Tabletop incident-response lab

Cyber resilience for community organizations

Practice the breach
before the breach.

A decision-driven incident-response simulator for nonprofits with limited staff, high trust, sensitive communities, and no time for a 200-page playbook during a crisis.

Choose the pressure test

Three missions. Real tradeoffs.

Each exercise contains three escalating injects. You will balance containment, evidence, coordination, and continuity—then receive a decision-by-decision debrief.

MISSION BRIEF

Ransomware at the resource center

A case manager reports renamed files, a ransom note, and an unavailable shared drive during client intake.

OPERATIONAL PRESSURE

Client services depend on the affected systems today.

Response is a team sport

What the simulator measures

Aligned with the idea that incident response is integrated across cybersecurity risk management, not isolated in an IT emergency binder.

01

Containment

Limit attacker access and spread using scoped actions that match the evidence.

02

Evidence

Preserve volatile, limited-retention, and decision-relevant records before they disappear.

03

Coordination

Activate technical, leadership, legal, insurance, partner, and communications roles.

04

Continuity

Protect essential services and define evidence-based criteria for safe recovery.

Authoritative references

Continue the exercise.

BreachCoach is a learning environment, not a replacement for professional response, legal advice, insurance requirements, or your organization’s approved plan.

NIST SP 800-61 Rev. 3Incident Response Recommendations and ConsiderationsOpen guidance ↗CISA#StopRansomware GuideOpen guidance ↗