Not invented here

Five public standards, doing five specific jobs.

Nothing about this hour is house opinion. Each of the standards below decides something concrete — the format of the exercise, the shape of the report, the way an update is classified, or the deadline a scenario is allowed to cite. This page is here so you can check any of it yourself.

  1. 01

    NIST SP 800-84

    The standard for running exercises. It defines the tabletop format — a discussion, not a live test — that this product follows.

  2. 02

    HSEEP

    Homeland Security Exercise and Evaluation Program. Where the shape of the hour comes from: timed updates, a debrief while the room is still together, an after-action report.

  3. 03

    CISA CTEP

    The US cyber agency's own free tabletop packs. They set the bar for what a scenario has to contain to be worth an hour of your team's time.

  4. 04

    NIST SP 800-61r3

    The current guide to handling an incident. It supplies the five response phases every update is classified against, and the reason the report is structured the way it is.

  5. 05

    UK / EU GDPR

    The law behind the notification deadlines in the scenarios. Article numbers are quoted so you can check any of them yourself.

Every update is classified twice.

Once by phase — where in the response you are — and once by lane, which is the kind of work it demands. The pair is what makes the report readable by someone who was not in the room, and it is why a drill surfaces communication and authority failures rather than only technical ones.

Phases

Identify
Working out what is actually happening, and how bad it is.
Contain
Stopping the spread before understanding the full picture.
Remove the cause
Removing the cause rather than the symptom.
Recover
Getting back to operating, and knowing when you are safe to.
Lessons
Turning what happened into something that changes practice.

These are a lens for reading the hour afterwards, never its running order — and the room never sees a phase label on the shared screen. A visible lifecycle telegraphs the answer, and people recite it instead of deciding.

Lanes

Decide
Authority and escalation — who can say yes, and how fast.
Communicate
Staff, donors, beneficiaries, partners, media.
Comply
Regulator, funder and legal clocks.
Technical
Systems, accounts, devices, backups.
Protect
People, beneficiary data, and safeguarding duties.

Every scenario has to touch at least four phases and at least three lanes. That floor is enforced by a check that runs before anything ships, not left to whoever wrote it.

Deadlines are quoted, never generated.

Where a scenario says a clock is running, it names the instrument and the article — GDPR Article 33(1) for the 72-hour supervisory-authority notification, 33(2) where a processor has to tell a controller, 34(1) where individuals have to be told. Anything a scenario invents for the sake of the exercise, such as a grant agreement's notification clause, is prefixed Scenario: so it can never be read as a claim about real law.

This is structural rather than editorial. The part of the system that talks to a language model has no write access to a scenario or a clock, so it is not able to add one — and a clock with no citation fails the content check.

The library today

Scenarios
10
Timed updates
101
Minutes per drill
60

Each one is written by hand, reviewed, and version-pinned when a drill starts — so a report always matches what its room was actually shown, even after the scenario is later revised.