Public Sector Ransomware Crisis
Table Top Exercise Courses
ID: CADMUS-SGTTX-01 Owner: CTI
Available for trainingMay 2026
Duration 5 hours
Platform Category Table Top Exercise
Proficiency Level Basic–Intermediate
Training Type Reskilling
Delivery Method Hybrid & Physical
ECSF Roles View Roles ▾
Cyber Legal, Policy & Compliance Officer Chief Information Security Officer (CISO) Cyber Incident Responder
ECSF Skills View Skills ▾
  • Practice all technical, functional and operational aspects of cybersecurity incident handling and response (Intermediate)
  • Communicate, coordinate and cooperate with internal and external stakeholders (Intermediate)
  • Analyse and comply with cybersecurity-related laws, regulations and legislations (Intermediate)
  • Manage cybersecurity resources (Basic)
  • Review and enhance security documents, reports, SLAs and ensure the security objectives (Intermediate)
Description View Description ▾
A practical tabletop exercise where a municipal administration faces a ransomware attack disrupting citizen services. Teams rank systems, negotiate priorities, write and send public messages, and coordinate with law enforcement and data protection authorities.
Enrolment
Please register before 6 May 2026
Critical Infrastructure Incident Response
Table Top Exercise Courses
ID: CADMUS-SGTTX-03 Owner: CTI
Available for training February 2027
Duration 6 hours
Platform Category Table Top Exercise
Proficiency Level Intermediate
Training Type Upskilling
Delivery Method Online instructor‑led
ECSF Roles View Roles ▾
Chief Information Security Officer (CISO) Cyber Incident Responder Cybersecurity Risk Manager
ECSF Skills View Skills ▾
  • Practice all technical, functional and operational aspects of cybersecurity incident handling and response
  • Enable business assets owners, executives and other stakeholders to make risk-informed decisions to manage and mitigate risks
  • Communicate, coordinate and cooperate with internal and external stakeholders
  • Analyse and consolidate organisation’s quality and risk management practices
  • Work under pressure
Description View Description ▾
A facilitator‑led tabletop exercise simulating a cascading cyber‑physical incident against a critical infrastructure operator. Participants work in roles to rank events, decide on containment vs. continuity, coordinate with external stakeholders (regulator, CERT, media), and conclude with a structured post-event analysis and discussion.
Cyber Security Audit Simulation & Compliance Review
Table Top Exercise Courses
ID: CADMUS-SGTTX-05 Owner: AU
Available for training June 2026
Duration 6 hours
Platform Category Table Top Exercise
Proficiency Level Intermediate
Training Type Upskilling
Delivery Method Hybrid & Physical
ECSF Roles View Roles ▾
Cybersecurity Auditor Cyber Legal, Policy & Compliance Officer Cybersecurity Risk Manager Chief Information Security Officer (CISO) Cybersecurity Implementer
ECSF Skills View Skills ▾
  • Analyse business processes, assess and review software or hardware security, as well as technical and organisational controls
  • Apply auditing tools and techniques
  • Audit with integrity, being impartial and independent
  • Collect, evaluate, maintain and protect auditing information
  • Communicate, present and report to relevant stakeholders
  • Decompose and analyse systems to identify weaknesses and ineffective controls
  • Follow and practice auditing frameworks, standards and methodologies
  • Organise and work in a systematic and deterministic way based on evidence
  • Work ethically and independently; not influenced and biased by internal or external actors
  • Work under pressure
Description View Description ▾
Cyber Security Audit Simulation & Compliance Review

This Tabletop Exercise simulates a complete cybersecurity audit, where participants act as the audit team responsible for evaluating the security posture of a fictional organisation. Participants review policies, logs, risk assessment documents, technical controls, and operational workflows; conduct interviews; validate evidence; classify findings; and deliver a professional audit report. The TTX replicates real-world audit pressure: incomplete documentation, conflicting evidence, stakeholder resistance and time constraints.
Asset & Risk Management – Organisational Exposure Assessment
Table Top Exercise Courses
ID: CADMUS-SGTTX-06 Owner: AU
Available for training December 2026
Duration 10 hours
Platform Category Table Top Exercise
Proficiency Level Intermediate
Training Type Upskilling
Delivery Method Hybrid & Physical
ECSF Roles View Roles ▾
Cybersecurity Risk Manager Cyber Legal, Policy & Compliance Officer
ECSF Skills View Skills ▾
  • Analyse and consolidate organisation’s quality and risk management practices
  • Assess and enhance an organisation’s cybersecurity posture
  • Enable business assets owners, executives and other stakeholders to make risk-informed decisions to manage and mitigate risks
  • Propose and manage risk-sharing options
  • Communicate, present and report to relevant stakeholders
  • Organise and work in a systematic and deterministic way based on evidence
  • Work under pressure
Description View Description ▾
Asset & Risk Management – Organisational Exposure Assessment

