The Lab
Spot drift in the wild
Read a real situation. Identify two stages of the Drift Model where the gap opened up. Get structured feedback on your reasoning. Theory only sticks when you apply it.
Where you are
You haven't attempted any scenarios yet. Pick one to begin — the Easy tier is a good starting point.
Domain
Difficulty
Type
The Quarterly Access Review
An Australian fintech's quarterly privileged-access review looks complete on paper. The reality is different.
Medibank — The MFA That Wasn't
Australia's largest health insurer had MFA on paper. Two prior audits flagged the gap. Then the breach happened.
Deakin University — The SMS Vendor
A staff member's credentials gave an attacker access to a third-party SMS provider holding details on 47,000 students.
DP World Australia — Ports Offline
Four major Australian ports went offline for three days. The vulnerability had been publicly known and patchable for over a year.
HWL Ebsworth — The Law Firm Holding Everything
A law firm holding data for the Big Four banks, RBA and most of the ASX 50 was breached. The exposure had been quietly accumulating for years.
Australian Clinical Labs — Acquired Without Inspection
ACL inherited a pathology business with weak security controls and treated the existing arrangements as adequate. Eight months later, the OAIC took action.
Western Sydney University — Three Breaches in a Year
WSU disclosed three separate breaches across 2023-2024. Each one revealed weaknesses that had been live during the previous one.
Riverstone Water — The Engineer's Convenience VPN
A regional water utility's after-hours remote access setup quietly grew into a parallel network nobody documented or audited.
Coming soon
A finance-sector hard scenario is being prepared.
Coming soon
A healthcare-sector hard scenario is being prepared.
Coming soon
An education-sector hard scenario is being prepared.
Coming soon
An industrial-sector hard scenario is being prepared.
Need a refresher on the model first? Read the Drift Model.