NewTry our Security Architecture simulation free — no sign-up required, just an email for your result. Start free trial →
Simulations grounded in real-world incidents

Cyber incident judgment simulations for the AI era

AI can generate an answer. Can you decide whether it’s the right one?

ScenarioLab places cyber professionals inside realistic, incident-inspired situations where evidence is incomplete, assumptions can be wrong, and decisions have consequences. Practise making and defending professional decisions — not memorising answers.

Real-world incident scenarios · structured scoring · role-based exercises

ai-pentest-report.txt

AI Security Analysis — Network Scan

CRITICAL · SQL injection on /api/users

CVSS 9.8 · Apply input sanitisation immediately.

MEDIUM · TLS 1.0 downgrade risk

Recommendation: disable TLS 1.2 and below.

LOW · CVE-2021-44228 reference...

Candidate must identify

CVSS score inconsistent with described impact
Remediation contradicts current TLS best practice
CVE reference misattributed to wrong vendor

ScenarioLab began with AI critical analysis assessments for cybersecurity interviews — still the flagship, proven use case. It now extends the same judgment-based approach into incident management, security architecture, and role-based cyber simulations, with Security Architect as the strongest example of where that’s headed.

How ScenarioLab works

Evidence → decision → consequence → adaptation → assessment

01

Enter a realistic scenario

You're placed into an incident-inspired professional situation.

02

Examine the evidence

Information may be incomplete, ambiguous, or contradictory.

03

Make a decision

Recommend an action, an architecture, or a response.

04

Reality changes

New evidence, constraints, or consequences may appear.

05

Defend and adapt

Explain your reasoning, and revise your decision when necessary.

06

Receive an assessment

See where your reasoning was strong, what you missed, and what to practise next.

In Hiring Mode, teams can invite candidates, run structured AI critical analysis assessments, and review deterministic scoring reports.

Three ways to use ScenarioLab

Built for hiring, training, and teaching

For hiring managers

AI Critical Analysis Tests for Interviews

Assess whether cybersecurity candidates can spot flawed AI-generated analysis, identify missing evidence, challenge unsafe assumptions, and explain their reasoning.

View Hiring Assessments

For professionals and learners

Incident Judgment Simulations

Practise cyber incident judgment, assessment critique, and role-based decision-making using simulations derived from real-world cyber incidents.

Explore Simulations

For educators

Cyber Simulations for the Classroom

The same simulations individuals use, orchestrated by you — assign a scenario to a class or cohort and review results across the group.

For Educators

The AI judgment gap

Cybersecurity knowledge is becoming easier to access. Judgment is not.

Generative AI can already assist with threat analysis, security recommendations, architecture suggestions, configuration, incident analysis, and documentation. That makes professional differentiation increasingly about the ability to challenge machine-generated recommendations, recognise inappropriate assumptions, determine whether evidence actually supports a conclusion, understand trade-offs, anticipate failure modes, and make accountable decisions. AI increases the importance of human judgment — it doesn’t replace it.

ScenarioLab trains the part of professional practice that can’t be reduced to simply asking an AI for the answer.

AI output looks authoritative

AI-generated security reports are increasingly polished — and increasingly wrong. Professionals who can't distinguish confident AI prose from sound analysis are a liability.

Judgment gaps hide until it's too late

Interviews, tabletop exercises, and classroom teaching rarely surface this gap. Scenario-based simulations reveal whether someone actually reasons through an incident or just pattern-matches.

Standard rubrics are subjective

Most soft-skill evaluation relies on a single reviewer's opinion. ScenarioLab scores against a fixed key — the same standard every time.

Featured lab

Security Architect Lab

Practise designing secure systems when the evidence is incomplete and the constraints are real. Security Architect simulations test whether you can identify flawed architectural assumptions, reason about trust boundaries, redesign security architecture, reduce blast radius, address identity and privilege, balance security against operational constraints, explain trade-offs, identify residual risk, and adapt when new evidence appears.

Foundation

~10 min

Identify an architectural weakness and propose a defensible redesign.

Intermediate

~25 min

Analyse incomplete evidence and interacting architectural weaknesses.

Advanced

~45 min

Make architecture decisions where security, operations, and legacy constraints conflict.

Example: SolarWinds-style supply chain compromise

Step into the role of a security architect reviewing suspicious trusted-update activity. Review the evidence feed, critique a flawed assessment, identify the architectural weakness, and recommend design improvements — trust boundaries, segmentation, egress control, service account monitoring, and residual risk.

Professional Judgment Labs

Security Architect is one lab. This is the platform.

Each lab places you in a different professional seat, facing the same kind of incomplete-evidence, consequential-decision situations from that role’s perspective.

Live

Security Architect

Design and defend secure architectures under real-world constraints.

Coming Soon

Incident Manager

Make decisions during evolving cyber incidents.

Coming Soon

AI Security Engineer

Evaluate and secure systems that incorporate AI components and agents.

Coming Soon

CISO

Balance cyber risk, business impact, and strategic response.

Coming Soon

GRC

Interpret evidence, controls, obligations, and residual risk.

