When the ransom note appears,
the whole company responds.
Exercise it that way.
Ransomware does not stay in the SOC. Within hours, it belongs to legal, communications, operations, finance, and the executive team.
Our cybersecurity tabletop exercises and full-scale cyber crisis simulations put everyone who would own the real incident in the same fight, against scenarios built from real threat actors and real tradecraft.
- Ransomware, double extortion, data breach, vendor compromise, and AI-accelerated threats
- From a two-hour tabletop for your incident team to a multi-day enterprise simulation
- Built and facilitated by practitioners who have worked real cyber crises
Schedule an Initial Consultation
Explore the Scenario Library
What We Hear
“Our IR plan is solid. Our crisis plan is solid. Nobody has ever tested the handoff between them.”
“Security runs their tabletop. Legal runs theirs. The real incident won’t be that polite.”
“Our cyber insurer is asking when we last exercised. So is our biggest customer.”
“The last vendor read us a slide deck about ransomware. Our engineers were on their phones by minute ten.”
A cyber crisis fails at the seams: between detection and declaration, between the incident team and the crisis team, between what information security knows and what leadership decides.
That seam is what we exercise.
How We Build Cyber Exercises
- Real threat actors, real tradecraft. Scenarios modeled on the groups actually working your sector, with their techniques: help desk social engineering, data theft before encryption, leak-site pressure, double extortion.
- The whole company is in the fight. Security and IT respond, but legal weighs privilege and disclosure, communications drafts the statement, and executives face the pay-or-refuse call with a live negotiation running. One scenario, every seam.
- Injects through your real channels. Email, SMS, Teams, and phone. The leak-site screenshot, the reporter’s deadline, the regulator’s inquiry, the customer’s demand for answers.
- Judgment, not software theatrics. Simulation platforms generate injects. We bring practitioners who read the room, adapt the scenario to your decisions, and turn the exercise into an after-action roadmap your program actually executes.
- Standards and stakeholders covered. Aligned to NIST, FFIEC, HITRUST, and ISO 22361 expectations, with after-action reporting built to satisfy auditors, insurers, and customers asking for evidence.
The AI Threat Is Here. We've Already Exercised It.
CISA has conducted federal AI security tabletop exercises. RAND and the UK AI Security Institute have warned European governments against AI-enabled cyber crises.
The Cloud Security Alliance’s “AI Vulnerability Storm” paper advises CISOs to run tabletop exercises for multiple simultaneous high-severity incidents.
We have already designed and delivered that exercise for a commercial enterprise: an AI-accelerated vulnerability storm hitting products, infrastructure, and vendors at once.
Scenarios
- Ransomware and double extortion, with negotiation, disclosure, and leak-site pressure
- Data breach and regulatory notification cascades (HIPAA, state AGs, SEC)
- AI-accelerated vulnerability storm (marquee, links AI spoke)
- Third-party and vendor software compromise
- Cloud provider outage with recovery decisions under uncertainty
Every exercise is custom-built from your environment, your vendors, and your incident history.
Exercise Formats
- Technical tabletop. Your incident response and engineering teams against a realistic scenario. Tests the IR plan, escalation triggers, and technical decision-making.
- Cyber crisis tabletop. The crisis team and the incident team together. Tests the handoff, severity calls, and the move from response to crisis management. Starting at $25,000.
- Executive cyber exercise. The decisions only the top can make, with counsel in the room.
- Enterprise cyber simulation. Multi-day, multi-team, full escalation chain, real-channel injects.
“
This complex cybersecurity simulation was the closest thing to a real-life incident I have experienced.
Participant · Multi-Day Enterprise Cybersecurity Simulation
$18M → $8M
ransom negotiated in-exercise through a real negotiation firm
60+
exercise players in a single data incident response exercise
40+
injects delivered through real channels in one exercise
4
follow-on exercises commissioned by one client in the year after
What You Get
- Custom scenario built from your environment and real threat intelligence
- Run of play, moves, and injects delivered through your real channels
- Senior practitioner facilitation, with legal, comms, and executive layers integrated
- Decision log, anonymous participant survey, and observation capture
- After-action report with prioritized recommendations, built to stand up with auditors, insurers, and customers
- Executive debrief and a defined exercise cadence for the year
Frequently Asked Questions
What does a cybersecurity tabletop exercise cost?
Facilitated cyber crisis tabletops start at $25,000. Technical tabletops, executive cyber exercises, and enterprise simulations are scoped to your organization after a consultation.
Who should participate in a cyber crisis exercise?
Everyone who would own the real incident: security and IT, legal, communications, operations, HR, finance, and the executive layer. The seams between those groups are where real incidents break down, so we exercise them together.
How realistic are the scenarios?
Scenarios are modeled on real threat actors and their actual tradecraft, from social engineering entry through data theft, encryption, and leak-site extortion pressure. One participant called our simulation the closest thing to a real-life incident they had experienced.
Will this satisfy our insurer, auditors, and customers?
Yes. Exercises align to NIST, FFIEC, HITRUST, and ISO 22361 expectations, and the after-action report is built as evidence you can hand to cyber insurers, auditors, and enterprise customers who ask when you last exercised.
How is this different from a penetration test or purple team?
Technical testing probes your controls. Our exercises test your people and decisions: escalation, severity calls, legal privilege, communications, and executive choices under pressure. The two are complements, and we design exercises that build on your technical testing results.
Do you cover AI-driven threats?
Yes. We designed and delivered the first commercial AI-accelerated vulnerability storm exercise, the scenario class CISA, RAND, and the Cloud Security Alliance now tell organizations to practice. See our AI Crisis Exercises page.
The threat actors rehearse. Most companies don’t.
Fifteen minutes with a practitioner gets you a straight answer on the right cyber exercise for your team, what it costs, and when it can run.

