The Anatomy of Disinformation

The Anatomy of Disinformation

Disinformation is older than the printing press and sharper than ever. Learn to take it apart before it takes you in.

100% Online • Self-Paced • Start Immediately

Intermediate
• 70,000+ students trained • 4.9/5 average rating

What's Included

  • 20+ hours of training content
  • 3100+ practice questions
  • 40 engaging exercises
  • 35+ assessments
  • arcX final exam and free re-test included
Secure checkout 12 months access

Trusted by leading organisations worldwide

Deloitte
United States Air Force
Cyber Security Agency of Singapore
Ernst and Young
UK Ministry of Defence
Barclays
Accenture
KPMG
Raytheon
Hiscox
Crowdstrike
ST Engineering

See the machinery behind the message

They've Been Doing This Since Rome. You Just Scroll Faster.

1 course

Disinformation decides elections, shapes court cases, moves public health, and fills the feed you scroll before breakfast. Most of the time it works precisely because you never stop to name what is being done to you. A phrase like "fake news" is no defence; it collapses an honest mistake, a deliberate lie, and a true story someone wants buried into one useless slogan.

By the end of this course you will be able to look at a tweet, a speech, or a flyer pushed through your door and do three things fast: name the exact tactic, explain why it lands, and pull it apart on the spot. You will trade loose language for precise vocabulary, misinformation, disinformation, malinformation, propaganda, and back it with analytical frameworks you can apply to any claim, from any source, including the ones you already agree with.

You get there by working through real material rather than theory. You will trace the same manipulation from defaced Roman coins and Octavian's forged will through the printing press, radio, television, and the micro-targeted feed. You will dissect conspiracy theories, pseudoscience, moral panics, and violent extremism using named models: SWOT, the white-grey-black psyops spectrum, RAND's Truth Decay, McLuhan's "the medium is the message", Stanley Cohen's stages of panic, and the Moghaddam staircase. The tricks stop feeling like magic and start looking like method.

Product Overview

Disinformation drives elections, court cases, public health, and what you scroll through every day. Most people can feel it happening. Very few can name exactly what is being done to them.

This course closes that gap. Across five modules, you learn to recognise disinformation on sight, name the specific tactic being used, and take it apart on the spot.

What you will learn:

You will retire the phrase "fake news" from your vocabulary on day one and replace it with the precise institutional definitions used by the EU, the CDC, the RAND Corporation, and Edward Bernays's 1928 book Propaganda. You will pick up a suite of analytical frameworks the course uses throughout, from SWOT and Facebook's intent-versus-truth quadrant to Cohen's four stages of moral panic and the Moghaddam staircase of radicalisation. You will pick up a six-move diagnostic toolkit (tech speak, volume, cognitive jumps, fringe over-representation, possibility versus probability, and shifting the frame of evidence) that you can run on any piece of content you meet in the wild.

Focus and scope:

This is a course in diagnostic literacy. You will leave able to look at a piece of disinformation and understand what is being done, why it works, and how to refuse it. The course is not an investigator's manual: it does not train OSINT tools, network attribution methodology, or forensic infrastructure analysis. Those are the domain of professional investigation training. This course is the conceptual grounding that sits underneath that training and that most people who need it never receive.

Your Journey

This module builds the vocabulary and the analytical kit the whole course runs on, retiring "fake news" in favour of misinformation, disinformation, and malinformation as the EU, CDC, and RAND define them, plus propaganda drawn from Bernays. You then trace deception through history, from defaced Roman coins and Octavian's forged will to the printing press, radio, television, and the micro-targeted feed, applying SWOT, the white-grey-black psyops spectrum, Facebook's actor-versus-content quadrant, and RAND's Truth Decay along the way. It closes on the mechanics that make it work: information asymmetry, McLuhan's "the medium is the message", the Trump case study as the most documented disinformation operator of the modern era, and the collision between subjective and objective reality.

