Breach
Simulation
A full crisis, rehearsed: detection, escalation, the executive decision, containment, recovery, and every message sent while it happens.
In private preview, not generally available. A badly facilitated crisis exercise is worse than none, so it stays in preview until the delivery playbook is proven on pilots.
What it will be
A penetration test says what is exploitable. A red team says whether an adversary is seen. This starts after both and asks the next question: once your organization knows it has a serious incident, what does it actually do?
The exercise runs on injects: timed events dropped into a controlled scenario that participants have to respond to. Nothing is encrypted, nothing real is exposed, every action is reversible. What is measured is decision quality, escalation, coordination and recovery under time pressure.
In development
Inject-driven scenarios modelled on ransomware, insider abuse, and supply chain compromise.
Instrumented decision points across security, engineering, legal, and executive participants.
Observation and scoring against the response actually taken, not the plan on file.
An after-action report that separates process gaps from tooling gaps from training gaps.
Engagements you can book now
Each of these tests part of what breach simulation will cover, and each is a sensible prerequisite for it.
Available
Red Team Engagements
One stated objective, pursued against your detection stack while your team is not told. Measures what fired, what did not, and how long each took.
Available
Insider Threat Simulation
A provisioned account run as a specific insider persona. Tests whether DLP, behaviour analytics and access controls catch abuse that looks authorized.
Available
Penetration Testing
Agent swarms across applications, APIs, cloud and internal networks. Establishes what is exploitable before you rehearse what happens once it is.
Model the exposure while the engagement is in preview
Both tools produce an output that would feed directly into scenario design, and both are useful on their own.
How to start
Preview engagements are taken selectively. Describe your incident response maturity, which functions would participate, and the scenario you would want rehearsed. If the preview is not a fit, we will point you at the engagement type that is.
Direct: hello@principlebreach.com
What preview participants get
- Priority access when scheduling opens
- Scenario briefing and scope workbook
- Input into how the exercise is designed
- Notice ahead of general availability