Security

Your exercise is yours alone.

Cyber Ambush is built for governance, risk and compliance (GRC) and information security teams who have to answer for what a platform can see. Every exercise, inject, response, decision and after-action report is scoped to the organization that owns it and enforced in the database on every request.

Account isolation

Seven guarantees that keep one organization's exercise out of another's console.

Every record is filtered in the database, not the screen

Access rules live on the data itself. A request that asks for an exercise, inject, response, decision or after-action report belonging to another organization returns nothing at all. There is no client-side filter to bypass, and no shared query that could leak rows.

AC-3AC-4PR.AA-05

Organization membership decides the boundary

Each account belongs to exactly one organization. Sponsors and operators can only reach exercises owned by that organization; the check is evaluated on the server for every single read and write.

AC-2AC-6GV.RR

Participants see only the exercise they joined

A participant reads the situation brief, released injects and the roster for exercises they actually joined with a code — nothing before release, nothing from any other exercise, and no other participant's submissions.

AC-6PR.AA-05

Evaluations are never exposed to the people being evaluated

Scoring and evaluation content is stored apart from participant submissions and is readable only by sponsors and operators of the owning organization, so an exercise cannot be gamed from the inside.

AC-6(1)IR-3

Roles cannot be self-granted

A signed-in person can update their own name and department, but attempts to change their own role or move their account into another organization are rejected by the database itself.

AC-5AC-6(10)GV.RR-02

Live updates inherit the same rules

Real-time exercise traffic is delivered through the same access rules as ordinary reads, so nothing is broadcast to an account that could not already request it.

SC-8AC-4

Contact form is write-only

Inquiries submitted from the public contact form can be created but not read back through the public interface, so form data cannot be enumerated.

SI-10SC-7

Control mapping — NIST SP 800-53 Rev. 5

  • AC-2 / AC-3Account management & access enforcement

    Accounts are provisioned per organization with a single role each; enforcement happens server-side on every request.

  • AC-6Least privilege

    Participants get the narrowest view that still lets them play; only sponsors and operators can plan, approve, release or score.

  • AU-2 / AU-3Audit events & content

    Exercise records keep who released each inject, who committed each response, who approved guidance, who called ENDEX and when.

  • IA-2 / IA-5Identification & authenticator management

    Email and password sign-in with managed sessions; passwords are never stored by the application.

  • IR-2 / IR-3 / IR-8IR training, testing and plan

    Each completed exercise is documented, scored evidence of incident response training and annual testing against your own plan.

  • SC-8 / SC-13Transmission confidentiality & cryptography

    All traffic is served over HTTPS; data at rest is encrypted by the managed cloud platform.

  • CA-7 / RA-5Continuous monitoring & vulnerability management

    Automated access-rule and dependency scans run against the platform, and findings are remediated before release.

What auditors ask for

The evidence a Cyber Ambush exercise produces, lined up against the expectation it satisfies.

Compliance expectations & evidence

StandardExpectationEvidence produced
NIST CSF 2.0GV.RR, ID.IM, RS.MA, RS.CO outcomes are exercised and improved on a cycle.Objective-by-objective ratings and corrective actions in each after-action report.
NIST SP 800-53 Rev. 5IR-2, IR-3, IR-4, IR-6, IR-8 implemented and tested.Dated exercise record, participant roster, inject timeline and improvement plan.
NIST SP 800-171 Rev. 33.6.1 – 3.6.3 incident handling capability, tested periodically.Exercise export retained as the periodic test artefact.
ISO/IEC 27001:2022A.5.24 – A.5.27 incident management planning, assessment and learning.After-action report plus tracked corrective actions with owners and due dates.
SOC 2 (Availability / Confidentiality)CC7.3 – CC7.5 incident evaluation, response and recovery.Exercise timeline, decision log and remediation follow-through.
CIS Controls v8Control 17.1 – 17.8 incident response process, roles and exercises.Assigned roles in the exercise plus the scored exercise record.
PCI DSS v4.0Requirement 12.10 incident response plan tested at least annually.Annual tabletop record with findings and plan updates.
HIPAA Security Rule164.308(a)(6) security incident procedures and response.Documented response walk-through and notification-clock decisions.

Running exercises securely — practitioner guidance

  • Use a distinct account per person — shared logins destroy the audit trail that makes an exercise defensible.
  • Treat join codes as short-lived exercise material: share them in the channel your participants already trust, and run a new exercise rather than reusing an old code.
  • Keep real casework out of injects. Write scenarios with realistic but synthetic names, systems and customer data.
  • Nominate a sponsor who is genuinely authorized to make the decisions the scenario demands, or the escalation test proves nothing.
  • Export the after-action report at the end of the exercise and file it with your compliance evidence while the detail is fresh.
  • Close corrective actions in your own tracker with an owner and a date — an unowned finding is not remediation.

Scope & honest limits

  • Not a certification — Cyber Ambush produces evidence that supports an assessment. It does not issue an attestation, and no platform can certify your program on your behalf.
  • Not a legal opinion — notification clocks and regulatory references are exercise material for practice and discussion. Confirm your real obligations with counsel.
  • Exercise data only — the platform is designed for synthetic scenario content. Do not enter live case material, regulated personal data or production secrets.
  • Demo mode is a sample — the DEMO toggle shows a fixed sample exercise that is never written to your organization's records.

Want the framework detail behind the scoring? See how exercises map to NIST CSF 2.0, or ask us a security question.