About

Why BreachIQ exists

Cybersecurity outcomes are decided by judgment under pressure — what someone chooses, in what order, with incomplete evidence and a clock running. Most training teaches tools and content. BreachIQ practises the decisions, and scores them.

The problem it addresses

Analysts read, watch and certify, then meet their first real incident with no reps in the decisions that matter: what to contain, what to escalate, what to leave alone, and when to say you do not know enough yet. Nothing in that path produces evidence that judgment is improving.

BreachIQ turns that into repetition you can measure. Incidents are authored and pinned to a version; AI adjudicates your decisions against the authored rubric and drives the mentor and the adversary's reactions inside that authored envelope. Every run is scored, and the result moves your readiness instead of a completion bar.

How a run works

A scenario opens as a live incident: a clock, a stream of evidence, and choices that change what happens next. You act — contain, escalate, preserve, communicate — and, where the scenario has an adversary, it reacts to what you commit within the authored scenario envelope. Some incidents are authored with no adversary at all, and BreachIQ says so rather than inventing one. That envelope itself stays fixed: objectives, attack chain and evidence set are authored and pinned to a scenario version, so runs stay comparable and fair to score.

Adjudication is anchored to the authored scenario and cites the Reference Library where relevant material exists. In the debrief, committed actions are judged individually, the expected actions you never took are named separately, and you can contest a call you disagree with. Contested cases are reviewed and feed back into scenario quality. Scored runs move your readiness across five competencies; BreachIQ then identifies the weaker ones, recommends the right difficulty, and suggests scenarios for your next run.

Who builds it

BreachIQ is built by Mircea Neagu. Twenty years in the automotive industry, across execution and leadership roles, taught the habit the product is built on: outcomes are decided by the quality of decisions made with imperfect information, and decision quality can be trained.

He joined the AI revolution at the end of 2025 and now builds applications intended to add real customer value, including NextLeadium and BreachIQ.

To be plain about it: he is an experienced engineering and technology leader and an AI-native product builder — not a practising cybersecurity analyst. Scenario content and scoring rubrics are authored to be checked and challenged by practitioners, and the founder beta exists precisely so people who do the work every day can tell us where the simulation is wrong. If you find something that does not hold up, write to contact@breachiq.ai.

What we commit to

  • The learner decides. AI generates, adjudicates and coaches. It never acts on real systems on anyone's behalf.
  • Everything is synthetic. Incidents, logs, alerts, artefacts and personas are invented. No real customer, employee or third-party data enters a simulation.
  • Defensive only. Attacker behaviour is modelled at the level required for defensive learning — tactics, indicators, artefacts — and stops short of working exploit code or operational instructions against real systems.
  • No pretending. AI-generated content is never presented as human-authored, and you can ask why a decision was scored the way it was.
  • Your data is yours. Performance data belongs to the learner; sharing it with anyone else, including an employer, requires explicit opt-in. See the Privacy Notice.

Where it is today

BreachIQ is in founder beta and invite-only. 25 authored scenarios — some with a reacting adversary, some deliberately benign — the grounded mentor, the adjudicated debrief and the readiness map are working today; team and organisation features are not built yet. The product is being built with a small group of practitioners rather than for an imagined one. No payment is taken during the beta.

Create an account and request access, or see plans and pricing.