CISA CTEP-Aligned  ·  OT/ICS Edition

The Professional Tabletop Exercise Platform for Critical Infrastructure

65 ready-to-run ICS/OT cybersecurity exercises — from Foundational to Advanced. AI-powered facilitation, After Action Reports, and live multi-participant sessions. 4 languages. Purpose-built for operational technology environments.

✓ CISA CTEP-Aligned ✓ IEC 62443 ✓ NIST SP 800-82 ✓ NIS2 & DORA ✓ NERC CIP ✓ ISO 27001
65
Ready-to-Run Exercises
4
Languages (EN/FR/PT/ES)
20
Critical Infrastructure Sectors
87%
Ransomware Increase vs OT
Regulatory & Framework Alignment

Built for Every Regulatory Landscape

Every exercise maps to the frameworks your regulators expect — from CISA guidance to EU directives to industrial control standards.

CISA CTEP
Cyber Tabletop Exercise Program

All 65 exercises align to CISA CTEP objectives with CISA CPG 2.0 framework alignment and structured AAR export.

IEC 62443
Industrial Cybersecurity Standard

Scenarios map to IEC 62443 security levels and control domains for industrial automation and control systems.

NIST SP 800-82
ICS Security Guide (Rev. 3)

Threat scenarios reference NIST SP 800-82 r3 controls for OT and industrial control system environments.

NIST CSF 2.0
Cybersecurity Framework

Exercises cover all CSF 2.0 core functions: Govern, Identify, Protect, Detect, Respond, and Recover.

NIS2
EU Network & Information Security

Pro plan includes NIS2 compliance filters for essential and important entity requirements under the EU directive.

DORA
Digital Operational Resilience Act

Financial sector scenarios address ICT risk management and incident classification under the EU DORA regulation.

NERC CIP
Critical Infrastructure Protection

Energy sector exercises align to NERC CIP standards for bulk electric system cybersecurity and incident response.

ISO 27001
Information Security Management

Scenarios support ISO/IEC 27001 Annex A controls for information security risk assessment and incident response.

The Problem

Why Most Tabletop Exercises Fail

Generic, poorly facilitated exercises leave critical gaps unaddressed and give teams false confidence in their response capabilities.

🎭
Too Generic

Off-the-shelf exercises ignore your sector's specific OT architecture, threat actors, and regulatory requirements. Generic doesn't prepare teams for real incidents.

📋
No Facilitation Guide

Without structured injects and discussion prompts, exercises devolve into unfocused meetings. Facilitators are left improvising with no clear path forward.

📭
No Follow-Through

Exercises end without captured learnings. No structured After Action Report means gaps identified are never addressed and history repeats.

The Solution

Everything You Need to Run World-Class Exercises

A complete end-to-end platform purpose-built for OT/ICS environments — from scenario selection through to After Action Report export.

📁
65 Ready-to-Run Scenarios

Foundational, Intermediate, and Advanced difficulty tiers. OT/ICS Core, Warehousing & Logistics, Pharmaceutical, Oil & Gas, Nuclear, and more — each with complete facilitator guides and timed injects.

Guided Exercise Runner

Step-by-step facilitation engine: Briefing → Module 1 Injects → Discussion → Module 2 Escalation → Hot Wash. Run world-class exercises without improvisation.

AI-Powered Facilitation

AI Custom Facilitator Briefings personalized to your organization. AI After Action Report summaries. Semantic scenario recommendations based on your exercise history. Powered by Claude claude-3-5-haiku.

🔴
Live Multi-Participant Sessions

Host real-time exercises across distributed teams. Participants join via a 6-digit code and receive live step updates. No video conferencing add-ons needed — built directly into the platform.

📄
After Action Reports & Analytics

Export AI-enhanced AARs as structured .txt files. Track recurring capability gaps with a visual heatmap. Generate executive PDF progress reports for board and regulatory audiences.

🌐
4-Language Support

Full translations in English, French, Portuguese, and Spanish. AI facilitation outputs are language-aware. Serve global and multilingual critical infrastructure teams seamlessly.

