Cyber Day · NUST · Presented by Winville

Namibia National Cyber Security Competition

Five short challenges on phishing, links, passwords and scams, plus a career assessment that turns your answers into a certification plan. Play on your phone, see why each answer is right or wrong, and find out where you place on the leaderboard.

Five challenges, 100 points each

Each one takes one to three minutes. Play them in any order and replay as often as you like. Only your best score counts.

    Find your cybersecurity career path

    Answer 27 questions about what you enjoy, how you work and what you already know. You get your best-fit career path, the reasons behind it, a certification roadmap in the right order and a quotation from Tenebix School of Excellence.

    No sign-up. We only ask for an email after you have seen your results, and only if you want a copy.

    The eight paths we score

    1. Penetration Testing / Ethical Hacking
    2. Red Teaming
    3. Blue Teaming / SOC Analysis
    4. Digital Forensics and Incident Response
    5. Threat Intelligence
    6. Cloud Security
    7. Governance, Risk and Compliance
    8. Security Engineering / SIEM Engineering

    How the competition works

    1. 01

      Pick a nickname

      Only your nickname appears on the board. No email address, phone number or password needed.

    2. 02

      Play the challenges

      Five ranked challenges, each worth up to 100 points. Start with whichever looks easiest.

    3. 03

      Learn from every answer

      After each question you see what gave it away, so the next scam is easier to catch.

    4. 04

      Climb the board

      Your best score in each challenge adds up to a total out of 500. Replays can only raise it.

    Six habits that stop common scams

    None of these need technical skills. They work on email, WhatsApp, SMS and phone calls.

    1. Check the real sender

      Look at the email address, not the display name. nust.na and nusl.na are two very different senders.

    2. Go to the site yourself

      If a message says your account needs attention, open the app or type the address instead of tapping the link.

    3. Keep one-time codes private

      No bank, IT desk or friend needs your OTP. Anyone asking for it is trying to get into your account.

    4. Unique passwords and MFA

      A password manager remembers them for you. MFA means a leaked password alone is not enough to get in.

    5. Treat QR codes as links

      Check the address a QR code opens before you type anything into the page it shows.

    6. Slow down when it is urgent

      Deadlines, threats and prizes are there to rush you. Stop and check through a channel you already trust.

    What to do if something goes wrong

    I clicked a link and typed my password

    Change that password now, starting from the real site or app. If you used the same password anywhere else, change it there too. Turn on MFA, then tell your IT desk or bank so they can watch the account.

    I keep getting MFA prompts I did not ask for

    Deny every one. Someone has your password and is hoping you tap Approve by mistake. Change the password and check which devices are signed in to the account.

    Someone called asking for a code or a payment

    Hang up. Call the organisation back on a number from their official website or the back of your card, never one the caller gave you.

    A friend's account is asking me for money

    Call your friend on a number you already have. If their account has been taken over, warn the groups you share so nobody else pays.

    Leaderboard

    Rankings update as soon as a ranked challenge is finished.

    Join the competition

    You can play without joining, but only joined players appear on the leaderboard.

    • We only keep your nickname plus your best score and time for each challenge.
    • No email address, phone number, student number or password.
    • Sharing a device at the stand? Use Switch player when you are done so the next person can join.

    Join the competition