Security drills
Example availableExample: “Phishing Triage: The Monday Inbox”
Who it's for
For the people who prepare the response
SOC & incident-response teams
Rehearse runbook decisions and handoffs so the team has already discussed the hard calls.
Security-awareness leads
Turn phishing and social-engineering lessons into situations where people choose a response and see what follows.
CISOs & exercise facilitators
Run a branching discussion with leadership while keeping sensitive procedure content under the organization’s control.
Example scenario shapes
What a security drill looks like in Cynario
Each Scene presents a decision point. Outputs can change Scenario state, and later paths or endings can react to what happened earlier in the same playthrough.
Ransomware response drill
Detection fires at 2 a.m. Isolate, escalate, or observe? Each selected response changes the situations that follow.
Phishing triage
A wire-transfer request lands. Verify out of band, report it, or proceed — the selected path becomes the lesson.
IR runbook walkthrough
Guide a newer analyst through containment and recovery choices, revealing later options only when the Scenario’s rules allow them.
Why security teams use it
Practice sensitive decisions in a controlled Scenario
- Scenarios can be kept in local browser storage or exported as files under the author’s control.
- Encrypted sharing and collaboration options keep Scenario content encrypted in transit, while ordinary network metadata may still be visible to transport services.
- Conditional paths can model dependencies between earlier and later response decisions.
- The bundled phishing examples provide a concrete starting point that can be edited or replaced.