Framework

Built on NIST, run like HSEEP.

Cyber Ambush is a tabletop exercise (TTX) platform. We're lightyears beyond a static slideshow with a role-play script. Every objective, inject, and after-action item traces to the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) 2.0, NIST Special Publication (SP) 800-61r3 incident response, SP 800-84 exercise guidance, the SP 800-53 incident response (IR) control family, and the Homeland Security Exercise and Evaluation Program (HSEEP) / Cybersecurity and Infrastructure Security Agency (CISA) Cyber Tabletop Exercise Package (CTEP) exercise lifecycle. Your tabletop produces evidence, not just a good story.

NIST Cybersecurity Framework (CSF) 2.0

The six CSF 2.0 functions organize every scenario. Categories below are the exercise-relevant subset Cyber Ambush scores against.

GV — GOVERN

  • GV.OCOrganizational Context

    Scenario scoping ties injects to mission-critical services and stakeholders identified in your context statement.

  • GV.RMRisk Management Strategy

    Exercise objectives are drawn directly from your organization's stated risk tolerance and priorities.

  • GV.RRRoles, Responsibilities & Authorities

    Master Scenario Events List (MSEL) escalation injects test whether the right person actually has, and uses, decision authority.

  • GV.SCCybersecurity Supply Chain Risk Management

    Vendor and third-party notification injects verify contracts, contacts, and escalation paths are current.

ID — IDENTIFY

  • ID.IMImprovement

    After action review (AAR) findings feed directly back into ID.IM as tracked corrective actions with owners and dates.

PR — PROTECT

  • PR.AAIdentity Management, Authentication & Access Control

    Help-desk reset, multi-factor authentication (MFA) re-enrollment and privileged-access injects test who can grant access under pressure.

  • PR.IRTechnology Infrastructure Resilience

    Segmentation, backup isolation and hypervisor-protection injects test whether the environment can absorb the attack it is designed to resist.

DE — DETECT

  • DE.CMContinuous Monitoring

    Injects simulate monitoring alerts to test whether analysts correctly triage signal from noise.

  • DE.AEAdverse Event Analysis

    Time-to-declare metrics are scored against DE.AE analysis expectations for the exercise scenario.

RS — RESPOND

  • RS.MAIncident Management

    The facilitator tracks incident declaration, severity assignment, and management activation against the clock.

  • RS.ANIncident Analysis

    Forensic-preservation injects force a choice between fast containment and evidence integrity.

  • RS.COIncident Response Reporting & Communication

    Notification-clock injects check legal, regulatory, and executive communications against real deadlines.

  • RS.MIIncident Mitigation

    Containment decisions are scored on whether they stop the bleeding without destroying the evidence.

RC — RECOVER

  • RC.RPIncident Recovery Plan Execution

    Restoration injects test backup integrity checks and restoration sequencing before systems go live again.

  • RC.COIncident Recovery Communication

    All-clear criteria and customer/stakeholder messaging are drafted and reviewed live during the exercise.

SP 800-61r3 — Incident Response Lifecycle

  • CSF-aligned lifecycle — 800-61r3 retires the old "phases" model in favor of mapping incident handling directly onto CSF 2.0 functions. Cyber Ambush scenarios follow that same mapping end to end.
  • Triage by risk — injects force prioritization decisions under time pressure, scored against organizational risk tolerance rather than a fixed checklist.
  • Evidence integrity — containment injects are written so speed and forensic preservation are in tension, the way they are in a real breach.
  • Leadership status updates — the MSEL schedules executive briefings so participants practice giving accurate, calibrated status without over- or under-committing.

SP 800-84 — Test, Training & Exercise Guidance

  • Design & development — objectives, scope, and MSEL are built before day of, per 800-84's exercise planning cycle.
  • Conduct — the platform runs facilitator and evaluator consoles side by side so injects and observations happen in real time.
  • Evaluation — evaluators score each objective against pre-defined success criteria, not after-the-fact impressions.
  • Facilitator & evaluator roles — the console keeps injects, timing, and scoring in separate lanes so one person running the room doesn't also have to grade it.
  • Required AAR content — exercise summary, objective-by-objective analysis, strengths, areas for improvement, and an improvement plan with owners and dates — generated directly from the exercise record.