This TTX simulates the process of identifying organisational assets, assessing risks, prioritising treatment actions and preparing risk reports for executive decision-makers. Participants work through dynamic scenario injects and incomplete information, performing asset classification, BIA, risk scoring, and mitigation planning. The exercise mirrors real-world governance and risk workflows, requiring participants to collaborate across technical, legal, business and compliance domains.
Cybersecurity Crisis Management for Public Authorities
Table Top Exercise Courses
ID: CADMUS-SGTTX-07 Owner: AU
Available for training June 2026
Duration 8 hours
Platform Category Table Top Exercise
Proficiency Level Intermediate
Training Type Upskilling
Delivery Method Hybrid & Physical
ECSF Roles View Roles ▾
Cyber Incident Responder Cyber Legal, Policy & Compliance Officer Cybersecurity Risk Manager
ECSF Skills View Skills ▾
  • Communicate, coordinate and cooperate with internal and external stakeholders
  • Practice all technical, functional and operational aspects of cybersecurity incident handling and response
  • Analyse and comply with cybersecurity-related laws, regulations and legislations
  • Enable business assets owners, executives and other stakeholders to make risk-informed decisions to manage and mitigate risks
  • Work under pressure
  • Build a cybersecurity risk-aware environment
Description View Description ▾
Cybersecurity Crisis Management for Public Authorities

This course prepares public authorities to manage and coordinate cybersecurity crises affecting government services. Through a combination of LMS-based theoretical modules and a live, instructor-led tabletop exercise, participants gain practical experience in crisis communication, inter-agency cooperation, regulatory compliance and the protection of essential public services. The final TTX places learners in a realistic scenario where they must coordinate across ministries, municipalities, national CERT/CSIRT and external partners while maintaining continuity of vital public services.
Incident Response – Cross-Functional Crisis
Table Top Exercise Courses
ID: CADMUS-SGTTX-08 Owner: AU
Available for training June 2026
Duration 6 hours
Platform Category Table Top Exercise
Proficiency Level Intermediate
Training Type Upskilling
Delivery Method Hybrid & Physical
ECSF Roles View Roles ▾
Cyber Incident Responder Cyber Legal, Policy & Compliance Officer
ECSF Skills View Skills ▾
  • Communicate, coordinate and cooperate with internal and external stakeholders
  • Practice all technical, functional and operational aspects of cybersecurity incident handling and response
  • Analyse and comply with cybersecurity-related laws, regulations and legislations
  • Identify and solve cybersecurity-related issues
  • Work under pressure
  • Collaborate with other team members and colleagues
Description View Description ▾
This Tabletop Exercise provides a realistic, multi-phase simulation of a major cyber incident affecting a fictional enterprise. Participants assume role-specific responsibilities-Management, Legal, HR, or PR-and respond to escalating scenario injects. Each team performs its own tasks while collaborating with others to manage incident impact, regulatory obligations, staff issues, communications and executive expectations. The TTX replicates real-world crisis dynamics: incomplete information, operational pressure, regulatory deadlines, and media attention.
Implementing Cryptography Correctly
Table Top Exercise Courses
ID: CADMUS-SGTTX-09 Owner: CTI
Available for training February 2027
Duration 6 hours
Platform Category Table Top Exercise
Proficiency Level Intermediate
Training Type Upskilling
Delivery Method Online instructor‑led
ECSF Roles View Roles ▾
Cybersecurity Architect Cybersecurity Implementer Cyber Incident Responder
ECSF Skills View Skills ▾
  • Implement cybersecurity risk management frameworks, methodologies and guidelines and ensure compliance with regulations and standards
  • Analyse and implement cybersecurity policies, certifications, standards, methodologies and frameworks
  • Select appropriate specifications, procedures and controls
  • Practice all technical, functional and operational aspects of cybersecurity incident handling and response
  • Analyse and consolidate organisation’s quality and risk management practices
Description View Description ▾
A facilitator-led exercise where teams face escalating scenarios of crypto misuse (e.g., weak random numbers, deprecated algorithms, improper key storage). Participants decide on trade-offs between quick fixes, long-term solutions, and regulatory compliance. Ends with a collaborative post event analysis and remediation actions.