Most security training is a slideshow people click through with the sound off. Ours is fourteen real games — phishing, social engineering, cloud misconfig, AI prompt injection and more — where employees do the attack and defend against it. They learn because it's fun, and you get audit-ready completion records for SOC 2 and ISO 27001.
No credit card to start. Free for individuals; team reporting & compliance records on the Team plan.
Each module is a hands-on game with four difficulty tiers — not a quiz. Skills map to the threats your auditors and your attackers both care about.
Spot domain spoofs, urgency cues, gift-card and business-email-compromise scams. The #1 breach vector, drilled until it's reflex.
Pretexting, tailgating, baiting and vishing — the human attacks no firewall stops.
Find public buckets, open security groups and over-permissive IAM. Least-privilege in practice.
Recognize prompt injection and jailbreaks — modern training for teams shipping AI features.
SQL injection and XSS in a live sandbox — so engineers feel the bug, not just read about it.
Work a SOC alert queue: escalate real intrusions, dismiss false positives. Detection muscle.
…plus password security, hash cracking, cryptography, recon and crypto/Web3 scam detection — 14 games in total, always growing.
Spin up a team in seconds and invite employees with a link. No IT project, no LMS migration.
People train because they want to — earning XP and ranks across real attack-and-defend scenarios.
Your admin dashboard shows who completed what, and exports an audit-ready training transcript per person.
Same goal, two outcomes — one your employees click through with the sound off, the other they actually play.
Live per-employee completion → one-click SOC 2 / ISO 27001 evidence. (Sample data.)
Security-awareness training is a control auditors check directly. We make the evidence trivial to produce:
People finish games. The hard part of any program is getting employees to actually engage — that's what we're built for.
Live sandboxes and graded scenarios mean employees practice the decision, not memorize a slide for the quiz.
Browser-based, invite by link, nothing to install. You can have a team training this afternoon.
Security awareness training is a control your auditor checks directly. See exactly which requirement it satisfies — and how our completion records become your evidence.
Training + completion evidence for Common Criteria CC2.2 / CC1.4.
Training + records for Annex A 6.3 (information security awareness).
The § 164.308(a)(5) security awareness & training safeguard, documented.
New to the terms? Browse the plain-English security awareness glossary — every term links to a game that teaches it.
SOC 2 and ISO 27001 require that you provide security-awareness training and keep evidence of completion. HACKIN'GAMES delivers the training across the major threat domains and gives you per-employee completion records plus an exportable training transcript to hand your auditor. Your auditor makes the final determination, but this gives you both the training and the evidence in one place.
Phishing simulators test one thing — whether someone clicks a fake email. We cover phishing and social engineering, cloud misconfiguration, application security, AI/LLM security and incident response, as hands-on games rather than a single annual gotcha test. Many teams run us alongside a phishing simulator.
No install — it runs in any browser. Individuals can start playing instantly with no sign-up. For team reporting and compliance records, members join your team with a link and their completions roll up to your admin dashboard.
Individuals play free. The Team plan adds the admin dashboard, member management and audit-ready compliance records. See plans & pricing ▸
Yes. We add modules for emerging threats — AI prompt injection and crypto/Web3 scams are already in, and more ship over time. Your team gets new content without renegotiating anything.