simler

Features

A complete platform that covers the entire tabletop exercise lifecycle — from context analysis to compliance reporting.

The secure MCP layer

Your sources, read-only. Every answer, cited.

simler connects to the systems you already keep — never writing, always logging — and feeds them into every exercise.

AI-Generated Simulation Scripts

Generate complete tabletop exercise scripts, including roles, timeline, injects, and the incident's ground truth, in minutes instead of weeks. Every scenario is grounded in your own policy documents and organization profile: industry, revenue, systems, and regulatory frameworks.

  • Select which policy documents serve as ground truth per simulation
  • Scenario types from ransomware to insider threat, in English or Dutch
  • Realistic injects that escalate in severity over the timeline
  • Financial figures calibrated to your organization's size and revenue
  • Editable scripts with recorded document provenance, ready to review before execution
Generate simulation

Scenario type

Ransomware Attack

Ground truth

Information Security Policyfinal
Incident Response Planfinal
Generate simulation

Policy Documents as Ground Truth

Generate your Information Security Policy, Business Continuity Plan, Incident Response Plan, and Disaster Recovery Plan step-by-step, or upload the ones you have. Simulations are designed against them, so every exercise also reveals the gaps in your plans.

  • Guided AI generation for ISP, BCP, IRP, and DRP
  • Upload existing documents (PDF, Word, Excel, PowerPoint)
  • Version management with full edit history
  • Per-simulation document selection with recorded provenance
  • Exercises stress-test your plans and expose what's missing
Documents
final

ISP

final

BCP

draft

IRP

final

DRP

Digital War Room

Execute exercises in a purpose-built real-time environment. A shared group chat where all participants, human and AI, collaborate, plus private DMs and a facilitator channel, just like your real tools during a real incident.

  • Real-time group chat with threaded replies and file attachments
  • Private 1-on-1 DMs and a facilitator channel for spoiler-free hints
  • Automated inject distribution at scheduled timeline moments
  • Support for remote, on-site, or hybrid participation
  • Full session logging and transcript for post-exercise analysis
War room · Live session
inject · critical

Unusual encryption activity detected on file servers.

SOC ManagerAI agent

Isolating affected servers. IT Manager, backup status?

Type a message…Send

Adaptive Injects

Flip one switch and the exercise writes itself live. In adaptive mode, every inject is generated during the session — reacting to what your team says, decides, or ignores — while the scenario's beat plan keeps timing, severity, and coverage exactly on track. Nobody reads the script in advance. Not even you.

  • Injects written live as the exercise unfolds, on top of your scenario and documents
  • The outside world reacts: journalists quote your statements, attackers mock your mitigations
  • The beat plan stays in charge — timing, severity, and targets never derail
  • The scripted inject stands by as instant fallback, so the exercise never stalls
  • A surprise for everyone, including the organizer — repeat runs stay fresh
War room · Adaptive injects
Communications Lead

Statement is out: “systems stable, no customer data affected.”

inject · highwritten live

Eva Smit (journalist): “You say no customer data — then why is a sample being offered on a leak forum right now?”

T+35m · sealed — written when it fires

In-Character AI Teammates

Can't fill every role? AI agents play them like real colleagues: they respond to injects, coordinate with each other, share evidence such as log files, drafted emails, and breaking news, and actively involve the human players in every key decision.

  • In-character responses grounded in the scenario's fixed facts
  • Agents share real artifacts: log exports, emails, social posts, news articles
  • Autonomous progress when the room goes quiet: they push the incident forward
  • Deliberately involve human participants in decisions their role owns
  • No more postponed exercises due to availability issues
War room · AI teammates
CISOAI agent

Pulled the auth logs from the jump host, three failed admin logins right before the encryption started. See attached.

auth-server-export.loggenerated
Communications LeadAI agent

Press is calling. Drafted a holding statement, IT Manager can you approve before it goes out?

Waiting on you…

Automatic Debriefing & Reporting

Every session is fully logged, enabling automatic generation of comprehensive debriefing reports. Get per-role compliance and competency scores, response times, and missed steps, ready for compliance documentation.

  • Procedure compliance scoring against your IRP, per role
  • Competency rubric: decision-making, communication, procedure adherence, coordination
  • Response time analysis per role on critical injects
  • Full transcript of every channel, exportable as PDF
  • NIS2-ready reports for audit documentation
Session debrief

Procedure compliance

Audit-ready
IT Manager (you)74
SOC Manager81
CISO68

Response times · missed steps · full transcript · PDF export

Personal Readiness Tracking

Every team member tracks their own performance across exercises: skill trends, scores per scenario type, and an AI coach that distills it into one measurable focus for the next session. Admins see the whole team's readiness at a glance.

