INDUSTRIAL CYBER RESILIENCE EXERCISES
What happens when a cyber incident reaches your operations?
Generic tabletop exercises stop at the network. OT Crucible starts where operational technology gets difficult: safe operations, service continuity, physical consequences, public trust, regulators, and recovery — whether you run a plant, a grid, a pipeline, or an airport.
Not another generic ransomware tabletop.
- 08:10MFG · STATUS UPDATE
Helpdesk reports multiple users cannot access shared engineering resources.
- 08:24WTR · SYSTEM ALERT
Chemical dosing setpoints outside the safe band. Change history cannot attribute the edits to any operator.
- 08:35PWR · OPERATOR REPORT
Breakers opening across the territory. No dispatcher issued the commands.
- 08:45AVN · QUALITY FINDING
The sorter can no longer say which bags were screened. Departures are due.
- DECISION POINT
Do you keep operating? Who makes that call?
HOLD OPERATIONSCONTINUE ON LOCAL CONTROLISOLATE & ASSESS
Build a realistic model of your facility. Break it on purpose.
Run an interactive industrial cyber exercise, see where decisions break down, and leave with a prioritized improvement plan.
Facility resilience profile
Model your facility's real dependencies — identity and business systems down to control systems, field operations, and the vendors in between — in about fifteen minutes. No credentials, no network diagrams, no sensitive detail required.
Live control room
A facilitator publishes injects, forces decisions, and records observations while your team argues about what to do. The arguing is the point.
Operational consequences
A deterministic engine tracks service and production availability, safety margin, public trust, and containment as your decisions play out. No dice, no hand-waving.
Evidence-backed after-action
Every finding traces to a decision someone made under pressure. Owners, priorities, target dates, framework references — an improvement plan, not a platitude.
The OT Crucible series
149 scenarios across 15 series — spanning manufacturing and process industries, water and power, oil & gas and chemicals, food and agriculture, transportation and logistics, resource extraction, healthcare, the built environment, and space systems, plus cross-sector capstones. Each one forces the questions a real crisis will ask.
149 SCENARIOS · 15 SERIES
BLACK FORGE
Ransomware meets the factory
Enterprise systems degrade, then the floor feels it. What do you isolate, what keeps running, and what does a trustworthy restart require?
CAUSTIC TIDE
When the dose becomes the danger
Dosing setpoints drift outside the safe band and the change history can't say who moved them. Manual control, public advisories, regulators — in what order?
SEVERED PHASE
No dispatcher touched a breaker
The territory is going dark on commands nobody issued. What do you trust — the SCADA screens, the field crews, or neither?
PAPER HORIZON
The morning the shared platform went dark
The system every airline at the airport depends on stops answering. Departures are due, passengers are queuing, and paper is all you have.
Plus 145 more across every series — loss of view under uncertainty, safety-instrumented-system trust, cold-chain and record integrity, autonomous-fleet safety, precautionary shutdowns, and shared-dependency cascades that strike many sectors at once. Every scenario is grounded in a documented real-world incident — including QUICKSILVER, an agentic-AI adversary at machine speed.
THE QUESTION EVERY SCENARIO RETURNS TO
How do you know?
- →How do you know the process is safe to run?
- →How do you know the control logic is authentic?
- →How do you know the readings are real?
- →How do you know the backup is actually usable?
- →How do you know the attacker is contained?
- →How do you know the vendor connection is safe?
- →How do you know operations can restart?
