Passive training alone rarely changes behaviour. These exercises require participants to inspect evidence, make a decision and observe the consequences in a controlled environment.
The scenarios are short examples of the organisation-wide programmes OffSeq delivers, including phishing and social-engineering simulations and adversarial testing of AI systems.
Select a scenario
01–11Open a scenario to start the full 3D simulation.
- 01
Identify a phishing email
Inspect a suspicious email, including the sender, links and urgency cues, and decide whether to report it or proceed.
Red team · Phishing - 02
Identify a fraudulent support call
A caller claims to be IT support and requests access or verification information. Assess the request and verify the caller before taking action.
Social engineering · Voice - 03
Detect indirect prompt injection
An AI assistant is about to process a document containing hidden instructions. Identify the injection before the system performs an unsafe action or discloses data.
AI red-teaming · LLM - 04
Verify a suspected deepfake request
A video call appearing to come from an executive requests an urgent transfer. Verify the request through an independent channel before authorising payment.
Social engineering · Synthetic media - 05
Identify invoice-redirection fraud
A message appearing to come from a known supplier requests new bank details for a genuine invoice. Verify the change before making the payment.
Fraud · BEC - 06
Test an AI assistant for information disclosure
Assess whether a customer-facing chatbot can be induced to disclose its system prompt, embedded secrets or other restricted information.
AI red-teaming · LLM - 07
Recognise social-engineering techniques
A stranger requests a small exception or favour. Identify the pretext, authority and urgency cues before bypassing an established process.
Social engineering · Human factors - 08
Assess an unapproved cloud application
A colleague begins using an unapproved cloud application. Trace the data exposure and decide how the tool should be reviewed before company information is uploaded.
Attack surface · Shadow IT - 09
Assess what a social-media post reveals
Review an apparently harmless post and see how public details can be combined into a target profile for a tailored attack.
OSINT · Oversharing - 10
Identify credential-stuffing risk
A password exposed in an unrelated breach is being tried against your organisation’s accounts. Examine how password reuse enables credential-stuffing attacks and how to respond.
Credentials · Account security - 11
Manage the first hour of an incident
Investigate initial signs of a network incident and choose the correct sequence for detection, containment, escalation and reporting.
Incident response
Ready to demonstrate your practical skills?
OffSeq Training provides structured learning paths, scored practical assessments and certificates based on demonstrated skills.
Apply the training across your organisation.
OffSeq delivers role-based phishing, voice-phishing and social-engineering simulations, as well as adversarial testing of AI systems. Programmes include measurable outcomes, targeted follow-up training and documented results.
- Phishing and SMS-phishing simulations with campaign measurement and targeted follow-up training
- Voice-phishing and social-engineering exercises for operational teams and service desks
- Adversarial testing of AI and LLM systems, including prompt injection, data disclosure and agent abuse