Skip to main content
Simulation environment readySynthetic data onlyDeterministic outcomes

Cyber-crisis decision simulator

The signal is weak.
Your decision cannot be.

Take the seat of a CISO, CIO, DPO, risk, communications, executive or incident-response lead. Assess incomplete evidence, balance operational pressure and make decisions you can defend.

Start an exerciseReview the 3-minute guide30 / 60 minSingle-player exercise
EXERCISE PF-30Payment Freeze
Active
SIMULATED TIME00:07:42
  1. SOC

    Suspicious PowerShell activity observed on a payment host.

  2. IAM

    Privileged sign-in pattern conflicts with the change window.

  3. OPS

    Payment latency now exceeds the customer-impact threshold.

    Response due · 02:18

Built for decisions that cross technical and executive lines.

CISOCIORisk analystDPOCommunicationsExecutiveCSIRT / SOC

The exercise method

Not a quiz. A chain of consequences.

01

Enter the situation

Select your sector, role and crisis profile. You receive only the information your role would reasonably hold.

02

Decide under pressure

Inspect synthetic evidence, record uncertainty and make structured choices as the incident evolves.

03

Debrief the evidence

Trace each decision to its consequence, review missed indicators and leave with a practical action plan.

Scenario catalogue

One incident. Multiple truths to manage.

The same core event changes across banking, retail, and defence & security. Role lenses control what you see—not what is true.

01Service disruptionAvailability, containment, recovery30 / 60 min
02Low-noise access anomalyObservation, persistence, uncertainty30 / 60 min
03External data reportScope, privacy, public trust30 / 60 min
04Privileged activity alertVerification, restraint, escalation30 / 60 min

Evidence, not vibes

Every assessment has a receipt.

The simulator records an immutable exercise timeline. Debriefs cite the injects you opened, the evidence you preserved, the choices you made and the opportunities you let expire—while keeping scenario truth and scoring rules on the server.

Privacy & safety

The pressure is realistic. The data is not real.

Exercises use clearly marked synthetic artefacts only. No real credentials, customer records, malware, or live system connections are used. Participant notes are never included in application logs.