Coming Soon

DFIR

Reason from incomplete forensic evidence and competing hypotheses.

Incident library

A growing library of cyber decisions

ScenarioLab scenarios are inspired by real-world cyber incidents, architectural failures, cloud and identity compromises, supply-chain trust breakdowns, and emerging AI-related security situations — reconstructed into safe, educational simulations. New scenarios are added progressively, not on a fixed schedule.

The objective isn’t to memorise the scenario. It’s to practise reasoning when the next one is different.

SolarWinds-style supply chain compromise

A trusted software update channel is used to distribute a backdoor to thousands of downstream organisations.

Log4Shell-style exposure and response

A critical remote-code-execution flaw in a ubiquitous logging library forces emergency triage across an estate.

Colonial Pipeline-style ransomware disruption

A single compromised credential leads to ransomware, forcing an operational shutdown decision.

Uber-style identity and access compromise

MFA fatigue and hardcoded credentials give an attacker a path from a single login to broad internal access.

Lazarus-style social engineering campaign

A fabricated recruiter persona delivers malware through a convincing, targeted job offer.

Cloud credential misuse

Leaked or over-permissioned cloud credentials are used to pivot across accounts and services.

Healthcare ransomware

Ransomware in a clinical environment forces tradeoffs between patient safety and containment speed.

AI agent workflow abuse

An AI agent with excessive tool access is manipulated into taking unsafe or unauthorised actions.

Reports & outcomes

Measurable cyber judgment, not just quiz scores

Cyber professionals rarely operate with complete information and a single correct answer, so ScenarioLab evaluates the quality of reasoning, not merely whether a predefined keyword was mentioned. Traditional learning is Question → Correct Answer. ScenarioLab is Situation → Evidence → Decision → New Information → Trade-off → Revision.

ScenarioLab uses structured scoring for objective decisions. Hiring mode can use deterministic rubrics with no LLMs in the scoring loop. Training simulations focus on structured feedback showing your strengths, what you missed, the quality of your reasoning, and where to practise next — role-based learning outcomes, not a pass/fail quiz score.

Example reports

  • Candidate assessment report
  • Learner feedback report
  • Team capability report
  • Architecture decision output
  • Incident management decision summary

Feedback categories — see how you think

Evidence reasoningAI critiqueDecision qualityArchitecture judgmentTrust-boundary reasoningTradeoff awarenessAdaptationResidual-risk awarenessCommunication clarityEscalation judgment

Example: hiring assessment report

Alex M.

a7f3...c91e@candidate

Senior SOC Analyst Screening · Phishing Campaign Attribution

MID

Submitted 10 Apr 2026 · Time taken 17m 42s

68 / 100

Proficient

Critical thinking profile

Strongest area

Threat attribution

Weakest area

Remediation reasoning

Summary

Strong attribution instincts; remediation steps lack precision under time pressure.

Evaluation narrative

Alex correctly identified the misattributed threat actor and flagged the CVSS inconsistency on Q2. Remediation responses were directionally correct but lacked the specificity expected at mid level — particularly around lateral movement containment. Overall reasoning is sound; gaps are addressable with structured mentorship.

Recommendation: Proceed to final interview with focus on incident response depth.

Dimension breakdown

Threat attribution85%

Strong

Evidence evaluation72%

Strong

Risk prioritisation60%

Adequate

Remediation reasoning42%

Weak

DimensionScoreMaxBand
Threat attribution1720Strong
Evidence evaluation1825Strong
Risk prioritisation1525Adequate
Remediation reasoning1830Weak

One scenario tests your response. A series of scenarios reveals how you think.

As you complete different scenarios, ScenarioLab can progressively surface where you’re strong, recurring blind spots, architecture domains worth further practice, and how well you adapt across different situations.

Built for security teams

Designed with rigour in mind

Deterministic hiring scoring

Hiring assessments use structured rubrics and deterministic scoring for consistent candidate evaluation.

Time-limited by design

Time-boxed sessions. Realistic pressure without the noise of open-book take-homes.

Structured simulation feedback

Training simulations provide dimension-based feedback on evidence reasoning, decision quality, tradeoff awareness, escalation judgment, and communication clarity.

Real incident context

Every simulation gives background on the real-world incident it's derived from — context, not a vacuum.

Privacy-first

Candidate emails are hashed after OTP verification. Raw answers are never written to the database.

For professionals

Practise before the real decision matters.

  • Challenge your professional judgement
  • Prepare for senior technical roles
  • Practise unfamiliar scenarios
  • Identify reasoning blind spots
  • Improve architecture and decision-making capability

For organisations

Evaluate how people reason — not just what they know.

  • Hiring
  • Professional development
  • Training
  • Competency assessment
  • University education
  • Scenario-based exercises

Pricing

Free access

Free during early access — pricing will be introduced later.

Early access

All features included while we're in early access — no credit card required.

Free · Early access

  • All simulations and assessments
  • AI critical analysis hiring tests
  • Incident management simulation exercises
  • Unlimited learners/candidates during early access
  • PDF reports and exports

Security decisions are easy when the answer is obvious.

ScenarioLab begins when it isn’t.