Award-Winning Security Awareness Training Library
No animation. No anime. No AI slop.
61 courses, filmed in-house with real actors and real writers. Psychology instead of fear — which is why people finish them.
- G2 High Performer Fall 2026
- G2 Best Support Mid-Market
- G2 Easiest To Do Business With Mid-Market
- G2 Best Meets Requirements Mid-Market
- SOC 2 Type 2
- Courses
- 61Courses
- Series
- 8Series
- Run time
- 10.7 hrsRun time
- Compliance tracks
- 3Compliance tracks
Showing 61 of 61 courses
22 minPreviewAnnual Training with Wilderness Jack
Annual Training with Wilderness Jack - Security awareness training featuring outdoor survival analogies for cybersecurity concepts.
Annual Training
30 minPreviewAnnual Training with...Steven
This year, we took cybersecurity training up a notch. From learning why cybersecurity matters to spotting the latest in digital threats, our annual training dives deep—and keeps it entertaining.
Annual Training
46 minPreviewPsySec Essentials
PsySec Essentials creates a baseline knowledge for your employees, and brings new employees up to speed on Cyber Security threats. This annual training course touches on each area of security an employee should know for the year.
Annual Training
40 minPreviewThe Too Late Show Annual Training
Hook Security's premier training is back. Grab a snack and get ready to laugh. The Too Late Show with host Kimberly Caine has games, guests, and a few extra surprises! Covering topics such as social engineering, passwords, safe web browsing, malware, and more!
Annual Training
30 minWilderness Jack: Concrete Jungle
Get ready to trade pine trees for office plants! Wilderness Jack is back, and this time, he's venturing into the wildest terrain of all: corporate life. From phishing emails to deepfake scams, Jack tackles modern cybersecurity threats with his signature mix of grit, humor, and heart.
Annual Training
30 minGDPR Security Awareness Training
GDPR compliance training educates employees on the principles, requirements, and best practices for protecting personal data of individuals within the EU and EEA.
Compliance Track
16HIPAA Advanced Safeguards for IT & Leadership
This course helps IT and organizational leaders implement strong safeguards, manage risk, and build a lasting foundation for HIPAA compliance.
Compliance Track
16HIPAA Habits for Admins
This course gives administrative staff simple, practical ways to protect patient information, avoid common HIPAA mistakes, and handle sensitive situations with confidence.
Compliance Track
16HIPAA in Real Life: Everyday Habits for Clinical Care Providers
This course helps clinical providers protect patient privacy by applying HIPAA best practices in everyday actions, conversations, and real-world situations.
Compliance Track
30 minPreviewHIPAA Security Awareness Training
Welcome to your HIPAA Security Awareness Training for HIPAA covered entities and business associates. Our HIPAA Compliance Training gives employees a HIPAA introduction including how to recognize PHI (protected health information), proper uses and disclosures of PHI, how to keep PHI secure, and how to report a breach of PHI.
Compliance Track
30 minPreviewPCI Security Awareness Training
PCI (Payment Card Industry) compliance training is designed to educate employees on the requirements and best practices for protecting payment card data. Compliance with PCI standards is required by contractual agreements between organizations and payment card brands.
Compliance Track
8 minPreviewInsider Threats with Mike Fry The Cyber Guy
Insider Threats with Mike Fry The Cyber Guy - Security awareness training
Mike Fry The Cyber Guy
8 minMalware with Mike Fry The Cyber Guy
Malware with Mike Fry The Cyber Guy - Security awareness training
Mike Fry The Cyber Guy
8 minMobile Devices with Mike Fry The Cyber Guy
Mobile Devices with Mike Fry The Cyber Guy - Security awareness training
Mike Fry The Cyber Guy
8 minPasswords with Mike Fry The Cyber Guy
Passwords with Mike Fry The Cyber Guy - Security awareness training
Mike Fry The Cyber Guy
8 minPreviewPhishing with Mike Fry The Cyber Guy
Phishing with Mike Fry The Cyber Guy - Security awareness training
Mike Fry The Cyber Guy
8 minRansomware with Mike Fry The Cyber Guy
Ransomware with Mike Fry The Cyber Guy - Security awareness training
Mike Fry The Cyber Guy
8 minSafe Web Browsing with Mike Fry The Cyber Guy
Safe Web Browsing with Mike Fry The Cyber Guy - Security awareness training
Mike Fry The Cyber Guy
8 minSocial Engineering with Mike Fry The Cyber Guy
Social Engineering with Mike Fry The Cyber Guy - Security awareness training
Mike Fry The Cyber Guy
8 minSocial Media Scams with Mike Fry The Cyber Guy
Our Mike Fry The Cyber Guy series adds a new and fun character to our monthly courses. The Social Media Scams course dives deep into the dangers accompanied by social media, providing employees with examples of popular scams and tips to avoid them.
