For funders and networks
You already ask grantees about cyber-preparedness. This is how you find out.
A questionnaire tells you whether an organization has a policy. It cannot tell you whether anyone has read it, who would authorize disconnecting a server at 2am, or how long it would take to warn the people they serve. An hour of rehearsal tells you all three — and leaves the grantee better off either way.
A capacity-building line, not a software purchase.
Grantees resist buying tools and reflexively accept training. This is training — facilitated, documented, and evidenced — which is why it survives a budget conversation that a subscription would not.
Sponsor the cohort
One agreement covers every grantee in the portfolio. They sign in and run their own drills; nobody has to raise a purchase order for $50.
They keep the report
The After-Action Report belongs to the organization that ran the drill. It is theirs to act on and theirs to send you — the value does not depend on you seeing it.
You see the roll-up
Which organizations have rehearsed, which response phases the cohort is weakest in, and how many corrective actions actually closed. Not a self-assessment score.
What it is not
Nobody is being tested, scored or ranked.
A drill where the grantee suspects the funder is marking them produces a performance, not a rehearsal — and the gaps you most need to know about are exactly the ones nobody volunteers. So decisions are recorded against a role and never against a person, and the roll-up reports on the cohort rather than grading its members.
It is also not a penetration test, a red team or a security audit. Nothing is deployed into a grantee's systems and no credential is ever requested. It is a discussion in a room, on a clock.
Honest about the stage
The drill, the report and the export are built and working. The cohort roll-up is not — the tenancy boundary it needs exists and is tested, but the dashboard itself comes after action tracking.
If a cohort is something you would fund, the useful next step is a conversation now rather than a waiting list. Early cohorts shape what the roll-up reports.
10 scenarios today, each an hour, covering ransomware, payment fraud, account takeover, insider access, vendor breach, accidental disclosure and public-platform compromise.
Start with one grantee, and one hour.
Pick an organization you trust to be candid, have them run a drill, and read the report they produce. If it tells you something a grant report never has, the cohort conversation is easy. If it does not, you have spent an hour.