Custom threat scenario training

Training built around a threat scenario you choose, written for your systems and teams and run as a tabletop, a hands-on lab exercise, or both.

On this page

Program overview

Some training needs do not fit a standard program. A threat group may be targeting your sector, a new system may change how an incident would play out, or a past incident may have exposed a gap. This service designs an exercise around that one scenario.

It suits security leaders who want a particular risk tested, and any mix of teams: SOC, incident response, IT operations, engineering, leadership, or communications. DeployOpen engineers design and facilitate the exercise and run the debrief.

What a scenario can focus on

Threats to your sector

Techniques publicly reported for threat groups that target your industry, written into a sequence your team can investigate.

Your critical systems

Attacks on the services that matter most to you, such as payment systems, customer data stores, or identity providers.

Past incidents and near misses

A replay of an incident or near miss from your organization, with details changed, to check whether follow-up actions worked.

New technology

Risks from systems you have recently adopted, such as AI assistants and agents, new cloud services, or an acquired company's network.

Suppliers and third parties

Incidents that start at a supplier, managed service provider, or software dependency.

Leadership decisions

Decisions on disclosure, extortion, business continuity, and external communication during a major incident.

How the program runs

We meet the scenario sponsor to agree the question the exercise should answer, the participants, and the decisions they should practice. We review the relevant systems, procedures, and any past incidents you share.

Formats

FormatWho it suitsWhat it covers
Tabletop exerciseLeadership, communications, and cross-team groupsA discussion-based scenario with injects written for each group's decisions
Hands-on lab exerciseSOC, incident response, IT, and engineering teamsTechnical investigation and response in an isolated lab
Combined exerciseOrganizations testing the chain from detection to executive decisionOne scenario run across technical and leadership groups, with a joint debrief
Scenario seriesTeams working through several related risksA set of linked scenarios, each with its own debrief

Example scenarios

Sector-specific intrusion

A threat group known to target your sector gets in through a VPN appliance and moves toward a core business system.

Deepfake-assisted fraud

A cloned executive voice requests an urgent change to payment details, followed by a phishing message to the finance team.

Compromised AI assistant

An internal AI assistant with access to documents and tickets is manipulated into sharing data or changing records.

Managed service provider breach

Attackers use a provider's remote access tool to reach several of your servers.

Insider with privileged access

An administrator who is leaving the company copies data and creates a hidden account.

Loss of a critical service

A destructive attack takes a key service offline. Teams work through recovery order, communications, and continuity decisions.

What you receive

The outputs record what the scenario showed and give your team what it needs to run it again.

Debrief and exercise report

  • Scenario timeline and decisions made
  • Objectives met and not met
  • Observations for each participant group

Detection and response findings

  • Where detection, escalation, or decisions were delayed
  • Evidence and information that was missing
  • Gaps in tooling or access

Recommended improvements

  • Changes to plans and runbooks
  • Detection and logging changes
  • Ownership and decision authority to clarify

Scenario package

  • Controller guide with inject timing and expected responses
  • Participant brief
  • Lab files for the technical parts of the scenario

Common questions

How does this differ from your other training programs?

Our other programs cover a defined skill set for one group. Here the scenario comes first: we design the exercise around one risk you choose and pick the formats and participants to suit it.

Who should attend?

The people who would be involved if the scenario happened. We help you identify the groups, which can include technical teams, executives, legal, communications, and suppliers.

Can non-technical staff take part?

Yes. Tabletop parts of the scenario are written for leadership and business staff, with injects about the decisions they own.

Do exercises use our tools and data?

Scenarios are tailored to your environment and tools. Technical work runs in an isolated lab with synthetic data. We sign an NDA on request.

Is it remote or on-site?

Remote or on-site delivery can be agreed.

Can it be repeated, and how is progress measured?

Yes. You receive the scenario package to rerun it, and we can update the scenario as your environment changes. Comparing a rerun with the first debrief shows whether the recommended changes have taken effect.

How to prepare

Bring the risk or question you want the exercise to address, and the context behind it: threat reports you rely on, past incidents, audit findings, or planned changes to systems.

Name a sponsor who approves the scenario and a small planning group who can review it without taking part. Keep scenario details from participants so the exercise tests how they respond to new information.

Planning references

Scenario techniques are described with MITRE ATT&CK, which gives a shared vocabulary for detection and response findings. Only techniques that serve the exercise objective are included.

Exercise planning, inject design, and evaluation draw on CISA exercise planning materials and NIST SP 800-84.

Sources and further reading

Talk to our team.

Tell us what you're working on, whether it's a deployment, an audit, a security test or a cyber range. You'll speak with an engineer who can help you scope it.

  • 30-minute call: free, with no obligation.
  • NDA on request: we can sign before you share details.
  • Clear next steps: a scope and plan after the call.