INJ-002

Your CFO forwards a $4,200 charge from a vendor nobody in finance recognizes. No message, and no reply since. Your SIEM is quiet.

WHAT DO YOU DO?

That is where an exercise starts here — not with an alert, and not with a script. Outcomes are rolled during play, inside bands built from your organization's real data holdings. Nobody in the room knows how it ends. Including the facilitator.

Most tabletops are a reading exercise

Someone writes a scenario. Someone reads it aloud. The team describes what the plan says they would do, everyone agrees the plan is sound, and a memo confirms the exercise was held.

Nobody was ever uncertain. Nobody had to decide anything under pressure, because the ending was written before the room sat down — and everyone could feel it.

An exercise that cannot surprise you cannot tell you anything you did not already know.

Three things that make it different

EXTERNAL DETECTION

Every internal tabletop starts with a SOC alert

Yours might start with a finance anomaly, a journalist's call, an industry peer's tip, or a customer who found their own data somewhere it shouldn't be. Detection often arrives from outside the security stack, and most teams have never rehearsed for that version of the call.

CALIBRATED ENTROPY

The dice are bounded by your data

Randomness stays inside what is plausible for your environment — your data holdings, systems, jurisdictions, notification duties. You cannot lose records you do not hold. Roll bands are built to straddle the statutory and contractual thresholds that actually apply to you, not round numbers, which is what turns a disclosure decision into a decision.

TRACEABLE FINDINGS

Findings cite the log, not a memory

Injects, rolls and decision points are logged as they occur during play. The report's findings cite those entries rather than the facilitator's recollection, so a finding can be checked against what actually happened in the room. The exercise grades the process, not the people running it. Run it again next year and you get a delta against your own prior results rather than a fresh opinion.

How a roll actually works

At intake, an organization gives its plausible range for a given class of records. That range becomes a band. During play the dice place the outcome somewhere inside it — and the band is built so the statutory threshold falls within reach, not safely outside it.

EXAMPLE BAND · CUSTOMER RECORDS IN A SINGLE BUSINESS UNIT
1,000 — NOTIFICATION THRESHOLD
400 RECORDS1,800 RECORDS
Press roll. The band, the threshold and the dice are all fixed in advance — the only unknown is where this particular exercise lands.

In a real exercise the band is yours, the threshold is the one that applies to you, and the result stands. There is no re-rolling a number the room dislikes.

A few injects from the bank

Scenarios are built per engagement. These are representative of the kind of pressure they apply.

INJ-004

A reporter emails asking for comment on "the breach." You have not had a breach. That you know of.

WHAT DO YOU DO?
INJ-009

The stated RTO is twelve hours. Finance says the business does not survive past four. Two people wrote those numbers. They have never met.

FINDING
ROLL-04 · d6 → 2

The restore succeeds. It lands eleven hours after you believe the intrusion started.

WHAT DO YOU DO?
INJ-003

A Tier 3 database server goes offline. The tier was assigned by its owner. Four Tier 1 systems are now down.

FINDING
INJ-005

Legal asks whether the incident is "material." Nobody in the room can define the word. The window closes in four business days.

DISCLOSURE CLOCK RUNNING
ROLL-06 · 2d10 → 3

900 records. Below every threshold that applies to you. Your comms lead has already drafted the statement.

NO DUTY TRIGGERED

What you receive

Three documents, deliberately separated, because a report that has to satisfy an auditor cannot also be candid enough to be useful internally.

DocumentWhat it isWho reads it
Hot wash Same-day summary of what happened, delivered before everyone leaves the room Participants
After-action report Findings traced to logged events, with remediation candidates. This is the artifact NIST SP 800-171 practice 3.6.3 (CMMC IR.L2-3.6.3) expects as evidence of incident-response testing — the one most companies can't produce when an assessor asks. Internal
Statement of Exercise Performance Factual record of what was performed, by whom, on what date, against which scenario Auditors and insurers

Supports incident response testing evidence under PCI DSS 12.10.2, NERC CIP-008, CMMC and NIST SP 800-171, SOC 2, ISO 27001, and cyber-insurance underwriting.

Client data is destroyed 30 days after delivery, subject to any lawful preservation obligation received first. The report is the durable record — bring it to the next exercise for the year-over-year comparison.

