Security awareness training your team will actually finish
Most awareness training is an hour-long video people click through with the sound off. IT Lunchroom is 37 short, plain-English lessons and 12 hands-on simulations covering the decisions that actually cost businesses money: fake invoices, phishing, account takeover, and oversharing files.
Free to use, with no seat count and no login required. Send your team a link and they can start in seconds.
Or email us directly at hello@itlunchroom.com. We answer every message ourselves.
Why this works when the annual video doesn't
People don't fail security training because they don't care. They fail because the training was about policy, and the moment they actually face is a decision: this email says the supplier's bank details changed, and the invoice is due today. Every one of our lessons is built around one of those moments, and every security lesson has a simulation where you make the call before it is real, with nothing to install and no account to create.
Each learner can create a free account if they want their own progress saved across devices. When someone finishes a track they get a shareable certificate with their name and the date, which they can forward to you as proof they completed it.
Straight answers about what this is
Is it really free?
Yes. The lessons and the simulations are free to use, with no seat licences and no login needed to start. If we add paid features for organizations later, the free lessons stay free.
Do you have an admin dashboard where I assign lessons and track completion?
Not today, and we would rather tell you that plainly than imply otherwise. Right now the honest workflow is: send your team the link, and ask them to forward you the certificate they earn at the end of a track. If a proper team workspace is what you need, tell us — it is the thing most likely to get built next, and hearing from real teams is what decides it.
Does this satisfy our compliance requirement?
That depends on your framework and your auditor, and we will not pretend otherwise. Several standards require periodic security awareness training that covers phishing and social engineering, including PCI DSS requirement 12.6.3.1 and the HIPAA Security Rule's awareness provisions. Our 4 tracks cover that material and produce a dated, per-person certificate. Whether your auditor accepts it is a conversation worth having with them, and we are happy to help you answer their questions.
Try it the way your team would
Don't take our word for it. Open a simulation and click through it yourself — it takes about two minutes and needs nothing from you.