Corporate cyber + AI awareness training

Train the workday decisions attackers exploit.

Solis Learn turns awareness training into realistic decision practice: inbox pressure, AI data handling, MFA fatigue, file-sharing traps, voice fraud, incident reporting, and mobile work risk. Every mission teaches one practical habit employees can use the same day.

33story missions
4risk tracks
Replaybest-score XP
Live simulation preview
Facilities DeskRoutine maintenance
Brightlane SupplyNew remittance before 4 PM
Authenticator3 sign-in prompts from unknown location
Learner decision

Verify through a trusted channel, report the message, keep the workflow intact.

Lookalike domain Pressure deadline Process bypass
92%
Scenario judgement score
Mission catalogue

Awareness content that feels like a workplace simulation.

Every mission is designed around realistic employee behaviour: read the brief, make the calls, review the reasoning, and build confidence through repetition.
Mission 01

Inbox Siege: Phishing & Business Email Compromise

Cybersecurity

Work through a live-looking inbox, inspect a suspicious vendor message, and make the safest next move before money or credentials are lost.

Starter 14 min 180 XP 4 checkpoints
Threat recognition and safer response habits
The workday starts badly. Accounts payable is short-staffed, invoices are piling up, and three “urgent” messages arrive within ten minutes. One is routine. One is risky. One is engineered to make you rush.
Mission 02

MFA Meltdown: Passwords, Prompt Fatigue & Account Hygiene

Cybersecurity

Build safer password habits, spot MFA fatigue, and decide how to recover when a login pattern looks wrong.

Starter 11 min 155 XP 3 checkpoints
Threat recognition and safer response habits
A coworker solved password fatigue by reusing one “strong” password everywhere. Now their phone is lighting up with approval requests they swear they did not start.
Mission 03

Prompt & Prejudice: Safe Generative AI at Work

AI

Decide what belongs in an AI prompt, what must stay out, and how to use AI without leaking sensitive business context.

Starter 12 min 165 XP 3 checkpoints
Prompt, data, and model-output judgement
A manager wants a quick summary before a meeting and says, “Just dump it into AI and make it sound polished.” The problem is the draft includes customer data, HR notes, and confidential strategy.
Mission 04

Face/Off Payroll Edition: Deepfakes, Voice Clones & Executive Fraud

AI

Practice resisting urgent requests that sound real, look real, and still need independent verification.

Standard 11 min 170 XP 3 checkpoints
Prompt, data, and model-output judgement
Late in the day, a voicemail arrives from someone who sounds exactly like the CEO. They need a sensitive favour done before the board dinner starts.
Mission 05

The QR Trap: Mobile Safety, Smishing & Public Wi‑Fi

Cybersecurity

Practice safer decisions around text-message lures, QR codes, and work performed from cafés, airports, and event spaces.

Starter 10 min 150 XP 3 checkpoints
Threat recognition and safer response habits
A text says your package is delayed and includes a short link. At the same time, an airport lounge poster offers “free secure Wi-Fi” through a QR code near the gate.
Mission 06

Permission Slip: Shadow AI, Plug-ins & Connected Apps

AI

Understand why browser plug-ins, AI assistants, and unsanctioned SaaS tools can quietly gain access to more company data than expected.

Standard 10 min 155 XP 3 checkpoints
Prompt, data, and model-output judgement
A helpful-looking AI browser extension promises instant meeting summaries, but the install screen wants access to mail, calendar, contacts, and all websites you visit.
Mission 07

ChatOps Impersonator: Teams, Slack & Internal Message Fraud

Cybersecurity

Practice spotting internal-style message fraud, fake help requests, and the “quick favour” tone that thrives in chat tools.

Standard 10 min 160 XP 3 checkpoints
Threat recognition and safer response habits
A direct message from “Help Desk” asks you to share a code from your authenticator app so they can finish a login repair. In the next channel over, a fake coworker asks for a file “before the client sees it.”
Mission 08

Incident Radar: Reporting, Evidence & First Response

Cybersecurity

Know what to report, what evidence helps, and how to respond without making the situation worse.

