Skip to content
CybertactikRequest a demo

Rehearse the cyber crisis before it is real.

Eight roles, a clock that does not stop, evidence buried in real logs, decisions that cost money, and at the end the report your board reads.

Silent loop of a Cybertactik session: the clock at T+0, the service tiles, and the first inject arriving.

What passes for a crisis exercise today

  • The exercise is a slide deck and a facilitator reading from it.
  • Nobody decides anything and nothing costs anything.
  • The report is the same deck with a date on it.

How a session plays

A crisis cell of up to eight people, each in their own role, in a browser. The clock runs on the server, not on anyone's laptop. Nobody installs anything: an invitation link carries the mission brief and opens one seat, with no password to remember.

T+0. The room opens.

The clock starts and the first inject lands on the roles it is addressed to. Eleven hospital services run down the right side, each one up or down. Five gauges read Services, Threat, Capacity, Trust and Team. A counter adds up what the crisis is costing, in euros, for every hour a service stays down.

The Cybertactik room just after T+0: the session clock counting down in the header, the five gauges and the eleven hospital service tiles in the right-hand panel, and the first inject arriving in the channel.

A wrong answer has a price.

The SOC opens a VPN log and has to name the account that opened a session from outside the perimeter at 02:09. Answer wrong and a legitimate radiologist is locked out. Stress climbs, the cost counter moves, and the whole room watches it happen.

An investigation card open on the SOC seat: the VPN log in monospace, the question under it, an answer field, and the false-lead message posted on the channel.

What one role finds unlocks another.

The right answer becomes a discovery written on the shared timeline. The SOC transmits it to the roles that need it, and a card that was blocked opens up on the Communication seat. Nobody gets through this alone.

A discovery on the timeline and the transmit dialog, with Incident Commander, Communication and Legal already ticked.

Hesitate and the room slows down.

The crisis cell was meant to be activated in the first few minutes. When it is not, the scenario says so, and the Team gauge climbs to 4 of 5. At stress 4 or above every action takes half again as long. Exactly like a real one.

The room's gauge panel: Services, Threat, Capacity, Trust, and Team stress at 4 out of 5, with the slowdown notice under the gauges.

The document that outlives the exercise

When the clock runs out the debrief opens for everyone. Every decision is put back in order with the time it happened, the five scores come out of what the room actually did, and the written account is generated from the real transcript.

  • A timestamped timeline of every decision
  • Five scores
  • The key moments, each with its time on the clock
  • A written after-action narrative

This is the document a board, an insurer or an auditor reads.

Scenarios

One scenario is published and playable today. Three more are being written.

  • Available

    Hospital: patient data breach

    An endpoint alert at 06:40 that nobody has read, and 48,200 patient records that left the building overnight, between 02:14 and 04:36. Eleven hospital services, forty-five minutes on the clock.

  • Coming

    Factory: DDoS and production stoppage

    A denial of service on the plant network, and a production line at a standstill.

  • Coming

    Warehouse: ransomware and blocked shipments

    Ransomware in the warehouse systems, and shipments that stop leaving the dock.

  • Coming

    Hospital: pharmacy paralysed

    The hospital pharmacy is at a standstill and the wards still need their medication.

Create your own cyber crisis scenarios

Five steps take a scenario from a draft to a published version. A validator checks that it holds together before anyone can publish, and a published version stays fixed, so a session always knows exactly what it is playing. Your own staff can author in it, and Brainstorm writes a client's first scenario with them.

See the configurator
Create your own cyber crisis scenarios

Where it goes

Three directions the product is heading. None of this is in it today.

  • Scenarios built from your own context

    A scenario drawn from the organisation's sector, its size and its continuity plans, then refined by the facilitator before anyone plays it.

  • Counterparts played by AI

    The journalist, the regulator, the insurer and the attacker answering for themselves instead of arriving as a message written in advance.

  • The same room on the real day

    The room used to run an actual incident, with the same clock, the same roles and the same record of who decided what.

Who makes it

Cybertactik is a product of Brainstorm CyberRisk, an independent advisory firm working across Montréal, Paris and Martinique. The firm is led by its founder, Tania Tanic, who runs crisis exercises for leadership teams.

brainstorm-cyberrisk.com

Request a demo

Tell us who you are and Brainstorm sets up a session. You watch a crisis cell play the hospital scenario, then you read the report it produced.

What you send is used to answer you and for nothing else. See the privacy policy.

Rehearse it.