Free practice tool
Cyber security incident simulationPractise the decisions before you need them.
A cyber security incident simulation lets you practise response decisions without touching live systems. Choose ransomware, phishing, insider access or a supplier breach, read each fictional situation and receive feedback on your choices. Use the final review to identify questions for your own response plan.
Choose a scenarioDealing with a real incident? Use the first-hour response guide rather than this exercise.
Choose your scenario
Start with a decision your team might face
All situations are fictional. Read each choice together, discuss your own process, then use the feedback to check your reasoning.
Use it with your team
Turn a practice decision into a checked procedure
- Step 1
Choose a relevant situation
In this tool: The simulator provides a fictional incident and a clear decision at each stage.
Your team: Choose a scenario and bring your current response plan if you have one.
- Step 2
Discuss before deciding
In this tool: Each choice receives an explanation and a link to relevant Australian guidance.
Your team: Ask who can authorise the action, what evidence you need and who must be contacted.
- Step 3
Review every choice
In this tool: The final screen shows your choices, their scores and the reasoning behind them.
Your team: Write down gaps, assign owners and agree what needs to change in your plan.
- Step 4
Revisit the plan a month later
In this tool: You can restart any exercise to check your understanding of the decisions.
Your team: Check that the agreed changes happened, then rehearse again with the people responsible.
What this does and does not do
A browser exercise is a starting point, not a system test
ASD describes tabletop exercises as discussions of hypothetical incidents, without impacting systems. Use this tool for practice, then check how your own people, contacts and procedures would work.
ASD: Exercise in a Box(opens in a new tab)Decision-making
In this toolChoose a response to a fictional situation.
In your teamCheck who can authorise the action in your organisation.
Systems and contacts
In this toolNo live systems, suppliers or customer records are accessed.
In your teamCheck your contact list, dependencies and approved recovery procedures.
Evidence of readiness
In this toolA score explains choices in this exercise, not business readiness.
In your teamRecord gaps, decisions, owners and completed follow-up actions.
Need help checking the gaps in your plan? Bring your current procedures and exercise notes to a discussion with Real Bytes. We can scope the review before you approve any work.
Discuss your response planBefore you start
Incident simulation questions
What is a cyber security incident simulation?
It is a practice exercise where you decide how to respond to a fictional cyber incident. This Real Bytes tool explains each choice and provides a final review. It does not attack, scan or change your systems.
ASD: Exercise in a Box(opens in a new tab)Is this simulator free, and do I need to sign up?
The simulator is free to use and does not require a sign-up form. Start any of the four scenarios, work through the decisions and review the feedback. It is self-paced, with no promised completion time.
Does a high score prove our business is ready for an incident?
No. The score is a learning rubric for the choices in this exercise, not a certification, security audit or readiness assessment. A team rehearsal should also test your actual contacts, decision authority, recovery procedures and response plan.
ASD: Exercise in a Box(opens in a new tab)Who should join a team exercise?
Include the people who would make and carry out decisions during the incident. Depending on the scenario, that may mean the business owner, IT lead, finance, operations, HR, privacy or legal advisers and communications. Use your own plan to check who has authority.
ASD: Exercise in a Box(opens in a new tab)Are my choices saved, and what should I do afterwards?
Your choices stay in page memory and are cleared when you restart or reload. The simulator does not ask for customer records, credentials or incident evidence. Record the gaps you identify, assign owners and rehearse the revised plan.
When must an Australian business report a data breach?
The duties depend on the entity, information and incident. Under the Notifiable Data Breaches scheme, covered entities must promptly assess a suspected eligible breach, taking all reasonable steps to complete the assessment within 30 calendar days. Once an eligible breach is established, notification to the OAIC and affected individuals must follow as required. This is not permission to wait 30 days; other obligations may also apply.
OAIC: Notifiable Data Breaches scheme(opens in a new tab)
Remote Support