Scenario-based cybersecurity hiring assessment

Can your candidates spot what AI gets wrong?

ScenarioLab gives security hiring teams a scenario lab — candidates analyse deliberately flawed AI-generated reports under time pressure. Scoring is fully deterministic. No LLMs in the loop.

Free trial · no credit card required

ai-pentest-report.txt

AI Security Analysis — Network Scan

CRITICAL · SQL injection on /api/users

CVSS 9.8 · Apply input sanitisation immediately.

MEDIUM · TLS 1.0 downgrade risk

Recommendation: disable TLS 1.2 and below.

LOW · CVE-2021-44228 reference...

Candidate must identify

CVSS score inconsistent with described impact
Remediation contradicts current TLS best practice
CVE reference misattributed to wrong vendor

The hiring gap

AI writes the reports now. Who’s reading them critically?

AI output looks authoritative

AI-generated security reports are increasingly polished — and increasingly wrong. Candidates who can't distinguish confident AI prose from sound analysis are a liability.

Interviews don't surface this gap

Technical screens test memorised CVEs and syntax. Scenario-based assessments reveal whether candidates actually reason through an analysis or just pattern-match.

Standard rubrics are subjective

Most soft-skill assessments rely on interviewer opinion. ScenarioLab scores against a fixed key — same standard for every candidate, every time.

How it works

Three steps from sign-up to insight

01

Choose a scenario

Select from curated scenarios — each contains an AI-generated security report with embedded analytical flaws, scored against a fixed rubric.

02

Invite candidates

Paste a candidate email and we send them a private assessment link. They authenticate with a one-time code — no account creation needed.

03

Review the results

Each submission produces a detailed evaluation report: per-question scores, reasoning quality, and an overall band. Export as PDF for your records.

Sample report

This is what you get after every submission

Every completed assessment generates a full evaluation — per-dimension scores, a critical thinking profile, and a hiring recommendation. No interpretation needed.

Alex M.

a7f3...c91e@candidate

Senior SOC Analyst Screening · Phishing Campaign Attribution

MID

Submitted 10 Apr 2026 · Time taken 17m 42s

68 / 100

Proficient

Critical thinking profile

Strongest area

Threat attribution

Weakest area

Remediation reasoning

Summary

Strong attribution instincts; remediation steps lack precision under time pressure.

Evaluation narrative

Alex correctly identified the misattributed threat actor and flagged the CVSS inconsistency on Q2. Remediation responses were directionally correct but lacked the specificity expected at mid level — particularly around lateral movement containment. Overall reasoning is sound; gaps are addressable with structured mentorship.

Recommendation: Proceed to final interview with focus on incident response depth.

Dimension breakdown

Threat attribution85%

Strong

Evidence evaluation72%

Strong

Risk prioritisation60%

Adequate

Remediation reasoning42%

Weak

DimensionScoreMaxBand
Threat attribution1720Strong
Evidence evaluation1825Strong
Risk prioritisation1525Adequate
Remediation reasoning1830Weak

Built for security teams

Designed with rigour in mind

No AI in scoring

Every response is evaluated against a deterministic rubric. Scoring is a pure function — reproducible and auditable.

Time-limited by design

20-minute sessions. Realistic pressure without the noise of open-book take-homes.

Structured evaluation

Per-question scoring with overall bands. Clear signal on where a candidate's reasoning breaks down.

Privacy-first

Candidate emails are hashed after OTP verification. Raw answers are never written to the database.

Pricing

Simple, transparent plans

Try it on your next hire

Run 3 real candidates through a scenario before you commit to anything.

Free — no credit card required

  • 2 assessments (lifetime)
  • 3 candidates per assessment
  • 3 Junior scenarios
  • No PDF export
Most popular

Screen at hiring pace

For teams making regular security hires who need consistent, repeatable signal.

$29 / month

  • 10 assessments / month
  • 15 candidates each
  • All scenarios
  • PDF export

Hire without limits

Unlimited assessments and candidates — built for high-volume teams and agencies.

$99 / month

  • Unlimited assessments
  • Unlimited candidates
  • All scenarios
  • PDF export

Start assessing in minutes

Free trial, no credit card. Two assessments, three candidates — enough to see whether ScenarioLab fits your hiring process.