09:14 · Tuesday · a finance team, somewhere

Run the day before it happens.

Finance joins a video call with the CFO. The face is right, the voice is right, the deal is real. The CFO is on a plane. CyberDrill puts your team in that room on a quiet afternoon, with the clock running, so the first time is not the real time.

Tabletop exercises with timed injects, decisions that change what happens next, a log nobody can edit afterwards, and evidence an auditor can verify without trusting us.

No card to start · Business features during the trial · Prices shown on this page are read from our billing provider

Deepfake Video Call Wire Fraud
T+00:00READY
In the roomMAFinanceROTreasuryDKSecuritySNLegalFacilitated by J. Olayemi

The drill starts when this panel is on screen.

Injects arrive on the clock. Nobody types the timeline afterwards.

What your team does

Plan it in an afternoon. Run it in two hours. Close it with a record.

01 · Plan

Pick the incident you are most afraid of. The injects come with it.

One hundred and twenty-three template scenarios, thirteen of them written for AI-era incidents: voice clones at the helpdesk, deepfake wire fraud, a hijacked sales agent, a leaking internal assistant. Each carries its timed injects and at least one decision point.

Or describe your own threat and the generator drafts the scenario and its injects, saved to your organisation, never seen by anyone else.

Scenarios · library
  • AI Voice Clone Attack on IT Helpdeskinjects · decision
  • Deepfake Video Call Wire Fraud3 injects · 1 decision
  • Rogue Autonomous AI Agent with Excessive Permissionsinjects · decision
  • Internal RAG Assistant Leaks Confidential Datainjects · decision
  • Prompt Injection Against Customer-Facing Chatbotinjects · decision

+118 more · filter by industry, framework, maturity

02 · Run

The clock releases the injects. The room makes the calls. Nobody types the timeline afterwards.

Every participant is signed in by name, so every action, message and decision is attributed to a person, not a free-text field. The facilitator can pause, steer and drop an unscheduled inject.

A decision releases only the inject that follows from it. The other branches never fire, and the record shows which path the room took.

Live drill · facilitator view
T+00:03 · VIDEO CALL · to Finance, Treasurydelivered
T+00:08 · DECISION · Financepending
T+00:09 · INJECT · release / hold / dual-controlwaits for the decision
Clockserver time · pause · resume

03 · Close

When the drill ends, the log locks. Findings get owners. The report writes itself from the record.

Completion seals injects, actions, messages and notes and stores a SHA-256 hash of the sealed log. Anything that changes after that goes to an audit log nobody can edit or delete through the product, administrators included.

The after-action report reads the real log, is kept in numbered versions, and every finding is tracked to closure with an owner and a due date, ready for the next drill.

Drill · completed
Statuscomplete · log locked
SHA-256c07adee3607d4af9…
After-action reportversion 2 · generated by name
Findings4 open · 2 owners assigned
Audit entriesappend-only

What your auditor sees

A drill is only evidence if someone else can check it.

Every completed drill exports as one signed document: the sealed log, the decisions, the findings, the after-action report and the audit entries, with the log's SHA-256 inside it and a signature over the whole file.

The panel on the right is not a picture. It is the public verification endpoint being called from this page, right now, on a real export from our own demonstration drill. The same endpoint an auditor would use, with no account.

If your records live elsewhere, the same document is delivered to your endpoint the moment a drill locks, signed with a secret only you and the platform hold.

Open the verification page
Verify evidence · liveREADY
Signature valid
n/a
Log hash matches the document
n/a
Log hash matches the platform record
n/a
After-action report hash matches
n/a
Export known to the platform
n/a
Locked at
2026-10-01 01:50:31 UTC
Export eec8c3c4… · Showcase: Deepfake Video Call Wire Fraud · our own organisation, not a customer result.

Who runs it

The client, their consultant, or a partner. The record looks the same.

Your own team

An owner sets up the organisation, invites the room by link, and runs the drill with the clock. Nothing to install and no consultant required.

Roles: owner, admin, facilitator, participant · every action attributed to a signed-in person

A consultant you already trust

Invite them as a facilitator. They can plan, run and close drills and invite participants. They cannot touch billing, settings or the audit log, and they cannot delete a record.

Facilitator permissions are enforced on the server, not hidden on the screen

A partner running it for several clients

One account, many client organisations, each fully separated. A switch in the header changes organisation through a server check and clears everything from the previous one.

Each switch is written to the audit log · client data never shares a screen

Scenario library

123 templates. Thirteen written for the incidents of this decade.

Ransomware, OT and healthcare drills are in the library too. The thirteen below are the ones most teams have never rehearsed.

  1. 01AI Voice Clone Attack on IT Helpdesk
  2. 02AI-Generated Hyper-Personalized Phishing Wave
  3. 03Adversarial Evasion of AI Security Controls
  4. 04Compromised Open-Source Model from Public Hub
  5. 05Deepfake Disinformation Targeting Company Reputation
  6. 06Deepfake Video Call Wire Fraud
  7. 07Healthcare Diagnostic AI Producing Unsafe Outputs
  8. 08Internal RAG Assistant Leaks Confidential Data
  9. 09LLM API Key Theft and Abuse (LLMjacking)
  10. 10Prompt Injection Against Customer-Facing Chatbot
  11. 11Rogue Autonomous AI Agent with Excessive Permissions
  12. 12Shadow AI: Sensitive Data Pasted into Public LLMs
  13. 13Training Data Poisoning of Fraud Detection Model

Threat intelligence on template scenarios is refreshed weekly against the CISA Known Exploited Vulnerabilities catalogue.

Pricing

Two plans, read from the billing system as you look at them

Both include a 30-day trial with Business features and no card to start. Annual plans are billed once. Cancel in the billing portal at any time.

Standard

$499 USDper month, billed monthly
$4,990 USDper year, billed once

Annual costs 17% less than twelve monthly payments

For growing security teams running quarterly drills.

  • Unlimited drills
  • Scenario library + AI generator
  • 10 team members
  • Standard reporting
  • Email support

Business

Most chosen
$1,666 USDper month, billed monthly
$16,660 USDper year, billed once

Annual costs 17% less than twelve monthly payments

For compliance-driven teams that need framework mapping.

  • Everything in Standard
  • Full compliance mapping (NIST, ISO, HIPAA, SOC 2)
  • 50 team members
  • CISA KEV threat scoring
  • After Action Report exports
  • Priority support

Enterprise

Talk to us

For large organizations with custom requirements.

  • Unlimited users
  • Custom integrations
  • Dedicated success manager
  • Custom playbooks
  • SLA & DPA

Annual plans are billed once for twelve months. The price shown at checkout applies, exclusive of GST/HST where it applies. Cancel a monthly plan any time before the next billing date.

Questions

Questions we get a lot

The first time should not be the real time

Run your next drill on the clock, and keep the record.

Thirty days with Business features. No card to start. Your organisation, your invitees, your evidence.

Replay the drill