Platform Capabilities

Everything a realistic crisis needs.

Live injects, multi-channel communications, technical challenges and comprehensive assessment, all running in your browser, no infrastructure required.

01
Live inject engine

65+ injects across 20+ categories (ransomware, data breach, phishing, media pressure, OT/ICS, insider threat) with adaptive paths that respond to decisions.

02
Simulated phone calls

An incoming-call interface with realistic ringtone. Urgent calls from the CEO, regulators, journalists and law enforcement land mid-exercise.

03
Video briefings

Pop-up briefing injects for executive updates, threat-intel feeds and escalation notices. Mixed inject types keep teams on their toes.

04
Technical challenges

Hands-on terminal-style tasks embedded in the exercise: analyse logs, decode payloads and make critical calls under a running clock.

05
News & social media

Dynamic news articles and an X-style feed react to incident progression. Watch public pressure mount in real time as the story breaks.

06
Multi-team delivery

Run several teams through the same scenario in parallel sessions, each scored independently, brought together in one debrief.

07
Business-impact simulation

Real-time tracking of share price, reputation, regulatory exposure and customer churn. See how each decision hits the bottom line.

08
SLA timers & deadlines

Built-in SLA clocks create urgency. Missed deadlines cost score and business impact, training teams to prioritise under real constraints.

Show, don't tell

An inject as it actually lands.

Injects arrive as the real thing: an inbox, a ringing phone, a breaking-news wire, not a bullet on a slide. Your team reads, decides, and the console reacts.

It looks real, because it is

Every channel is rendered as the interface your team knows: inbox, call screen, news ticker, social feed.

It escalates on your decisions

Contain fast and the story stays small. Hesitate and the press, the regulator and the board all arrive at once.

Inbox · external14:32
Rransom-group-notice.comExternal sender
URGENT: Your files have been encrypted
All critical databases and file servers have been encrypted. You have 72 hours before we publish 47 GB of exfiltrated data.
Incoming · CEO officeT+45:12
SMSarah MitchellChief Executive Officer
“There's a ransom note on every machine in finance. Production is offline. What should we do?”
Breaking news · wireReuters · 14:32
Manufacturer hit by cyber attack; production lines halted
Sources say the attack encrypted control systems, forcing an emergency shutdown. Shares fell 8.3% at the open, and are still sliding.
2.4k shares · trending #outage
Communication Channels

Pressure arrives from every direction.

A real crisis isn't an inbox: it's phones, press, social, regulators and the boardroom firing at once.

Email
Phone call
Video call
News wire
Social / X
Press conference
Internal memo
SIEM alert
Threat intel
Dark web
Legal counsel
Law enforcement
Board update
Insurer
Cloud provider

+ 2 more (PR agency, works council)

Attack Path

Watch the intrusion propagate.

A live network view shows the adversary pivoting from the external actor toward the OT segment; injects fire as the path advances, so the technical picture and the human decisions move together.

Architecture

Nothing to install. Nothing touching production.

The exercise runs in the browser: no agents, no VPN, no access to your production systems. Exercise data lives in a tenant-isolated workspace under a data processing agreement, and it is yours to export or delete.

  • Browser-based delivery: no installation, no agents
  • No access to your production environment required
  • Tenant-isolated exercise workspace
  • Your exercise data: export or delete at any time
Verdus Cyber · exercise engine
────────────────────────
exercise running · t+00:42:10
┌────────────────────┐
│ inject #14 · SIEM │
└────────────────────┘
tenant-isolated workspace
DPA (AVV) as standard
export & delete anytime

Want to see it live?