Education

Cyber Risk Scenario Trainer

A cyber risk scenario trainer walks you through realistic security incidents, ransomware spreading over the network, a lost laptop, leaked credentials, a public storage bucket, and asks for the best first response. The choices are shuffled, each has a defined right answer, and every option comes with why it is better or worse.

Last reviewed by the Radiatus Cloud team

Need this done properly for your business?

Radiatus delivers secure cloud, DevOps & compliance engineering.

Book a free consult

How it works

Eight scenarios run in sequence. Each presents an incident and four responses in random order, so the answer is never in the same place. Pick one and the trainer marks whether it was the best response, shows the reasoning, and explains why the others delay containment, destroy evidence, or create legal exposure. Your score is tallied at the end.

The pattern it teaches

Nearly every scenario rewards the same instinct: contain first, preserve evidence, then decide. Isolating a ransomware host beats rebooting it, because a reboot can trigger destructive routines and wipes volatile memory. Revoking a leaked API key beats rewriting git history, because scanners already have the key. Wiping a lost laptop and rotating credentials beats rushing to notify a regulator, because an encrypted device with no evidence of access is usually not a notifiable breach. The trainer makes that pattern explicit so it becomes a reflex.

What each scenario covers

  • Ransomware containment versus reboot or ransom payment.
  • Lost device, encryption, and the notification threshold.
  • Phishing credential theft and session revocation.
  • Responsible-disclosure handling of an exposed bucket.
  • A vendor breach and your controller obligations.
  • A leaked API key, DDoS during a launch, and lingering ex-employee access.

Who it is for

Security awareness training for engineers, on-call staff and managers who may make the first call in an incident. It is decision practice, not a certification, and the scenarios are simplified; real incidents carry more ambiguity. The value is rehearsing the contain-first sequence before you need it under pressure.

Related tools

Frequently Asked Questions

Are the answer positions fixed?

No. The four options are shuffled for every scenario, so you cannot learn that the first or last choice is always correct. Each has a defined best answer with an explanation.

What is the recurring lesson?

Contain first, preserve evidence, then decide. Most scenarios reward isolating the threat and keeping forensic data over reacting in a way that spreads the incident, destroys evidence, or creates legal problems.

Is this a certification?

No. It is decision-practice for security awareness. It builds the reflexes that help during a real incident but does not replace formal incident-response training or tabletop exercises with your own runbooks.

Who should use it?

Engineers, on-call responders and managers who might make the first decision in a security incident. Even non-specialists benefit, because the first hour of an incident is often handled by whoever is available.

Why is rebooting a ransomware machine wrong?

A reboot can trigger destructive routines the malware scheduled and destroys the volatile memory that forensics needs. Isolating the host from the network stops spread while preserving evidence, which is why the trainer marks isolation as the best response.

Privacy & Security

Training done locally.

Data: None
Client-side-Side
Active
v1.0

About This Tool

This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started — no registration or login required.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.