Standard 9 min 160 XP 3 checkpoints
Threat recognition and safer response habits
You realize you clicked something you should not have. The clock starts immediately: do you hide it, fix it yourself, or help responders with a clean timeline?
Mission 09

Meeting Mirage: Calendar Invites, Fake Join Links & Last-Minute Pressure

Cybersecurity

Practice resisting fake meeting invites that weaponize calendar trust, browser logins, and executive timing pressure.

Standard 9 min 165 XP 3 checkpoints
Threat recognition and safer response habits
A client meeting suddenly appears on your calendar minutes before it starts. The invite claims the CFO is already inside and waiting for you to join through the browser.
Mission 10

File Share Frenzy: OAuth Consent, Shared Docs & Cloud Collaboration Traps

Cybersecurity

Spot malicious shared-document flows, fake file portals, and connected-app consent traps before access tokens are handed away.

Advanced 11 min 175 XP 3 checkpoints
Threat recognition and safer response habits
Finance shares a “board forecast” file minutes before a review. The link opens something that looks close enough to SharePoint to be dangerous.
Mission 11

The Helpful Stranger: Data Handling, AI Assistants & Secure Collaboration

AI

Practice handling over-helpful AI assistants, broad data-access requests, and collaboration shortcuts that can expose more than employees realize.

Advanced 10 min 170 XP 3 checkpoints
Prompt, data, and model-output judgement
A new tool promises to “work its magic” across email, chat, files, and calendars. At the same time, a collaborator asks for a quick shortcut on a document that contains more sensitive detail than they realize.
Mission 12

Agent Autopilot: AI Tool Use, Approvals & Human Review

AI

Control agentic AI workflows before an assistant sends email, changes records, or takes action with the wrong context.

Advanced 12 min 180 XP 3 checkpoints
Prompt, data, and model-output judgement
A team connects a new AI agent to email, CRM, documents, and ticketing. It saves time until a draft action is about to contact a customer using stale facts.
Mission 13

Model Mirage: Hallucinations, Sources & Decision Checks

AI

Catch unsupported AI claims, fabricated citations, and overconfident summaries before they influence real decisions.

Standard 10 min 165 XP 3 checkpoints
Prompt, data, and model-output judgement
A polished AI summary looks ready for leadership, but two cited sources are vague, one number is invented, and the recommendation ignores a recent exception.
Mission 14

Extension Exposure: Browser Add-ons, Tokens & Web Data

Cybersecurity

Evaluate browser extensions before they read every page, capture tokens, or quietly exfiltrate sensitive work data.

Standard 9 min 160 XP 3 checkpoints
Threat recognition and safer response habits
A productivity extension promises instant meeting notes and coupon codes, but its install screen asks to read and change data on every website you visit.
Mission 15

Ransomware Ready: Backups, Isolation & First Decisions

Cybersecurity

Practice the first hour of a ransomware suspicion: isolate, preserve evidence, report fast, and avoid making recovery harder.

Advanced 13 min 190 XP 3 checkpoints
Threat recognition and safer response habits
A shared drive suddenly fills with renamed files, a workstation shows a ransom note, and a manager asks whether they should reboot everything immediately.
Mastery 01

Advanced Threat Intelligence Models

AI

Use AI to turn CVE, KEV, IOC, vendor, ATT&CK, and report feeds into ranked, decision-ready security intelligence.

Mastery 18 min 240 XP 4 checkpoints
AI cyber defence design, governance, and operational assurance
The SOC has 10,000 new vulnerability records, three urgent vendor advisories, a KEV update, and a board question: what should we patch first and why?
Mastery 02

Autonomous Agents for Cyber Defence

AI

Design cyber defence agents with scoped authority, guardrails, auditability, approvals, and rollback for production SOC use.

Mastery 17 min 245 XP 4 checkpoints
AI cyber defence design, governance, and operational assurance
A containment agent can isolate hosts, close tickets, query EDR, and message executives. It is fast, but nobody has defined where its authority ends.
Mastery 03

Adversarial Red-Teaming AI

AI

Test AI-enabled security systems for prompt injection, poisoning, evasion, extraction, unsafe tool use, and output manipulation.

