TABLETOP SIMULATIONS
Your team has rehearsed the fire drill. Never the incident.
Facilitated tabletop simulations that drop a team into a scenario, ask them to secure it, then hit them with the complication and let them feel the impact — discussing and committing to every decision together, not watching a slide deck.
Switched On Security is built by Adam Smallhorn, who has taught cybersecurity at UNSW since 2017 and led security-culture and cyber-outreach programs at Okta and Australia's largest bank.No spam, no sales sequence — you'll talk to the founder.
Choose a sim
Shadow SaaS
Everyone's team
The cocktail-party phone
Travel
The border seizure
Travel
The bypassed launch
Engineering
Exec tabletops rehearse the wrong room, with the wrong questions
Most tabletop exercises are run once a year, for the executive team, around a boardroom table. They rehearse the CISO's decisions. The person whose day-to-day work actually creates the exposure — the deadline call, the shortcut, the tool nobody signed off — is never in the room.
The questions are usually softballs anyway: easy, obviously-correct choices that nobody has to think hard about. Real judgment calls are tough on purpose — that's what makes them worth discussing as a team before anyone commits to an answer.
Tabletop Simulations puts the team that actually faces the decision in the driver's seat instead: a scenario with elevated risk to secure, a complication that hits and has to be handled in the moment, then the implication — the impact on the company, debriefed together. No Dorothy-Dixers, no lecture: every choice gets teachable feedback on whether it made the company more or less secure, so the group leaves understanding not just what happened but why it mattered.
- rounds per session — scenario, complication, implication
- 3
- rounds per session — scenario, complication, implication
- individual scores — team-level only, by design
- 0
- individual scores — team-level only, by design
Walkthrough
How a session runs
One worked example: "Shadow SaaS." A team's standard workaround quietly relies on a tool nobody approved — the sim plays out what that costs.
Choose a sim
Shadow SaaS
Everyone's team
The cocktail-party phone
Travel
The border seizure
Travel
The bypassed launch
Engineering
Pick the sim your team could live on a Tuesday
Choose from a library matched to real exposure — Shadow SaaS for any team with a deadline and a workaround, a phone left unlocked at a cocktail party, a phone seized at a border, an app launched to market on a cloud service while bypassing controls. No generic ransomware theatre.
Why it's different
Built around practice, not policy
No Dorothy-Dixers
Every question is genuinely tough, built to evoke discussion — the group works its way to the answer by sharing what each person already knows, not by picking the obvious option.
Teachable feedback on every choice
Each decision comes back with a read on whether it made the company more or less secure — the moment to explain what a control is and why it earns its place.
Security is everyone's business
After the incident, the team sees how their individual calls affected the whole company, and practises communicating it appropriately — internally and with customers.
Auto-analysed into the Human Risk Dashboard
The platform can read the group's decisions and discussion with an LLM and feed that signal straight into the Human Risk Dashboard.
Questions
Frequently asked
How long is a session?
45 minutes, including the debrief. Built to fit inside a normal meeting slot.
Who facilitates — you or us?
We facilitate the pilot sessions ourselves. A train-your-facilitator methodology, so your own team can run these independently, is on the roadmap.
Does it work remote?
Yes — the scenario, complication and implication arrive over the same channels your team already uses (Slack, email, a shared call), so remote and in-person teams run the identical exercise.
Is anyone scored individually?
No. Scoring is team-level only, by design — the goal is a shared habit to change, not a leaderboard of who chose what.
What's an example scenario?
"Shadow SaaS": the team's own workaround relies on an unapproved tool. Round 1 asks them to secure it under deadline pressure; Round 2 hits them with the vendor breach and asks how to respond; Round 3 shows the blast radius and what a data-processing agreement, an approved-tools list, and a tested disclosure plan would have changed.
How does this connect to the Human Risk Dashboard?
The group's decisions and discussion can be auto-analysed with an LLM, and that read feeds into the Human Risk Dashboard as a signal alongside the Social Engineering Simulation.
Ready to see tabletop simulations on your own team?
Switched On Security is in active development with a small group of design partners — early access is free, and it shapes the roadmap.
Ask us about tabletop simulations
Every enquiry gets a short call with the founder to talk it through — not an instant trial, not a sales sequence.
Prefer to talk?
Book a 25-minute call directly — no form, no back-and-forth.
Book a 25-minute callSwitched On Security is built by Adam Smallhorn, who has taught cybersecurity at UNSW since 2017 and led security-culture and cyber-outreach programs at Okta and Australia's largest bank.