Crisis exercises for security and IT leaders

Rehearse the worst day before it happens.

Put your executives inside a live ransomware attack, breach or fraud for one hour. Each makes private, timed decisions in their own role. You see where the plan holds and where it breaks, before an attacker shows you.

  • Free facilitated pilot
  • No accounts for participants
  • 45–75 minutes

Have a room code?

Photo: Adrien Olichon on Pexels

13 crises, ready to run.

The problem

Response plans are tested on paper, not under pressure.

Too many teams find out during the incident. A plan written by one team and read by few others can’t show you how your CEO, CISO, CFO, counsel and comms lead decide together, with half the facts and the clock running.

Find out on a quiet Tuesday afternoon instead.

03:12, Saturday. A domain admin account signs in over VPN with no MFA challenge. By 06:10, order processing is encrypted and a ransom note demands 40 BTC.

Who decides whether to isolate every site? Who calls the insurer? Who warns the EU customers before their 24-hour notice window closes?

Photo: Mizuno K on Pexels

How it works

One room. Private decisions. A shared debrief.

  1. 01

    Launch a crisis

    The facilitator picks a scenario, sets the chaos level and shares a five-letter room code.

  2. 02

    Take a seat

    Executives join from any browser, without an account, and choose their role: Chief Executive, CISO, CFO, General Counsel or Head of Comms.

  3. 03

    Decide, reveal, debrief

    Each role answers its own questions privately, against the clock. The facilitator reveals the turn, applies the consequences and escalates.

A participant’s private decision, with the turn timer running
A participant’s private decision, with the turn timer running
The facilitator’s table: who has answered, with answers hidden until reveal
The facilitator’s table: who has answered, with answers hidden until reveal

An hour in the room

What the hour looks like.

  1. T+0

    The brief

    The facilitator opens the first inject. Everyone sees the situation, plus private facts that only their role would know.

  2. T+5

    Private decisions

    Each role answers its own questions against a five-minute timer. Nobody sees anyone else’s call.

  3. T+10

    The reveal

    All answers appear at once. Consequences land and the scores move. This is where the disagreements surface.

  4. T+15

    Escalation

    The crisis reacts to what you decided. A leaked sample, a regulator’s call, backups under fire: the next inject follows your choices.

  5. T+45

    The debrief

    Walk through the timeline, the scores and the calls that mattered while the discussion is still fresh.

Photo: Mikhail Nilov on Pexels

What you get

Built for the room, not the slide deck.

  • Questions for each role

    The CFO decides on the insurer, counsel on notification, the CISO on isolation. Everyone works on what they actually own, and a fallback role covers empty seats.

  • Escalations that follow your decisions

    Rules watch the choices and propose the next inject. The facilitator confirms, swaps or skips it, so the exercise stays realistic without going off the rails.

  • Crisis committee

    Some calls belong to the group. Put a committee on them, and the chair (the Chief Executive by default) records the joint decision.

  • Private until revealed

    Nobody anchors on the boss’s answer. Choices stay hidden until the facilitator reveals the turn, and the database enforces it, not just the screen.

  • Audit timeline

    Every action is logged with who and when, so the debrief works from facts, not memory.

  • Scored outcomes

    Continuity, containment, legal, trust and recovery are scored after every turn, so you see which decision moved which risk.

  • Your own scenarios

    Duplicate a built-in crisis and adapt it to your systems, suppliers and regulators, or write one from scratch.

  • English and Spanish

    Each person picks their language, and the scenario follows. Regional teams can play in the same room.

  • A report you can hand over

    Download a PDF with an executive summary for leadership and an evidence appendix for auditors: attendance, every decision with its time, missed calls and your notes.

  • Play it again, compare

    Replay a finished exercise on the exact same path or a fresh one, then see the score, each dimension and every decision side by side with the first run.

  • AI copilot for the facilitator

    After each reveal, get a risk summary drafted from what the room decided; after the exercise, a debrief narrative. Nothing reaches the room until you approve it.

  • Notes and an exercise library

    Write private notes on each turn while it’s fresh. Find past exercises by status, scenario and date; archive what’s done.

What you walk away with

Leave with evidence, not impressions.

  • A score for each dimension

    Where the response was strong and where it was exposed, across five dimensions.

  • The strongest decision and the largest risk

    Named explicitly, so you know what to keep and what to fix first.

  • Every decision, with its reasoning

    Each answer carries the rationale the executive wrote at the time, in their own words.

  • The full timeline

    Every inject, decision and escalation with timestamps, ready for your after-action review.

  • A PDF report for leadership and auditors

    Executive summary first, evidence after: who took part, what was missed or late, and what the facilitator observed.

  • Progress you can measure

    Run the same crisis again and see exactly what improved, dimension by dimension.

Frameworks

Rehearse what your auditors ask for.

Most security frameworks expect an incident response plan that has actually been tested. Pick the frameworks when you create an exercise, and the report maps every decision to their incident response controls: tested, gap or not exercised, with the evidence behind each.

  • SOC 2

    CC7.4–CC7.5

    Respond to and recover from security incidents

  • NIST

    SP 800-61 · CSF 2.0

    Incident response, Respond and Recover functions

  • ISO/IEC 27001

    Annex A 5.24–5.27

    Plan, assess, respond to and learn from incidents

  • PCI DSS

    Requirement 12.10

    An incident response plan, reviewed and tested every year

Critios isn't certified by or affiliated with these bodies. Exercises support your evidence; your auditor decides what satisfies a requirement.

