Extortion and availability · 75 min · 4 injects
Ransomware in core operations
Order processing is encrypted at 06:10. A ransom note demands 40 BTC within 72 hours.
Photo: Rafael Minguet Delgado on Pexels
Crisis exercises for security and IT leaders
Put your executives inside a live ransomware attack, breach or fraud for one hour. Each makes private, timed decisions in their own role. You see where the plan holds and where it breaks, before an attacker shows you.
Have a room code?
Photo: Adrien Olichon on Pexels
13 crises, ready to run.
The problem
Too many teams find out during the incident. A plan written by one team and read by few others can’t show you how your CEO, CISO, CFO, counsel and comms lead decide together, with half the facts and the clock running.
Find out on a quiet Tuesday afternoon instead.
03:12, Saturday. A domain admin account signs in over VPN with no MFA challenge. By 06:10, order processing is encrypted and a ransom note demands 40 BTC.
Who decides whether to isolate every site? Who calls the insurer? Who warns the EU customers before their 24-hour notice window closes?
Photo: Mizuno K on Pexels
How it works
Launch a crisis
The facilitator picks a scenario, sets the chaos level and shares a five-letter room code.
Take a seat
Executives join from any browser, without an account, and choose their role: Chief Executive, CISO, CFO, General Counsel or Head of Comms.
Decide, reveal, debrief
Each role answers its own questions privately, against the clock. The facilitator reveals the turn, applies the consequences and escalates.


An hour in the room
The brief
The facilitator opens the first inject. Everyone sees the situation, plus private facts that only their role would know.
Private decisions
Each role answers its own questions against a five-minute timer. Nobody sees anyone else’s call.
The reveal
All answers appear at once. Consequences land and the scores move. This is where the disagreements surface.
Escalation
The crisis reacts to what you decided. A leaked sample, a regulator’s call, backups under fire: the next inject follows your choices.
The debrief
Walk through the timeline, the scores and the calls that mattered while the discussion is still fresh.
Photo: Mikhail Nilov on Pexels
What you get
Questions for each role
The CFO decides on the insurer, counsel on notification, the CISO on isolation. Everyone works on what they actually own, and a fallback role covers empty seats.
Escalations that follow your decisions
Rules watch the choices and propose the next inject. The facilitator confirms, swaps or skips it, so the exercise stays realistic without going off the rails.
Crisis committee
Some calls belong to the group. Put a committee on them, and the chair (the Chief Executive by default) records the joint decision.
Private until revealed
Nobody anchors on the boss’s answer. Choices stay hidden until the facilitator reveals the turn, and the database enforces it, not just the screen.
Audit timeline
Every action is logged with who and when, so the debrief works from facts, not memory.
Scored outcomes
Continuity, containment, legal, trust and recovery are scored after every turn, so you see which decision moved which risk.
Your own scenarios
Duplicate a built-in crisis and adapt it to your systems, suppliers and regulators, or write one from scratch.
English and Spanish
Each person picks their language, and the scenario follows. Regional teams can play in the same room.
A report you can hand over
Download a PDF with an executive summary for leadership and an evidence appendix for auditors: attendance, every decision with its time, missed calls and your notes.
Play it again, compare
Replay a finished exercise on the exact same path or a fresh one, then see the score, each dimension and every decision side by side with the first run.
AI copilot for the facilitator
After each reveal, get a risk summary drafted from what the room decided; after the exercise, a debrief narrative. Nothing reaches the room until you approve it.
Notes and an exercise library
Write private notes on each turn while it’s fresh. Find past exercises by status, scenario and date; archive what’s done.
What you walk away with
A score for each dimension
Where the response was strong and where it was exposed, across five dimensions.
The strongest decision and the largest risk
Named explicitly, so you know what to keep and what to fix first.
Every decision, with its reasoning
Each answer carries the rationale the executive wrote at the time, in their own words.
The full timeline
Every inject, decision and escalation with timestamps, ready for your after-action review.
A PDF report for leadership and auditors
Executive summary first, evidence after: who took part, what was missed or late, and what the facilitator observed.
Progress you can measure
Run the same crisis again and see exactly what improved, dimension by dimension.
Frameworks
Most security frameworks expect an incident response plan that has actually been tested. Pick the frameworks when you create an exercise, and the report maps every decision to their incident response controls: tested, gap or not exercised, with the evidence behind each.
SOC 2
CC7.4–CC7.5
Respond to and recover from security incidents
NIST
SP 800-61 · CSF 2.0
Incident response, Respond and Recover functions
ISO/IEC 27001
Annex A 5.24–5.27
Plan, assess, respond to and learn from incidents
PCI DSS
Requirement 12.10
An incident response plan, reviewed and tested every year
Critios isn't certified by or affiliated with these bodies. Exercises support your evidence; your auditor decides what satisfies a requirement.
