Not invented here
Five public standards, doing five specific jobs.
Nothing about this hour is house opinion. Each of the standards below decides something concrete — the format of the exercise, the shape of the report, the way an update is classified, or the deadline a scenario is allowed to cite. This page is here so you can check any of it yourself.
- 01
NIST SP 800-84
The standard for running exercises. It defines the tabletop format — a discussion, not a live test — that this product follows.
- 02
HSEEP
Homeland Security Exercise and Evaluation Program. Where the shape of the hour comes from: timed updates, a debrief while the room is still together, an after-action report.
- 03
CISA CTEP
The US cyber agency's own free tabletop packs. They set the bar for what a scenario has to contain to be worth an hour of your team's time.
- 04
NIST SP 800-61r3
The current guide to handling an incident. It supplies the five response phases every update is classified against, and the reason the report is structured the way it is.
- 05
UK / EU GDPR
The law behind the notification deadlines in the scenarios. Article numbers are quoted so you can check any of them yourself.
Every update is classified twice.
Once by phase — where in the response you are — and once by lane, which is the kind of work it demands. The pair is what makes the report readable by someone who was not in the room, and it is why a drill surfaces communication and authority failures rather than only technical ones.
Phases
- Identify
- Working out what is actually happening, and how bad it is.
- Contain
- Stopping the spread before understanding the full picture.
- Remove the cause
- Removing the cause rather than the symptom.
- Recover
- Getting back to operating, and knowing when you are safe to.
- Lessons
- Turning what happened into something that changes practice.
These are a lens for reading the hour afterwards, never its running order — and the room never sees a phase label on the shared screen. A visible lifecycle telegraphs the answer, and people recite it instead of deciding.
Lanes
- Decide
- Authority and escalation — who can say yes, and how fast.
- Communicate
- Staff, donors, beneficiaries, partners, media.
- Comply
- Regulator, funder and legal clocks.
- Technical
- Systems, accounts, devices, backups.
- Protect
- People, beneficiary data, and safeguarding duties.
Every scenario has to touch at least four phases and at least three lanes. That floor is enforced by a check that runs before anything ships, not left to whoever wrote it.
Deadlines are quoted, never generated.
Where a scenario says a clock is running, it names the instrument and the article — GDPR Article 33(1) for the 72-hour supervisory-authority notification, 33(2) where a processor has to tell a controller, 34(1) where individuals have to be told. Anything a scenario invents for the sake of the exercise, such as a grant agreement's notification clause, is prefixed Scenario: so it can never be read as a claim about real law.
This is structural rather than editorial. The part of the system that talks to a language model has no write access to a scenario or a clock, so it is not able to add one — and a clock with no citation fails the content check.
The library today
- Scenarios
- 10
- Timed updates
- 101
- Minutes per drill
- 60
Each one is written by hand, reviewed, and version-pinned when a drill starts — so a report always matches what its room was actually shown, even after the scenario is later revised.