ROADMAP
What we're building next.
We are continuously improving Cyber Ambush. Customers and pilot participants shape what comes next. Here's what's available, what we're working on now, and what's planned. Timing is a target, not a commitment.
Available9
Enforced multi-factor authentication
Every account uses an authenticator app; enforced in the database on every request.
Organization isolation in the database
Every exercise, response and after-action review is scoped to its owning organization server-side.
Live exercise clock and timed injects
One shared clock for distributed teams; injects released on time or automatically.
AI Planning Assistant
Scenario shaping, inject drafting and guidance review for Sponsors and Operators only.
Instant after-action review
AI-drafted after-action review at end of exercise (ENDEX), mapped to NIST CSF 2.0, SP 800-61r3, SP 800-84 and HSEEP; human-approved before it circulates.
Evaluator and Observer seats
Read-only seats with private notes per objective, for auditors, insurers and board members.
Corrective actions carry forward
Open findings return as injects in your next exercise.
Twelve-vector inject library
Reusable injects tagged by vector, severity and CSF function.
Improvement plan tracking
Track corrective actions to closure with owners, due dates and status in the platform.
Now2
SOC 2 Type I
Our examination is in progress; the report will be available under NDA once issued.
New scenario packs
Healthcare, financial services and professional services scenarios built from current threat activity.
Next8
SAML 2.0 single sign-on
Sign in with your identity provider (for example Microsoft Entra ID, Okta or Google Workspace) and apply your own MFA and access policies.
SCIM user provisioning
Add and remove users automatically from your identity provider.
Independent penetration test
Third-party testing of the platform, with a summary letter available on request.
Audit log export
Export a complete account and exercise activity log for your own records.
Corrective-action export
Send findings to Jira, ServiceNow or CSV with owners and due dates.
Microsoft Teams and Slack delivery
Deliver injects and exercise alerts where your team already works.
One-click CISA package import
Turn a CISA Tabletop Exercise Package into a timed Cyber Ambush exercise.
Partner console for MSPs and consultancies
Multi-tenant client workspaces, white-label AARs and consolidated billing.
Later6
SOC 2 Type II
Ongoing assurance over the operating effectiveness of our controls.
Executive and board mode
A shorter format focused on disclosure, materiality and crisis communication decisions.
Configurable data retention
Choose how long exercise records are kept.
Accessibility conformance report
Published VPAT against WCAG 2.2 AA.
Sector packs for K-12, local government and manufacturing (OT/ICS)
Scenarios and objectives tailored to each sector's realities.
Spanish-language exercises
Run exercises with Spanish-speaking teams.
Have a feature request or need something for a vendor review? Email cyberambush@sterlingllc.com.
Last updated October 4, 2026