Custom threat scenarios

Attack scenarios we build for your organization from the threats that concern you, run in a private range modelled on your systems. Each exercise ends with a debrief on detection, response and areas to improve.

On this page

What it is

A custom scenario starts from a specific concern: a threat group active in your sector, a past incident, a new system, or a business process that depends on trust, such as payments or account recovery. We turn it into an attack sequence and run it in a private range built from your environment.

It suits security leads and risk owners who need a scenario that fits their organization, and teams that have already worked through standard scenarios. Facilitated programs built on custom scenarios are under custom threat scenario training.

Starting points

Threat groups in your sector

We build an attack sequence from the published techniques of a group known to target your industry, using MITRE ATT&CK.

Your own incidents

We rebuild a past incident or near miss so your team can work it again with current tools and procedures.

Deepfake and impersonation fraud

Synthetic voice or video of your executives targets payment approval, vendor bank detail changes, or help desk account recovery.

AI systems and agents

Prompt injection, data leakage or tool misuse involving the AI assistants and agents you have deployed.

New systems and changes

A scenario aimed at a system before or after launch, such as a new identity provider, a cloud migration or an acquisition.

Suppliers and third parties

Compromise through a vendor, managed service provider, software update or shared credentials.

How an exercise runs

We work with your team to define the concern, the objectives and the participants. We research the relevant techniques and write a scenario with stages, injects, expected detections and decision points. You review and approve it before build.

What each scenario includes

Scenario brief

Objectives, scope, permitted actions, stop conditions and participant roles.

Attack sequence

Stages and techniques mapped to MITRE ATT&CK, and to MITRE ATLAS for steps involving AI systems.

Range build

The systems, identities, security tools and logs the scenario needs, built from your architecture.

Injects and materials

Emails, calls, tickets, documents and synthetic media delivered to participants on a schedule.

Scoring sheet

Expected detections and decisions at each stage, used in the debrief.

Exercise formats

FormatHow it worksWhen it fits
TabletopParticipants talk through each stage using scenario materials, without live attack activity.Leadership, fraud and business process scenarios, or a first pass on a new scenario.
Live-fireOur operators run the attack in the range while your team detects and responds.Testing detection and response for the specific threat.
Purple teamAttack and defense work together stage by stage to check telemetry and tune detection.Building detection for the techniques in the scenario.

What you receive

Each exercise ends with a debrief. You keep the scenario and the written findings.

Debrief session

  • Scenario stages against your team's actions
  • Decisions reviewed with the people who made them
  • Observations from participants

Detection findings

  • Stages that were detected, missed or detected late
  • Log sources and rules needed for this threat
  • Notes on alert quality

Response findings

  • Containment and escalation decisions
  • Business process steps that held or failed
  • Communication between technical and business teams

Reusable scenario

  • Scenario document and range configuration
  • Scoring sheet for reruns
  • Recommended changes to test on the next run

Questions

Does the scenario touch production?

No. The scenario runs in an isolated range. Calls, emails and other injects go to participants inside the exercise only.

How do you decide what the scenario covers?

We start from your concern and threat model, then check it against published threat information. You approve the written scenario before we build it.

Can non-technical staff take part?

Yes. Finance, help desk, executive assistants and leadership often have a role in fraud and impersonation scenarios. Their part of the debrief stays non-technical.

Can we keep and rerun the scenario?

Yes. Each scenario is kept in a library for your range, with its configuration and scoring sheet. You can rerun it with a new group, or after changing a rule or procedure to compare results.

How is sensitive information handled?

Scenarios based on your incidents or systems can contain sensitive detail. We use synthetic data, limit access to named people, sign an NDA on request, and agree retention and deletion rules.

Who facilitates?

A controller from our team runs the exercise and leads the debrief, and our operators run the attack stages. Your team can facilitate reruns if you prefer.

How to prepare

Write down the concern in a few sentences, with any material behind it: incident reports, threat intelligence, audit findings or a planned change. Name the teams and decision-makers who should take part.

For impersonation scenarios, agree whose voices or likenesses may be used and get consent from those people.

Sources and further reading

Talk to our team.

Tell us what you're working on, whether it's a deployment, an audit, a security test or a cyber range. You'll speak with an engineer who can help you scope it.

  • 30-minute call: free, with no obligation.
  • NDA on request: we can sign before you share details.
  • Clear next steps: a scope and plan after the call.