Mike Fry The Cyber Guy
VariesWorking Remotely with Mike Fry The Cyber Guy
Working Remotely with Mike Fry The Cyber Guy - Security awareness training
Mike Fry The Cyber Guy
8 minPreviewPsySec Deep Dive: Incident Reporting
PsySec Deep Dive: Incident Reporting - Security awareness training
PsySec Deep Dive
10 minPreviewPsySec Deep Dive: Malware
PsySec Deep Dive: Malware - Security awareness training
PsySec Deep Dive
10 minPreviewPsySec Deep Dive: Mobile Devices
Our PsySec Deep Dive series unpacks and explains different subjects in a fun and engaging way. Our Mobile Devices deep dive takes an in-depth look at the risks accompanied with owning a mobile device.
PsySec Deep Dive
8 minPreviewPsySec Deep Dive: Passwords
Our PsySec Deep Dive series unpacks and explains different subjects in a fun and engaging way. Our Passwords Deep Dive takes an in-depth look at the importance of keeping our passwords secure.
PsySec Deep Dive
10 minPreviewPsySec Deep Dive: Phishing
Our PsySec Deep Dive series unpacks and explains different subjects in a fun and engaging way. Our Phishing Deep Dive provides an in-depth look at popular phishing tactics cybercriminals are utilizing today.
PsySec Deep Dive
10 minPsySec Deep Dive: Physical Security
Our PsySec Deep Dive series unpacks and explains different subjects in a fun and engaging way. Our Physical Security Deep Dive takes an in-depth look at the physical world around us and security flaws that can put our company at risk.
PsySec Deep Dive
10 minPreviewPsySec Deep Dive: Ransomware
Our PsySec Deep Dive series unpacks and explains different subjects in a fun and engaging way. Our Ransomware deep dive provides an in-depth look at what ransomware is and looks like, and what to do if you've fallen victim to a ransomware attack.
PsySec Deep Dive
10 minPreviewPsySec Deep Dive: Removable Media
Our PsySec Deep Dive series unpacks and explains different subjects in a fun and engaging way. Using removable media devices, such as USB drives and external hard drives, to gain access and information from your devices is a popular tactic used by cybercriminals.
PsySec Deep Dive
8 minPreviewPsySec Deep Dive: Safe Web Browsing
PsySec Deep Dive: Safe Web Browsing - Security awareness training
PsySec Deep Dive
9 minPreviewPsySec Deep Dive: Social Engineering
This course on social engineering will provide a comprehensive overview of the threats and tactics involved in this type of cyber attack. You will learn how to identify vulnerable targets, craft effective strategies to exploit weaknesses, and develop steps to protect yourself.
PsySec Deep Dive
10 minPsySec Deep Dive: Vishing
Our PsySec Deep Dive series unpacks and explains different subjects in a fun and engaging way. Our Vishing Deep dive takes an in-depth look at a popular tactic used by cybercriminals called Vishing.
PsySec Deep Dive
9 minPreviewPsySec Deep Dive: Working Remotely
PsySec Deep Dive: Working Remotely - Security awareness training
PsySec Deep Dive
2 minPreviewQuick Hit: Incident Reporting
Sometimes, when you're the victim of a cyberattack, you feel like it's somehow your fault. In this Quick Hit, we're discussing the steps you should take to assess and start repairing the damage caused by hacking, phishing, or a ransomware attack.
Quick Hits
2 minPreviewQuick Hit: Physical Security
As technology goes on to develop, danger can come from anywhere, and physical security becomes more important. In this Quick Hit, we're covering what physical security is, how it works, and how you can keep your software and office safe!
