Ferrum ResponseLab Ferrum ResponseLab
Defensive incident-response readiness

Rehearse the incident before it's real.

For SMEs, MSPs & consultants · simulated scenarios only · no offensive tooling

Ferrum ResponseLab is a tabletop simulator for security teams. Run realistic, fictional incident drills, capture every decision and gap as it happens, and walk away with a board-ready after-action report — so the day it's real, your team has already done it once.

Fictional scenarios only No offensive tooling, ever Facilitator + participant rooms Incident-command roles Board-ready PDF reports Strict tenant isolation
01 What you walk away with

Not a slideshow — a drill your team will remember.

A realistic drill, on the clock

Timed injects push the exercise forward — a ransom note, a customer call, an executive question — while you facilitate from a live room. Pressure, not PowerPoint.

Every decision & gap, captured live

Log decisions, observations, and improvement actions as they happen — with the role, the rationale, and the moment in the timeline. Nothing gets lost after the room clears.

A readiness grade leadership reads

Rate performance across ten response categories for an A–F readiness grade — one score your board and your clients understand, backed by the evidence behind it.

A board-ready after-action report

Generate an immutable PDF and HTML after-action report — timeline, decisions, gaps, scores, and the action plan — ready to send to leadership, an auditor, or your client.

02 The scenario library

Realistic incidents, ready to run today.

Start from a built-in, defensive scenario — or design your own. Each one is a full facilitation kit: timed injects, role assignments, injected artifacts, decision points, and a scoring rubric.

RansomwareBeginner

Ransomware Monday Morning

Locked file shares, an uncertain backup, customer impact, and a ransom question land on the leadership team before the first coffee.

BECIntermediate

Business Email Compromise

A fraudulent invoice-change request leads to a misdirected payment. Verify, recover, involve law enforcement, and decide on notifications.

SupplierIntermediate

Supplier Breach

A key supplier announces an incident with uncertain data exposure. Assess third-party risk, obligations, and what to tell your customers.

AI data leakAdvanced

AI Chatbot Data Leak

A customer sees another customer's data in chatbot output. Weigh AI governance, containment, logging, and customer communication.

CloudAdvanced

Cloud Admin Credential Exposure

An admin key surfaces in a public repo and audit logs show suspicious access. Drive containment, ownership, and leadership updates.

Library

…and a growing library

Data breach, lost & stolen device, website defacement, and insider scenarios — plus your own custom designs, authored once and reused across your team.

Browse the library →
Inside every scenario
  • Timed injects
  • Role assignments
  • Injected artifacts
  • Decision points
  • Facilitator guidance
  • Scoring rubric
03 How it works

From scenario to signed-off report in four steps.

  1. 1

    Pick a scenario

    Choose a defensive tabletop from the library or design your own, then schedule the exercise and invite your team.

  2. 2

    Run the exercise

    Assign incident-command roles and release timed injects from the facilitator room. The participant room keeps everyone on the same beat.

  3. 3

    Capture & score

    Record decisions, observations, and gaps as they surface, then grade readiness across the ten response categories.

  4. 4

    Report & improve

    Generate the after-action report, assign the improvement actions, and track them through to done before the next drill.

04 Built for your role

One simulator, the proof each buyer needs.

In-house security & IT

Run a credible drill without a full crisis-management program. Find the gaps in your plan before an attacker does, and show leadership you're ready — in an afternoon.

MSP & vCISO

Deliver tabletop exercises as a repeatable service across every client workspace, with white-label after-action reports that justify the retainer and win renewals.

Consultant & facilitator

Walk into any engagement with a ready scenario library, facilitate a polished session, and hand over a professional report your client can act on the same day.

05 Defensive by design

Safe isn't a footnote — it's the whole premise.

Ferrum ResponseLab teaches detection, escalation, containment, recovery, and communications using fictional organizations and artifacts only. It exists to make defenders better — never to help anyone attack.

It never

  • Ships malware, exploits, or payloads
  • Includes real, operational attack steps
  • Uses real victims' data or live infrastructure
  • Teaches anyone how to run an incident against others
  • Dresses up a fictional drill as a real breach

It always

  • Uses fictional organizations & artifacts
  • Teaches the defensive playbook end to end
  • Keeps every exercise isolated to your organization
  • Records an auditable decision & action trail
  • Produces evidence you can show leadership or an auditor
06 Pricing & packages

Simple, transparent pricing.

From a single in-house team to a whole client portfolio. Prices in USD, billed monthly. Start a free workspace — no card required.

For SMEs & in-house teams

Starter

$99/mo

  • 3 exercises / month
  • Up to 25 participants
  • Full scenario library
  • After-action reports
Start free
Compliance

$499/mo

  • Unlimited exercises
  • Evidence library
  • Custom scenarios
  • Priority support
Start free

For MSPs & consultants

MSP Starter

$399/mo

  • Up to 10 client workspaces
  • 25 exercises / month
  • Portfolio dashboard
Start free
Enterprise

Custom

  • Unlimited client workspaces
  • Custom scenario design
  • Onboarding & facilitation
Talk to us →

One-time services also available — custom scenario design and facilitated sessions. Pricing is indicative and may change during the beta.

07 Questions, answered

The things buyers ask first.

Is this a hacking tool, or does it teach people to attack?

No — the opposite. ResponseLab is a defensive training tool. Every scenario uses fictional organizations and artifacts, contains no operational attack steps, and exists to rehearse detection, escalation, containment, recovery, and communications. It ships no offensive tooling, ever.

How long does an exercise take?

Built-in scenarios are designed for about 60 minutes, paced by the facilitator. You can pause, resume, and release injects on your own clock, so a session fits a lunch-and-learn or a half-day workshop equally well.

Do we need a dedicated security team to run it?

No. The scenario library comes with role assignments, injected artifacts, decision prompts, and facilitator guidance built in — so an IT lead, an office manager, or an outside consultant can facilitate a credible drill without writing a scenario from scratch.

Can we run it remotely?

Yes. Everything runs in the browser. The facilitator releases injects from a live room while participants follow along in theirs — in person, fully remote, or hybrid. No installs, no downloads.

What's actually inside a scenario?

Each scenario is a full facilitation kit: a cast of incident-command roles with responsibilities, a timeline of timed injects (each assigned to the right roles and backed by a realistic fictional artifact), decision points with options and scoring guidance, and a rubric that maps to the readiness categories.

Does this help with compliance or cyber insurance?

Tabletop exercises are a common control for ISO 27001, SOC 2, NIS2, and cyber-insurance questionnaires. ResponseLab gives you the immutable after-action report — who decided what, which gaps surfaced, and the improvement plan — as evidence you can hand to an auditor or insurer.

Run the drill

Run your first tabletop this week.

Spin up a workspace, invite your team, pick a scenario, and rehearse — in minutes. The next time it's real, it won't be the first time.