CISA CTEP-Aligned  ·  OT/ICS Edition

The Professional Tabletop Exercise Platform for Critical Infrastructure

22 ready-to-run ICS/OT cybersecurity exercises. Guided facilitation engine. After Action Reports. 4 languages. Purpose-built for operational technology environments.

✓ CISA CTEP-Aligned ✓ IEC 62443 ✓ NIST SP 800-82 ✓ 4 Languages ✓ No Backend Required
22
Ready-to-Run Exercises
4
Languages (EN/FR/PT/ES)
16
Critical Infrastructure Sectors
87%
Ransomware Increase vs OT
The Problem

Why Most Tabletop Exercises Fail

Generic, poorly facilitated exercises leave critical gaps unaddressed and give teams false confidence in their response capabilities.

🎭
Too Generic

Off-the-shelf exercises ignore your sector's specific OT architecture, threat actors, and regulatory requirements. Generic doesn't prepare teams for real incidents.

📋
No Facilitation Guide

Without structured injects and discussion prompts, exercises devolve into unfocused meetings. Facilitators are left improvising with no clear path forward.

📭
No Follow-Through

Exercises end without captured learnings. No structured After Action Report means gaps identified are never addressed and history repeats.

The Solution

Everything You Need to Run World-Class Exercises

A complete end-to-end platform purpose-built for OT/ICS environments — from scenario selection through to After Action Report export.

📁
22 Ready-to-Run Scenarios

OT/ICS Core, Cross-Sector Threats, Sector-Specific, and Executive & Leadership. Each scenario includes complete facilitator guides with timed injects.

Guided Exercise Runner

Step-by-step facilitation engine: Briefing → Module 1 Injects → Discussion → Module 2 Escalation → Hot Wash. No improvisation needed.

🌐
4-Language Support

Full translations in English, French, Portuguese, and Spanish. Serve global teams and international critical infrastructure operators seamlessly.

📄
After Action Reports

Export complete session notes as a structured AAR .txt file. Document findings, action items, and next steps automatically from within the runner.

🎯
OT/ICS Threat Intelligence

Scenarios mapped to real threat groups: VOLTZITE, BAUXITE, GRAPHITE, ELECTRUM. Grounded in real-world TTPs targeting critical infrastructure.

CISA CTEP & IEC 62443 Aligned

Every exercise maps to CISA Cyber Tabletop Exercise Program (CTEP) objectives and IEC 62443 control domains for regulatory defensibility.

Platform Preview

22 Professional Exercise Scenarios

Each scenario is a complete exercise package: facilitator guide, participant briefing, timed injects, discussion questions, and AAR template.

OT / ICS
Industrial Control Systems Compromise

A nation-state threat actor conducts spear-phishing targeting IT/OT convergence personnel. Lateral movement into OT networks results in adversary access to SCADA HMI.

ICS/SCADA Intrusion VOLTZITE IEC 62443
⏳ 3–4 Hours 👥 8–15 Players Advanced
Cross-Sector
Ransomware: OT/IT Simultaneous Attack

Ransomware encrypts enterprise IT systems while a second payload targets OT historian servers and engineering workstations, threatening operational continuity.

Ransomware BAUXITE NIST SP 800-82
⏳ 3–4 Hours 👥 10–20 Players Advanced
Executive & Leadership
Board-Level Crisis Management

A major OT breach goes public. The board convenes an emergency session. Regulatory notifications are required within 72 hours and media inquiries are escalating.

Board Crisis Executive SEC Rules
⏳ 2–3 Hours 👥 5–10 Players Foundational
Pricing

Choose Your Plan

Start free with 3 exercises. Upgrade anytime with no lock-in.

Monthly
Annual Save 17%
Starter
$0 / month

Perfect for evaluating the platform

  • 3 Exercises (OT/ICS Core)
  • Guided Exercise Runner
  • After Action Report Export
  • English Language
  • Full 22-Exercise Library
  • Multi-Language Support
  • Priority Support
Get Started Free
White-Label
Enterprise
Contact Us

For MSSPs, consultancies, and large organizations

  • Everything in Professional
  • White-Label / Custom Branding
  • Custom Scenario Development (1–3/yr)
  • Unlimited Seats / Organizations
  • SLA-backed Support
  • MSSP Reseller Rights
  • Dedicated Onboarding
Contact Sales

All plans include a 14-day free trial. No credit card required for Starter. Cancel anytime.

Trusted By

Built for Critical Infrastructure Teams

Security professionals across energy, utilities, and industrial sectors trust Skyhigh to deliver measurable exercise outcomes.

[Organization Name], Energy Sector

"The exercise runner alone saved us hours of preparation time. Our OT and IT teams were aligned after the first session in a way we hadn't achieved in years of meetings."

— Head of OT Security
[Organization Name], Water Utility

"The CISA CTEP alignment gave us instant credibility with our regulators. The French translation was a game-changer for our Canadian operations team."

— CISO
[Organization Name], Industrial Manufacturer

"We ran the ICS Compromise scenario with our board and got more meaningful discussion in 3 hours than in 3 years of tabletop history."

— VP Operations
FAQ

Common Questions

Everything you need to know about the platform before getting started.

A tabletop exercise is a structured discussion-based exercise where key personnel walk through a simulated cyber incident scenario. Unlike live drills, tabletops focus on decision-making, communication, and process rather than technical response. They are the most cost-effective way to identify gaps in your incident response capabilities.

No. Each exercise includes complete facilitator guides with structured injects, timed discussion prompts, and step-by-step instructions. The guided exercise runner handles the flow so your facilitator can focus on driving discussion rather than managing logistics.

Yes. Every exercise includes a customizable organization name field. All scenario narratives use [ORGANIZATION] placeholders that are replaced with your organization's name during the briefing step, making each exercise feel tailored to your specific environment.

All 22 exercises are designed in alignment with CISA's Cyber Tabletop Exercise Program (CTEP) objectives. Each scenario maps to CISA CPG 2.0 controls and IEC 62443 security levels, providing a defensible framework for regulatory reporting and audit purposes.

All exercise notes are stored locally in your browser session and exported on demand as a .txt After Action Report. No data is transmitted to external servers during the exercise. Your sensitive findings remain entirely under your control.

Ready to Elevate Your Cyber Preparedness?

Join critical infrastructure teams running professional tabletop exercises with Skyhigh.