Platform
A control room, a room full of roles, and a report at the end
TableTop Sim replaces the slide deck and the shared inbox with a purpose-built simulation environment for cybersecurity tabletop exercises.
Facilitator control room
Run the whole exercise from one screen
Release injects on your cue or on a timer. Pause when the discussion is worth having. Watch responses arrive by role, annotate them while they're fresh, and keep private facilitator notes that participants never see. When the room takes an unexpected turn, accept an AI-improvised inject that follows what was actually said instead of dragging everyone back to the script.
- Inject timeline with release, hold and complete states
- Live response feed grouped by role and seat
- Inline annotation captured straight into the report
- AI improvisation suggestions you approve or discard
Inject window
Northwind Logistics · Ransomware · Standard
- Detection
- Triage
- Containment
- Escalation & Notification
- Eradication & Recovery
- Public & Legal
- Recovery & Lessons
Helpdesk escalation: three users locked out of the finance share
Two accounts payable clerks and a controller report that files on the finance share now end in .nwlk and open as gibberish. A README appears in every folder. The helpdesk has already rebooted one machine.
Inject timeline
- 00:04Helpdesk escalation: three users locked out of the finance sharereleased · CISO
- 00:11EDR timeline: service account authenticated from an unmanaged hostqueued · IT Operations
- 00:23The CFO asks whether to shut down the ERPqueued · CEO
- 00:34A customer emails a screenshot of your data on a leak sitequeued · General Counsel
- 00:48Trade press calls for comment before your statement is readyqueued · Comms Director
Live response feed
- 00:06CISO
Isolating FILE-02 and the three endpoints now. Do not reboot anything else — we need the volatile evidence.
Dana W.
Start the clock to watch responses land
Participant rooms
Everyone sees exactly what their seat would see
Participants join with a code — no account, no install, no onboarding. Each role lands in a bespoke incident bridge: their brief, their private information, the shared situation board, and the exercise clock. Observers and note-takers get the same view read-only, so training staff can watch without nudging the outcome.
- Join-code access with no participant accounts
- Role-specific injects for CEO, CISO, General Counsel, Comms and more
- Shared situation board with live status tiles
- View-only observer and note-taker seats
Your seat
CEO — Priya S.
- Detection
- Triage
- Containment
- Escalation & Notification
- Eradication & Recovery
- Public & Legal
- Recovery & Lessons
Your brief
You own the trading decision. Every hour of ERP downtime costs roughly one day of margin recovery, and your board chair will ask what you knew and when.
Private to this seat
Private to you: the board's risk committee meets tomorrow morning. Your cyber policy has a 24-hour notification clause you have not yet triggered.
No other participant can see this panel
Do you keep shipping running while the blast radius is still unknown?
Shared situation board
- 00:04another role's lane
CISO received new information
- 00:11another role's lane
IT Operations received new information
- 00:23your lane
The CFO asks whether to shut down the ERP
On the bridge
- Priya S.CEO
- Dana W.CISO
- Alan R.General Counsel
- Lena K.Comms Director
- R. Alvarezobserver
- T. Okaforobserver
After-action reporting
A report you would hand to a board
The exercise record becomes the deliverable. Decisions and timings, response quality by role, lessons learned, AI-recommended alternatives to the choices made, and hot-wash feedback collected from the room — as a web report and a branded PDF, ready before the debrief coffee goes cold.
- Web report plus branded PDF export
- Decision timeline with timings by role
- Lessons learned and recommended alternatives
- Hot-wash feedback captured in-session
After-action report
Ransomware in the finance shared drive — Northwind Logistics
2.8 / 5
Confidence before
4.1 / 5
Confidence after
11
Injects released
23
Decisions logged
executive summary
What happened
observed
Strengths
- Containment instinct was fast and correct — isolation before reboot, evidence preserved.
- The service-account pivot was recognised from the EDR artefact without facilitator prompting.
- Legal engaged outside counsel early and refused direct actor contact.
observed
Gaps
- No single owner for the regulatory notification clock; it was discussed by three seats and started by none.
- The ERP availability decision was verbal, with no recorded risk acceptance or review time.
- Backup integrity was assumed. Nobody asked when the last restore test passed.
ai analysis
Alternative actions the AI recommends
- Name a notification owner in the first ten minutes of any incident, before scope is known.
- Require a timestamped risk acceptance for any decision that keeps a business system online during active encryption.
- Add 'last successful restore test' to the incident-commander opening checklist.
carry forward
Lessons learned
- The room defaults to technical containment and defers business decisions upward without a deadline.
- Comms and Legal were working from different assumptions about what had already leaked.
- Downtime procedures exist on paper but nobody could say where to find them under pressure.
action plan
Recommendations
- CISO · 30 daysAdd a notification-owner field to the IR plan's first-hour checklist.
- IT Operations · 45 daysRun a documented restore test on the finance volume and record the result.
- Comms · 30 daysDraft holding statements for encryption and leak-site scenarios, approved by Legal.
- General Counsel · 60 daysMap customer contract notification clauses into a single reference table.
Also included
The details that make it repeatable
AI environment tailoring
Describe the client's environment once — cloud, remote or hybrid, device estate, sector, regulators — and every inject, artefact and role prompt is rewritten to fit.
Multi-tenant organizations
Manage members and roles per organization, keep client exercises isolated, and reuse tailored scenarios across engagements.
Themes, per org and per exercise
Mission Control, Corporate, Wardroom, Cyberpunk or D&D. Set an org default and override it for a single exercise when the audience calls for it.
Scenario authoring
Fork a library scenario or build one from scratch: injects, timings, role targeting, artefacts and facilitator notes.
Timers and pacing control
Per-inject countdowns, global pause, and pacing that adapts when a discussion is worth extending.
Exercise history
Every session is retained with its injects, responses and report so you can show progress between exercises.
