09:14 · Tuesday · a finance team, somewhere
Finance joins a video call with the CFO. The face is right, the voice is right, the deal is real. The CFO is on a plane. CyberDrill puts your team in that room on a quiet afternoon, with the clock running, so the first time is not the real time.
Tabletop exercises with timed injects, decisions that change what happens next, a log nobody can edit afterwards, and evidence an auditor can verify without trusting us.
No card to start · Business features during the trial · Prices shown on this page are read from our billing provider
The drill starts when this panel is on screen.
What your team does
01 · Plan
One hundred and twenty-three template scenarios, thirteen of them written for AI-era incidents: voice clones at the helpdesk, deepfake wire fraud, a hijacked sales agent, a leaking internal assistant. Each carries its timed injects and at least one decision point.
Or describe your own threat and the generator drafts the scenario and its injects, saved to your organisation, never seen by anyone else.
+118 more · filter by industry, framework, maturity
02 · Run
Every participant is signed in by name, so every action, message and decision is attributed to a person, not a free-text field. The facilitator can pause, steer and drop an unscheduled inject.
A decision releases only the inject that follows from it. The other branches never fire, and the record shows which path the room took.
03 · Close
Completion seals injects, actions, messages and notes and stores a SHA-256 hash of the sealed log. Anything that changes after that goes to an audit log nobody can edit or delete through the product, administrators included.
The after-action report reads the real log, is kept in numbered versions, and every finding is tracked to closure with an owner and a due date, ready for the next drill.
What your auditor sees
Every completed drill exports as one signed document: the sealed log, the decisions, the findings, the after-action report and the audit entries, with the log's SHA-256 inside it and a signature over the whole file.
The panel on the right is not a picture. It is the public verification endpoint being called from this page, right now, on a real export from our own demonstration drill. The same endpoint an auditor would use, with no account.
If your records live elsewhere, the same document is delivered to your endpoint the moment a drill locks, signed with a secret only you and the platform hold.
Who runs it
An owner sets up the organisation, invites the room by link, and runs the drill with the clock. Nothing to install and no consultant required.
Roles: owner, admin, facilitator, participant · every action attributed to a signed-in person
Invite them as a facilitator. They can plan, run and close drills and invite participants. They cannot touch billing, settings or the audit log, and they cannot delete a record.
Facilitator permissions are enforced on the server, not hidden on the screen
One account, many client organisations, each fully separated. A switch in the header changes organisation through a server check and clears everything from the previous one.
Each switch is written to the audit log · client data never shares a screen
Scenario library
Ransomware, OT and healthcare drills are in the library too. The thirteen below are the ones most teams have never rehearsed.
Threat intelligence on template scenarios is refreshed weekly against the CISA Known Exploited Vulnerabilities catalogue.
Both include a 30-day trial with Business features and no card to start. Annual plans are billed once. Cancel in the billing portal at any time.
Annual costs 17% less than twelve monthly payments
For compliance-driven teams that need framework mapping.
Annual plans are billed once for twelve months. The price shown at checkout applies, exclusive of GST/HST where it applies. Cancel a monthly plan any time before the next billing date.
The first time should not be the real time
Thirty days with Business features. No card to start. Your organisation, your invitees, your evidence.