CISA CTEP-Aligned  ·  OT/ICS Edition

The Professional Tabletop Exercise Platform for Critical Infrastructure

47 ready-to-run ICS/OT cybersecurity exercises. Guided facilitation engine. After Action Reports. 4 languages. Purpose-built for operational technology environments.

✓ CISA CTEP-Aligned ✓ IEC 62443 ✓ NIST SP 800-82 ✓ NIS2 & DORA ✓ NERC CIP ✓ ISO 27001
47
Ready-to-Run Exercises
4
Languages (EN/FR/PT/ES)
16
Critical Infrastructure Sectors
87%
Ransomware Increase vs OT
Regulatory & Framework Alignment

Built for Every Regulatory Landscape

Every exercise maps to the frameworks your regulators expect — from CISA guidance to EU directives to industrial control standards.

CISA CTEP
Cyber Tabletop Exercise Program

All 47 exercises align to CISA CTEP objectives with CISA CPG 2.0 control mappings and structured AAR export.

IEC 62443
Industrial Cybersecurity Standard

Scenarios map to IEC 62443 security levels and control domains for industrial automation and control systems.

NIST SP 800-82
ICS Security Guide (Rev. 3)

Threat scenarios reference NIST SP 800-82 r3 controls for OT and industrial control system environments.

NIST CSF 2.0
Cybersecurity Framework

Exercises cover all CSF 2.0 core functions: Govern, Identify, Protect, Detect, Respond, and Recover.

NIS2
EU Network & Information Security

Pro plan includes NIS2 compliance filters for essential and important entity requirements under the EU directive.

DORA
Digital Operational Resilience Act

Financial sector scenarios address ICT risk management and incident classification under the EU DORA regulation.

NERC CIP
Critical Infrastructure Protection

Energy sector exercises align to NERC CIP standards for bulk electric system cybersecurity and incident response.

ISO 27001
Information Security Management

Scenarios support ISO/IEC 27001 Annex A controls for information security risk assessment and incident response.

The Problem

Why Most Tabletop Exercises Fail

Generic, poorly facilitated exercises leave critical gaps unaddressed and give teams false confidence in their response capabilities.

🎭
Too Generic

Off-the-shelf exercises ignore your sector's specific OT architecture, threat actors, and regulatory requirements. Generic doesn't prepare teams for real incidents.

📋
No Facilitation Guide

Without structured injects and discussion prompts, exercises devolve into unfocused meetings. Facilitators are left improvising with no clear path forward.

📭
No Follow-Through

Exercises end without captured learnings. No structured After Action Report means gaps identified are never addressed and history repeats.

The Solution

Everything You Need to Run World-Class Exercises

A complete end-to-end platform purpose-built for OT/ICS environments — from scenario selection through to After Action Report export.

📁
47 Ready-to-Run Scenarios

OT/ICS Core, Cross-Sector Threats, Sector-Specific, and Executive & Leadership. Each scenario includes complete facilitator guides with timed injects.

Guided Exercise Runner

Step-by-step facilitation engine: Briefing → Module 1 Injects → Discussion → Module 2 Escalation → Hot Wash. No improvisation needed.

🌐
4-Language Support

Full translations in English, French, Portuguese, and Spanish. Serve global teams and international critical infrastructure operators seamlessly.

📄
After Action Reports

Export complete session notes as a structured AAR .txt file. Document findings, action items, and next steps automatically from within the runner.

🎯
OT/ICS Threat Intelligence

Scenarios mapped to real threat groups: VOLTZITE, BAUXITE, GRAPHITE, ELECTRUM. Grounded in real-world TTPs targeting critical infrastructure.

CISA CTEP & IEC 62443 Aligned

Every exercise maps to CISA Cyber Tabletop Exercise Program (CTEP) objectives and IEC 62443 control domains for regulatory defensibility.

Platform Preview

47 Professional Exercise Scenarios

Each scenario is a complete exercise package: facilitator guide, participant briefing, timed injects, discussion questions, and AAR template.

OT / ICS
Industrial Control Systems Compromise

A nation-state threat actor conducts spear-phishing targeting IT/OT convergence personnel. Lateral movement into OT networks results in adversary access to SCADA HMI.

ICS/SCADA Intrusion VOLTZITE IEC 62443
⏳ 3–4 Hours 👥 8–15 Players Advanced
Cross-Sector
Ransomware: OT/IT Simultaneous Attack

Ransomware encrypts enterprise IT systems while a second payload targets OT historian servers and engineering workstations, threatening operational continuity.

Ransomware BAUXITE NIST SP 800-82
⏳ 3–4 Hours 👥 10–20 Players Advanced
Executive & Leadership
Board-Level Crisis Management

A major OT breach goes public. The board convenes an emergency session. Regulatory notifications are required within 72 hours and media inquiries are escalating.

Board Crisis Executive SEC Rules
⏳ 2–3 Hours 👥 5–10 Players Foundational
Pricing

Choose Your Plan

Start free with 3 exercises. Upgrade anytime with no lock-in.

Monthly
Annual Save 17%
Starter
$0 / month

Perfect for evaluating the platform

  • 3 Exercises (OT/ICS Core)
  • Guided Exercise Runner
  • After Action Report Export
  • English Language
  • Full 47-Exercise Library
  • Multi-Language Support
  • Priority Support
Get Started Free
5 Seats
Team
$199 / month

For MSSPs, consultancies, and large organizations

  • Everything in Pro
  • 5 Facilitator Seats
  • Custom Branding
  • Priority Support
  • Usage Analytics
  • Offline / Air-Gapped Packs
  • Dedicated Onboarding
Get Team

All plans include a 14-day free trial. No credit card required for Starter. Cancel anytime.

Trusted By

Built for Critical Infrastructure Teams

Security professionals across energy, utilities, and industrial sectors trust Skyhigh to deliver measurable exercise outcomes.

Energy Sector

"The exercise runner alone saved us hours of preparation time. Our OT and IT teams were aligned after the first session in a way we hadn't achieved in years of meetings."

— Head of OT Security
Water Utility

"The CISA CTEP alignment gave us instant credibility with our regulators. The French translation was a game-changer for our Canadian operations team."

— CISO
Industrial Manufacturer

"We ran the ICS Compromise scenario with our board and got more meaningful discussion in 3 hours than in 3 years of tabletop history."

— VP Operations
FAQ

Common Questions

Everything you need to know about the platform before getting started.

A tabletop exercise is a structured discussion-based exercise where key personnel walk through a simulated cyber incident scenario. Unlike live drills, tabletops focus on decision-making, communication, and process rather than technical response. They are the most cost-effective way to identify gaps in your incident response capabilities.

No. Each exercise includes complete facilitator guides with structured injects, timed discussion prompts, and step-by-step instructions. The guided exercise runner handles the flow so your facilitator can focus on driving discussion rather than managing logistics.

Yes. Every exercise includes a customizable organization name field. All scenario narratives use [ORGANIZATION] placeholders that are replaced with your organization's name during the briefing step, making each exercise feel tailored to your specific environment.

All 47 exercises are designed in alignment with CISA's Cyber Tabletop Exercise Program (CTEP) objectives. Each scenario maps to CISA CPG 2.0 controls and IEC 62443 security levels, providing a defensible framework for regulatory reporting and audit purposes.

All exercise notes are stored locally in your browser session and exported on demand as a .txt After Action Report. No data is transmitted to external servers during the exercise. Your sensitive findings remain entirely under your control.

Ready to Elevate Your Cyber Preparedness?

Join critical infrastructure teams running professional tabletop exercises with Skyhigh.