Skip to main content

Free interactive tool

Rehearse your breach response before the breach rehearses you

Breach Tabletop runs a full incident-response tabletop exercise in your browser: pick a scenario, work through timed decision points as breaking injects land, get scored on readiness, and leave with an after-action report. Six scenarios, no signup, nothing leaves your device.

A quick disclaimer:this is an educational training aid, not legal advice and not a compliance certification. The scenarios are fictional; the notification duties they reference are real and worth discussing with counsel.

Why run a tabletop at all

Every breach-notification regime in Canada assumes you already know what to do. PIPEDA expects notification to the Privacy Commissioner and affected individuals when there is a real risk of significant harm; Québec's Law 25 adds its own confidentiality-incident notification duties. None of them give you extra time because your team had never practiced.

A tabletop is the cheapest way to find out where your plan breaks: who calls the forensics firm at 2 a.m., who decides whether to pay a ransom, who drafts the customer notice, and whether anyone knows the notification clock has already started. Regulators publish free scenario packs, but static PDFs don't push back. This simulator does: injects arrive mid-decision, the clock runs, and your choices are scored.

Six scenarios, ready to run

Each scenario opens with a briefing, then runs three to four phases of timed decisions with breaking injects. Finish with a readiness score and an after-action report you can take back to your team.

  1. OP_BLACKOUT

    01DarkHydra Double-Extortion Ransomware

    EDR alerts fire on 14 domain controllers at 02:15 UTC. Servers are locked, a $4.2M demand is on screen, and 850GB of data has already left the network. Decide on isolation, ransom, disclosure, and customer communication.

    Open this scenario
  2. OP_POISON_PILL

    02Vendor CI/CD Pipeline & Supply Chain Poisoning

    A trusted vendor's signed update is pushing malicious code to your build pipeline. Weigh global credential revocation against phased expiration, and decide what to tell customers who installed the poisoned release.

    Open this scenario
  3. OP_VELVET_SHADOW

    03Stolen Executive Laptop: Unencrypted M&A Dossier

    An executive's laptop with an unencrypted M&A dossier is stolen from a car. The deal is not public. Choose between remote wipe and tracking, and decide whether trading must halt.

    Open this scenario
  4. OP_REPLY_ALL

    04Mass Customer Financial Record Email Blast

    A spreadsheet of customer financial records goes to the wrong distribution list. Kill the mail queues or send a recall, then face the notification math: who must be told, and how fast?

    Open this scenario
  5. OP_OPEN_VAULT

    05Exposed Cloud Bucket: 4.2M Customer Records

    A storage bucket holding 4.2M customer records has been publicly readable for months, and the access logs are incomplete. Scope the exposure and decide what verifiable statements you can make.

    Open this scenario
  6. OP_INSIDE_JOB

    06Disgruntled Database Architect: Mass Exfiltration & Logic Bomb

    A departing database architect exfiltrates data and plants a logic bomb. The hardest calls are about people: access removal, evidence preservation, and what the team is told on Monday morning.

    Open this scenario

How a run works

  1. 1

    Pick a scenario and read the briefing

    Each operation starts with a situation brief: what is known, what is not, and who is in the (virtual) room.

  2. 2

    Make timed decisions as injects land

    Phases present decision points with trade-offs: cost, time, and trust move with every choice. Breaking injects interrupt mid-phase, the way real incidents do.

  3. 3

    Get scored and read the after-action report

    A readiness score summarizes each phase, and the report captures your decisions with facilitator notes for the team debrief.

  4. 4

    Check the doctrine library

    Playbooks summarizing real notification duties (GDPR Articles 33/34, SEC cyber disclosure, HIPAA, NIST SP 800-61, NYDFS), with links to deeper reading on movahedi.ca.

Your runs stay on your machine

The simulator makes no network calls. There is no account, no analytics, and no backend. Decisions, scores, and exercise history live in your browser's local storage, where you can review past runs or clear them at any time. A training tool about confidentiality incidents should not create one.

Questions

What is a tabletop exercise?

A facilitated discussion where your team walks through a simulated incident, phase by phase, and makes the decisions a real breach would force: containment, evidence, notification, and communication. The point is to find the gaps in your playbooks before a real incident finds them.

Do I need an account or an internet connection to run it?

No. The simulator loads once and then runs entirely in your browser. There is no account, no signup, and no analytics. Your decisions and exercise history are stored in your browser's local storage only. Nothing is sent to any server.

Is this a compliance certification or legal advice?

No. It is an educational training aid. Running a scenario does not certify compliance with PIPEDA, Quebec Law 25, or any other regime, and nothing in the simulator is legal advice. The doctrine library summarizes public regulatory sources so your team can discuss real notification duties during the exercise.

How long does a scenario take?

About 15 to 30 minutes per scenario for a focused run, longer if a facilitator pauses for team discussion at each decision point. Each scenario has three to four phases with timed decision points and breaking injects.

Who is it for?

Privacy, security, and incident-response teams running their first tabletop or refreshing an existing program; privacy officers who need to rehearse breach-notification decisions; and executives who want to feel the pace of disclosure decisions before a real incident sets it.

Can I share a direct link to a scenario?

Yes. Every scenario has a deep link, for example /tabletop/#/scenario/darkhydra-ransomware, so a facilitator can send the team straight to the briefing. Links to a drill or report open the scenario briefing instead, since live exercise state is not encoded in the URL.

Go deeper