Draft a tabletop exercise scenario with injects
A tabletop exercise walks a team through a fictional incident to test decisions and communications. Writing a good one takes hours. Apex Flash can draft the scenario, timed injects and discussion questions, which you then tailor to your real systems.
Set it up
- Decide the objectives, such as testing escalation and communications.
- List your real roles, systems and constraints (without secrets).
- Send them to apex-flash with the scenario prompt.
- Edit injects so they match your tools and contacts.
- Have legal and communications review the scenario.
- Run the session, record decisions and write an after-action report.
Authorisation boundary
This is a discussion exercise only. The scenario describes a fictional incident for decision-making; it contains no instructions for carrying out an attack, and you should not run any real activity against production systems as part of it.
Sanitised sample input
Organisation: 300 staff NZ logistics company, one data centre, SaaS email.
Objectives: test escalation to executives, customer communication,
and the decision on whether to take systems offline.
Participants: IT manager, security lead, COO, communications, legal.
Duration: 2 hours.
Constraints: no real names, no live systems.The prompt and the call
CISA publishes tabletop exercise packages (CTEPs) with template objectives, scenarios, discussion questions, a slide deck, and an after-action report template, so you can compare the output with a published structure at cisa.gov.
Draft a tabletop exercise for the organisation below. Fictional ransomware outage; no technical attack instructions.
Include: objectives, scope and assumptions, roles, a timeline of 6 injects (each with a time, what the participants are told, and 2 discussion questions), decision points, and evaluation criteria with what good looks like.
Make injects escalate: first signs, scope grows, a deadline, media interest, a recovery decision.
Add a facilitator note per inject on common mistakes.
<org>
...description...
</org>import os
from openai import OpenAI
client = OpenAI(base_url="https://wildwestapi.com/v1",
api_key=os.environ["WILDWEST_API_KEY"])
resp = client.chat.completions.create(
model="apex-flash",
temperature=0.2,
messages=[
{"role": "system", "content": "You design realistic, discussion-only tabletop exercises."},
{"role": "user", "content": open("tabletop_prompt.txt", encoding="utf-8").read()},
],
)
print(resp.choices[0].message.content)Keys look like sk-ww-...; keep yours in the WILDWEST_API_KEY environment variable, never in the script. Calls to /v1/chat/completions use the OpenAI format, billing is pay-as-you-go, and prompts are not retained on /v1.
Inject example
A useful inject is specific and creates a decision:
- T+0:30. Finance reports that invoice files will not open and a note on a shared drive demands payment. Question: who is told, and by when?
- T+1:15. Backups for the file server are found to be on the same network. Question: what do you restore first, and who decides?
- T+1:40. A journalist emails asking about an outage. Question: who speaks, and what is said?
What to check
- Injects match your environment. Replace generic systems with yours.
- The scenario is plausible, not dramatic. Over-the-top scenarios teach less.
- Roles and contact steps reflect your real incident plan. NIST SP 800-61 Rev. 3 is a good reference for the response phases (NIST).
- No real names, domains or customers appear.
Both apex-flash and glm-5.3-flash-cyber are security-tuned models with a 1M-token context window, tool calling and vision. They are not uncensored models, and they are meant for defensive and authorised work like this. Have someone who did not write the scenario run through it once.
Where this fits
Feed the lessons into a threat model, rehearse the timeline work in incident timelines, and test the entry point with phishing triage. See DFIR use cases and red team tools.
FAQ
Can it write the after-action report?
Yes, from your notes of what was decided. Check that it records what happened, not what should have happened.
Will it include real attacker techniques?
Keep it to effects the team must respond to. The scenario should not contain operational attack steps.
How long should an exercise run?
Two hours is common for a first one, with a focused objective. Adjust to your team.