The Multiverse School
The Defender · 4 of 10 scheduled
Join the waitlist

🛡️ The Defender · stay-secure

Defend your devices, your identity, your comms and your people.

Ten classes, ordered outward from your own house. Four of them are on the calendar at $60 each. Six are written and have no date yet. You are reading which is which on the first screen, because a security course that overstates itself has already failed the subject it teaches.

4 scheduled 6 written, no date

Centre is your own house. The rim is your organisation. The four you can book are the four nearest you.

10classes on the path
18capabilities they teach
4you can book today, $60 each
1.0hours of recorded video, in total

Threat-model router

Security advice is worthless until it knows who you are hiding from.

Four questions. It ranks these ten classes against your answers, tells you why each one placed where it did, marks whether you can actually book it, and shows the whole arithmetic underneath. No score, no grade — a short-list you can argue with.

01 Who are you actually worried about?

02 What would hurt most to lose?

03 Who are you responsible for?

04 Do you build or sign off on software that acts on its own?

Answer any question and the list updates. Nothing is sent anywhere.

Pick an answer above and your short-list appears here, ordered, with a reason per class. If you have JavaScript off, the full sequence below lists all ten classes, what each one defends against and whether it is scheduled — the router only reorders what is already on this page.

Inventory, measured

What you get, and what does not exist yet.

Live sessions

Four classes with dates

Home Network Defense, Consumer Device Rescue and Defense, Scam and Fraud Home Defense, Digital Identity Defense. Two hours each, live, $60 each. Between them they teach 6 distinct capabilities out of this path's 18 — the personal-defence end of the ladder.

Recordings

1.0 hour, on one class

The Dark Arts (Red Team) has 1 recorded clip. That is the entire video inventory for this path. If you came for an archive to work through on your own schedule, this is not that; the live sessions and the written exercises are the product here.

Written, not scheduled

6 classes, 48 exercises

Field Opsec and Blue Team Common Certification alone hold 20 and 24 written exercises. All 48 exercises on this path sit in classes you cannot book yet. That is the honest shape of it: the curriculum ran ahead of the calendar.

The recurring hour

Secure Hour, being scheduled

The hour that carries this philosophy exists in the plan, led by liz, with no cadence set. When it lands it is the standing session this path hangs off. It is not running this week, so it is not something you are buying today.

Reference material

Pages you can read right now

Public, no enrolment, no account:

Total load

33 hours if all ten ran

Video plus exercises at a quarter hour each plus two live hours per class. 8.0 of those hours are bookable now; 25.0 are in the six with no date. The exercise estimate is a guess and is the only figure on this page that is not measured.

The order

Outward from your own house.

Personal defence first, then operational security, then the professional certification track, then offence, then the AI-specific work. This ordering is provisional — it is the ontology's current claim about what stands on what, not a fixed syllabus.

  1. 01 Home Network Defense Scheduled · 30 Sep

    Find out what is actually on your network, including the things you did not put there, and the account that really owns the router.

    • 8locate every device on your own network
    2.0 h load self-serve: reference book · $60
  2. 02 Consumer Device Rescue and Defense Scheduled · 28 Oct

    Take a phone or a laptop that somebody else has had their hands on, and make it yours again — checklist first, guesswork never.

    • 7follow a device hardening checklist
    2.0 h load self-serve: reference book · $60
  3. 03 Scam and Fraud Home Defense Scheduled · 25 Nov

    Read a pretext for what it is, and hold a callback rule that survives being rushed by somebody who sounds official.

    • 9operate a callback rule against incoming contact
    • 10classify an incoming contact as genuine or pretext
    2.0 h load self-serve: reference book · $60
  4. 04 Digital Identity Defense Scheduled · 26 Aug

    Attack your own account recovery, find where it folds, and rebuild it so that losing the device is not the same as losing the account.

    • 9configure recovery that survives losing the device
    • 11falsify your own account recovery by attempting it
    • 10classify an incoming contact as genuine or pretext
    • 9operate a callback rule against incoming contact
    2.0 h load self-serve: reference book · $60
  5. 05 Field Opsec Written · no date

    Write the threat model for your actual situation, drill the playbook it calls for, and reconcile all of it with what people will really do under pressure.

    • 9produce a threat model for your own situation
    • 8execute a security playbook in a drill
    • 10classify a situation into the playbook it calls for
    • 13reconcile security with what people will actually do
    7.0 h load 20 exercises self-serve: no app yet
  6. 06 Blue Team Common Certification Written · no date

    The defender's professional track: enumerate where untrusted input enters a system and characterise the injection surface it opens.

