The Lab

Spot drift in the wild

Read a real situation. Identify two stages of the Drift Model where the gap opened up. Get structured feedback on your reasoning. Theory only sticks when you apply it.

Where you are

You haven't attempted any scenarios yet. Pick one to begin — the Easy tier is a good starting point.

Hard tier

Domain

Difficulty

Type

Showing 12 scenarios
Finance · Easy

The Quarterly Access Review

An Australian fintech's quarterly privileged-access review looks complete on paper. The reality is different.

Start scenario →
Healthcare · Easy
Real-world

Medibank — The MFA That Wasn't

Australia's largest health insurer had MFA on paper. Two prior audits flagged the gap. Then the breach happened.

Start scenario →
Education · Easy
Real-world

Deakin University — The SMS Vendor

A staff member's credentials gave an attacker access to a third-party SMS provider holding details on 47,000 students.

Start scenario →
Industrial · Easy
Real-world

DP World Australia — Ports Offline

Four major Australian ports went offline for three days. The vulnerability had been publicly known and patchable for over a year.

Start scenario →
Finance · Moderate
Real-world

HWL Ebsworth — The Law Firm Holding Everything

A law firm holding data for the Big Four banks, RBA and most of the ASX 50 was breached. The exposure had been quietly accumulating for years.

Start scenario →
Healthcare · Moderate
Real-world

Australian Clinical Labs — Acquired Without Inspection

ACL inherited a pathology business with weak security controls and treated the existing arrangements as adequate. Eight months later, the OAIC took action.

Start scenario →
Education · Moderate
Real-world

Western Sydney University — Three Breaches in a Year

WSU disclosed three separate breaches across 2023-2024. Each one revealed weaknesses that had been live during the previous one.

Start scenario →
Industrial · Moderate

Riverstone Water — The Engineer's Convenience VPN

A regional water utility's after-hours remote access setup quietly grew into a parallel network nobody documented or audited.

Start scenario →
Finance · Hard
LockedComing soon

Coming soon

A finance-sector hard scenario is being prepared.

Score 7+ on 2 Easy or Moderate scenarios to unlockIn development
Healthcare · Hard
LockedComing soon

Coming soon

A healthcare-sector hard scenario is being prepared.

Score 7+ on 2 Easy or Moderate scenarios to unlockIn development
Education · Hard
LockedComing soon

Coming soon

An education-sector hard scenario is being prepared.

Score 7+ on 2 Easy or Moderate scenarios to unlockIn development
Industrial · Hard
LockedComing soon

Coming soon

An industrial-sector hard scenario is being prepared.

Score 7+ on 2 Easy or Moderate scenarios to unlockIn development

Need a refresher on the model first? Read the Drift Model.