Live AI-supported tabletop exercises

CYBERAMBUSH— live, cloud-based cybersecurity tabletop exercises for public and private organizations

Put your team inside a live cyber incident. Release injects on the clock, capture every decision, and use AI to assess responses against your guidance while the exercise unfolds. Have a complete Action Action Review prepared within seconds of ENDEX.

Exercise live
T+00:14:32
Inject 03 / HighReleased 02:18 ago

Payment systems are encrypted. The threat actor claims customer data was exfiltrated.

Decide whether to isolate the payment environment and activate breach counsel.

IT / SOCCommitted
LegalAssessing
ExecutiveCommitted
AI assessmentGuidance met

The response protects core operations and preserves evidence. Escalation authority is clear.

Decision qualityStrong
Response time01:46
NIST CSF 2.0RS.MA-01

02 / How it feels

Watch a one-hour exercise in thirty seconds.

Injects arrive on the clock, departments commit decisions, ENDEX is called, and the after action review (AAR) is drafted before anyone leaves the room.

One hour, played in thirty seconds

Ready — plays when scrolled into view
Idle — the replay starts when this panel scrolls into view

03 / 2026 Threat picture

Why the rehearsal matters

eCrime breakout time

29 min

Average time for an intruder to move from the first compromised host to another system — faster than most escalation calls.

Source: CrowdStrike 2026 GTR

Median attacker dwell

14 days

Global median dwell time before detection, published March 23, 2026 by Mandiant and Google Cloud.

Source: Mandiant M-Trends 2026

Human element in breaches

62%

62 percent of breaches involved a person; 48 percent involved a third party and 48 percent involved ransomware.

Source: Verizon DBIR 2026

Average breach cost

$4.99M

Global average, July 29, 2026; the United States average is $11.5M and one in four malicious breaches was artificial intelligence (AI) enabled.

Source: IBM Cost of a Data Breach 2026

SOURCES AND VERIFICATION

04 / The exercise

Rehearse the next incident.

Realistic injects

SEV / HIGH

Time-phased injects drawn from 2025-2026 threat activity: edge appliance zero-days, deepfake authorization calls, software-as-a-service (SaaS) tenant compromise, and double-extortion ransomware against operations.

T+00:14 — inject 03 released

Instant After Action Review (AAR)

CSF / RS

An AI-drafted after-action review the moment ENDEX (end of exercise) is called — decisions, timing, gaps, and recommendations, mapped to the framework and ready to circulate.

ENDEX → draft in seconds

05 / Attack vectors

Twelve vectors, one shared taxonomy.

Every scenario, inject, response, and AAR finding is tagged to the same vector set.

RANSOMWARE

Encryption plus data-theft extortion against production systems and backups.

SOCIAL ENGINEERING / DEEPFAKE

Voice-cloned executives and help-desk pretexting used to move money or reset access.

SUPPLY CHAIN / SAAS

A trusted vendor, managed service provider (MSP), or software-as-a-service (SaaS) tenant becomes the path into your environment.

IDENTITY / MFA

Identity and multi-factor authentication (MFA) attacks: push fatigue, token theft, and session hijack that bypass second factors.

CLOUD MISCONFIG

Exposed storage, over-scoped roles, and orphaned keys in cloud tenancy.

OT / ICS

Operational technology (OT) and industrial control system (ICS) disruption, where safety and physical process take priority.

INSIDER

Malicious or negligent staff exfiltrating data or sabotaging operations.

DDOS

Distributed denial of service (DDoS): volumetric and application-layer floods that take public services offline.

EDGE ZERO-DAY

Unpatched virtual private network (VPN), firewall, or file-transfer appliance exploited at the perimeter.

BEC / WIRE FRAUD

Business email compromise (BEC): mailbox takeover and invoice manipulation that redirect outbound payments.

API / INTEGRATION ABUSE

Application programming interface (API) abuse: stolen tokens, abused webhooks, and over-permissive integrations between software-as-a-service systems.

WIPER / DESTRUCTION

Destructive malware with no ransom demand, aimed at denying recovery and erasing evidence.

06 / What it does

The full exercise loop.

Artificial Intelligence (AI) Planning Assistant

Scenario shaping, inject drafting, and guidance review — available to Executive Sponsors and Operators only.

Live Response Capture

Every Participant response is time-stamped and matched against the Planning Guidance for that inject.

Build a Scenario Fast

Pick a vector, set the stage gates, and generate a time-phased inject chain in minutes.

Run It From Anywhere

Cloud-hosted and browser-based. Distributed teams, one shared exercise clock.

Inject Library

Reusable injects tagged by vector, severity, and Cybersecurity Framework (CSF) function across all twelve attack vectors.

NIST-Aligned After Action Review

After action review mapped to the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) 2.0, Special Publication (SP) 800-61r3, and SP 800-84.

07 / Roles

Three seats at the table.

Flip any card to see a day in that console.

EXECUTIVE SPONSOR

Own the outcome. Set the guidance.

Approve the scenario, define Planning Guidance, and read the after action review (AAR) against your risk posture.

Enter
OPERATOR

Build and run the exercise.

Assemble injects, control the clock, release stage gates, and call ENDEX (end of exercise).

Enter
PARTICIPANT

Decide under pressure.

Receive injects live, log decisions, and see how the team performed once the exercise closes.

Enter
CYBER AMBUSH

08 / Get started

Ready to exercise?