Quick Hits
2 minPreviewQuick Hit: Ransomware
Ransomware has become more prevalent in the past few years. In this Quick Hit, we're covering what ransomware is, how it works, and how you can fight against it.
Quick Hits
2 minPreviewQuick Hit: Removable Media
Over the years, technology has advanced to allow for more accessible storage of documents and files. However, with every advance in technology come new challenges. In this Quick Hit, we're covering ways in which you can keep your portable devices protected!
Quick Hits
2 minPreviewQuick Hit: Safe Web Browsing
We all know to use our discretion when browsing for information online. But it's easy to get distracted by links, ads, videos - even your social media feeds. In this Quick Hit, we're discussing three tips for browsing the web safely!
Quick Hits
3 minPreviewQuick Hit: Social Engineering
Even the most technically impenetrable cybersecurity strategy still has one innate flaw: the possibility of human error. In this Quick Hit, we're discussing the four most common types of social engineering attacks!
Quick Hits
3 minPreviewQuick Hit: Vishing
The past couple of years has seen a global rise of cybercrime through various channels. One of them is "vishing." In this Quick Hit, we're discussing what vishing is, how it's carried out, and ways in which you can spot and avoid these attacks!
Quick Hits
2 minPreviewQuick Hits: Cybersecurity at Home
The Quick Hits series are short courses that help remind your employees of popular Cyber Security Topics while providing quick refreshers. Our Cybersecurity at Home Quick Hit provides employees with steps to take to ensure their company's information and data is secure at home.
Quick Hits
2 minPreviewQuick Hits: Malware
The Quick Hits series are short courses that help remind your employees of popular Cyber Security Topics while providing quick refreshers. Our Malware Quick Hit explains the dangers that come with malware, how to spot it, and what to do if one believes their device has been infected.
Quick Hits
2 minPreviewQuick Hits: Mobile Device Attacks
The Quick Hits series are short courses that help remind your employees of popular Cyber Security Topics while providing quick refreshers. Our Mobile Device Attacks Quick Hit provides employees with tips and tricks needed to prevent attacks on their mobile devices.
Quick Hits
2 minQuick Hits: Passphrases
The Quick Hits series are short courses that help remind your employees of popular Cyber Security Topics while providing quick refreshers. Our Passphrases Quick Hit provides employees with the knowledge needed to take their passwords to the next level.
Quick Hits
2 minPreviewQuick Hits: Phishing
Phishing attacks are one of the oldest forms of cybercrime on the Internet. So it's vital to understand how these attacks work and how to prevent them. In this Quick Hit, we're discussing four of the most common forms of phishing!
Quick Hits
6 minPreviewCybersecurity Best Practices: Financial Institutions
Walk through cyber threats unique to the world of Finance. This course will inform and protect your teams from threats like phishing attacks and data loss.
Industry Best Practices
5 minCybersecurity Best Practices: Healthcare
In this Best Practices course, we'll walk you through cyber threats unique to the world of Healthcare facilities. This course will inform and protect your teams from threats like phishing attacks, data loss, and more.
Industry Best Practices
5 minPreviewCybersecurity Best Practices: Higher Education
Walk through cyber threats unique to the world of Higher Ed. This course will inform and protect your teams from threats like wire fraud and phishing attacks.
Industry Best Practices
5 minCybersecurity Best Practices: Law Firms
Walk through cyber threats unique to the world of Law Firms. This course will inform and protect your teams from threats like wire fraud and phishing attacks.
Industry Best Practices
5 minCybersecurity Best Practices: Real Estate
Walk through cyber threats unique to the world of Real Estate. This course will inform and protect your real estate teams from threats like wire fraud and phishing attacks.
Industry Best Practices
5 minCybersecurity Best Practices: Small Businesses
Walk through cyber threats unique to Small businesses. This course will inform and protect your teams from threats like phishing and ransomware.
Industry Best Practices
VariesPreview#Trending Attacks
A new set of bite-sized courses covering today's hottest threats. From AI-powered scams, to deepfakes, to sneaky QR code traps, these lessons break down how the latest attacks actually work, why they're dangerous, and how to spot them.