How an engagement runs

ABOUT 90 MINUTES OF YOUR TIME

Intake

A structured questionnaire and one working session. Capability categories and ranges — not architecture diagrams, not system inventories, not named individuals. If you cannot state a record count precisely, a best-guess range with a confidence level is the honest answer, and that uncertainty becomes a finding in its own right.

NO TIME FROM YOU

Scenario design

The scenario is bound to your organization: calibration bands, notification thresholds, decision points, inject sequence and roll structure.

ABOUT 30 MINUTES

Confirmation

Scope and objectives reviewed with you before the build is finalized, so nothing arrives on the day that shouldn't.

HALF DAY OR FULL DAY

The exercise

Facilitated on-site or remote. Leadership and incident-response stakeholders in one room, deciding under genuine uncertainty while injects, rolls, and decision points are logged as they occur.

HOT WASH SAME DAY · DOCUMENTS WITHIN 10 BUSINESS DAYS

Delivery

Hot wash before everyone leaves the room. After-action report and Statement of Exercise Performance follow.

Pricing

Priced by phase, so you can see what you are buying and drop what you do not need. Fixed fee, quoted in writing before anything is signed.

Component Remote half-day On-site half-day On-site full-day
Intake and scenario design$9,500$9,500$11,500
Exercise delivery and facilitation$4,500$6,500$9,000
After-action report and evidence package$5,000$5,000$6,000
Total$19,000$21,000$26,500

Travel billed directly at cost. On-site delivery available worldwide.

Repeat engagements

For a returning client with no material change in profile — headcount, data holdings, jurisdictions, systems — since the prior exercise. Intake is lighter the second time; delivery and reporting effort don't shrink, and the scenario itself is rebuilt, since repeat participants can't play the same injects and still face genuine uncertainty.

Component Remote half-day On-site half-day On-site full-day
Intake and scenario design$5,500$5,500$7,500
Exercise delivery and facilitation$4,500$6,500$9,000
After-action report and evidence package$5,000$5,000$6,000
Total$15,000$17,000$22,500

A material change in profile since the prior engagement reverts intake to full scope. The year-over-year comparison runs on White Cell's own log format and calibration methodology, across White Cell-delivered exercises only — a year run by another provider, or run internally, isn't part of that comparison.

Multi-property and portfolio programs

Organizations running several properties or business lines are quoted in three layers: scenario architecture built once, adaptation per business line, and tailoring plus delivery per property, with a portfolio synthesis at the end.

The shared architecture is the point. Ten bespoke scenarios produce ten unrelated reports and nothing to benchmark; a common spine is what makes cross-portfolio comparison valid. A lighter single-scenario version is a legitimate option and quoted on request.

Request a quote

Who runs it

White Cell Exercises is a single-practitioner practice. The person who designs your scenario is the person who facilitates it and writes your report — there is no handoff to a subcontractor and no script being read by someone who has never met you.

Drew Shumate spent his early career in the Navy and served on the white cell for the CNO Global Wargame and for USSTRATCOM's Global Lightning 11 joint command post exercise, run from Germany concurrently with USEUCOM's Austere Challenge 11. He later worked as a principal global enterprise security architect at CDW, and spent two years designing and running a multi-property tabletop program for a diversified holding company with genuinely unrelated business lines — the engagement that produced the calibration approach used here.

The method draws on the wargaming literature, particularly Perla and McGrady's Why Wargaming Works in the Naval War College Review: the designer owns believability, and the players own the consequences. Getting the facts wrong, in either direction, teaches the wrong lesson.

  • CISSP — ISC²
  • CISA — ISACA
  • ISO/IEC 27001 Lead Implementer
  • Navy veteran
  • White cell — CNO Global Wargame
  • White cell — Global Lightning 11, USSTRATCOM
  • Based in Hampton Roads, Virginia
  • On-site delivery worldwide

Start with a scoping call

Thirty minutes, no charge, nothing signed. Enough to establish which testing requirement applies to you, who belongs in the room, and whether a half-day or a full-day fits. A written scope and a fixed quote follow within two business days.

Please keep this general — no system names, no architecture detail.

Request received

I'll reply within one business day, usually sooner.

This form asks nothing about your infrastructure on purpose. Scoping happens on the call, and even at intake the questions stay at the level of categories and ranges. Your details are used to reply to you and nothing else.

Prefer email? drew@whitecellexercises.com