How to choose the right exercise type and scenario before you schedule a crisis simulation.
Exercise types
Immersive Crisis Simulations has three exercise types: single player, drill, and presentation. Choosing the right one depends on your objectives, your audience, and whether you need participants to work simultaneously or in their own time.
Single player and drill exercises are asynchronous — participants complete them when it suits them, within the time window you set. Presentation exercises are facilitated and live: a host runs the session for a group who all take part at the same time.
Single player
Each participant works through the scenario individually, making their own decisions at every point. It's the best way to test end-to-end crisis response at the individual level and to understand how different members of your team approach the same situation. You'll get completion metrics and a clear view of each person's choices and reasoning.
Drill
A drill assigns each participant a specific role within the scenario, so individuals only respond to the injects that are relevant to them. Multiple participants complete the exercise independently, but their responses come together to show how the team would function in a real crisis. You can only assign one user per role, though the same user can hold multiple roles. Drills are well suited to testing communication between team members, measuring response times, and identifying skill gaps.
Presentation
Presentation mode is for facilitated, live group exercises — whether you're in a room together or working remotely over video conferencing. Participants vote on the best course of action at each decision point as the scenario unfolds. Anyone can be invited to join, and there's no upper limit on group size. The facilitator guides the group through the narrative, highlighting learning points and prompting debate. Note that presentation exercises don't produce individual metrics, and they require everyone to be available at the same time.
Comparing the three types
| Single player | Drill | Presentation | |
| Format | Individual, self-paced | Role-assigned, asynchronous team | Facilitated, live group |
| Best use case | Testing individual end-to-end response | Testing team communication and role-specific response | Group learning, leadership exercises, large audiences |
| Individual metrics | Yes | Yes, per role | No (votes can be named or anonymous) |
| Requires simultaneous participation | No | No | Yes |
| Scenario compatibility | All scenarios | Drill-compatible scenarios only | All scenarios |
Choosing a scenario
When you browse the scenario catalog, use the filters on the left to narrow by industry sector, attack vector, or threat actor. This helps you find scenarios that are directly relevant to your organization and your participants.
Not every scenario works with drill — use the Exercise Compatibility filter in the catalog to see which ones do.
Before you schedule anything, preview the scenario. Select the scenario you're interested in, then choose to preview it in single player mode or presentation mode. That way you'll see exactly what participants experience before committing to a date.
For help choosing a custom scenario, contact our Support Team or your Customer Success Manager.
Common attack vectors
- Insider threat — malicious or accidental action by an employee that causes a security incident.
- Ransomware — scenarios covering how ransomware attacks unfold, the decisions required, and the organizational impact.
- Unauthorized access — illegitimate access to systems, accounts, or data by an internal or external actor.
- Supply chain compromise — manipulation of products or delivery mechanisms before they reach the end consumer, affecting hardware, software, or update channels.
- Phishing — users are tricked into selecting malicious links in seemingly legitimate emails or text messages.
- Targeted attack — a specific organization is targeted by a sophisticated attacker, often combining several of the above categories.
- Remote working — attacks targeting remote workforces, reflecting the threat landscape that emerged during and after the pandemic.