Run tabletop exercises that prove readiness,
not just attendance.
TTXLab gives security, resilience, and governance teams guided simulations, role-based prompts, and audit-ready reports without waiting weeks for a facilitator.
No account or credit card required for the live demo.
Veteran-owned and operated.
IR Exercise — Ransomware Scenario
Acme Corp · Started 2:47 PM
How It Works
From scenario setup to after-action report
in one guided workflow.
Invite the people who own the response
Create the workspace, add participants, and give each role a clear place in the run.
Choose the scenario and roles
Select the exercise type, tune the scenario, and confirm who owns decisions, communications, and recovery.
Run the live tabletop
The AI facilitator delivers injects, prompts the right roles, and captures the transcript as the team responds.
Leave with evidence and actions
Export scores, findings, transcript detail, and remediation direction leadership and audit teams can use.
Audit-Ready Reports
One report for leadership, responders,
and auditors.
Every completed run ends with scores, transcript context, findings, and action items in one artifact instead of scattered notes and screenshots.
IR Exercise — Ransomware Scenario
Communication
85%
Decision Making
72%
Escalation
68%
Procedures
88%
Improve escalation timing for legal notification
NIST SP 800-61Legal was notified 12 minutes after containment. Target notification within 5 minutes of confirmed data exposure.
Establish pre-drafted holding statements
SANS IRCommunications team did not have pre-approved templates available. Pre-draft statements for top 3 scenario types.
Formalize evidence preservation checklist
ISO 27035No explicit evidence preservation step was triggered. Add forensic hold checklist to incident playbook.
Complete transcript
Timestamped record of facilitator prompts, participant responses, and decision points from the full run.
Scored performance
Track all five scoring dimensions — communication, decision quality, role adherence, escalation, and procedural compliance — in one summary view.
Sourced recommendations
Each recommendation is tied to recognized frameworks instead of unsourced generic AI guidance.
Auditor-ready PDF
Export a structured artifact that leadership, compliance, and audit stakeholders can review quickly.
Exercise Library
Pick the scenario.
Keep the operating model.
Run different tabletop scenarios through the same facilitation, scoring, and reporting workflow so teams can compare performance over time.
IR Incident Response
Coordinate detection, containment, eradication, and recovery actions.
Default Roles
What Gets Tested
- Detection and triage speed
- Cross-team escalation
- Containment decision-making
- Evidence preservation
- Post-incident review
Example Scenario
A SOC analyst flags anomalous outbound traffic from a payment processing server at 2 AM. The team must coordinate containment while preserving forensic evidence.Explore Incident Response→
WV Executive Workplace Violence
Practice executive crisis coordination for workplace violence and active assailant scenarios.
Default Roles
What Gets Tested
- Crisis activation
- Employee protective action communications
- Law enforcement and medical coordination
- Employee accountability and family support
- Business continuity and recovery planning
Example Scenario
Conflicting employee reports suggest a possible active assailant near headquarters. Leaders must activate crisis coordination, communicate with employees, coordinate with law enforcement, account for personnel, and plan continuity.Explore Executive Workplace Violence→
BCP Business Continuity Planning
Maintain critical business operations through disruptive events.
Default Roles
What Gets Tested
- Business impact assessment
- Alternate operations activation
- Stakeholder communication
- Recovery prioritization
Example Scenario
A regional data center loses power during peak hours. Teams must activate continuity plans and reroute critical services within the defined RTO.Explore Business Continuity Planning→
DR Disaster Recovery
Restore IT systems, applications, and data after outages.
Default Roles
What Gets Tested
- System restoration sequencing
- Backup validation
- RTO/RPO adherence
- Failover coordination
Example Scenario
A corrupted storage array takes the primary database offline. The team must restore from backups and verify data integrity before resuming operations.Explore Disaster Recovery→
CC Crisis Communication
Align internal and external communications during incidents.
Default Roles
What Gets Tested
- Message consistency
- Stakeholder mapping
- Media response timing
- Internal alignment
Example Scenario
News outlets begin reporting on a suspected data breach before the company has confirmed details. The comms team must align internal and external statements under time pressure.Explore Crisis Communication→
RW Ransomware
Drive executive and technical response to ransomware events.
Default Roles
What Gets Tested
- Ransom decision framework
- Lateral movement containment
- Legal and regulatory notification
- Decryption assessment
- Business impact quantification
Example Scenario
Encrypted file extensions appear across shared drives and a ransom note demands payment in 48 hours. Leadership must decide on negotiation posture while technical teams isolate affected systems.Explore Ransomware→
VR Third-Party / Vendor Risk
Respond to disruptive events originating from critical vendors.