Signature & Standalone
5 minPreviewCorporate Chaos
Corporate Chaos is a 6-course series of cybersecurity sketches. From SMShing to Social Engineering, Passwords and MFA, the comedic stories shine a light on common cyber habits.
Signature & Standalone
30 minPreviewDeepfake Awareness Course
Learn about what Deepfakes are and how they are created, the various ways Deepfakes can be delivered, how to recognize Deepfake-based threats, and the crucial role you play in defending against them.
Signature & Standalone
25 minPreviewGone Phishing
This course, called "Gone Phishing", follows two people on a fishing excursion. Along the way, they learn how to identify several phishing red flags, and catch a few "fish" of their own.
Signature & Standalone
VariesPreviewPartition: An AI Course
Welcome to the future of workplace training, where psychology meets machine learning. Partition isn't your typical awareness course. Set inside a surreal, eerily calm office inspired by retro-futurist aesthetics, this immersive experience walks you through the five emotional stages of adapting to AI in your work life.
Signature & Standalone
5 minPreviewPhishing for Answers
Follow along as we answer common questions regarding cybersecurity and dive deep into specific terms. Plus - learn how to spot and avoid these common attacks. Available courses: Updating Devices, Too good to be true offers, Spyware, MFA, Passphrases, Evil Twin Attacks, Email Attachments
Signature & Standalone
15Security Awareness Training Express
Cyber threats don’t slow down, and neither should your awareness. This quick refresher from Hook Security brings together the “greatest hits” of security awareness in one fast, engaging course.
Signature & Standalone
12 minPreviewSMShing
When it comes to cyber attacks, we all know a good ole Phishing email when we see it. But Cyber Criminals are adaptive and creative. Our SMShing course teaches your employees how to spot and avoid these text message attacks.
Signature & Standalone
VariesPreviewWelcome to Hook Security - Introduction to Phishing
In this course, learners will be introduced to Hook Security, learn what to expect with cybersecurity training, and understand what Phishing is and why phishing awareness is important. It's a great option for new hire training.
Signature & Standalone
5 minPreviewTech Stack Tips (Series)
Tech Stack Tips, comprised of 24 individual courses, is crafted to boost productivity and fortify security within an organization's tech ecosystem. Courses include Microsoft Outlook, 1Password, Box, ChatGPT, Google Drive, Salesforce, Dropbox, Slack, Jira, and more.
Tech Stack Tips
Eight series, eight different jobs
Not a pile of videos. Eight series with different jobs, lengths and cadences — so you can build a year instead of picking at random.
| Series | Courses | Length | Cadence | What it's for |
|---|---|---|---|---|
| Annual Training | 5 | 22–46 min | Once a year | Wilderness Jack, Steven, The Too Late Show and PsySec Essentials each cover every core topic in one sitting, in a different comic register. Pick the one your culture will actually watch. |
| Compliance Track | 6 | 16–30 min | Annual / on hire | HIPAA, PCI DSS and GDPR taught as their own subject. HIPAA splits three ways by role: clinical care, admin staff, IT and leadership. |
| PsySec Deep Dive | 12 | 8–10 min | Monthly | One topic, unpacked properly — video, graphics, tips and a quiz. Built to roll out one a month after the annual course. |
| Mike Fry The Cyber Guy | 10 | 8 min | Monthly | The same topics, different host, different jokes. An alternative monthly track for teams who have already seen the Deep Dives. |
| Quick Hits | 12 | 2–3 min | Monthly / ad hoc | Sixty-to-ninety-second refreshers plus a quiz. For a nudge after an incident, or a team that cannot spare ten minutes. |
| Industry Best Practices | 6 | 5–6 min | On hire / annual | Healthcare, financial institutions, law firms, real estate, higher education and small business — wire fraud, student data, client confidentiality. |
| Tech Stack Tips | 26 | ≈5 min | Ad hoc | Security inside the tools people already use — Outlook, 1Password, Slack, Box, ChatGPT, Google Drive, Salesforce, Dropbox, Jira. |
| Signature & Standalone | 10 | 5–30 min | Ad hoc | The one-offs worth their own slot: Gone Phishing, SMShing, the Deepfake course with Breacher.ai, Partition, Corporate Chaos, #Trending Attacks and new-hire onboarding. |
What it takes, what it proves
How many minutes this takes from every person on your payroll. Two shapes, built from the run times above. Both tick the compliance box — only one changes what people do.
