Free interactive tool
Rehearse your breach response before the breach rehearses you
Breach Tabletop runs a full incident-response tabletop exercise in your browser: pick a scenario, work through timed decision points as breaking injects land, get scored on readiness, and leave with an after-action report. Six scenarios, no signup, nothing leaves your device.
A quick disclaimer:this is an educational training aid, not legal advice and not a compliance certification. The scenarios are fictional; the notification duties they reference are real and worth discussing with counsel.
Why run a tabletop at all
Every breach-notification regime in Canada assumes you already know what to do. PIPEDA expects notification to the Privacy Commissioner and affected individuals when there is a real risk of significant harm; Québec's Law 25 adds its own confidentiality-incident notification duties. None of them give you extra time because your team had never practiced.
A tabletop is the cheapest way to find out where your plan breaks: who calls the forensics firm at 2 a.m., who decides whether to pay a ransom, who drafts the customer notice, and whether anyone knows the notification clock has already started. Regulators publish free scenario packs, but static PDFs don't push back. This simulator does: injects arrive mid-decision, the clock runs, and your choices are scored.
Six scenarios, ready to run
Each scenario opens with a briefing, then runs three to four phases of timed decisions with breaking injects. Finish with a readiness score and an after-action report you can take back to your team.
OP_BLACKOUT
01DarkHydra Double-Extortion Ransomware
EDR alerts fire on 14 domain controllers at 02:15 UTC. Servers are locked, a $4.2M demand is on screen, and 850GB of data has already left the network. Decide on isolation, ransom, disclosure, and customer communication.
Open this scenarioOP_POISON_PILL
02Vendor CI/CD Pipeline & Supply Chain Poisoning
A trusted vendor's signed update is pushing malicious code to your build pipeline. Weigh global credential revocation against phased expiration, and decide what to tell customers who installed the poisoned release.
Open this scenarioOP_VELVET_SHADOW
03Stolen Executive Laptop: Unencrypted M&A Dossier
An executive's laptop with an unencrypted M&A dossier is stolen from a car. The deal is not public. Choose between remote wipe and tracking, and decide whether trading must halt.
Open this scenarioOP_REPLY_ALL
04Mass Customer Financial Record Email Blast
A spreadsheet of customer financial records goes to the wrong distribution list. Kill the mail queues or send a recall, then face the notification math: who must be told, and how fast?
Open this scenarioOP_OPEN_VAULT
05Exposed Cloud Bucket: 4.2M Customer Records
A storage bucket holding 4.2M customer records has been publicly readable for months, and the access logs are incomplete. Scope the exposure and decide what verifiable statements you can make.
Open this scenarioOP_INSIDE_JOB
06Disgruntled Database Architect: Mass Exfiltration & Logic Bomb
A departing database architect exfiltrates data and plants a logic bomb. The hardest calls are about people: access removal, evidence preservation, and what the team is told on Monday morning.
Open this scenario
How a run works
- 1
Pick a scenario and read the briefing
Each operation starts with a situation brief: what is known, what is not, and who is in the (virtual) room.
- 2
Make timed decisions as injects land
Phases present decision points with trade-offs: cost, time, and trust move with every choice. Breaking injects interrupt mid-phase, the way real incidents do.
- 3
Get scored and read the after-action report
A readiness score summarizes each phase, and the report captures your decisions with facilitator notes for the team debrief.
- 4
Check the doctrine library
Playbooks summarizing real notification duties (GDPR Articles 33/34, SEC cyber disclosure, HIPAA, NIST SP 800-61, NYDFS), with links to deeper reading on movahedi.ca.
Your runs stay on your machine
The simulator makes no network calls. There is no account, no analytics, and no backend. Decisions, scores, and exercise history live in your browser's local storage, where you can review past runs or clear them at any time. A training tool about confidentiality incidents should not create one.
Questions
What is a tabletop exercise?
A facilitated discussion where your team walks through a simulated incident, phase by phase, and makes the decisions a real breach would force: containment, evidence, notification, and communication. The point is to find the gaps in your playbooks before a real incident finds them.
Do I need an account or an internet connection to run it?
No. The simulator loads once and then runs entirely in your browser. There is no account, no signup, and no analytics. Your decisions and exercise history are stored in your browser's local storage only. Nothing is sent to any server.
Is this a compliance certification or legal advice?
No. It is an educational training aid. Running a scenario does not certify compliance with PIPEDA, Quebec Law 25, or any other regime, and nothing in the simulator is legal advice. The doctrine library summarizes public regulatory sources so your team can discuss real notification duties during the exercise.
How long does a scenario take?
About 15 to 30 minutes per scenario for a focused run, longer if a facilitator pauses for team discussion at each decision point. Each scenario has three to four phases with timed decision points and breaking injects.
Who is it for?
Privacy, security, and incident-response teams running their first tabletop or refreshing an existing program; privacy officers who need to rehearse breach-notification decisions; and executives who want to feel the pace of disclosure decisions before a real incident sets it.
Can I share a direct link to a scenario?
Yes. Every scenario has a deep link, for example /tabletop/#/scenario/darkhydra-ransomware, so a facilitator can send the team straight to the briefing. Links to a drill or report open the scenario briefing instead, since live exercise state is not encoded in the URL.
Go deeper
Confidentiality incidents, defined
The glossary entry on what counts as a breach under Québec Law 25: useful pre-reading before the notification decisions.
Breach-response readiness
When the tabletop surfaces real gaps, fractional privacy leadership is the service that closes them: playbooks, notification procedures, and rehearsal.
Breach analysis, weekly
Real incidents and enforcement actions, analyzed for what they teach about response: the raw material for your next tabletop.
Law 25 notification playbook
Jump straight into the doctrine library: the Quebec Law 25 breach playbook, with deadlines, penalties, and the mandatory disclosure checklist.