Labs
21 hands-on labs.
Each lab gives you a real company brief, a written-artifact prompt, and an AI rubric. Free tier saves locally; Pro runs the AI review.
Build a Risk Register
Identify, score, and record 8–12 risks for a SaaS company with remote engineers.
Open →Guided Risk Register — WovenCart
Build a structured 9-risk register for a mid-size D2C retailer using a guided form with 5×5 scoring and printable output.
Open →Calibrate a 5×5 Scoring Matrix
Write the org-specific likelihood/impact definitions so two analysts score the same risk the same way.
Open →ISO 27001 Gap Analysis
Map an existing control set to Annex A and produce a remediation roadmap.
Open →Review a Vendor SOC 2 Report
Read a SOC 2 Type II and produce a memo on what to trust, what to verify, and which exceptions matter.
Open →Write an Executive Summary
Translate a 60-page audit report into one page a CFO will actually read.
Open →Design a Policy Hierarchy
Lay out policy, standards, procedures, and guidelines for an org you have to brief.
Open →Build a Control Matrix
Map each Annex A or TSC criterion to the actual control, owner, test method, and frequency.
Open →Plan an Internal Audit
Scope, resource, schedule, and risk-based test plan for an annual internal audit cycle.
Open →Score a New Vendor
Apply a tiered vendor risk model and recommend the right level of due diligence.
Open →Classify an Incident
Apply an incident severity model to a real scenario and write the customer notification.
Open →GDPR DPIA Outline
Outline a Data Protection Impact Assessment for a new product feature.
Open →Craft a Board Risk Update
Five slides an actual board can read at 10pm the night before.
Open →Evidence Checklist
Build an evidence collection checklist for a SOC 2 walkthrough.
Open →Remediation Tracker
Convert an audit findings list into a tracker with priority, owner, and due date.
Open →Remediation Plan Narrative
Write the half-page narrative that goes with the tracker.
Open →Draft an Information Security Policy — pick AUP / IR / AC for WovenCart
Pick Acceptable Use, Incident Response, or Access Control; complete the per-type sections for WovenCart; receive an AI rubric review; print a polished policy document to record lab completion.
Open →Compliance Checklist — WovenCart
Walk a 12–18 control statement checklist for HIPAA, PCI DSS, or GDPR and print a coverage scorecard with severity totals.
Open →Gap Analysis — WovenCart
Score 10–14 control areas on a 0–3 maturity scale for NIST CSF 2.0, ISO 27001, or SOC 2 and print a Gap Analysis report (current vs target, average, remediation list low → high).
Open →Vendor Risk Assessment — WovenCart
Score three realistic vendors across 8 yes/no/N-A risk dimensions and print a vendor risk report with a risk band (Low/Moderate/Elevated/High) and prioritized recommendations.
Open →Incident Response Tabletop — Ransomware at Northbeam Analytics
Draft the first 90 minutes of an IR plan for a Friday-afternoon ransomware hit at a mid-size SaaS — roles, communication tree, containment decisions, and a recovery decision — score yourself against a four-criterion rubric and print the Tabletop Brief.
Open →