Scenarios
From ransomware and insider theft to deepfake calls, phishing in your name, jammed signals and leaked cloud keys. Each has its own roles, private facts and escalations. Run it as is, or adapt it to your company.
Extortion and availability · 75 min · 4 injects
Ransomware in core operations
Order processing is encrypted at 06:10. A ransom note demands 40 BTC within 72 hours.
Photo: Rafael Minguet Delgado on Pexels
Insider and AI data leakage · 60 min · 4 injects
Salary & contract data breach
A spreadsheet with every salary and three unsigned vendor contracts is circulating outside the company.
Photo: Tima Miroshnichenko on Pexels
Financial and executive fraud · 45 min · 4 injects
Compromised corporate bank account
A $2.4M wire to a 'new supplier account' is pending release. The approval came from the CFO's mailbox.
Photo: Monstera Production on Pexels
Supply chain compromise · 45 min · 4 injects
Trojanized vendor update
A routine update from your IT management vendor installed a backdoor on 1,200 servers. The vendor hasn't confirmed anything yet.
Photo: Ollie Craig on Pexels
Insider threat · 45 min · 4 injects
Departing engineer takes customer data
A senior engineer resigned yesterday to join a competitor. Overnight, 380,000 customer records were exported from their account.
Photo: Jakub Zerdzicki on Pexels
Vulnerability and availability · 45 min · 4 injects
Zero-day in the customer portal
A researcher reports an unpatched flaw that lets anyone read other customers' accounts. The portal serves 2 million users.
Photo: Mathias Reding on Pexels
Advanced persistent threat · 60 min · 4 injects
The silent intruder
Threat hunting finds an attacker who has been inside your network for four months, reading executive email.
Photo: panumas nikhomkhai on Pexels
Physical intrusion · 45 min · 4 injects
The contractor who wasn't
A man with a forged maintenance badge spent 40 minutes in your data center. This morning, a small device was found plugged into a network switch.
Photo: Susanne Plank on Pexels
Executive impersonation · 45 min · 4 injects
The CEO's voice
A finance manager gets a call in the CEO's voice asking for a confidential $1.8M transfer for an acquisition. Half of it has already been sent.
Photo: energepic.com on Pexels
Brand impersonation · 45 min · 4 injects
Customers phished in your name
A cloned login page with your logo is stealing customer passwords through emails and text messages that look like yours.
Photo: RDNE Stock project on Pexels
Jamming and physical disruption · 45 min · 4 injects
Signals jammed
GPS and Wi-Fi go dark at your main distribution center: scanners, forklifts and truck tracking stop. Then an email demands payment to make it stop.
Photo: GB The Green Brand on Pexels
Extortion and availability · 45 min · 4 injects
Pay or go dark
Two days before your biggest sales weekend, a group knocks your checkout offline for ten minutes as a 'demo' and demands 15 BTC to leave you alone.
Photo: Kindel Media on Pexels
Cloud and human error · 45 min · 4 injects
Leaked cloud keys
A developer pushed cloud admin keys to a public code repository. Within an hour someone used them, and your cloud bill is climbing by the minute.
Photo: Luis Gomes on Pexels
Who it’s for
CISOs and security leaders
Test the plan with the executives who have to carry it out.
IT and operations
Rehearse containment and recovery, and the business calls that come with them.
Risk, legal and compliance
Practice notification deadlines and disclosure decisions before they are real.
Photo: August de Richelieu on Pexels
Questions
45 to 75 minutes, depending on the scenario. Plan another 15 minutes for the debrief.
No. They open a link or enter a five-letter room code in any browser, on a laptop or a phone. Only the facilitator signs in.
Yes. Everyone joins from their own browser, so a video call is enough. It works just as well with everyone in one room.
Until the facilitator reveals a turn, each person sees only their own answers, and the database enforces it. The room sees who has submitted, never what.
Yes. Duplicate a built-in crisis and edit it in a form editor, or write one from scratch. Past exercises keep the version they ran with.
Only to help the facilitator: a drafted risk summary after each reveal and a draft debrief narrative, built from decisions already revealed. Every draft is labelled, and nothing reaches the room or the report until the facilitator approves it.
Nothing. The pilot is one facilitated session for your five executive seats, including the debrief. There’s no commitment afterwards.
Free pilot
We facilitate one session for your executive team, then send you the debrief. No cost, no commitment.
Photo: Vitaly Gariev on Pexels
Want to see it first? The live demo takes five minutes and needs no sign-in.
See a live demo