Built by a working hospital CISO.
Astraea Cyber exists because most healthcare security training is written by people who've never had to decide, at three in the morning, whether to take the domain down and lose badge access to the medication room.
Shelby Price, founder
Shelby is the Chief Information Security Officer of a multi-site, HIPAA-regulated hospital system, where she leads the incident security response team and runs the security education program. Astraea Cyber is her independent practice.
Crucible started as internal work. Tabletops for hospital leadership, and scored labs for a service desk that needed to get better at caller verification and escalation, not better at passing a quiz. It works because it was built for one specific building with its actual constraints, then tested on people who had to use it the next day.
She's finishing an undergraduate degree in Cyber Leadership and Intelligence at Dakota State, and came to this from an arts and design background, which is why the exercises look like operational tools instead of compliance software.
An exercise everyone passes taught nothing
Scenarios are built so the gaps most hospitals already have surface on their own. A good score isn't the goal. The goal is one finding you can fix before it costs you something.
Fictional hospitals, real procedures
Scenarios run against fictional health systems and fictional people. The procedures, the regulatory clocks and the clinical consequences are all real, because that's where the learning lives.
Evidence beats attendance
A completion percentage proves somebody clicked through. A timestamped decision record shows what your team actually did, and gives you something to hand a surveyor or your carrier.
Where to start.
The free tabletop kit is the fastest way to see how these are built. Run it with your own team and decide from there. If you'd rather talk it through first, early access is open.