HOW IT PLAYS

Four acts, simulating one bad day.

Every tabletop follows the same arc. The script is written for you, and the pressure is real.

01
PHASE ONE

Scenario Design

An attack scenario tuned to your industry, stack, and crown jewels. Not a template. A script written for your risk profile.

02
PHASE TWO

Kickoff & Framing

Roles assigned, ground rules set, comms channels opened. Everyone at the table knows what they're playing before the first inject drops.

03
PHASE THREE

Live Play

Injects, timeouts, curveballs, media pressure. The facilitator escalates in real time based on your team's decisions. The attacker never waits.

04
PHASE FOUR

Debrief & Report

What went right, what stalled, where the runbook broke. Findings prioritized, gaps sized, next steps handed back the same week.

THE SCENARIOS

Pick your bad day.

01

Ransomware & Extortion

Encryption event, extortion clock ticking, exfil leverage. Modern operators layer double- and triple-extortion. Your team practices the paying-or-not decision under real pressure.

02

Business Email Compromise

A wire transfer request from the CFO, right before a holiday weekend. Practice the pause. Who catches it, who greenlights it, who calls the bank.

03

Insider Threat

Departing engineer, cloud credentials, a leaked repo. Legal, HR, and IR at the same table for once, deciding who owns the response.

04

Third-Party Compromise

Your SaaS vendor gets popped. Their data is your data. Do you have contract language, notification obligations, and the phone number for their CISO?

05

AI Risk

The largest threat to any orginization right now.

06

Physical & Social

Tailgating, badge cloning, or a pretext call to the help desk. The tabletop that reminds every board member why the front-desk hire matters.

IN THE END

It's all about the report.

Big on content, short on fluff.

01

After-Action Report

Board-ready readout of how your team performed under pressure. What decisions held, which ones didn't, and what leadership needs to know.

02

Gap Analysis

Every stall, missed handoff, and unclear ownership moment, categorized by severity and the runbook section it belongs to.

03

Playbook Updates

Concrete edits to your IR plan: new escalation paths, updated contact trees, tightened decision points. Handed back the same week.

Real incident commanders.

The facilitator running your tabletop has run the real ones. Ransomware negotiations, breach comms, board briefings at 2am. They bring what actually happens, not what a course said might.

GCIHGCFACISSPCISM

Insurance-approved.

Ask your cyber insurance provider about premium discounts for annual IR tabletops. A few major carriers offer them for proactive cyber security services. We've run tabletops that paid for themselves in the next renewal cycle.

Ready to run the drill?

Tell us the scenario keeping you up at night. We'll come back within a few business days with a tailored plan and dates.

RUN THE DRILL

In the end

It's all about the report.

We're big on content, short on fluff. 
cyberpunk sign on computer that says Executive Summary with charts and graphs

Executive Summary

More art than science, conveying the results of a very technical work to non-technical people is a skillset unto itself. We believe we've cracked the code on making this content accessible and understandable to the highest levels of management in an organization.

Strategic recommendations to support and enable executives in making decisions, packaged for executive delivery.

cyberpunk sign on computer that says Results and has picture of hacker

Assessment Results

Findings—categorized, prioritized, and ranked by criticality and estimated remediation effort. 

Each finding receives a detailed breakdown including a description of the risk, detailing the threat it poses to the organization, where that issue was observed and how to remediate it. When applicable, screen captures and steps to reproduce the issue are documented.

cyberpunk sign on computer that says Appendix

Appendices

Cyber Kill Chains provide step-by-step walkthroughs, illustrating the severity and impact of various risks and how an attacker may leverage them.

Detailed summaries, processes, and results for engagement campaigns (i.e., recon, wireless, physical testing), which include images, statistics, tools, and techniques used.

In short,  we provide all the steps necessary to show our work.