Switched On SecuritySwitched On Security

TABLETOP SIMULATIONS

Your team has rehearsed the fire drill. Never the incident.

Facilitated tabletop simulations that drop a team into a scenario, ask them to secure it, then hit them with the complication and let them feel the impact — discussing and committing to every decision together, not watching a slide deck.

Switched On Security is built by Adam Smallhorn, who has taught cybersecurity at UNSW since 2017 and led security-culture and cyber-outreach programs at Okta and Australia's largest bank.No spam, no sales sequence — you'll talk to the founder.

Exec tabletops rehearse the wrong room, with the wrong questions

Most tabletop exercises are run once a year, for the executive team, around a boardroom table. They rehearse the CISO's decisions. The person whose day-to-day work actually creates the exposure — the deadline call, the shortcut, the tool nobody signed off — is never in the room.

The questions are usually softballs anyway: easy, obviously-correct choices that nobody has to think hard about. Real judgment calls are tough on purpose — that's what makes them worth discussing as a team before anyone commits to an answer.

Tabletop Simulations puts the team that actually faces the decision in the driver's seat instead: a scenario with elevated risk to secure, a complication that hits and has to be handled in the moment, then the implication — the impact on the company, debriefed together. No Dorothy-Dixers, no lecture: every choice gets teachable feedback on whether it made the company more or less secure, so the group leaves understanding not just what happened but why it mattered.

rounds per session — scenario, complication, implication
3
rounds per session — scenario, complication, implication
individual scores — team-level only, by design
0
individual scores — team-level only, by design

Walkthrough

How a session runs

One worked example: "Shadow SaaS." A team's standard workaround quietly relies on a tool nobody approved — the sim plays out what that costs.

Pick the sim your team could live on a Tuesday

Choose from a library matched to real exposure — Shadow SaaS for any team with a deadline and a workaround, a phone left unlocked at a cocktail party, a phone seized at a border, an app launched to market on a cloud service while bypassing controls. No generic ransomware theatre.

1 / 5

Why it's different

Built around practice, not policy

No Dorothy-Dixers icon

No Dorothy-Dixers

Every question is genuinely tough, built to evoke discussion — the group works its way to the answer by sharing what each person already knows, not by picking the obvious option.

Teachable feedback on every choice icon

Teachable feedback on every choice

Each decision comes back with a read on whether it made the company more or less secure — the moment to explain what a control is and why it earns its place.

Security is everyone's business icon

Security is everyone's business

After the incident, the team sees how their individual calls affected the whole company, and practises communicating it appropriately — internally and with customers.

Auto-analysed into the Human Risk Dashboard icon

Auto-analysed into the Human Risk Dashboard

The platform can read the group's decisions and discussion with an LLM and feed that signal straight into the Human Risk Dashboard.

Questions

Frequently asked

How long is a session?

45 minutes, including the debrief. Built to fit inside a normal meeting slot.

Who facilitates — you or us?

We facilitate the pilot sessions ourselves. A train-your-facilitator methodology, so your own team can run these independently, is on the roadmap.

Does it work remote?

Yes — the scenario, complication and implication arrive over the same channels your team already uses (Slack, email, a shared call), so remote and in-person teams run the identical exercise.

Is anyone scored individually?

No. Scoring is team-level only, by design — the goal is a shared habit to change, not a leaderboard of who chose what.

What's an example scenario?

"Shadow SaaS": the team's own workaround relies on an unapproved tool. Round 1 asks them to secure it under deadline pressure; Round 2 hits them with the vendor breach and asks how to respond; Round 3 shows the blast radius and what a data-processing agreement, an approved-tools list, and a tested disclosure plan would have changed.

How does this connect to the Human Risk Dashboard?

The group's decisions and discussion can be auto-analysed with an LLM, and that read feeds into the Human Risk Dashboard as a signal alongside the Social Engineering Simulation.

Ready to see tabletop simulations on your own team?

Switched On Security is in active development with a small group of design partners — early access is free, and it shapes the roadmap.

Ask us about tabletop simulations

Every enquiry gets a short call with the founder to talk it through — not an instant trial, not a sales sequence.

Prefer to talk?

Book a 25-minute call directly — no form, no back-and-forth.

Book a 25-minute call

Switched On Security is built by Adam Smallhorn, who has taught cybersecurity at UNSW since 2017 and led security-culture and cyber-outreach programs at Okta and Australia's largest bank.