
Beginner
35 min
Pro

Compliance Checklist — WovenCart

Walk a 12–18 control statement checklist for HIPAA, PCI DSS, or GDPR and print a coverage scorecard with severity totals.

Open →
Controls
Intermediate
45 min
Pro

Gap Analysis — WovenCart

Score 10–14 control areas on a 0–3 maturity scale for NIST CSF 2.0, ISO 27001, or SOC 2 and print a Gap Analysis report (current vs target, average, remediation list low → high).

Open →
Controls
Intermediate
40 min
Pro

Vendor Risk Assessment — WovenCart

Score three realistic vendors across 8 yes/no/N-A risk dimensions and print a vendor risk report with a risk band (Low/Moderate/Elevated/High) and prioritized recommendations.

Open →
Controls
Intermediate
40 min
Pro

Incident Response Tabletop — Ransomware at Northbeam Analytics

Draft the first 90 minutes of an IR plan for a Friday-afternoon ransomware hit at a mid-size SaaS — roles, communication tree, containment decisions, and a recovery decision — score yourself against a four-criterion rubric and print the Tabletop Brief.

Open →