AI-native cybersecurity decision simulator

The flight simulator for cybersecurity professionals.

Security teams are judged on decisions made under pressure with incomplete evidence. BreachIQ lets them practise those decisions — with an adversary that reacts where there is one — and proves they are getting better.

Invite-only during the founder beta. Create an account and request access in setup.

Midnight Ledger

Sev 1 · Active

Containment window

00:14:22

  • T+04:12Finance workstation beacons to an unrecognised host.
  • T+06:48Backup service account authenticates from a new region.

Authored scenarios

25live

BEC, ransomware, insider, cloud, supply chain

Scored dimensions

5per run

Triage, evidence, containment, comms, blast radius

Score scale

0–4benchmark 2.50

Same scale on every run, open to challenge

The pressure

Outcomes are decided by judgment, not by tooling.

01Partial telemetry

The evidence is never complete

Calls get made on a noisy timeline, with someone asking for an answer now.

02A person decides

Tooling does not make the call

Detection surfaces a signal. Isolate, watch, escalate or hold is judgment.

03Runbooks only

Nobody practises the hard part

Teams rehearse tools. Almost nobody rehearses the decision under a clock.

Inside a run

An incident, a clock, and consequences that answer back.

  1. Evidence arrives

    Alerts, logs, messages and dead ends, unfolding in real time.

  2. You act, the incident answers

    Isolate, escalate, preserve, notify or hold — and where there is an adversary, it adapts to what you committed.

  3. Committed actions are scored

    Committed actions judged individually, plus the actions you never took. You can contest any of it.

The debrief

Every action explained, and open to challenge.

Adjudication is anchored to the authored scenario and cites the Reference Library where relevant material exists. You see how your committed actions were judged, the expected actions you missed, the sources behind the call — and you can contest any of it.

Debrief · illustrative

Sound judgment

Midnight Ledger · Ransomware staging

  • Containment effectiveness3.40/4
  • Evidence discipline2.60/4
  • Escalation & communication judgment3.20/4

Strong isolation call at T+09. Backup credentials were rotated before the forensic image was taken, which cost you the staging host's memory state.

Readiness over time

Judgment you can actually measure.

Each scored run moves your readiness across five competencies. BreachIQ then identifies your weaker ones, recommends the right difficulty, and suggests scenarios for your next run.

Competency shape · illustrative

0–4 scale
Detection & triage speedTriageEvidence disciplineEvidenceContainment effectivenessContainmentEscalation & communication judgmentEscalationBlast-radius awarenessBlast radius

Benchmark 2.50 / 4 across five competencies

Run score across six runs

1.20 of 4

Illustrative trajectory · benchmark 2.50 / 4

Questions

What people ask before their first run.

01

What is BreachIQ?

BreachIQ is an AI-native decision simulator for cybersecurity. It runs authored, synthetic incidents against a clock, lets the adversary react to the actions you commit where the scenario has one, and scores those actions against an authored rubric so your judgment can be measured over time.

02

Who is BreachIQ for?

Working SOC analysts sharpening triage between real incidents, aspiring analysts building their first reps, and career switchers testing whether the work suits them. A team lead can practise alongside their analysts and track their own readiness; shared team views are planned, not built.

03

How is your judgment scored?

Committed actions are judged individually against the scenario's rubric, anchored to the authored scenario and citing the Reference Library where relevant material exists. The debrief also names the expected actions you never took. Every run is scored on a 0–4 scale, and scores across runs build your readiness across five competencies. You can contest any judgment.

04

Is BreachIQ a cyber range or technical lab?

No. A range trains tool operation on live systems. BreachIQ trains judgment: what you do, in what order, with incomplete evidence and time running. There is nothing to install and no infrastructure to spin up.

05

Are the scenarios safe and synthetic?

Yes. Every scenario, log line, alert and persona is synthetic. No real customer, employee or third-party data is used. Attacker behaviour is modelled at the level needed for defensive learning and stops short of working exploit code.

06

Does the simulation react to what I do?

Yes. Where a scenario has an adversary, it reads the actions you have committed and changes its posture and next move accordingly, so two runs can play out differently because the next consequence responds to what you commit. The scenario envelope — objectives, attack chain and evidence set — stays fixed so runs remain comparable and fair to score. Some incidents are authored with no adversary at all, and BreachIQ says so rather than inventing one: there you are judged on whether you escalated a false alarm. Between runs, BreachIQ identifies your weaker competencies, recommends the right difficulty, and suggests scenarios for your next run.

07

How do I get access?

BreachIQ is invite-only during the founder beta. Create an account, then request access during setup. No payment is taken and no card is required.

Founder beta

We are building BreachIQ with practitioners, in the open.

25 authored scenarios, a reacting adversary where the scenario has one, a grounded mentor and scored debriefs are live today. Invite-only.

Start free — request beta access