Features
A complete platform that covers the entire tabletop exercise lifecycle — from context analysis to compliance reporting.
The secure MCP layer
Your sources, read-only. Every answer, cited.
simler connects to the systems you already keep — never writing, always logging — and feeds them into every exercise.
AI-Generated Simulation Scripts
Generate complete tabletop exercise scripts, including roles, timeline, injects, and the incident's ground truth, in minutes instead of weeks. Every scenario is grounded in your own policy documents and organization profile: industry, revenue, systems, and regulatory frameworks.
- Select which policy documents serve as ground truth per simulation
- Scenario types from ransomware to insider threat, in English or Dutch
- Realistic injects that escalate in severity over the timeline
- Financial figures calibrated to your organization's size and revenue
- Editable scripts with recorded document provenance, ready to review before execution
Scenario type
Ground truth
Policy Documents as Ground Truth
Generate your Information Security Policy, Business Continuity Plan, Incident Response Plan, and Disaster Recovery Plan step-by-step, or upload the ones you have. Simulations are designed against them, so every exercise also reveals the gaps in your plans.
- Guided AI generation for ISP, BCP, IRP, and DRP
- Upload existing documents (PDF, Word, Excel, PowerPoint)
- Version management with full edit history
- Per-simulation document selection with recorded provenance
- Exercises stress-test your plans and expose what's missing
ISP
BCP
IRP
DRP
Digital War Room
Execute exercises in a purpose-built real-time environment. A shared group chat where all participants, human and AI, collaborate, plus private DMs and a facilitator channel, just like your real tools during a real incident.
- Real-time group chat with threaded replies and file attachments
- Private 1-on-1 DMs and a facilitator channel for spoiler-free hints
- Automated inject distribution at scheduled timeline moments
- Support for remote, on-site, or hybrid participation
- Full session logging and transcript for post-exercise analysis
Channels
Team · 4
Unusual encryption activity detected on file servers.
Isolating affected servers. IT Manager, backup status?
Adaptive Injects
Flip one switch and the exercise writes itself live. In adaptive mode, every inject is generated during the session — reacting to what your team says, decides, or ignores — while the scenario's beat plan keeps timing, severity, and coverage exactly on track. Nobody reads the script in advance. Not even you.
- Injects written live as the exercise unfolds, on top of your scenario and documents
- The outside world reacts: journalists quote your statements, attackers mock your mitigations
- The beat plan stays in charge — timing, severity, and targets never derail
- The scripted inject stands by as instant fallback, so the exercise never stalls
- A surprise for everyone, including the organizer — repeat runs stay fresh
Statement is out: “systems stable, no customer data affected.”
Eva Smit (journalist): “You say no customer data — then why is a sample being offered on a leak forum right now?”
In-Character AI Teammates
Can't fill every role? AI agents play them like real colleagues: they respond to injects, coordinate with each other, share evidence such as log files, drafted emails, and breaking news, and actively involve the human players in every key decision.
- In-character responses grounded in the scenario's fixed facts
- Agents share real artifacts: log exports, emails, social posts, news articles
- Autonomous progress when the room goes quiet: they push the incident forward
- Deliberately involve human participants in decisions their role owns
- No more postponed exercises due to availability issues
Pulled the auth logs from the jump host, three failed admin logins right before the encryption started. See attached.
Press is calling. Drafted a holding statement, IT Manager can you approve before it goes out?
Automatic Debriefing & Reporting
Every session is fully logged, enabling automatic generation of comprehensive debriefing reports. Get per-role compliance and competency scores, response times, and missed steps, ready for compliance documentation.
- Procedure compliance scoring against your IRP, per role
- Competency rubric: decision-making, communication, procedure adherence, coordination
- Response time analysis per role on critical injects
- Full transcript of every channel, exportable as PDF
- NIS2-ready reports for audit documentation
Procedure compliance
Audit-readyResponse times · missed steps · full transcript · PDF export
Personal Readiness Tracking
Every team member tracks their own performance across exercises: skill trends, scores per scenario type, and an AI coach that distills it into one measurable focus for the next session. Admins see the whole team's readiness at a glance.
- Score and skill trends across exercises, per competency
- Breakdown per scenario type: see where you're strong and where you're not
- AI coaching review: strengths, growth areas, and one measurable next focus
- Focus targets verified in the next exercise: goals you can actually hit
- Team readiness view for admins with per-member drill-down
Focus for the next exercise
Confirm backup integrity before authorizing recovery
Target: Procedure adherence ≥ 80
Grounded in Your Real Organization
Connect the sources your organization already keeps — system inventories, contact lists, on-call rosters — and every exercise knows your real environment. Scenarios name your actual systems and owners, AI teammates consult them mid-exercise, and Ask your systems lets you test what your organization knows before an incident asks. Built on MCP, the open standard for connecting AI to existing software. Connections are optional — your profile and policy documents alone ground great exercises.
- Read-only by design: connectors can never write to or change your systems
- Scoped access: you grant per source and per use case, revocable in one click
- Every query logged in an access log your admins can audit
- Scenarios cite real systems, owners, and teams instead of generic placeholders
- Starting with Google Sheets — the connector registry grows on the same gateway
Exercise Against Current Threats
Connected sources ground the defender — the threat landscape grounds the attacker. simler distills public advisories from CISA and NCSC-NL into a weekly threat landscape, matched to your sector and systems, every claim cited to its source. Pick a current threat and the exercise models the real adversary: their attack chain, their tempo, their extortion style — while your organization and the incident stay fictional. Train on this month's threats, not last year's template.
- A weekly threat landscape distilled from public advisories — every claim cited
- Ranked for your organization: your sector, systems, and size decide what surfaces first
- Attack chains mapped to MITRE ATT&CK, from initial access to impact
- Live actuality: which groups are claiming victims on leak sites right now
- One click from threat to exercise — and the debrief shows what you were tested against
Interlock ransomware encrypts VMs and exfiltrates data for double-extortion
For youTargets healthcare — your industry
T1189 Drive-By Compromise → T1486 Impact · 6 techniques
The improvement loop
Your team decides. Agents run the process.
Threat to verified fix: your team makes the decisions, at the exercise length you choose — thirty minutes or two hours. Everything in between runs itself.
Pick the threat
Choose what worries you from this week's ranked landscape.
Watches the landscape
Distills public advisories weekly, cites every claim, ranks them for your org.
Play the exercise
Make the calls a real incident would demand — at the length you choose.
Runs the war room
Plays CEO, Legal, CRM owner; delivers injects; keeps the pressure on.
Findings land
Missed steps and knowledge gaps arrive as owned actions — no report to write.
Captures the findings
Logs every missed step live and turns it into an owned action, with severity and owner.
Review & apply fixes
Approve AI-drafted fixes to plans, rosters and inventories.
Drafts the fixes
Turns findings into concrete edits — IRP steps, contact lists, escalation paths.
Watch readiness climb
52 → 61 → 72 → 84. Proof for the board, not promises.
Verifies & schedules
Re-checks fixes against your systems via MCP and loads them into the next retest.
Most organizations stop after the exercise — findings die in a slide deck, and next year starts from zero. The loop is the product.
Quarterly loops compound.
Annual exercises reset to zero.
Each run is a full loop — exercise, findings, fixes, verification — and the next one starts on top of it. That's the difference between practicing and improving.
Every run glyph is the same four steps — exercise, findings, fixes, verified — and each one starts where the last ended. That's compounding readiness.
Try the loop in the tour →Ready to transform your incident readiness?
Run your first exercise this week — plans from €99 per month.