727 security lessons from stories people already know. The Simpsons, Shakespeare, the King James Bible, Star Wars, Breaking Bad, real heists, Greek myth, and a hundred years of actual incidents.
Every one mapped to NIST CSF 2.0 and ISO/IEC 27001:2022 Annex A.
Free. No signup. Use them in your training, your slides, your client work, whatever you want.
The phishing talk stops working the fourth time somebody hears it.
Security Is a Team Sport, and the whole job is persuasion. You are trying to get a warehouse manager, a paralegal, and a CFO to care about something that has never happened to them. Framework language does not do that. A story they already know does.
Say "insider threat with privileged access and a personal motive" and eyes glaze over. Say "it was never a ghost, it was always the caretaker" and the room is with you.
That is the whole idea.
Sorting 727 stories by NIST function turned up something I did not expect.
Recover has 45 lessons. Protect has 309.
Stories are about the attack and the chase. The heist, the betrayal, the reveal. Almost nobody writes about the restore, because the restore is boring.
Neither do most security programs. Same reason.
That gap is not a coincidence and it is worth sitting with.
| Collection | Lessons | What it is |
|---|---|---|
| The Simpsons | 114 | All seasons. Springfield is what happens when nobody owns risk. |
| 100 Years of Incidents 🔎 | 75 | Real events, last century. The ones we should have learned from. |
| Movies 2000-2026 | 57 | Modern film. Heists, hacks, insiders. |
| Movies (Classic) | 50 | WarGames through the early 2000s. |
| The Bible (KJV) | 47 | Social engineering and insider betrayal, before the common era. |
| Top 100 Films | 43 | The all-time list, read as security case studies. |
| The Office | 38 | Nine unbroken seasons of governance failure. |
| Marvel | 38 | Supply chain, insider threat, one entity holding every key. |
| 2000 Years of Incidents 🔎 | 36 | Trojan Horse to now. Same attacks, different centuries. |
| Breaking Bad + Better Call Saul | 30 | Cover identities, hidden infrastructure, documentation that convicts you. |
| Brooklyn Nine-Nine | 26 | The Halloween Heist is the best red team exercise on television. |
| Star Wars | 20 | An unpatched exhaust port took down a battle station. We have all shipped that. |
| Fairy Tales | 18 | Grimm was writing threat models. |
| Mythology | 17 | Mostly stories about ignoring the risk assessment. |
| Drone Show Ops 🔎 | 15 | A thousand networked flying computers. What could go wrong. |
| Sports Cheating Scandals 🔎 | 14 | Signal stealing, doping, deflated footballs. |
| Video Games | 14 | Some of the best-documented incident response in history happened in an MMO. |
| Real World Heists 🔎 | 14 | Physical security and monitoring nobody watched. |
| SpongeBob SquarePants | 14 | The Krusty Krab formula is Bikini Bottom's most valuable IP and it is protected badly. |
| Shakespeare | 13 | Four hundred years old and still the best writing on insider threat. |
| Christmas Specials | 12 | A Christmas Carol is a three-phase audit. Santa runs continuous monitoring. |
| Looney Tunes | 12 | Wile E. Coyote is a threat actor with a budget problem and no lessons-learned process. |
| Scooby-Doo | 10 | It was never a ghost. It was always an insider with a motive and physical access. |
🔎 = real events. Verify figures before formal use. Everything else is fiction and works as a training analogy, not a case study.
By NIST CSF Function for when you are building a deck around Govern, or Detect, or Respond.
By ISO 27001 Control covers 75 Annex A controls with at least one story attached. You need an example for A.5.7 threat intelligence and you need it in ten minutes.
By Category has 511 categories. Social engineering and insider threat top the list, which tracks. Both are people problems, and people problems are what stories are made of.
Framework Key explains the codes and the fiction/real split.
Or skip all of it and grab data/all-lessons.csv. Everything in one file, tagged fiction or real. Filter it however you like.
In awareness training. Open with the story, land the control. People remember Ephialtes showing the Persians the goat path a lot longer than they remember "insider risk from privileged local knowledge."
In a board deck. One slide. One story they already know. Then the number.
In a tabletop. Half of these are ready-made scenario seeds. See tabletop-library.
In a policy rollout. Nobody reads the acceptable use policy. Everybody watches the two-minute talk that opens with the Trojan Horse. If you need the policies themselves, Security-Program-Starter is the sibling repo, written to the same rules.
With your kids. I mean it. Security Starts at Home, and the fairy tales, Scooby-Doo, and Christmas collections work on a nine year old. A stranger with a convincing story at the door is a threat model they can hold onto.
A story is not a control test. Do not cite a Simpsons episode in an audit response.
The mapping is a lookup, not an authority. It exists so you can find the right example fast.
If one looks wrong to you, it might be. No One Is as Dumb as All of Us. Open an issue.
collections/ 23 markdown files, one per collection
indexes/ by NIST function, by ISO control, by category
data/ CSV per collection, plus all-lessons.csv
xlsx/ the workbooks. The master library holds a cover sheet plus every collection.
FRAMEWORK-KEY.md
This is the repo I most want help with. There are thousands more stories out there and I have seen a fraction of them.
Want: new collections, missed episodes, better mappings, corrections. Anything where you read a lesson and thought "that is not what that story is about."
Format: match the columns in an existing collection. Source, lesson, category, NIST function, ISO controls. CSV or a markdown table both work. Do not worry about matching the tone, I will edit.
Do not: submit anything that needs the plot explained before the lesson lands. If you have to summarize the story first, it is the wrong story.
See CONTRIBUTING.md.
CC BY 4.0. Use them in paid training, client work, a book, a conference talk. Just say where you got them.
The underlying works belong to their owners. These are short descriptive references for education and commentary.
© 2026 Harrison Ward
Cyber risk and technology exec. 30 years across financial services, professional services, and critical infrastructure. Former CTO, most recently SVP in Kroll's Cyber Risk practice.
I talk in analogies because framework language does not move anybody. This is 727 of them.
github.com/HarrisonWard · LinkedIn
Published under these principles. Security Shouldn't Be Paywalled.