INDUSTRIAL CYBER RESILIENCE EXERCISES

What happens when a cyber incident reaches the factory floor?

Generic tabletop exercises stop at the network. OT Crucible starts where manufacturing gets difficult: production, safety, machine state, product integrity, suppliers, customers, and recovery.

Not another generic ransomware tabletop.

OTC-001·BLACK FORGE
LIVE EXERCISE
  1. 08:10
    STATUS UPDATE

    Helpdesk reports multiple users cannot access shared engineering resources.

  2. 08:24
    SYSTEM ALERT

    Security monitoring indicates suspicious activity affecting multiple enterprise systems.

  3. 08:35
    OPERATOR REPORT

    New jobs cannot reliably retrieve required digital manufacturing information. Some machines hold local programs.

  4. 08:45
    QUALITY FINDING

    Unexpected revision discrepancy found on manufacturing data for a current production job.

  5. DECISION POINT

    Do you continue production? Who makes that call?

    HOLD PRODUCTIONCONTINUE ON LOCAL DATAISOLATE & ASSESS

Build a realistic model of your facility. Break it on purpose.

Run an interactive industrial cyber exercise, see where decisions break down, and leave with a prioritized improvement plan.

Facility resilience profile

Model your plant's real dependencies — identity to ERP to MES to production cells to inspection — in about fifteen minutes. No credentials, no network diagrams, no sensitive detail required.

Live control room

A facilitator publishes injects, forces decisions, and records observations while your team argues about what to do. The arguing is the point.

Operational consequences

A deterministic engine tracks production availability, integrity confidence, and containment as your decisions play out. No dice, no hand-waving.

Evidence-backed after-action

Every finding traces to a decision someone made under pressure. Owners, priorities, target dates, framework references — an improvement plan, not a platitude.

The OT Crucible series

33 manufacturing-specific scenarios, from ransomware to supply chain to a multi-site capstone. Each one forces the questions a real crisis will ask.

33 SCENARIOS · 1 SERIES

OTC-001AVAILABLE

BLACK FORGE

Ransomware meets the factory

Enterprise systems degrade, then the floor feels it. What do you isolate, what keeps running, and what does a trustworthy restart require?

OTC-002AVAILABLE

GHOST TOOLPATH

Can you trust the part?

Unexplained differences appear between authorized and production versions of manufacturing data. Which files — and which parts — are still trustworthy?

OTC-003AVAILABLE

FALSE PASS

When quality data cannot be trusted

Conflicting measurements surface in the quality system. Can product ship? Which lots need reinspection? How far back does the investigation go?

OTC-004AVAILABLE

REMOTE HAND

The vendor connection

Suspicious activity appears on a machine vendor's remote-support pathway. Manage the uncertainty without presuming guilt — or losing support.

Plus 29 more, all fully authored — loss of view, broken backups, safety-monitoring assurance, and the IRON TEMPEST capstone; an extended supply-chain and geostrategic series (supplier collapse, counterfeit parts, export-control shock, primes under breach, conflict logistics, grid instability, disinformation, espionage); insider and controlled-data incidents (departing-employee sabotage, CUI/ITAR spillage, payment/BEC fraud, M&A integration, end-of-support exploitation, impersonation); and QUICKSILVER, an agentic-AI adversary operating at machine speed.

THE QUESTION EVERY SCENARIO RETURNS TO

How do you know?

  • How do you know the machine is safe to run?
  • How do you know the CNC program is authentic?
  • How do you know the product is trustworthy?
  • How do you know the backup is actually usable?
  • How do you know the attacker is contained?
  • How do you know the vendor connection is safe?
  • How do you know production can restart?