🎯
OT/ICS Threat Intelligence

Scenarios mapped to real threat groups: VOLTZITE, BAUXITE, GRAPHITE, ELECTRUM. Every exercise is grounded in real-world TTPs and MITRE ATT&CK for ICS techniques.

🔒
Encrypted Offline Pack

Download AES-256-GCM encrypted offline exercise packs for air-gapped or classified environments. Run exercises with zero internet connectivity — Pro and Team plans only.

CISA CTEP & IEC 62443 Aligned

Every exercise maps to CISA CTEP objectives and IEC 62443 control domains for regulatory defensibility. NIS2, DORA, NERC CIP, and NIST CSF 2.0 filters included.

Ready to See It in Action?

Start with 3 free exercises — no credit card, no setup. Your first exercise can be running in under 5 minutes.

Start Free — 3 Exercises Talk to Our Team →
Platform Preview

65 Professional Exercise Scenarios

Foundational to Advanced. Each scenario is a complete exercise package: facilitator guide, participant briefing, timed injects, discussion questions, and AI-powered AAR.

⭐ Foundational
First OT Ransomware Response

Your organization's first cyber incident. Ransomware appears on IT systems and the OT team is unsure if their PLCs are affected. Roles, escalation paths, and communication are tested for the first time.

Ransomware Incident Response All Sectors
⏳ 1.5–2 Hours 👥 6–12 Players Foundational
Warehousing / 3PL
ASRS & Shuttle System Ransomware

Ransomware propagates from WMS servers into WCS controlling automated storage and retrieval systems (ASRS). Shuttle fleets halt. 50,000 pallet locations are locked. Order fulfilment stops entirely.

Ransomware WCS / WMS ASRS / Shuttles
⏳ 2–3 Hours 👥 8–15 Players Intermediate
OT / ICS
Industrial Control Systems Compromise

A nation-state threat actor conducts spear-phishing targeting IT/OT convergence personnel. Lateral movement into OT networks results in adversary access to SCADA HMI.

ICS/SCADA Intrusion VOLTZITE IEC 62443
⏳ 3–4 Hours 👥 8–15 Players Advanced
Post & Parcel
Automated Sortation System Attack

A malicious firmware update pushed via a compromised vendor remote access channel corrupts WCS logic controlling high-speed cross-belt sorters. 40,000 parcels per hour halt. Next-day delivery SLAs collapse.

Firmware Attack WCS / Sorters Supply Chain
⏳ 2–3 Hours 👥 8–15 Players Intermediate
Executive & Leadership
Board-Level OT Cyber Crisis

A major OT breach goes public. The board convenes an emergency session. Regulatory notifications are required within 72 hours and media inquiries are escalating rapidly.

Board Crisis Executive NIS2 / DORA
⏳ 2–3 Hours 👥 5–10 Players Intermediate
Pharmaceutical
Cold Chain WMS Integrity Attack

An insider threat manipulates temperature thresholds in a pharmaceutical warehouse WMS. Vaccines stored at 2–8°C are silently exposed to excursions. DSCSA traceability data is corrupted. Recall procedures activate.

Insider Threat Cold Chain / WMS FDA / DSCSA
⏳ 2–3 Hours 👥 8–14 Players Intermediate
Pricing

Choose Your Plan

Start free with 3 exercises — no credit card required. Every paid plan includes AI features, live session mode, and all 65 scenarios. Upgrade anytime. Cancel anytime.

Monthly
Annual Save 25%
Starter
$0 / month

Perfect for evaluating the platform

  • 3 Exercises (OT/ICS Core)
  • Guided Exercise Runner
  • After Action Report Export
  • English Language
  • Full 65-Exercise Library
  • Multi-Language Support
  • Priority Support
Get Started Free
Enterprise
Team
$6,490 / month

For MSSPs, consultancies, and large organizations

  • Everything in Pro
  • Up to 250 Seats
  • Live Multi-Participant Sessions
  • Custom Branding (White-Label)
  • Compliance Evidence Package
  • Priority Support
  • Usage Analytics & Gap Heatmap
  • Dedicated Onboarding & CSM
Get Team

Start free with 3 exercises — no credit card required. Upgrade anytime. Cancel anytime.