Scenarios

13 crises, ready to run.

From ransomware and insider theft to deepfake calls, phishing in your name, jammed signals and leaked cloud keys. Each has its own roles, private facts and escalations. Run it as is, or adapt it to your company.

  • Extortion and availability · 75 min · 4 injects

    Ransomware in core operations

    Order processing is encrypted at 06:10. A ransom note demands 40 BTC within 72 hours.

    Photo: Rafael Minguet Delgado on Pexels

  • Insider and AI data leakage · 60 min · 4 injects

    Salary & contract data breach

    A spreadsheet with every salary and three unsigned vendor contracts is circulating outside the company.

    Photo: Tima Miroshnichenko on Pexels

  • Financial and executive fraud · 45 min · 4 injects

    Compromised corporate bank account

    A $2.4M wire to a 'new supplier account' is pending release. The approval came from the CFO's mailbox.

    Photo: Monstera Production on Pexels

  • Supply chain compromise · 45 min · 4 injects

    Trojanized vendor update

    A routine update from your IT management vendor installed a backdoor on 1,200 servers. The vendor hasn't confirmed anything yet.

    Photo: Ollie Craig on Pexels

  • Insider threat · 45 min · 4 injects

    Departing engineer takes customer data

    A senior engineer resigned yesterday to join a competitor. Overnight, 380,000 customer records were exported from their account.

    Photo: Jakub Zerdzicki on Pexels

  • Vulnerability and availability · 45 min · 4 injects

    Zero-day in the customer portal

    A researcher reports an unpatched flaw that lets anyone read other customers' accounts. The portal serves 2 million users.

    Photo: Mathias Reding on Pexels

  • Advanced persistent threat · 60 min · 4 injects

    The silent intruder

    Threat hunting finds an attacker who has been inside your network for four months, reading executive email.

    Photo: panumas nikhomkhai on Pexels

  • Physical intrusion · 45 min · 4 injects

    The contractor who wasn't

    A man with a forged maintenance badge spent 40 minutes in your data center. This morning, a small device was found plugged into a network switch.

    Photo: Susanne Plank on Pexels

  • Executive impersonation · 45 min · 4 injects

    The CEO's voice

    A finance manager gets a call in the CEO's voice asking for a confidential $1.8M transfer for an acquisition. Half of it has already been sent.

    Photo: energepic.com on Pexels

  • Brand impersonation · 45 min · 4 injects

    Customers phished in your name

    A cloned login page with your logo is stealing customer passwords through emails and text messages that look like yours.

    Photo: RDNE Stock project on Pexels

  • Jamming and physical disruption · 45 min · 4 injects

    Signals jammed

    GPS and Wi-Fi go dark at your main distribution center: scanners, forklifts and truck tracking stop. Then an email demands payment to make it stop.

    Photo: GB The Green Brand on Pexels

  • Extortion and availability · 45 min · 4 injects

    Pay or go dark

    Two days before your biggest sales weekend, a group knocks your checkout offline for ten minutes as a 'demo' and demands 15 BTC to leave you alone.

    Photo: Kindel Media on Pexels

  • Cloud and human error · 45 min · 4 injects

    Leaked cloud keys

    A developer pushed cloud admin keys to a public code repository. Within an hour someone used them, and your cloud bill is climbing by the minute.

    Photo: Luis Gomes on Pexels

Who it’s for

For the people who own the response.

  • CISOs and security leaders

    Test the plan with the executives who have to carry it out.

  • IT and operations

    Rehearse containment and recovery, and the business calls that come with them.

  • Risk, legal and compliance

    Practice notification deadlines and disclosure decisions before they are real.

Photo: August de Richelieu on Pexels

Questions

Before you ask.

How long does a session take?

45 to 75 minutes, depending on the scenario. Plan another 15 minutes for the debrief.

Do participants need an account or an install?

No. They open a link or enter a five-letter room code in any browser, on a laptop or a phone. Only the facilitator signs in.

Can we run it remotely?

Yes. Everyone joins from their own browser, so a video call is enough. It works just as well with everyone in one room.

Who can see our answers?

Until the facilitator reveals a turn, each person sees only their own answers, and the database enforces it. The room sees who has submitted, never what.

Can we use our own scenario?

Yes. Duplicate a built-in crisis and edit it in a form editor, or write one from scratch. Past exercises keep the version they ran with.

Does it use AI?

Only to help the facilitator: a drafted risk summary after each reveal and a draft debrief narrative, built from decisions already revealed. Every draft is labelled, and nothing reaches the room or the report until the facilitator approves it.

What does the pilot cost?

Nothing. The pilot is one facilitated session for your five executive seats, including the debrief. There’s no commitment afterwards.

Free pilot

Run your first exercise with us.

We facilitate one session for your executive team, then send you the debrief. No cost, no commitment.

We only use your details to arrange the pilot.

Photo: Vitaly Gariev on Pexels

  • One facilitated session, 45–75 minutes
  • Five executive seats, no accounts needed
  • PDF report with scores, decisions and the full timeline
  • A reply within 2 business days

Want to see it first? The live demo takes five minutes and needs no sign-in.

See a live demo