Mastery 18 min 245 XP 4 checkpoints
AI cyber defence design, governance, and operational assurance
A red team prompt makes a security assistant ignore its system rules and draft a risky SOAR command. The goal is not chaos; it is evidence and mitigation.
Mastery 04

SOAR + LLM Integration

AI

Connect LLMs into SOAR workflows for enrichment, classification, recommendations, approvals, and reversible response actions.

Mastery 17 min 240 XP 4 checkpoints
AI cyber defence design, governance, and operational assurance
An alert flows from Wazuh into Shuffle. The LLM explains the alert well, but the playbook is one click away from isolating a production server.
Mastery 05

AI Governance and Policy for Security Leaders

AI

Build AI cyber governance with risk registers, system inventories, accountability matrices, review boards, and approval workflows.

Mastery 19 min 250 XP 4 checkpoints
AI cyber defence design, governance, and operational assurance
Three teams have deployed AI into SOC workflows, but only one has documented owners, data sources, review status, risk controls, and incident escalation.
Mastery 06

AI-Enhanced Incident Response

AI

Use AI to support incident triage, clustering, timeline reconstruction, evidence review, response rationale, and reporting.

Mastery 18 min 245 XP 4 checkpoints
AI cyber defence design, governance, and operational assurance
Zeek conn.log, Suricata EVE JSON, endpoint events, SIEM alerts, and case notes all point to a possible intrusion. The model can help, but every recommendation needs evidence.
Mastery 07

AI Forensics and Behaviour Logging

AI

Preserve model, prompt, tool-call, decision, signer, timestamp, retention, and residency artefacts for forensic reconstruction.

Mastery 19 min 250 XP 4 checkpoints
AI cyber defence design, governance, and operational assurance
A containment decision is challenged by legal, privacy, and operations. The SOC must prove what the AI saw, what it did, who approved it, and whether logs are intact.
Consulting 01

Mission-Driven Security Consulting & Assessment Methodology

Security Consulting

Run a mission-first assessment: discovery interviews, messy inventories, evidence collection, risk translation, and practical executive summaries.

Advanced 26 min 260 XP 4 checkpoints
Mission-driven assessment, SaaS hardening, rollout planning, and senior client delivery
A 35-person nonprofit uses Google Workspace, Slack, Zoom, and 1Password with no dedicated security team. Leadership needs clarity without fear, jargon, or a fantasy budget.
Consulting 02

Microsoft 365 & Google Workspace Security Assessment

Security Consulting

Assess M365 and Google Workspace tenants for identity, admin privilege, email security, sharing, logging, evidence, and prioritized fixes.

Mastery 34 min 320 XP 4 checkpoints
Mission-driven assessment, SaaS hardening, rollout planning, and senior client delivery
Two tenants are waiting: one mature, one with nonprofit-style gaps. You need to orient quickly, validate the risks, and explain the trade-offs in plain language.
Consulting 03

SaaS Ecosystem, Identity, and Unfamiliar Tool Hardening

Security Consulting

Use a repeatable assessment lens for Slack, Zoom, 1Password, Okta, integrations, audit logs, retention, lifecycle, and unknown SaaS tools.

Advanced 27 min 275 XP 4 checkpoints
Mission-driven assessment, SaaS hardening, rollout planning, and senior client delivery
The client adds an unfamiliar donor-management platform to the scope halfway through the engagement. You have admin access, a business goal, and no checklist yet.
Consulting 04

Practical Security Rollout, Change Management, and Client Enablement

Security Consulting

Turn findings into safe implementation plans with phases, owners, communications, exceptions, rollback paths, champions, and adoption measures.