SP 800-53 — Incident Response (IR) Control Family

  • IR-2Incident Response Training

    Every exercise counts as documented, hands-on IR training for the participants involved.

  • IR-3Incident Response Testing

    Cyber Ambush tabletops satisfy the IR-3 annual testing requirement with a scored, repeatable record.

  • IR-4Incident Handling

    Scenario injects walk the full handling lifecycle: detection, analysis, containment, eradication, recovery.

  • IR-6Incident Reporting

    Notification-clock injects test whether the right reports reach the right parties inside the deadline.

  • IR-8Incident Response Plan

    The exercise is scored against your actual IR plan, and gaps in the plan surface as AAR corrective actions.

HSEEP / CISA Cyber Tabletop Exercise Package (CTEP)

  • Situation Manual — the scenario brief participants read before the exercise, generated from your objectives and threat profile.
  • MSEL — the Master Scenario Events List drives every inject, timed and sequenced against exercise objectives.
  • Evaluation guides — objective-specific evaluator guides define what "good" looks like before the exercise starts, not after.
  • After Action Review / Improvement Plan (AAR/IP) delivery — HSEEP practice is a draft after action report about 30 days after the exercise, with the final AAR/Improvement Plan typically within 60 to 90 days (older HSEEP guidance; agencies set their own deadlines). Cyber Ambush drafts the AAR/IP the same day, so those windows are a review period rather than a scramble.

Exercise objective → CSF 2.0 outcome → SP 800-53 control → after action review (AAR) evidence

The full traceability chain Cyber Ambush maintains from planning through the after-action report.

Exercise objective→ CSF 2.0 outcome→ SP 800-53 control→ AAR evidence
Recognize and declare an incidentDE.AE, RS.MA-01IR-4, IR-6time to declaration, severity assigned
Escalate to executivesGV.RR, RS.COIR-8, IR-6decision-makers reached, authority documented
Contain without destroying evidenceRS.MI, RS.ANIR-4(12)isolation decisions, forensic preservation
Meet notification clocksRS.CO-02/03IR-6, IR-4(8)SEC/GDPR/HIPAA/state timelines identified
Coordinate vendors, insurer, law enforcementGV.SC, RS.COIR-4(10), IR-7contacts and contracts current
Restore and verifyRC.RP, RC.COIR-4(3), CP-10backup integrity, restoration order, all-clear criteria
Capture lessonsID.IM-03/04IR-3(3), IR-4cAAR delivered, corrective actions with owners and dates

Regulatory clocks

Exercises stress-test whether your organization can actually hit these deadlines, not just recite them.

RegimeClockTrigger
Securities and Exchange Commission (SEC) Form 8-K Item 1.054 business daysfrom materiality determination
General Data Protection Regulation (GDPR) Art. 3372 hoursfrom becoming aware of a personal data breach
Health Insurance Portability and Accountability Act (HIPAA) Breach Notification Rule60 daysfrom discovery of the breach
New York Department of Financial Services (NYDFS) Part 50072 hoursafter determining a cybersecurity incident occurred; 24 hours after an extortion payment; 30-day written explanation of the payment
Network and Information Security Directive 2 (NIS2)24 hours early warning, 72 hours notificationfrom becoming aware of a significant incident
Digital Operational Resilience Act (DORA)4 hours initial notificationfrom classification of a major information and communications technology (ICT) incident
United States (US) state breach laws30 to 60 days where fixedfrom discovery. California, Colorado, Florida and Washington are at 30 days and many states at 45 to 60; roughly 30 states require notice only without unreasonable delay
Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA)Proposed: 72 hours for a covered incident, 24 hours for a ransom paymentstill a PROPOSED rule (notice of proposed rulemaking April 4, 2024). CISA's target for the final rule is September 2026; as of September 8, 2026 no final rule has been published and reporting is voluntary until it takes effect

Clocks above are indicative and vary by jurisdiction, sector, and fact pattern — counsel confirms which regimes and deadlines actually apply to your incident. Each regime, with publisher and date, is listed on the sources and verification page (verified September 8, 2026).