Cybersecurity Incident Response Team eXPerience
Gamified Live Play Exercises
Can Your Organisation Handle A cybersecurity incident?
Every day, It seems that every day we hear of a company being hacked, a hospital unable to provide patient care due to ransomware taking over their systems, our details accidentally published online for the world to see.
Tabletop exercises, live-play, simulations and war gaming are all effective ways to find out how your team would cope in a cybersecurity crisis.
At Cybility, we provide a unique gamified learning experience with a highly interactive and immersive scenario that is tailored to your organisation.
It is a business focused experience designed for leaders, senior management, and subject matter experts from across the organisation that are likely to be involved in responding to a cyber security incident.
NOTE: This is an interactive experience. If someone else is there at the same time as you, you can go on camera and / or mic to speak with them.
Case Study
This CSIRTxp case study showcases how a £20m UK organisation turned a fragmented incident response into a confident, collaborative CSIRT using a three‑phase, gamified learning journey: Prepare, Participate, Probe.
Through self‑paced e‑learning, a live CyberDeck8D™‑powered drill, and an interactive debrief, the client gained clearer roles, defined metrics, and a noticeable uplift in confidence handling cyber incidents.
CyberDeck8D™ INVESTIGATE
The CyberDeck8D™ Instinctive Incident Handler decks turn incident response from a dry checklist into a playable score, helping your CSIRT rehearse and refine their performance before, during, and after a cyber incident.
Induct gets your team ready with clear roles and playbooks, Immerse drops them into realistic scenarios, Hone drives rich debriefs and lessons learned, and the optional Get to Know You set builds trust and rapport so they perform as a cohesive ensemble when it really matters.
Try our Hone deck on Deckible (free trial requires signup).
Why Rehearse Incident Response?
As the compromises of organisations continue to Increase resulting in a halt to operations and increased costs; more organisations recognise the need for a cybersecurity incident response plan.
However, a written plan is only effective when it is tested on a regular basis – ideally using different scenarios and taking account of personnel availability and changes, and so on.
The process of going through a mock scenario is incredibly useful as it will:
- Enable the organisation to identify potential gaps in the plan and procedures that may be needed;
- Build incident response capability within the team;
- Increase understanding of the need for the different roles to be involved;
- Build a sense of comradery in the cybersecurity incident response team (CSIRT).
Like any activity – when repeated regularly it creates a habit. The more you do it, the more confident you can be in your organisation’s ability to respond to a cyber-attack.
Can you help our CFO understand why incident response exercises are important and secure the budget?
Our Solution

1. Prepare
Complete our 45 minute pre-exercise e-learning course to give everyone a solid baseline

2. Participate
Actively contribute to the Cyber Security Incident Response Exercise Scenario

3. Probe
Share candidly in the hot wash and cold wash (debriefs) to identify lessons learned

Iterate
On completion of the experience, your organisation is provided with an After-Action Report (AAR) that includes focus areas for improvement to inform your organisation’s cyber security resilience planning.

Celebrate
Participants receive a digital certificate and are issued with a Cybility Cybersecurity Incident Response Team Experience (CSIRTxp) Alumni badge which can be shared on LinkedIn.
Frequently Asked Questions
We don't have an incident response plan - can you help?
Yes, this is an area that Cybility can support you with in terms of preparing for a cybersecurity incident such as ransomware or a data breach. Please book a call to discuss your needs.
We do not provide an incident response service in the event of a security incident occurring. We recommend having a cybersecurity incident response provider on retainer if funds allow; alternatively, if you have cyber insurance, they typically have preferred companies that they use for crisis response.
What is the difference between a standard tabletop, gamified tabletop, simulation, and wargaming?
There are different ways to test an organisation’s cybersecurity incident response capability.
Different methods differ in audience, objectives, focus, format, scenario, realism, participation, and the level of preparation required, with full wargaming being the most interactive and resource-intensive.
At Cybility, we favour a gamified live play approach.
| Level 1 – Standard Tabletop | Level 2 – Gamified Live Play | Simulation (aka Red Team) | Wargaming | |
|---|---|---|---|---|
| Audience | Executives | Executives and mid-level cyber and business staff | Working level cyber staff | Highly interactive with multiple teams / roles |
| Objective | Validate incident response plans / procedures | Promote engagement and information retention | Test technical incident response capabilities | Test overall cyber resilience and decision-making |
| Focus | Communication, coordination, macro-level business decisions and actions | Escalation; mapping to business impacts; technologies, processes, and tradecraft to recognise attacks or carry out courses of action | ‘Point’ cyber technologies and correlation | Strategic decision-making across adversarial teams/roles |
| Format | Discussion-based | Game-like with mechanics such as rules, story, and scoring | Hands-on technical exercise | Highly interactive with multiple teams / roles |
| Scenario | Facilitator presents scripted scenario | Immersive fictional scenario that evolves; facilitator acts as a ‘Games Master’ | Replicates cyber attacks in controlled environment | Dynamic real-world cyber attack scenarios |
| Realism | Moderate realism, limited by discussion format | More immersive through storytelling and game elements | High technical realism by replicating real attacks | High conceptual realism by simulating adversarial attacks |
| Participation | Discuss roles, responsibilities, actions | Creative problem-solving, novel solutions | Use actual tools, systems, and procedures | Strategic decision-making under pressure |
| Preparation | Moderate preparation of exercise design | Significant preparation for game design | Extensive preparation of technical environment | Extensive preparation of dynamic scenarios |
Can you provide a written summary or recording of the session?
We will be taking notes throughout and provide these to you as an After-Action-Report (AAR). With the client’s permission we may record to assist in producing the AAR, we typically do not provide recordings of the sessions to clients unless explicitly requested as part of the project scope.
Do you offer discounts for charities?
Yes, we offer a 15% discount for this service for charities that are registered in the UK.
To claim this discount the charity must be active and currently registered with one of the following:
- Charity Commission in England and Wales,
- Scottish Charity Regulator in Scotland (OSCR);
- Charity Commission for Northern Ireland (CCNI).