  • You will define misinformation, disinformation, and malinformation, and separate them by intent and harm using the EU, CDC, and RAND frameworks
  • You will apply SWOT, the psyops colour spectrum, and Facebook's quadrant model to diagnose a false claim's spread and origin
  • You will trace how each medium, from Roman coins to hashtags, reshapes the same lie, and read McLuhan's "the medium is the message" against real propaganda
  • You will use information asymmetry to explain cases like the staged Iraqi Walmart action figure and the AI-generated downed-helicopter image
  • You will stress-test your own objectivity against the Washington Post's documented record of Trump's claims and the January 6th aftermath

Inside this module

  • Definitions of disinformation
  • Why we never say "fake news"
  • Frameworks for taking it apart
  • History and mechanics
  • Two thousand years of liars
  • Information asymmetry: learned the hard way
  • Donald Trump as a working case study
  • The medium is the message
  • The audience of one
  • Reality and perception
  • Subjective and objective reality
  • When consensus reality breaks

This module defines what a conspiracy theory actually is, separating real conspiracies from false ones and introducing synthetic folklore, the blend of something real with something fabricated that makes disinformation go down like sugar. It shows why conspiracy beliefs interlink into self-reinforcing systems, working through David Icke, a Spike Lee quote from the course's core conspiracy textbook, and the slide from flat earth into antisemitism. It also treats the psychology honestly, explaining pareidolia and the pattern-finding mind while arguing this is not mental illness, and ends on salad-bar extremism and modern folklore.

  • You will distinguish a genuine conspiracy from a conspiracy theory using a clear structural checklist
  • You will spot synthetic folklore and use the cocktail model's diagnostic questions to separate the factual kernel from the false framing
  • You will explain why beliefs cluster into self-reinforcing systems rather than standing alone
  • You will recognise pareidolia and the appeal of comfortable explanations without pathologising the believer
  • You will trace how a seemingly harmless theory like flat earth can carry extremist ideas beneath it

Inside this module

  • What a conspiracy theory actually is
  • Welcome to the building blocks
  • What is a conspiracy theory
  • Conspiracism versus a conspiracy theory
  • Synthetic folklore
  • The cocktail and the fourth wall
  • How a film leaked into the Iraq war
  • Belief systems
  • Why no one believes only one
  • Taking Spike Lee apart
  • When flat earth slides into antisemitism
  • The psychology of conspiracism

This module hands you four criteria for separating science from pseudoscience and then puts them to work on health, science, and political claims, from the suggestion of injecting bleach to the QAnon Shaman's online university and Samuel Rowbotham's flat-earth legacy. It builds the disinformer's toolkit so you can name the tactics on sight: tech speak as a weapon, "do your research", appeals to volume, cognitive jumps, and over-represented fringe voices. It closes on reasoning traps, possibility versus probability, correlation versus causation via ice cream and shark attacks, and the platform infrastructure that keeps this content circulating off the mainstream.

  • You will apply four criteria, in order, to judge whether a claim is science or pseudoscience
  • You will spot tech speak, "do your research", volume, cognitive jumps, and fringe over-representation as recurring tactics
  • You will separate possibility from probability and correlation from causation using the course's worked examples
  • You will understand why a legitimate question, such as a possible lab leak, does not automatically qualify as pseudoscience
  • You will identify the platforms and infrastructure that carry pseudoscientific content once it leaves mainstream sites

Inside this module

  • What separates science from pseudoscience
  • When the President suggested injecting bleach
  • What separates the science from pseudoscience
  • The QAnon Shaman
  • The QAnon Shaman: up close
  • Inside the Shaman's online university
  • Flat earth
  • The man who flattened the earth
  • The disinformer's toolkit
  • "Do your research"
  • Tech speak as a weapon
  • Volume, cognitive jumps, and fringe voices

This module uses Stanley Cohen's four-stage model to show how a moral panic forms and where it can be caught early. Through the Satanic Panic, the McMartin case and Michelle Remembers, and Patricia Pulling's crusade against Dungeons & Dragons, it examines the questionable role of the "expert" and how the blurring of fantasy and reality manufactures folk devils. It then bridges to extremism, tracing how synthetic folklore and community anxiety can convert into real-world harm.

