PRICING

Better exercises.
A fraction of the cost.

A traditional tabletop exercise costs $25,000+ for a single engagement. Breachdeck gives your team unlimited practice starting at $4,000/year.

STARTER

$4,000 per year

One scenario per year with unlimited runs — ideal for annual compliance exercises

  • 1 scenario per year, unlimited runs
  • Choose from 5 core scenarios
  • SSO authentication
  • Full debrief & scoring
  • PDF report export
  • Email support

ENTERPRISE

Let's talk

Tailored to your environment and threat landscape

  • Everything in Team
  • SCIM provisioning
  • Custom-built scenarios
  • Dedicated account manager
  • SLA & uptime guarantee

Compare Plans

Starter Team Enterprise
Scenarios included 1 per year Unlimited + custom
Scenario runs Unlimited Unlimited
Scenario library access 5 core scenarios Full library + custom
Team members Up to 12 Unlimited
Scored debrief
Competency assessment
PDF report export
SSO authentication
Team benchmarking
Advanced analytics
Priority support
SCIM provisioning
Custom scenarios
Dedicated account manager
SLA & uptime guarantee

Built for compliance

PCI DSS 4.0, SOC 2, HIPAA, CMMC, and ISO 27001 require periodic IR testing. Breachdeck produces audit-ready documentation out of the box.

SOC 2HIPAAPCI DSSCMMCISO 27001

FREQUENTLY ASKED QUESTIONS

PRODUCT

How long does an exercise take?

Most exercises run 30–60 minutes depending on scenario complexity and team discussion depth. Beginner scenarios start at 30 minutes; advanced scenarios with multiple decision branches take closer to 60.

How many people can participate?

Exercises work best with 4–12 participants. One person shares their screen with the command center while the full team discusses and debates decisions together.

Do I need a facilitator?

No. Breachdeck guides the exercise automatically—presenting evidence, prompting decisions, and managing the scenario timeline. Your team focuses on response, not logistics.

What do I get at the end of an exercise?

A scored debrief with competency breakdowns across containment, communication, compliance, and business impact. You also get a one-click PDF export for audit documentation and team review.

COMPLIANCE & AUDIT

Which frameworks require tabletop exercises?

PCI DSS 4.0 (Req 12.10.2), SOC 2 (CC7.1/CC7.2), ISO 27001 (A.16.1.5), and GDPR (Article 32) all require periodic testing of incident response plans. HIPAA and CMMC have similar requirements.

What documentation does Breachdeck produce?

Each exercise generates a timestamped PDF report with scenario details, team decisions, outcome analysis, and competency scores. Reports are designed to satisfy auditor expectations for IR plan testing evidence.

Can I use exercise reports for SOC 2 / HIPAA / PCI DSS audits?

Yes. Reports include the exercise date, participants, scenario scope, decisions made, and scored outcomes—the key evidence auditors look for when reviewing IR testing controls.

Ready to train your team?

Try a demo scenario — no signup required.

▶ Try the Demo