AI-Facilitated Tabletop Exercises

Your team’s incident response readiness,
tested and documented in under an hour.

TTXLab gives security, resilience, and governance teams structured simulations with adaptive facilitation and audit-ready reports — no live facilitator required.

No demo call required. See a real exercise report in seconds.

IR Exercise — Ransomware Scenario

Acme Corp · Started 2:47 PM

AISMJRKLDP+2
AI
AI FacilitatorFACILITATOR2:47 PM
Welcome to today’s Incident Response exercise. Here’s your scenario:
INJECT: Your SOC has detected unusual outbound traffic from the payment processing server. 4.2GB transferred in the last 90 minutes and endpoint alerts are firing.
AI
AI FacilitatorFACILITATOR2:48 PM
Sarah, as Incident Commander, what is your first priority and who are you looping in?
SM
Sarah MitchellINCIDENT COMMANDER2:49 PM
First priority is containment. Isolate the payment server immediately. Pulling in Legal and Comms now.
AI
AI FacilitatorFACILITATOR2:49 PM
Good call on containment. James, as Comms Lead, what channels are you preparing and how quickly can you draft holding statements?
JR
James Rivera

Reports map findings to established frameworks

NIST 800-61SANS IHHISO 22301CISA HSEEP

From self-serve setup to audit-ready report
in one guided workflow.

01

Set up your workspace

Sign in, name your workspace, and invite your team. You are ready to run exercises in minutes.

02

Configure the exercise

Choose an exercise type, set your scenario parameters, and align participant roles before launch.

03

Facilitate live

Run a guided AI-facilitated session with adaptive injects, role-aware prompts, and transcript capture.

04

Share the report

Export structured findings, scores, and remediation direction your leadership and audit teams can review.

Reports leadership, responders,
and auditors can all use.

Every completed run ends in one structured artifact instead of scattered notes, screenshots, and ad hoc follow-up.

IR Exercise — Ransomware Scenario

Acme Corp · Feb 5, 2026 · 6 participants

Completed

Communication

85%

Decision Making

72%

Escalation

68%

Procedures

88%

Complete Transcript

Timestamped record of facilitator prompts, participant responses, and decision points from the full run.

Scored Performance

Track communication, escalation, decision quality, and procedural execution in one summary view.

Sourced Recommendations

Each recommendation is tied to recognized frameworks instead of unsourced generic AI guidance.

Auditor-Ready PDF

Export a structured artifact that leadership, compliance, and audit stakeholders can review quickly.

Eight exercise types.
One repeatable operating model.

Cover incident response, resilience, and communications drills with structure that lets teams compare runs over time instead of improvising a different process for each exercise.

IR Incident Response

Coordinate detection, containment, eradication, and recovery actions.

Incident CommanderSOC AnalystIT LeadLegal CounselCommunications LeadHR Lead
  • Detection and triage speed
  • Cross-team escalation
  • Containment decision-making
  • Evidence preservation
  • Post-incident review
A SOC analyst flags anomalous outbound traffic from a payment processing server at 2 AM. The team must coordinate containment while preserving forensic evidence.

Realistic exercises. Defensible reports.

A fast facilitator keeps the exercise moving. A deliberate adjudicator keeps the final report defensible. Two specialized models working together so your team gets practice that feels real and documentation that holds up.

LOW LATENCY

The Facilitator

Drives the live run by introducing injects, adapting scenario progression, and prompting the right role.

  • Realistic, adaptive exercises
  • Dynamic scenario adaptation
  • Role-aware question targeting
  • Realistic incident inject generation
HIGH ACCURACY

The Adjudicator

Scores responses, applies guardrails, and generates reporting your governance stakeholders can rely on.

  • Reports your auditors will accept
  • NIST / SANS / ISO citation support
  • Gap analysis and remediation direction
  • Content and tone guardrails
ExerciseFacilitatorAdjudicatorReport

Government-backed scenarios,
AI-powered execution.

Simple pricing that scales with your program.

Start with a single exercise or lock in a recurring plan. Every tier includes full reporting and the complete exercise library.

Pay Per Exercise

$299

one-time purchase

$299/exercise

Best for one-off validation drills and first-time pilots.

  • 1 exercise credit
  • Any exercise type
  • Full report export
  • 90-day artifact access

Starter Annual

$999

per year · 4 exercises/year

$250/exercise — save $49 each

For smaller teams building baseline readiness without monthly overhead.

  • 4 exercise credits/year
  • CISA template library
  • Role-based facilitation

Enterprise

Custom

contract pricing

For multi-team organizations with centralized readiness governance.

  • Everything in Professional
  • SSO / SAML enablement
  • Custom report branding
  • Cross-team benchmarking
  • Unlimited participants
  • SLA-backed uptime (see Trust Center)
  • Dedicated customer success manager
  • Data residency options
  • Advanced audit logs
  • Custom integrations (SIEM, GRC)

Typically responds within 1 business day

Frequently asked questions

Stop improvising.
Start proving readiness.

Every exercise builds evidence your auditors, board, and regulators can review. Set up your workspace in minutes and run your first exercise today. Or browse the starter kit, review the Trust Center, or check recent changes in the changelog.

See a real exercise report

Enter your work email to instantly download a sample audit-ready report from a ransomware tabletop exercise.

We'll send a copy to your inbox too. No spam, ever.