  • You will recognise the early stages of a moral panic using Cohen's four-stage model
  • You will see how self-appointed experts lend false authority, drawing on Laycock's work on the Satanic Panic
  • You will analyse how the Dungeons & Dragons scare turned fantasy into a folk devil
  • You will trace how a blurred fantasy-reality line converts anxiety into targeting of real people
  • You will connect the mechanics of panic to the pathway toward political violence

Inside this module

  • The anatomy of a panic
  • Anatomy of a panic
  • The satanic panic
  • McMartin, Michelle, and the satanic panic
  • Patricia Pulling and the Dungeons and Dragons scare
  • Trouble in the toy box
  • Bridge to extremism
  • Synthetic folklore and the violence to come
  • End of Module Assessment

This module draws the lines between protest, direct action, violent protest, violent extremism, and terrorism, then uses the Moghaddam staircase to explain radicalisation across its levels. Through the Blood Tribe and its leader Christopher Pohlhaus, it examines chilling effects, escalation, and the matchsticks model, and explains why modern extremist groups organise as loose networks rather than hierarchies, symbolised by the Boogaloo movement's Hawaiian shirts. It closes on stochastic terrorism and parasocial relationships, showing how kernels of disinformation are scattered across a receptive audience so violence becomes probable while the speaker stays deniable.

  • You will distinguish protest, direct action, violent extremism, and terrorism using clear criteria
  • You will describe the Moghaddam staircase and how disinformation feeds people onto its lower levels
  • You will explain stochastic terrorism and how rhetoric incites random violence while shielding the instigator
  • You will understand why hierarchies gave way to loose networks, using the Blood Tribe and Boogaloo cases
  • You will see how parasocial relationships turn audiences into potential actors

Inside this module

  • Definitions and the Staircase
  • Definitions and the Moghaddam Staircase
  • The Blood Tribe and chilling effects
  • Christopher Pohlhaus and the Blood Tribe
  • Chilling effects, escalation, and the matchsticks model
  • Organisational form
  • Why hierarchies died and Hawaiian shirts won
  • Stochastic terrorism
  • Stochastic terrorism and parasocial relationships
  • When the fantasy collapses
  • End of Module Assessment

What You'll Learn

Name the exact tactic behind a piece of content instead of reaching for "fake news"
Distinguish misinformation, disinformation, malinformation, and propaganda by intent and harm
Apply SWOT, the psyops colour spectrum, Facebook's quadrant model, and RAND's Truth Decay to any false claim
Diagnose a conspiracy theory's structure and separate its factual kernel from its false framing
Judge whether a claim is science or pseudoscience using four ordered criteria
Spot disinformer tactics such as tech speak, appeals to volume, cognitive jumps, and fringe over-representation
Recognise the early stages of a moral panic before it produces folk devils
Trace how rhetoric escalates toward stochastic terrorism while the speaker stays deniable
Analyse the same claim across text, video, and meme, and explain why each format persuades differently

Skills You'll Gain

Disinformation vocabulary and classificationAnalytical frameworks (SWOT, psyops spectrum, Truth Decay)Conspiracy theory deconstructionScience versus pseudoscience evaluationMedia and platform analysisMoral panic recognitionRadicalisation and extremism analysisCritical thinking under partisan pressureSource and context verification

How This Course Is Delivered

This course is delivered through a combination of interactive content and practical exercises.

Video Content

Immerse yourself in arcX's The Anatomy of Disinformation training course through its core delivery method: video. You'll have access to a comprehensive series of videos, collectively spanning over 12 hours of content.

Practical Exercises

Our bespoke testing engine will ensure you experience a combination of free-form and adaptive tests. These are thoughtfully integrated to reinforce your learning and consistently evaluate your skills.

Quizzes

You'll engage in numerous micro-scenarios, designed to put you in the driving seat and requiring just a few minutes to complete. You'll also have access to an enormous question bank of over 3,100 questions.

Reading Material

Reading material has been strategically created and provided to enhance your understanding of the taught concepts and expand upon them.

Who This Course Is For

This course is built for people who cannot afford to be wrong about what they are looking at.

