Built on NIST, run like HSEEP.
Cyber Ambush is a tabletop exercise (TTX) platform. We're lightyears beyond a static slideshow with a role-play script. Every objective, inject, and after-action item traces to the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) 2.0, NIST Special Publication (SP) 800-61r3 incident response, SP 800-84 exercise guidance, the SP 800-53 incident response (IR) control family, and the Homeland Security Exercise and Evaluation Program (HSEEP) / Cybersecurity and Infrastructure Security Agency (CISA) Cyber Tabletop Exercise Package (CTEP) exercise lifecycle. Your tabletop produces evidence, not just a good story.
NIST Cybersecurity Framework (CSF) 2.0
The six CSF 2.0 functions organize every scenario. Categories below are the exercise-relevant subset Cyber Ambush scores against.
GV — GOVERN
- GV.OCOrganizational Context
Scenario scoping ties injects to mission-critical services and stakeholders identified in your context statement.
- GV.RMRisk Management Strategy
Exercise objectives are drawn directly from your organization's stated risk tolerance and priorities.
- GV.RRRoles, Responsibilities & Authorities
Master Scenario Events List (MSEL) escalation injects test whether the right person actually has, and uses, decision authority.
- GV.SCCybersecurity Supply Chain Risk Management
Vendor and third-party notification injects verify contracts, contacts, and escalation paths are current.
ID — IDENTIFY
- ID.IMImprovement
After action review (AAR) findings feed directly back into ID.IM as tracked corrective actions with owners and dates.
PR — PROTECT
- PR.AAIdentity Management, Authentication & Access Control
Help-desk reset, multi-factor authentication (MFA) re-enrollment and privileged-access injects test who can grant access under pressure.
- PR.IRTechnology Infrastructure Resilience
Segmentation, backup isolation and hypervisor-protection injects test whether the environment can absorb the attack it is designed to resist.
DE — DETECT
- DE.CMContinuous Monitoring
Injects simulate monitoring alerts to test whether analysts correctly triage signal from noise.
- DE.AEAdverse Event Analysis
Time-to-declare metrics are scored against DE.AE analysis expectations for the exercise scenario.
RS — RESPOND
- RS.MAIncident Management
The facilitator tracks incident declaration, severity assignment, and management activation against the clock.
- RS.ANIncident Analysis
Forensic-preservation injects force a choice between fast containment and evidence integrity.
- RS.COIncident Response Reporting & Communication
Notification-clock injects check legal, regulatory, and executive communications against real deadlines.
- RS.MIIncident Mitigation
Containment decisions are scored on whether they stop the bleeding without destroying the evidence.
RC — RECOVER
- RC.RPIncident Recovery Plan Execution
Restoration injects test backup integrity checks and restoration sequencing before systems go live again.
- RC.COIncident Recovery Communication
All-clear criteria and customer/stakeholder messaging are drafted and reviewed live during the exercise.
SP 800-61r3 — Incident Response Lifecycle
- CSF-aligned lifecycle — 800-61r3 retires the old "phases" model in favor of mapping incident handling directly onto CSF 2.0 functions. Cyber Ambush scenarios follow that same mapping end to end.
- Triage by risk — injects force prioritization decisions under time pressure, scored against organizational risk tolerance rather than a fixed checklist.
- Evidence integrity — containment injects are written so speed and forensic preservation are in tension, the way they are in a real breach.
- Leadership status updates — the MSEL schedules executive briefings so participants practice giving accurate, calibrated status without over- or under-committing.
SP 800-84 — Test, Training & Exercise Guidance
- Design & development — objectives, scope, and MSEL are built before day of, per 800-84's exercise planning cycle.
- Conduct — the platform runs facilitator and evaluator consoles side by side so injects and observations happen in real time.
- Evaluation — evaluators score each objective against pre-defined success criteria, not after-the-fact impressions.
- Facilitator & evaluator roles — the console keeps injects, timing, and scoring in separate lanes so one person running the room doesn't also have to grade it.
- Required AAR content — exercise summary, objective-by-objective analysis, strengths, areas for improvement, and an improvement plan with owners and dates — generated directly from the exercise record.