Trusted By

Built for Critical Infrastructure Teams

Security professionals across 20+ critical infrastructure sectors — from energy grids and hospital operating theatres to school districts and university research labs — trust Skyhigh to deliver measurable exercise outcomes.

Energy & Power Water & Utilities Banking & Finance Healthcare Warehousing & 3PL Post & Parcel Oil & Gas Manufacturing Pharmaceutical Mining Food & Agriculture Chemical Transport & Logistics Nuclear & Space Government & Defence K-12 Education Higher Education
Energy & Power Sector

"The AI facilitator briefing was genuinely impressive — it referenced our plant's specific configuration in a way a generic exercise never would. Our OT and IT teams left aligned for the first time."

— Head of OT Security, Regional Utility
Water & Wastewater

"CISA CTEP alignment gave us instant credibility with our state regulator. The French translation was a game-changer for our cross-border Québec operations team. We ran our first exercise in under an hour of setup."

— CISO, Municipal Water Authority
3PL & Warehousing

"We finally have a scenario that covers our ASRS and WCS environment — not just generic IT scenarios. The Foundational tier let our ops team run their first exercise without a cybersecurity consultant in the room."

— VP Operations Technology, 3PL Provider
FAQ

Common Questions

Everything you need to know about the platform before getting started.

A tabletop exercise is a structured discussion-based exercise where key personnel walk through a simulated cyber incident scenario. Unlike live drills, tabletops focus on decision-making, communication, and process rather than technical response. They are the most cost-effective way to identify gaps in your incident response capabilities.

No. Each exercise includes complete facilitator guides with structured injects, timed discussion prompts, and step-by-step instructions. The guided exercise runner handles the flow so your facilitator can focus on driving discussion rather than managing logistics.

Yes. Every exercise includes a customizable organization name field. All scenario narratives use [ORGANIZATION] placeholders that are replaced with your organization's name during the briefing step, making each exercise feel tailored to your specific environment.

All 65 exercises are designed in alignment with CISA's Cyber Tabletop Exercise Program (CTEP) objectives and reference CISA CPG 2.0 and IEC 62443 security levels, providing a defensible framework for regulatory reporting and audit purposes.

All exercise notes are stored locally in your browser session and exported on demand as a .txt After Action Report. The optional AI AAR Summary calls our Edge Function with only the structured exercise data — no raw notes — and returns a three-part executive summary. No data is retained beyond the request.

Yes. We offer Foundational-difficulty exercises specifically designed for organizations running their first OT/ICS tabletop. Foundational scenarios run 1.5–2 hours, use plain-language facilitation guides, and focus on building basic incident response muscle memory — communication flows, escalation paths, and decision-making authority — before moving to Intermediate or Advanced scenarios that test technical depth.

Yes. The Team plan (up to 250 seats) and white-label branding features make Skyhigh ideal for MSSPs and independent consultants running exercises for multiple clients. You can customize the platform with your firm's logo and accent color, invite client team members as facilitator seats, and download encrypted offline exercise packs for air-gapped client environments. Contact us for partner and volume pricing.

Yes — and this is a growing area of the library. We now include dedicated scenarios for Warehouse Management Systems (WMS), Warehouse Control Systems (WCS), Warehouse Execution Systems (WES), ASRS and shuttle systems, AGV fleets, robotic picking, cross-belt sorters, and pharmaceutical cold chain environments. These scenarios are grounded in real-world CVEs and ICS Advisory Project threat data for logistics and distribution OT environments. Filter by sector in the exercise library to find them.

Yes. Team plan hosts can launch a Live Session that generates a 6-digit code. Participants navigate to the /join page, enter the code, and receive real-time step updates as the facilitator advances the exercise. Participant role cards, inject text, and discussion questions are displayed live in their browser — no app download, no video conferencing integration required. Live participant count is shown in the host control bar throughout the session.

Talk to Our Team

Not Ready to Self-Serve?

Large organization, procurement process, or want a live demo first? Fill in the form and we'll be in touch within one business day.

🔒 Work email required — inquiries from personal email accounts (Gmail, Yahoo, etc.) cannot be processed.

Your First Exercise Can Be Running in 5 Minutes

Start free with 3 exercises — no credit card required. Upgrade when you're ready. No lock-in. Cancel anytime.