Building a Security Awareness App
with OSINT Challenges
Security awareness training is usually a boring annual video that everyone clicks through without reading. I wanted something different: a short, interactive quiz with real OSINT spotting challenges that also produces clean audit evidence. This is how I built Aegis.
The Problem with Awareness Training
Most security awareness training fails for the same reason: it is passive. People watch a slideshow, click next until it ends, and retain almost nothing. Meanwhile ISO 27001 control A.6.3 requires evidence that staff actually receive and engage with security awareness training. The typical solution satisfies the auditor on paper while doing very little to change behavior.
I wanted to solve both sides at once: make the training genuinely engaging, and produce clean, automatic evidence of completion that maps directly to the compliance requirement.
What Aegis Does
Aegis is a lightweight web app that runs a training round of ten questions. Each round mixes two visual OSINT scenes with eight practical multiple-choice questions, drawn at random with no repeats and with the answer order shuffled every time. The pass mark is 80%.
The Compliance Angle
This is where the app earns its place beyond being a fun quiz. When a user passes, the result is written automatically to a Google Sheet that serves as ISO 27001 evidence for the awareness training control. Each row records who took it, when, the score, the result, and which topics they should review.
Crucially, only passing results at or above the 80% threshold are written, and that rule is enforced in two places: in the app's own backend and again in the script that writes to the sheet. Defense in depth, even for something this small. The result is a living, timestamped training register that an auditor can review at any time, generated with zero manual effort.
The Stack
The whole thing is deliberately lightweight. The frontend is React built with Vite, styled with a small design-token object rather than a heavy CSS framework. No local storage, no client-side database, no unnecessary dependencies.
Architecture Decisions Worth Noting
A few choices shaped the design. Keeping the pass-mark check on the server side, not just in the browser, means the threshold cannot be bypassed by editing client code. Having the Google Apps Script run under the owner account means the hosting platform holds no Google credentials at all, which keeps the security surface small. And separating the question bank into its own file means content can grow over time without touching the app logic.
What's Next
The roadmap is about depth and realism. The visual scene engine already supports images with clickable hotspot regions, so the next step is replacing illustrative scenes with real phishing screenshots and realistic workspace photos, making the OSINT challenges sharper. Beyond that: growing the question bank further so frequent takers never run out of new material, and adding simple reporting so pass rates across the team can be seen at a glance.
The broader lesson from building Aegis is that compliance and engagement are not opposites. A training tool people actually enjoy using produces better security behavior and better audit evidence at the same time. You just have to build it so that the useful record falls out of the process naturally.