Dispatches · Buyer's checklist
How to evaluate a tabletop exercise or cyber range platform: 12 questions for vendors
Name the gap first: analyst skill, team detection and containment, or executive decisions. Then send every vendor the same 12 questions in writing and weight the answers by that gap. Most vendors in this category publish no price, so the budget questions go to sales in the first call, not the last.
Editorial assessment · Assessed from vendor sites, product pages and published pricing, September 2026
By Security Training assessors · 26 August 2026
1-1What problem are you buying for?
Every question below depends on one earlier decision: which gap the purchase closes. A lab closes an individual skills gap. A live-fire range tests whether a SOC can detect and contain an attack on real tooling. A tabletop or crisis simulation tests whether the incident commander, legal, communications and executives can make decisions in time. Write the gap in one sentence before the first demo, and take the wording from your last incident review or audit finding. The exercise matrix shows which vendors sell which format to which audience.
1-2Questions on format and fit
- Which roles can take part in the same exercise? Ask for a list of roles, not personas. If executives, legal and the SOC can only be exercised in separate products, you will run separate exercises. Cyberbit, for example, sells Crisis Sim 360 only as an add-on to a Cyberbit Readiness plan.
- Is the scenario built from our environment or a generic one? Ask what inputs it uses: your technology stack, your playbooks, your public footprint, your telemetry. Ask how long it takes to go from those inputs to a runnable scenario, and who does the work.
- Are we buying a template, a platform or a service? CISA's Tabletop Exercise Packages are free templates you facilitate yourself. Incident response firms sell facilitated tabletops as a service. A platform sits between the two. Ask which one you are buying and what the vendor's own staff do in each exercise.
1-3Questions on realism
- What happens when players make a decision the scenario did not expect? This is the plainest test of scripted against adaptive. Ask to see it live, with your people making an unplanned choice, not a presenter.
- How current are the scenarios? Mandiant's M-Trends 2026, published on 23 March 2026, reports voice phishing as the second most common initial infection vector at 11%, and prior compromise as the top vector for ransomware at 30%. Ask when the scenario library last changed and whether you can build an exercise around a finding like these.
1-4Questions on evidence
- What does the report contain, and when do we receive it? Ask for a sample after-action report. Check that it records decisions, times and owners, not only a transcript or a score. See how to read an after-action report.
- Which frameworks does the evidence map to, and who does the mapping? Vendors in this review name DORA, NIS2, ISO 27001, ISO 22301, APRA CPS 230, NIST CSF and SOC 2 among others. Ask which mappings the platform generates and which exist only in the sales deck.
- Can we compare results across exercises and teams? Benchmarking is where iluminr and Immersive Labs put much of their emphasis. If the board will ask whether readiness improved this year, you need the same measures from one exercise to the next.
1-5Questions on effort
- How many staff hours does one exercise take, end to end? Count scenario design, scheduling, facilitation, the hotwash and the report. Vendor positions differ widely: TryHackMe states a 10-minute average launch for its tabletops, while Conducttr is built for teams that design their own exercises in a scenario editor.
- What happens when a key person cannot attend? Ask whether the exercise can run asynchronously, whether an absent role can be simulated, and whether the same exercise can be rerun for a second shift or region.
1-6Questions on price and contract
- What is the list price, and what is it per? In our price disclosure census, Conducttr publishes four team licences from £11,950 to £25,725 a year and Hack The Box publishes one business plan at $2,500 per seat per year. Reflex Security, Immersive Labs, Cyberbit and iluminr publish no price. Ask whether pricing is per seat, per exercise, per team or per platform, and what one extra exercise costs.
- What is included, and what is an add-on? Behavioural assessment is a paid add-on at Conducttr (Assessment Toolkit, from £4,536 a year). Crisis simulation is an add-on at Cyberbit. Ask for the complete list in writing before the proposal.
1-7How should you score the answers?
Put the 12 answers in a table with one column per vendor, and weight each question by the gap you wrote down at the start. A CISO whose problem is analyst skill should weight hands-on depth; one whose problem is the boardroom should weight cross-team participation and evidence.
Our own weights and per-criterion scores are published on How we assess and the rankings, so they can be re-weighted for a different brief. Before signing, ask for one exercise with your own people on your own scenario, and judge the vendor by the report it produces from that session.
Sources
- CISA Tabletop Exercise Packages: https://www.cisa.gov/resources-tools/services/cisa-tabletop-exercise-packages
- Google Cloud, M-Trends 2026: https://cloud.google.com/blog/topics/threat-intelligence/m-trends-2026
- Cyberbit Crisis Sim 360: https://www.cyberbit.com/product/crisis-simulation/
- TryHackMe tabletop exercises: https://tryhackme.com/business/solutions/tabletop-exercises
- Conducttr pricing: https://www.conducttr.com/pricing
- Hack The Box business pricing: https://www.hackthebox.com/business/pricing
- iluminr: https://iluminr.io/
- Immersive Labs: https://www.immersivelabs.com/