Advanced 29 min 285 XP 4 checkpoints
Mission-driven assessment, SaaS hardening, rollout planning, and senior client delivery
The recommendation is obvious: enforce MFA. The hard part is rolling it out across staff, contractors, shared inboxes, travel schedules, support limits, and executive anxiety.
Consulting 05

Polished Deliverables, Incident Response Planning, and Senior-Level Client Delivery

Security Consulting

Create client-ready reports, executive summaries, technical appendices, readouts, incident plans, tabletops, and calm evidence-backed recommendations.

Mastery 31 min 305 XP 4 checkpoints
Mission-driven assessment, SaaS hardening, rollout planning, and senior client delivery
Raw evidence is scattered across screenshots, logs, interview notes, and config exports. The client does not need panic; they need a report they can trust and act on.
Consulting Capstone

Capstone: Mission-Driven Security Engagement Simulation

Security Consulting

Complete a RipRap-style engagement from discovery through assessment, evidence, findings, roadmap, rollout plan, and client presentation trade-offs.

Mastery 42 min 360 XP 5 checkpoints
Mission-driven assessment, SaaS hardening, rollout planning, and senior client delivery
A mission-driven client uses Google Workspace, Slack, Zoom, 1Password, and one unfamiliar SaaS. You must assess, prioritize, plan fixes, and defend trade-offs to leaders.
COBOL 01

COBOL Foundations for Enterprise Delivery

COBOL

Learn COBOL structure by comparing valid programs, arranging divisions, and simulating a minimal batch run.

Starter 17 min 210 XP 4 checkpoints
Enterprise COBOL delivery, modernization, batch, data, and transaction reliability
You have joined a Sopra Steria delivery squad supporting a regulated mainframe estate. Your first task is to read and safely modify a tiny COBOL batch program without breaking compile standards.
COBOL 02

COBOL Data, Copybooks, and Financial Precision

COBOL

Practice PIC clauses, packed decimal judgement, copybook reading, and fixed-width record interpretation.

Intermediate 19 min 225 XP 4 checkpoints
Enterprise COBOL delivery, modernization, batch, data, and transaction reliability
A client batch job calculates fees from fixed-width account records. A one-byte layout misunderstanding could misstate amounts across thousands of records.
COBOL 03

COBOL Batch, JCL, and Operational Reliability

COBOL

Connect COBOL SELECT names to JCL DD names, handle file status, and design restartable batch changes.

Advanced 20 min 235 XP 4 checkpoints
Enterprise COBOL delivery, modernization, batch, data, and transaction reliability
A nightly client job abends after a deployment. The COBOL program, JCL, and operations evidence need to be read together before anyone changes production.
COBOL 04

COBOL DB2 and CICS Transaction Patterns

COBOL

Work with embedded SQL, SQLCODE handling, CICS response checks, and transaction-safe thinking.

Advanced 21 min 240 XP 4 checkpoints
Enterprise COBOL delivery, modernization, batch, data, and transaction reliability
A client online transaction sometimes returns a blank customer profile. The issue may be SQLCODE handling, CICS response handling, or weak validation between the screen and program.
COBOL 05

COBOL Modernization, Testing, and Code Review

COBOL

Modernize legacy COBOL safely with characterization tests, structured refactors, API boundaries, and production-aware review.

Mastery 23 min 255 XP 4 checkpoints
Enterprise COBOL delivery, modernization, batch, data, and transaction reliability
A client wants to expose a legacy calculation through a new digital service. The delivery team must improve testability without rewriting the whole system or changing financial behaviour.
Built for engagement

Why this content is built differently.

Scenario-first content

Each lesson starts with a recognizable workplace situation, then ties the decision back to the signal employees should remember.

Actionable debriefs

Results explain why a response works, what to avoid, and how to apply the same habit in email, chat, meetings, mobile work, and AI tools.

Momentum without gimmicks

Best-score XP, levels, and achievements create a reason to improve while keeping the experience grounded in business risk.

Top learners
#1 rnld
Risk Spotter
1225 XP
#2 nzinchen
New Recruit
490 XP
#3 soulfanca
New Recruit
420 XP
#4 SuperRitchie
New Recruit
0 XP
#5 orbit9112
New Recruit
0 XP