Default Roles
What Gets Tested
- Vendor communication protocols
- Contractual obligation review
- Supply chain impact assessment
- Alternate vendor activation
Example Scenario
A critical SaaS provider notifies your team of a breach affecting shared credentials. The team must assess downstream exposure and activate contingency agreements.Explore Third-Party / Vendor Risk→
DB Data Breach Response
Handle confirmed exposure of sensitive customer and employee data.
Default Roles
What Gets Tested
- PII exposure scoping
- Regulatory notification timelines
- Affected party communication
- Forensic chain of custody
Example Scenario
An engineer discovers a misconfigured S3 bucket has been publicly accessible for 72 hours containing employee PII. The team must scope the exposure and initiate breach notification procedures.Explore Data Breach Response→
IT Insider Threat
Coordinate cross-functional response to malicious or negligent insiders.
Default Roles
What Gets Tested
- Behavioral indicator recognition
- Cross-functional coordination
- Legal and HR engagement
- Access revocation procedures
Example Scenario
A departing employee's badge access logs show after-hours entry to a restricted area. IT flags large file transfers to personal cloud storage over the past week.Explore Insider Threat→
How the AI Works
Fast facilitation. Careful reporting.
A fast facilitator keeps the exercise moving. A deliberate adjudicator scores the run and builds the report. Two specialized models work together so practice feels live and the final artifact holds up in review.
The Facilitator
Drives the live run by introducing injects, adapting scenario progression, and prompting the right role.
- ✓ Adaptive live facilitation
- ✓ Dynamic scenario adaptation
- ✓ Role-aware question targeting
- ✓ Incident inject generation
The Adjudicator
Scores responses, applies guardrails, and generates reporting your governance stakeholders can rely on.
- ✓ Reports built for review
- ✓ NIST / SANS / ISO citation support
- ✓ Gap analysis and remediation direction
- ✓ Content and tone guardrails
CISA Template Library
Public-sector scenarios,
ready for live tabletop runs.
Pricing
Choose the cadence your readiness program can sustain.
Buy one run, schedule quarterly practice, or build a monthly program. Every paid tier includes facilitated exercises, report exports, and the full exercise library.
Pay Per Exercise
$299
one-time purchase
$299/exercise
Best when you need one documented run for a pilot, audit cycle, or board update.
- ✓ 1 exercise credit
- ✓ Any exercise type
- ✓ Full report export
- ✓ 90-day artifact access
Starter Annual
$999
per year · 4 exercises/year
$250/exercise — save $49 each
For smaller teams that want a repeatable quarterly cadence without monthly billing.
- ✓ 4 exercise credits/year
- ✓ Role-based facilitation
- ✓ Annual readiness reporting
Professional
$199
per month · 12 exercises/year
~$199/exercise — save $100 each
For teams running monthly exercises and tracking readiness improvements over time.
- ✓ 12 exercise credits/year
- ✓ All exercise types
- ✓ Exercise history and dashboard metrics
- ✓ Scheduling and reminders
- ✓ Priority support queue
Enterprise
Custom
contract pricing
For multi-team organizations that need procurement support, governance, and rollout control.
- ✓ Everything in Professional
- ✓ SSO / SAML enablement
- ✓ Custom report branding
- ✓ Cross-team benchmarking
- ✓ Unlimited participants
- ✓ SLA-backed uptime (see Trust Center)
- ✓ Dedicated customer success manager
- ✓ Data residency options
- ✓ Advanced audit logs
- ✓ Custom integrations (SIEM, GRC)
Typically responds within 1 business day
FAQ
Frequently asked questions
One exercise credit lets you run a single tabletop exercise session from start to finish, including AI facilitation, live injects, and a full post-exercise report. Credits do not expire within your billing period.
Yes. You can upgrade from Pay Per Exercise to Starter or Professional at any time. Your remaining credits carry forward, and the price difference is prorated.
All plans support up to 15 concurrent participants per exercise. Enterprise plans can accommodate larger groups and custom role configurations.
After an exercise completes, the report, transcript, and scoring artifacts remain accessible in your workspace for at least 90 days. Starter and Professional plans extend access for the duration of your subscription.
TTXLab uses a dual-AI architecture: a low-latency model drives the live facilitation, and a high-accuracy model handles scoring, gap analysis, and report generation. Both are hosted in SOC 2-aligned infrastructure.
Run the exercise.
Keep the evidence.
Every exercise gives your team a transcript, scores, findings, and follow-up actions your leadership, auditors, and regulators can review. Try the live demo, or browse the starter kit, review the Trust Center, or check recent changes in the changelog.