SP 800-53 — Incident Response (IR) Control Family
- IR-2Incident Response Training
Every exercise counts as documented, hands-on IR training for the participants involved.
- IR-3Incident Response Testing
Cyber Ambush tabletops satisfy the IR-3 annual testing requirement with a scored, repeatable record.
- IR-4Incident Handling
Scenario injects walk the full handling lifecycle: detection, analysis, containment, eradication, recovery.
- IR-6Incident Reporting
Notification-clock injects test whether the right reports reach the right parties inside the deadline.
- IR-8Incident Response Plan
The exercise is scored against your actual IR plan, and gaps in the plan surface as AAR corrective actions.
HSEEP / CISA Cyber Tabletop Exercise Package (CTEP)
- Situation Manual — the scenario brief participants read before the exercise, generated from your objectives and threat profile.
- MSEL — the Master Scenario Events List drives every inject, timed and sequenced against exercise objectives.
- Evaluation guides — objective-specific evaluator guides define what "good" looks like before the exercise starts, not after.
- After Action Review / Improvement Plan (AAR/IP) delivery — HSEEP practice is a draft after action report about 30 days after the exercise, with the final AAR/Improvement Plan typically within 60 to 90 days (older HSEEP guidance; agencies set their own deadlines). Cyber Ambush drafts the AAR/IP the same day, so those windows are a review period rather than a scramble.
Exercise objective → CSF 2.0 outcome → SP 800-53 control → after action review (AAR) evidence
The full traceability chain Cyber Ambush maintains from planning through the after-action report.
| Exercise objective | → CSF 2.0 outcome | → SP 800-53 control | → AAR evidence |
|---|---|---|---|
| Recognize and declare an incident | DE.AE, RS.MA-01 | IR-4, IR-6 | time to declaration, severity assigned |
| Escalate to executives | GV.RR, RS.CO | IR-8, IR-6 | decision-makers reached, authority documented |
| Contain without destroying evidence | RS.MI, RS.AN | IR-4(12) | isolation decisions, forensic preservation |
| Meet notification clocks | RS.CO-02/03 | IR-6, IR-4(8) | SEC/GDPR/HIPAA/state timelines identified |
| Coordinate vendors, insurer, law enforcement | GV.SC, RS.CO | IR-4(10), IR-7 | contacts and contracts current |
| Restore and verify | RC.RP, RC.CO | IR-4(3), CP-10 | backup integrity, restoration order, all-clear criteria |
| Capture lessons | ID.IM-03/04 | IR-3(3), IR-4c | AAR delivered, corrective actions with owners and dates |
Regulatory clocks
Exercises stress-test whether your organization can actually hit these deadlines, not just recite them.
| Regime | Clock | Trigger |
|---|---|---|
| Securities and Exchange Commission (SEC) Form 8-K Item 1.05 | 4 business days | from materiality determination |
| General Data Protection Regulation (GDPR) Art. 33 | 72 hours | from becoming aware of a personal data breach |
| Health Insurance Portability and Accountability Act (HIPAA) Breach Notification Rule | 60 days | from discovery of the breach |
| New York Department of Financial Services (NYDFS) Part 500 | 72 hours | after determining a cybersecurity incident occurred; 24 hours after an extortion payment; 30-day written explanation of the payment |
| Network and Information Security Directive 2 (NIS2) | 24 hours early warning, 72 hours notification | from becoming aware of a significant incident |
| Digital Operational Resilience Act (DORA) | 4 hours initial notification | from classification of a major information and communications technology (ICT) incident |
| United States (US) state breach laws | 30 to 60 days where fixed | from discovery. California, Colorado, Florida and Washington are at 30 days and many states at 45 to 60; roughly 30 states require notice only without unreasonable delay |
| Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) | Proposed: 72 hours for a covered incident, 24 hours for a ransom payment | still a PROPOSED rule (notice of proposed rulemaking April 4, 2024). CISA's target for the final rule is September 2026; as of September 8, 2026 no final rule has been published and reporting is voluntary until it takes effect |
Clocks above are indicative and vary by jurisdiction, sector, and fact pattern — counsel confirms which regimes and deadlines actually apply to your incident. Each regime, with publisher and date, is listed on the sources and verification page (verified September 8, 2026).