Zamlom

Gamified Cybersecurity Training Platform

Visit Website
August 16, 2026 Would your team survive the first 20 minutes of a breach?

Most security training is compliance theater. It tests whether you can memorize a definition, not whether you can make the right call when three alerts fire at once and someone's asking who has authority to pull the plug.

Real retention doesn't come from a 4-hour annual video. It comes from daily, low-friction practice — the same reason spaced repetition works for language learning. Security concepts decay the moment you stop touching them, and a plan nobody's ever practiced tends to fall apart exactly when it matters most.

We built Zamlom around two daily reflexes:

  1. 5-minute spaced practice across architecture, cloud, SOC, and GRC tracks — the engine tracks what you've already covered and resurfaces it right before you'd forget it.

  2. Live multiplayer tabletops that simulate a real breach in real time, with a facilitator role, live injects, and a board-ready After-Action Report at the end — without the five-figure consulting retainer.

It's free to start. Pick a track or run a tabletop pilot at zamlom.com.

1 Comment

  1. 1

    The contrast between annual training and repeated practice is clear. Curious which part of the experience teams actually engage with most once they start.

August 9, 2026 Zamlom started as a single HTML file to see if I even knew the concepts on the CISSP — it grew into a full platform almost by accident

I didn't set out to build a product. Someone I know took the CISSP, and I got curious whether I could pass it too. I hadn't even gotten as far as buying the study book yet — I just threw together a simple HTML file with some definitions and quiz questions to test myself and see how much I already knew. Then I started having fun adding to it — a streak counter here, XP there — and over the course of a few weeks it organically turned into something way bigger than a self-test. Tabletop exercises, an AAR generator, multiplayer, an admin backend — none of it was the plan on day one, it just kept growing because I kept enjoying building it. I've built the whole thing solo.

Where I'm at right now: I'm deliberately not focused on monetizing it. There's a team/enterprise angle I think could be worth something down the line, but right now the priority is making the platform itself genuinely good — something people actually get value out of — before I worry about charging for any of it.

The personal reason I keep coming back to it: I've got two young kids and a schedule that doesn't have room for sitting down and studying for hours at a stretch. This platform has basically replaced the time I'd otherwise spend mindlessly scrolling Reels — a few minutes here and there, actually learning something and staying sharp in my field instead.

Still very much a work in progress and solo-built, so I'd genuinely appreciate any feedback, especially on whether the tabletop scenarios feel realistic to anyone who's been through the real thing. zamlom.com if you want to poke around.

3 Comments

  1. 1

    The interesting part is how the original constraint seems to have shaped the product more than any initial roadmap did. A few minutes here and there is a very different learning workflow from sitting down for a dedicated study session. Curious which feature ended up becoming genuinely useful that you never expected to build.

    1. 1

      To be honest, I never expected to build an app at all, but the tabletops are probably the one thing I never originally intended to include. Security training tends to be one of the first things deprioritized when budgets get tight — it's a pretty common pattern across the industry, and it leaves a lot of teams without a practical way to stay sharp.

      Zamlom gives teams a way to read up on concepts they may not get regular hands-on experience with, or that they're just too busy to dedicate hours a day to in a structured course like the CISSP. The engine tracks what you've already covered and uses spaced repetition to bring it back after a while, so it stays fresh and you keep building on it.

      Also — if you're in architecture and engineering — how often do you actually have time to run tabletops with your team and stay prepared for a real incident? How often do you branch into GRC or SOC concepts? It's an easy way to widen your skillset a few minutes at a time.

      At least that's how I see it right now. If I can get more people on it, the feedback might point somewhere completely different — which is why I'm putting it out here.

      1. 1

        I'd be interested in hearing more about what you're seeing as you get more users on it. What's the best email to reach you on?

About

Security teams skip tabletops due to cost and time, and busy lives make continuous learning hard. Zamlom is micro-learning - a few minutes at a time - that you apply to virtual tabletops whenever it fits your schedule.