  • Score and skill trends across exercises, per competency
  • Breakdown per scenario type: see where you're strong and where you're not
  • AI coaching review: strengths, growth areas, and one measurable next focus
  • Focus targets verified in the next exercise: goals you can actually hit
  • Team readiness view for admins with per-member drill-down
My readiness

Focus for the next exercise

Confirm backup integrity before authorizing recovery

Target: Procedure adherence ≥ 80

Decision-making74
Communication82
Procedure adherence61

Grounded in Your Real Organization

Connect the sources your organization already keeps — system inventories, contact lists, on-call rosters — and every exercise knows your real environment. Scenarios name your actual systems and owners, AI teammates consult them mid-exercise, and Ask your systems lets you test what your organization knows before an incident asks. Built on MCP, the open standard for connecting AI to existing software. Connections are optional — your profile and policy documents alone ground great exercises.

  • Read-only by design: connectors can never write to or change your systems
  • Scoped access: you grant per source and per use case, revocable in one click
  • Every query logged in an access log your admins can audit
  • Scenarios cite real systems, owners, and teams instead of generic placeholders
  • Starting with Google Sheets — the connector registry grows on the same gateway
Connected via MCPlive
#System inventoryGoogle Sheets
#On-call rosterGoogle Sheets
read-onlyscopedloggedrevocable

Exercise Against Current Threats

Connected sources ground the defender — the threat landscape grounds the attacker. simler distills public advisories from CISA and NCSC-NL into a weekly threat landscape, matched to your sector and systems, every claim cited to its source. Pick a current threat and the exercise models the real adversary: their attack chain, their tempo, their extortion style — while your organization and the incident stay fictional. Train on this month's threats, not last year's template.

  • A weekly threat landscape distilled from public advisories — every claim cited
  • Ranked for your organization: your sector, systems, and size decide what surfaces first
  • Attack chains mapped to MITRE ATT&CK, from initial access to impact
  • Live actuality: which groups are claiming victims on leak sites right now
  • One click from threat to exercise — and the debrief shows what you were tested against
ActiveInterlock19 victims claimed · 30d

Interlock ransomware encrypts VMs and exfiltrates data for double-extortion

For youTargets healthcare — your industry

T1189 Drive-By Compromise → T1486 Impact · 6 techniques

CISA AA25-203A · citedExercise this

The improvement loop

Your team decides. Agents run the process.

Threat to verified fix: your team makes the decisions, at the exercise length you choose — thirty minutes or two hours. Everything in between runs itself.

You · 2 min

Pick the threat

Choose what worries you from this week's ranked landscape.

AI · auto

Watches the landscape

Distills public advisories weekly, cites every claim, ranks them for your org.

You · 30 min – 2 h

Play the exercise

Make the calls a real incident would demand — at the length you choose.

AI · auto

Runs the war room

Plays CEO, Legal, CRM owner; delivers injects; keeps the pressure on.

You · 0 min

Findings land

Missed steps and knowledge gaps arrive as owned actions — no report to write.

AI · auto

Captures the findings

Logs every missed step live and turns it into an owned action, with severity and owner.

You · 10 min

Review & apply fixes

Approve AI-drafted fixes to plans, rosters and inventories.

AI · auto

Drafts the fixes

Turns findings into concrete edits — IRP steps, contact lists, escalation paths.

You · 0 min

Watch readiness climb

52 → 61 → 72 → 84. Proof for the board, not promises.

AI · auto

Verifies & schedules

Re-checks fixes against your systems via MCP and loads them into the next retest.

Most organizations stop after the exercise — findings die in a slide deck, and next year starts from zero. The loop is the product.

Quarterly loops compound.
Annual exercises reset to zero.

Each run is a full loop — exercise, findings, fixes, verification — and the next one starts on top of it. That's the difference between practicing and improving.

With the loop — readiness scoreWithout — annual exercise, findings unfixed
1007040ANNUAL, CONSULTANT-LED · FLAT3 FIXES VERIFIED ✓4 FIXES VERIFIED ✓5 FIXES VERIFIED ✓52Q1 · RUN 1Ransomware61Q2 · RETEST + NEWSupply chain72Q3 · RETEST + NEWInsider threat84Q4 · RETEST + NEWCloud outage

Every run glyph is the same four steps — exercise, findings, fixes, verified — and each one starts where the last ended. That's compounding readiness.

Try the loop in the tour →

Ready to transform your incident readiness?

Run your first exercise this week — plans from €99 per month.