  • Journalists and communicators framing stories accurately under pressure
  • Threat intelligence analysts adding influence operations to their toolkit
  • Educators teaching media literacy from real cases
  • Policy advisors weighing claims and their real-world consequences
  • Any reader who wants to know exactly what is being done to them every day

Course Details

Stewart K Bertram

Instructor

Stewart K Bertram

Stewart has worked within the field of Intelligence and Security for the past 20 years with experience across both the private and public sector. Starting his career in 2004 in the Intelligence Corps of the British Army, Stewart entered the private sector in 2009 and has held a number of roles in Cyber Threat Intelligence (CTI) since then. These have included product development, service delivery and consulting, with his most recent roles involving the management of specialist teams involved in research into the cyber criminal underground and nation state threat actors. Holding both a Masters in Computing and a Master of Letters in Terrorism Studies from St. Andrews University. Stewart was also among the first in the world to pass the CREST Certified Threat Intelligence Manager (CCTIM) examination. Stewart’s research interests and work have always sat at the intersection of technology, security and people focused issues. These unique areas of focus are bought to bare within his role at arcX, where he is responsible for the design and delivery of the core CREST related CTI courses and oversight of the wider Cyber Threat Intelligence stream.

Difficulty Level

Intermediate

Language

en

On completion you can earn The Anatomy of Disinformation (CDA) credential, recognising your ability to name, classify, and take apart disinformation using the frameworks taught throughout the course.

Student Reviews

Trusted by Security Professionals

Join 70,000+ professionals who have advanced their careers with arcX training

Advanced Career

"The courses provided by arcX are the best in terms of content and structure I have come across, that are aligned to CREST's CPTIA and CRTIA exams. An absolute must for anyone wanting to pursue these certifications but also anyone wanting to gain a solid baseline knowledge set for a career in CTI."

C

Chris

Cyber Threat and Risk Manager

Earned Certification

"Great content and fantastic customer service. Put me in a great position to gain my qualification. 10/10 recommend."

D

Dan

Cyber Security Project Manager

Promoted to Senior

"I have done courses in offensive security, networking, forensics and malware. All from prestigious training vendors. None compare to arcX. I secured a straight transition into a senior CTI role. The platform provided me with insights into my strengths and weaknesses and allowed me to track changes. Very grateful to the guys for this!"

P

Pat

Senior Threat Intelligence Analyst

Frequently Asked Questions

About This Course

No. This course does not provide virtual labs. Any tools and techniques it covers should be practised on your own operating system.
No. It uses Donald Trump as a primary case study because the Washington Post's documentation makes it the richest available dataset, but it explicitly treats disinformation as a bipartisan, structural problem and includes left-leaning examples such as the Covington Catholic incident and the "fine people" hoax. The stated test of critical thinking is applying the same tools to claims you already agree with.
Yes. To analyse disinformation, propaganda, and extremist messaging effectively, the course includes real-world examples of harmful content, including Nazi propaganda and material relating to terrorism and political extremism. These are presented strictly for educational and analytical purposes, and some learners may find them distressing.
No. The approach is example-led and builds from everyday experience with your own feed. It introduces frameworks and named models step by step, so you can follow the reasoning without a specialist background.
Yes. The whole course is built around diagnosis: you work through named cases and frameworks, then apply diagnostic questions such as the cocktail model, the psyops spectrum, and possibility-versus-probability to real claims, tweets, and campaigns.

General Course FAQs

Click your avatar in the top right corner and select Contact Support, or email us directly at [email protected]. We typically respond within 24-hours.

You will have 12 months access after activating your course in accordance with our Terms & Conditions. You can work through your course at a pace that suits you. Once you have completed your course you will retain access and be able to refresh your knowledge anytime within the access period.

Our courses are delivered on-demand. This means you can start and stop learning whenever you like. There is no time limit and no restriction on how many times you can access course content.

No. CREST exam vouchers need to be purchased separately through CREST or Pearson VUE. You can find further information on our CREST Accreditation page.

Absolutely! Demonstrating your dedication to professional development in cyber security is always valuable. Our certifications are recognised by partner organisations who value our training.

Yes! You can create individual accounts and purchase courses through our portal for instant access. For multiple employees, please contact us for volume pricing.

Yes! We're always happy to speak with industry experts interested in producing high-quality training courses. Become an instructor and help make a positive impact on someone's career.

If you bought a course before this change, you keep lifetime access to it. The new terms only apply to new purchases.

Can't find what you're looking for? Get in touch