
You are three days into the security leadership seat at Apex Manufacturing. USD 1.1 million in supplier payments is due today. The board call is at 09:30. Nobody is coming to tell you what to do.
No account. No payment. 10–15 minutes.
Experience the responsibility before you inherit it.
Real decisions. Real pressure. Safe environment.
This is not a course
No lecture before you have something to think about. No trivia. The difficulty here is not obscure technical knowledge — it is uncertainty, conflicting priorities, time pressure, limited budget, stakeholder resistance, business impact and accountability. The same things that make the job hard.
Three to four professionally defensible options. Rarely one right answer. Every choice costs something somewhere else.
Cyber Risk Exposure, Business Disruption, Executive Trust, Time Pressure and Evidence Quality move with your choices — and against each other.
What you decide on Day 1 changes what you are told on Day 7 and what survives on Day 30.
The five conditions you are managing
You are not asked to maximise all of them — that is not possible, and it is not what leadership is. You are asked to keep the organisation in a defensible, survivable state while trading one pressure against another.
Episode 01 · Free · 10–15 min
Six scenes, from the alert nobody opened to the document you write at 17:40 that decides what the organisation actually learns. A full episode — not a sample.
After you finish
This reflects demonstrated performance within simulated professional experiences. It is not professional certification or evidence of actual CISO employment.
Season map
Eight episodes at Apex Manufacturing. Decisions persist. The season moves deliberately through six stages of professional development.
Your third day in the role. One account signs in from two continents within eleven minutes. Nobody else has noticed yet.
A critical supplier fails your security review. Operations says production stops without them. Procurement already signed.
"How exposed are we — on a scale of one to ten?" You have twenty minutes and no defensible number.
Your budget covers a third of what the organisation actually needs. Choosing what to leave unprotected is now your job.
You are told something in confidence that changes every risk assumption you have made. You cannot tell your own team.
Decisions are being attributed to you in meetings you were not invited to. Authority arrives before the mandate does.
The role is handed to you temporarily. Temporary decisions have permanent consequences.
Season finale. Production is encrypted. The recovery plan you approved on Day 15 is about to be tested for real.
Continue Season 1
Episodes 2–8 of Season 1 — Your First 30 Days. Your decisions persist across the season — the budget you defend on Day 15 is the recovery capability you rely on at 02:13 on Day 30.
One payment. Full season access. No subscription.
Before you start
Professional grounding
Episodes are engineered against the spirit of NIST CSF 2.0, NIST SP 800-61r3 and ISC2 cybersecurity leadership research — detection and response, prioritisation and escalation, roles and responsibilities, stakeholder communication, and continuous improvement. Scenarios are fictional composites engineered from recognised practice and recurring real-world patterns.