Security awareness training your team will actually finish.

Most security training is a slideshow people click through with the sound off. Ours is fourteen real games — phishing, social engineering, cloud misconfig, AI prompt injection and more — where employees do the attack and defend against it. They learn because it's fun, and you get audit-ready completion records for SOC 2 and ISO 27001.

Set up your team — free Take the 60-sec tour ▸ Try a game first ▸

No credit card to start. Free for individuals; team reporting & compliance records on the Team plan.

0
games
0
security domains
0
difficulty tiers
0
in your browser

Training that covers what actually breaches companies

Each module is a hands-on game with four difficulty tiers — not a quiz. Skills map to the threats your auditors and your attackers both care about.

🎣

Phishing & BEC

Spot domain spoofs, urgency cues, gift-card and business-email-compromise scams. The #1 breach vector, drilled until it's reflex.

🎭

Social engineering

Pretexting, tailgating, baiting and vishing — the human attacks no firewall stops.

☁️

Cloud security

Find public buckets, open security groups and over-permissive IAM. Least-privilege in practice.

🤖

AI / LLM security

Recognize prompt injection and jailbreaks — modern training for teams shipping AI features.

💉

App security

SQL injection and XSS in a live sandbox — so engineers feel the bug, not just read about it.

🚨

Incident response

Work a SOC alert queue: escalate real intrusions, dismiss false positives. Detection muscle.

…plus password security, hash cracking, cryptography, recon and crypto/Web3 scam detection — 14 games in total, always growing.

How it works

STEP 01

Create your team

Spin up a team in seconds and invite employees with a link. No IT project, no LMS migration.

STEP 02

They play, they learn

People train because they want to — earning XP and ranks across real attack-and-defend scenarios.

STEP 03

You get the records

Your admin dashboard shows who completed what, and exports an audit-ready training transcript per person.

Completion, not compliance theater

Same goal, two outcomes — one your employees click through with the sound off, the other they actually play.

▍ the typical LMS slideshow
Security Policy — Slide 14 of 40
☐ I have read and understood the policy
avg completion: 6% · last opened: never · what they retained: nothing
▍ HACKIN'GAMES — sample team
0%COMPLETE
@maya100%
@devon93%
@priya86%
@sam71%

Live per-employee completion → one-click SOC 2 / ISO 27001 evidence. (Sample data.)

Built for your SOC 2 & ISO 27001 evidence

Security-awareness training is a control auditors check directly. We make the evidence trivial to produce:

Why teams pick HACKIN'GAMES over click-through training

Completion, not compliance theater

People finish games. The hard part of any program is getting employees to actually engage — that's what we're built for.

🧠

Real skill, not recall

Live sandboxes and graded scenarios mean employees practice the decision, not memorize a slide for the quiz.

Zero rollout friction

Browser-based, invite by link, nothing to install. You can have a team training this afternoon.

Map your training to your framework

Security awareness training is a control your auditor checks directly. See exactly which requirement it satisfies — and how our completion records become your evidence.

📋

SOC 2

Training + completion evidence for Common Criteria CC2.2 / CC1.4.

🌐

ISO 27001

Training + records for Annex A 6.3 (information security awareness).

🏥

HIPAA

The § 164.308(a)(5) security awareness & training safeguard, documented.

New to the terms? Browse the plain-English security awareness glossary — every term links to a game that teaches it.

Frequently asked questions

Does this satisfy SOC 2 security-awareness training requirements?

SOC 2 and ISO 27001 require that you provide security-awareness training and keep evidence of completion. HACKIN'GAMES delivers the training across the major threat domains and gives you per-employee completion records plus an exportable training transcript to hand your auditor. Your auditor makes the final determination, but this gives you both the training and the evidence in one place.

How is this different from a phishing simulator?

Phishing simulators test one thing — whether someone clicks a fake email. We cover phishing and social engineering, cloud misconfiguration, application security, AI/LLM security and incident response, as hands-on games rather than a single annual gotcha test. Many teams run us alongside a phishing simulator.

Do employees need accounts or installs?

No install — it runs in any browser. Individuals can start playing instantly with no sign-up. For team reporting and compliance records, members join your team with a link and their completions roll up to your admin dashboard.

What does it cost?

Individuals play free. The Team plan adds the admin dashboard, member management and audit-ready compliance records. See plans & pricing ▸

Is the content kept up to date?

Yes. We add modules for emerging threats — AI prompt injection and crypto/Web3 scams are already in, and more ship over time. Your team gets new content without renegotiating anything.

Set up your team — free to start Browse all 14 games ▸
HACKIN'GAMES · all games · plans · teams · compliance · gamified security awareness training & SOC 2 / ISO 27001 evidence. · built by Looms.