Read the full story
Where this piece came from. It started at my kitchen table. My wife showed me an email, supposedly from her school principal. Subject line: "Dringende Aufgabe." Urgent task, stuck in meetings, cannot call, please just reply here. Her reaction: "Das kommt mir irgendwie komisch vor." Something felt off, and she could not say why. Neither could I at first, even though I have built data security courses before. It was a spoofing attempt, and it took both of us too long to be sure. That gap between feeling and knowing is what this module closes.
Who it is for. Employees who clicked a link in an internal CEO-spoofing simulation. They fell for it because nobody ever taught them what to look for. The module gives them one clear outcome: spot the warning signs in a suspicious email and take the right action.
Why training is the right fix here. Before building anything, I ran the topic through a question Mager and Pipe asked back in the 1970s: could they do it if their life depended on it? If the answer is yes, training will not solve the problem. For spotting spoofed emails, the answer is no. That is a genuine skill gap, and a course is the right intervention.
Constraints. Solo build in a realistic timebox, next to client work. The piece also had to work as a public portfolio item, so I chose a fictional scenario around a real brand and labeled it clearly as spec work. All numbers, including the 38%, belong to that fictional simulation.
The decisions I care about most.
The interaction shows a realistic email containing four warning signs and four plausible, harmless elements. Clicking a harmless element triggers its own feedback explaining why it looks suspicious and why it is fine. Real judgment means telling signal from noise, so the module trains exactly that discrimination instead of rewarding random clicking.
I picked the core interaction by learning purpose. The skill is recognizing patterns in context, so the centerpiece is a click-to-find on a full email with a counter, per-element feedback, and completion logic. A matching activity would have tested recall, and recall was never the gap.
The module is built to GitHub's public brand guidelines. I translated the brand material into Storyline: set up the fonts, created a font theme and a color theme, branded the player, and applied all of it across the layouts, from prebuilt slides to slides I built from scratch. I wanted this piece to show that I can pick up a client's brand guidelines and deliver a course that looks like it belongs to them.
Where AI fit into the workflow. The narration is an AI voiceover from ElevenLabs. I tested Storyline's built-in AI voices first and preferred the ElevenLabs result. The feedback sound effects came from Storyline's AI Assistant, and the theme setup was supported by my own Storyline Theme Genie GPT. For a solo build with limited resources, AI voiceover was the right call, and it can always be swapped for a professional speaker before a client rollout. To me this is the actual skill: knowing where AI fits into the production workflow and where it does not.
What I would improve. The phishing email itself is an AI-generated image. It looks convincing and it was fast to produce. It is also invisible to screen readers, and the text does not scale. Next time I would rebuild the email natively in Storyline with text elements and shapes. Slower to build, better for every learner.
A full video walkthrough of the build is in production on my YouTube channel.