Program overview
Some training needs do not fit a standard program. A threat group may be targeting your sector, a new system may change how an incident would play out, or a past incident may have exposed a gap. This service designs an exercise around that one scenario.
It suits security leaders who want a particular risk tested, and any mix of teams: SOC, incident response, IT operations, engineering, leadership, or communications. DeployOpen engineers design and facilitate the exercise and run the debrief.
What a scenario can focus on
Threats to your sector
Techniques publicly reported for threat groups that target your industry, written into a sequence your team can investigate.
Your critical systems
Attacks on the services that matter most to you, such as payment systems, customer data stores, or identity providers.
Past incidents and near misses
A replay of an incident or near miss from your organization, with details changed, to check whether follow-up actions worked.
New technology
Risks from systems you have recently adopted, such as AI assistants and agents, new cloud services, or an acquired company's network.
Suppliers and third parties
Incidents that start at a supplier, managed service provider, or software dependency.
Leadership decisions
Decisions on disclosure, extortion, business continuity, and external communication during a major incident.
How the program runs
We meet the scenario sponsor to agree the question the exercise should answer, the participants, and the decisions they should practice. We review the relevant systems, procedures, and any past incidents you share.
We write the scenario, map its techniques to MITRE ATT&CK where relevant, and build injects for each participant group. Technical parts are set up in an isolated lab with your tools where possible. You approve the scenario, the controller guide, and the participant brief.
Participants work through the scenario in the agreed format. A DeployOpen engineer controls the injects, logs decisions and evidence, and can pause the exercise if needed.
We review the scenario with participants, compare decisions with your procedures, and separate individual skill gaps from process, tooling, and ownership issues.
Formats
| Format | Who it suits | What it covers |
|---|---|---|
| Tabletop exercise | Leadership, communications, and cross-team groups | A discussion-based scenario with injects written for each group's decisions |
| Hands-on lab exercise | SOC, incident response, IT, and engineering teams | Technical investigation and response in an isolated lab |
| Combined exercise | Organizations testing the chain from detection to executive decision | One scenario run across technical and leadership groups, with a joint debrief |
| Scenario series | Teams working through several related risks | A set of linked scenarios, each with its own debrief |
Example scenarios
Sector-specific intrusion
A threat group known to target your sector gets in through a VPN appliance and moves toward a core business system.
Deepfake-assisted fraud
A cloned executive voice requests an urgent change to payment details, followed by a phishing message to the finance team.
Compromised AI assistant
An internal AI assistant with access to documents and tickets is manipulated into sharing data or changing records.
Managed service provider breach
Attackers use a provider's remote access tool to reach several of your servers.
Insider with privileged access
An administrator who is leaving the company copies data and creates a hidden account.
Loss of a critical service
A destructive attack takes a key service offline. Teams work through recovery order, communications, and continuity decisions.
What you receive
The outputs record what the scenario showed and give your team what it needs to run it again.
Debrief and exercise report
- Scenario timeline and decisions made
- Objectives met and not met
- Observations for each participant group
Detection and response findings
- Where detection, escalation, or decisions were delayed
- Evidence and information that was missing
- Gaps in tooling or access
Recommended improvements
- Changes to plans and runbooks
- Detection and logging changes
- Ownership and decision authority to clarify
Scenario package
- Controller guide with inject timing and expected responses
- Participant brief
- Lab files for the technical parts of the scenario
Common questions
How does this differ from your other training programs?
Our other programs cover a defined skill set for one group. Here the scenario comes first: we design the exercise around one risk you choose and pick the formats and participants to suit it.
Who should attend?
The people who would be involved if the scenario happened. We help you identify the groups, which can include technical teams, executives, legal, communications, and suppliers.
Can non-technical staff take part?
Yes. Tabletop parts of the scenario are written for leadership and business staff, with injects about the decisions they own.
Do exercises use our tools and data?
Scenarios are tailored to your environment and tools. Technical work runs in an isolated lab with synthetic data. We sign an NDA on request.
Is it remote or on-site?
Remote or on-site delivery can be agreed.
Can it be repeated, and how is progress measured?
Yes. You receive the scenario package to rerun it, and we can update the scenario as your environment changes. Comparing a rerun with the first debrief shows whether the recommended changes have taken effect.
How to prepare
Bring the risk or question you want the exercise to address, and the context behind it: threat reports you rely on, past incidents, audit findings, or planned changes to systems.
Name a sponsor who approves the scenario and a small planning group who can review it without taking part. Keep scenario details from participants so the exercise tests how they respond to new information.
Planning references
Scenario techniques are described with MITRE ATT&CK, which gives a shared vocabulary for detection and response findings. Only techniques that serve the exercise objective are included.
Exercise planning, inject design, and evaluation draw on CISA exercise planning materials and NIST SP 800-84.