Compliance minimum
≈71 minutes per employee, per year
One annual course, then a two-minute Quick Hit every month. Enough to evidence continuous training without asking real time from anyone.
Behaviour change
≈2 hrs 29 min per employee, per year
The same annual course, then a full PsySec Deep Dive every month. Nine minutes a month — less than one meeting.
Derived from the run times listed above, not from observed completion data.
Hook Security’s training satisfies the awareness requirement in a long list of standards. Three get their own dedicated track, because the subject matter goes past general awareness. Completion is reported per person and per group — the record auditors ask for.
Dedicated tracks
- HIPAA — A 30-minute core course plus three 16-minute role courses: clinical care providers, administrative staff, IT and leadership.
- PCI DSS — 30 minutes, 12 modules, employee obligations for payment card data.
- GDPR — 30 minutes, 12 modules, lawful processing, individual rights and breach protocol.
Met by general training
- ISO/IEC 27001 and 27002
- NIST 800-171 and NIST 800-53
- CMMC (Maturity Level 3 target)
- COBIT · NERC CIP · FISMA
- State and federal regulations requiring documented annual training
Selected courses ship with subtitles and voiceover. Here is exactly which — and how to get one that is not listed.
| Course | Format | Languages |
|---|---|---|
| PsySec Essentials International | Subtitles + voiceover | German · Spanish · French · French Canadian · Portuguese · Turkish |
| Deepfake Awareness Course | Subtitles | Czech · German · Spanish · Italian · Portuguese · Turkish · Chinese · Hindi |
| Annual Training with Wilderness Jack (part one) | Subtitles | Spanish |
Need a different course or language? Hook Security produces translated versions on request — hello@hooksecurity.co.
Courses are the scheduled half. The other half fires the second someone clicks a phishing simulation — worth more than any calendar invite, and it never involves telling anyone they got caught.
The Click Report
A short video, triggered by the click, breaking down the single red flag they missed — brand impersonation, a too-good-to-be-true offer, an urgent request, a scare tactic. Each video maps to a red flag, so it pairs with any of the thousands of phishing templates in the platform.
The Click Report Premium
The same moment, taken further: a guided walk through the entire email rather than one flag — spoofed brand, unusual sender address, urgent language, suspicious links. Employees learn how a phishing email is built, not just what they missed today.
Everything else, answered
What's in it
How many courses are in the library?
Every course is listed above — this page is the full library, not a sample.
Counted as modules, the unit most vendors quote, it runs past 300: PsySec Essentials alone is 14, and Tech Stack Tips covers 26 sessions. Hook Security counts courses here because a course is what you assign to a person.
How often are new courses added?
Monthly. Courses are produced in-house by Hook Security’s own studio rather than licensed in, which is why the cadence is steady and the tone is consistent across series.
The #Trending Attacks series exists for exactly this — short courses on what people are falling for right now: AI-generated voices, QR code traps, MFA approval tricks. Not examples from three years ago.
Can I watch a course before buying?
Yes. Tick “Has a preview” in the filters above and press play on any card — the preview opens right here, no form and no booking.
Full episodes are also free on Hook Studios and YouTube.
Can I download the full catalog?
Yes — the Hook+ Course Catalog (Spring 2026) is 43 pages covering every series, module counts, and the compliance and language detail. No email required; the link is at the top of this page.
Will it fit my organisation
Do you have training for my industry?
Six industries have their own course: healthcare, financial institutions, law firms, real estate, higher education and small businesses. Each is 5–6 minutes on the threats that industry actually meets — wire fraud in real estate and law, student data in higher ed, payment data in finance.
If yours is not one of the six, the general library still covers you. The industry course is an addition, not a replacement.
Is there role-specific training?
Yes, most developed on the HIPAA track, where the same regulation lands differently by job: clinical care providers, administrative staff, and IT and leadership each get their own 16-minute course. Remote workers get Working Remotely and Cybersecurity at Home.
Do you have new-hire training?