    • 9produce a list of where untrusted input enters a system
    • 10characterise an applications injection surface
    8.0 h load 24 exercises self-serve: no app yet
  7. 07 The Dark Arts (Red Team) Written · no date

    The other side of the same skill. Try to falsify an application's defences against a named attack class, because a defence nobody attacked is an assumption.

    • 11falsify an applications defences against a named attack class
    3.8 h load 3 exercises 1.0 h recorded self-serve: no app yet
  8. 08 Agentic AI Security: Securing What You Build Written · no date

    You shipped something that acts on its own. Where does untrusted input reach it, and can you verify model-written code against its specification?

    • 10characterise an applications injection surface
    • 9produce a list of where untrusted input enters a system
    • 11verify model written code against its specification
    2.2 h load 1 exercises self-serve: reference
  9. 09 AI-Assisted Attacks: What Actually Happened Written · no date

    How AI-assisted attacks actually unfolded, reconstructed. Cases, not predictions.

    • 10characterise how an ai assisted attack unfolded
    • 11falsify an applications defences against a named attack class
    • 7follow a device hardening checklist
    2.0 h load self-serve: reference
  10. 10 AI Security: Governance, Standards and Safety Cases Written · no date

    Find the standard that governs what you are building, work out which framework applies where you are in the lifecycle, and justify a safety case you would sign.

    • 8locate the standard that governs a system you are building
    • 10classify which framework applies where you are in the lifecycle
    • 11justify a safety case for a system that acts without you
    2.0 h load self-serve: reference

Why identity defence comes after scams. Falsifying your own account recovery means pretexting yourself: ringing the help desk, answering the security questions, seeing how far a plausible stranger gets. You cannot run that honestly until you can read a pretext, which is what the class before it teaches. Take them the other way round and you will grade your own attack too kindly.

Why offence sits after the blue team track. Falsifying a defence against a named attack class is only meaningful once you can enumerate where untrusted input gets in. Step 07 is a test of step 06's answer.

The ladder

All 18 capabilities, by complexity.

The number is the ontology's complexity order. This path starts at following a checklist and tops out at order 13, metasystematic — the point where security stops being a technical problem.

order 7 follow a device hardening checklist
order 8 locate every device on your own network
order 8 locate the standard that governs a system you are building
order 8 execute a security playbook in a drill
order 9 configure recovery that survives losing the device
order 9 produce a list of where untrusted input enters a system
order 9 operate a callback rule against incoming contact
order 9 produce a threat model for your own situation
order 10 characterise how an ai assisted attack unfolded
order 10 classify a situation into the playbook it calls for
order 10 classify an incoming contact as genuine or pretext
order 10 classify which framework applies where you are in the lifecycle
order 10 characterise an applications injection surface
order 11 falsify your own account recovery by attempting it
order 11 justify a safety case for a system that acts without you
order 11 verify model written code against its specification
order 11 falsify an applications defences against a named attack class
order 13 reconcile security with what people will actually do

Read the last one again. Reconcile security with what people will actually do. Every control on this path is negotiated against a household, a colleague or a volunteer who will route around it if it costs them too much. That is the top of the ladder, and it is why this is taught live rather than shipped as a video.

Disqualifiers

Who this is not for.

You want a certificate this quarter

Blue Team Common Certification is written and has no date. There is no sitting to book, and we are not going to sell you a seat at one that does not exist.

You want to watch it on your own schedule

1.0 hour of recorded video across ten classes. Other paths at this school have an archive. This one has a room and a time.

You want to be told you are safe

The ladder ends at reconciling security with what people will actually do. Nobody finishes this path secure; they finish it able to say what they are exposed to and what they decided to accept.

Someone is in your accounts right now

That is an incident, not a curriculum. A class on Thursday is the wrong instrument. Deal with the incident, then come back and make the second time harder.

Where this stands

Four are open. Six are written. The Secure Hour is still being scheduled.

There is no waitlist form on this page, because a form that quietly drops your address into a table nobody reads is exactly the kind of thing this path teaches you to spot. Here is the real state of it instead.

Open now · $60 each · book from the class page Written, waiting on a date
  • Field Opsec
  • Blue Team Common Certification
  • The Dark Arts (Red Team)
  • Agentic AI Security: Securing What You Build
  • AI-Assisted Attacks: What Actually Happened
  • AI Security: Governance, Standards and Safety Cases

If you want one of the six run, say which one and roughly when you could attend. That goes to a person, and the ones people ask for are the ones that get scheduled first. The same address works for Secure Hour, which is being scheduled now.

The Defender Not open for enrolment yet
What is open