TTX Commander
The incident-response exercise SOC 2 and ISO 27001 require. An AI game master improvises; the evidence trail doesn't.
SOC 2 and ISO 27001 both require you to exercise your incident response plan, not just write one. Most companies do it once a year, badly: a consultant charges five figures for an afternoon, everyone reads from a script, and the artifact is a slide deck nobody opens again. Then the auditor asks which controls the exercise actually tested, and the honest answer is that nobody was writing that down.
What it is
TTX Commander runs the exercise and writes the evidence at the same time. Your CISO, IT lead, legal counsel and comms lead work an incident that isn't happening. An AI game master delivers the complications, plays the ransomware crew and the CFO who wants systems back now, and adapts to what the room actually decides. When it ends, the after-action report is already written — and every "control exercised" claim in it links to the exact moment in the timeline that substantiates it.
The interesting engineering problem is not the roleplay. It is staying coherent for three hours. A model that improvises from a growing transcript starts contradicting itself around the ninety-minute mark: it revives a server the team already isolated, or re-announces an inject it delivered an hour ago. So the transcript is not the source of truth here. The exercise state lives outside the model — the clock, the pressure level, each actor's stance, the canonical facts, the open threads, the control coverage — and the game master reads a compact snapshot of it each turn and changes it only through validated tool calls. The improvisation is genuine; the state is not negotiable.
What it does well
The evidence is the product. Every event in the exercise gets an id. A control-coverage claim that cites nothing, or cites something that never happened, is rejected before it reaches the report. What the auditor receives is a matrix mapping SOC 2 Trust Services Criteria and ISO/IEC 27001:2022 Annex A controls to the minute of the exercise where the team demonstrated them.
Facilitator-optional. In co-pilot mode the game master proposes each material move and waits for the consultant to approve, edit or reject it — the human keeps the room, the machine keeps the state. In self-serve mode a company runs the whole thing with nobody hired. Same engine; the difference is one conditional edge.
Participants join from their phones. A signed link, no account, no email collected. They see the incident log and type what they would do. The facilitator sees everything, including the pending injects the room has not been handed yet.
Time moves whether or not anyone speaks. A beat clock advances simulated time on its own, so the complication scheduled for T+40 arrives at T+40 even in a quiet room. Silence is a decision the exercise is allowed to punish.
What-if branching. The most valuable question in the debrief is the one the room could not afford to ask live: what if we had paid? Fork the exercise at any completed turn and run the counterfactual. The real exercise is untouched, and its report is unchanged.
It narrates effects, not technique. The game master describes what the room observes and what the stakeholders do. It does not produce attack instructions, tooling, or anything resembling a runbook for the other side. That is enforced in the prompt, in a validator, and by a content classifier — and it is also why the thing is safe to sell.
Who it's for
Companies carrying a SOC 2 Type II or ISO 27001 certification who need the annual exercise done, documented, and defensible.
Fractional CISOs and security consultants who run tabletops for a living. Co-pilot mode is built for them: keep the client relationship and the judgment calls, hand off the state-keeping and the report writing, and run more engagements in the same week.
Security leaders who already run tabletops and are tired of the evidence being a photograph of a whiteboard.
What it looks like in practice
A thirty-person SaaS company schedules its annual exercise. The facilitator opens a session, picks the ransomware scenario, and sends four links — CISO, IT lead, legal, comms. Monitoring flags mass file renames on the finance file server. The IT lead isolates it. The clock moves; a second host lights up. Legal gets a ransom note claiming exfiltration and a forty-eight hour deadline. The CFO, played by the game master, wants to know when finance is back and does not care about forensics.
Ninety minutes later the room stops. The report is a document: a timeline, every decision with the game master's assessment of it, a coverage matrix showing which controls the exercise actually demonstrated and which it did not touch, and the gaps stated as gaps. The company files it. When the auditor asks how incident response was tested, there is a specific answer with dates and evidence ids attached.
What it's not
It is not a breach-and-attack simulation tool. Nothing is deployed on your network. No agents, no traffic, no scanning. This is a discussion-based exercise, which is exactly the kind the frameworks ask for.
It is not a phishing simulator. Different problem, different product.
It does not certify anything. It produces evidence a company can present. Whether that evidence satisfies a given auditor is the auditor's call, and any vendor telling you otherwise is selling you something they cannot deliver.
It is not a replacement for your incident response plan. It is the thing that finds out whether the plan survives contact.
Status
The engine is built and proven where it matters. A compressed three-hour exercise runs end to end under test with the coherence invariants asserted every turn: the clock never runs backward, no complication is delivered twice, every control claim resolves to a real event, the summary never loses a fact, and every narrative thread the game master opens gets closed. Four scenarios ship today — ransomware, cloud account compromise, insider threat, and supply-chain breach — each with its own control map rather than a copied one. Reports render to Word and PDF.
Pre-launch. The platform is being stood up at ttxcommander.com now. Multi-tenant billing and the scenario authoring interface are the next build. Reach out if you run tabletop exercises for clients, or if your own annual exercise is coming up and you would rather it produced something an auditor can read.