Welcome to Hook Security introduces new starters to what security training is and why phishing matters. Security Awareness Training Express is 15 minutes of the greatest hits, for people who joined mid-cycle and missed the annual course.
Are subtitles and captions available?
Subtitles ship with the multilingual courses listed under Languages above. For the rest of the library and for accessibility conformance, ask in the demo — we would rather give you the precise answer for your requirement than a general claim.
Who is Hook Security not for?
Worth saying plainly. Hook Security is built for SMBs and the channel — MSPs, MSSPs, VARs and agents. It is a poor fit if you need deep SIEM or SOC-tooling integration inside the training platform, if you only want a compliance checkbox and genuinely do not care whether anyone watches, or if you want a library you can rewrite yourself. The content is produced in-house and delivered as-is; that consistency is the point, but it is not flexibility.
Compliance and evidence
What evidence do I get for an audit?
Completion reporting per person and per group — who was assigned what, who finished, and when. That record is the practical difference between having a training programme and being able to prove you have one.
Will this satisfy my cyber insurance requirement?
Usually. Most carriers ask for documented annual security awareness training plus phishing simulation, and Hook Security produces exactly that evidence. Bring your carrier’s wording to the demo and we will match it line by line.
Is one annual course enough?
Enough for compliance. Not enough for behaviour.
An annual course is a single exposure, and people forget most of a one-off session within weeks. That is why the library is built around 2–10 minute monthly courses: reinforcement, not duration, is what moves the needle.
How it is delivered
How do employees receive the training?
Through Hook Security’s own LMS. People are enrolled, get an email with their assignment, and work through the course in the browser. Nothing to install, no portal to remember.
Can I use my own LMS?
Yes — the courses are SCORM compatible, so you can run them inside an LMS you already have and keep training in one place.
Are there quizzes?
Yes. Every Deep Dive, Mike Fry, Quick Hit and industry course ends with a quiz, and annual courses carry questions through their modules — not to catch anyone out, but because being asked is what makes a lesson stick. Pass thresholds and retakes are configurable.
Can I assign different courses to different teams?
Yes — that is the normal way to run it. Clinical staff get the HIPAA clinical course, admins get the admin one, finance gets the financial institutions course, everyone gets the annual. Groups are how assignment works, not an add-on.
Do I have to build the programme myself?
No. Autopilot is Hook Security running the whole thing — scheduling, enrolments, reminders, phishing simulations and reporting — so the programme happens whether or not anyone on your side has time that month.
What happens when someone clicks a phishing simulation?
They land on a page that tells them what just happened and plays a short Click Report video breaking down the red flag they missed. Premium versions walk through the entire email — spoofed brand, sender address, urgent language, suspicious links.
It is immediate, specific, and not punitive. A click is a learning moment, and training that arrives four seconds after the mistake is worth more than training scheduled for March.
Can MSPs resell or white-label this?
Yes — the channel is how most of this library reaches end users. Hook Security works with hundreds of MSP partners and supports multi-tenant management, so one console covers every client. See Hook Security for MSPs.
Proof, price, next steps
Will people actually finish it?
That is the whole product. Hook Security’s courses are written and filmed in-house as comedy — recurring characters, story arcs, real actors — because people finish what they enjoy and abandon what they do not. No stock animation, no AI narration, no anime avatar explaining ransomware.
For completion numbers against your industry and company size, ask in the demo. We will show you the real reporting rather than a statistic on a web page.
What does Hook Security report back?
Completion and engagement per person and per group, phishing simulation results including click and report rates, and change over time. Report rate matters more than click rate — a workforce that reports quickly contains an incident; a workforce that never clicks in a simulation may simply have stopped reading email.
What does it cost?
$2 per seat per month, $20 per seat per year billed annually, or a flat $999 per year under 50 seats. Those are MSRP.
Buying through an MSP or reseller? They set their own pricing for their clients, so the number your provider quotes is theirs, not this one. Full pricing detail.
Can I license the content for my own platform?
Yes, as a bespoke arrangement — terms depend on volume, territory and whether you are re-hosting or embedding. Worth a conversation rather than a price list.
See the whole library.
A demo is every annual course, every compliance track, and Autopilot running the programme for you. Thirty minutes, the real platform, no slides.