Astraea Cyber
Cyber resilience for healthcare operations

Practice the incident before you have it.

Astraea Cyber builds scored tabletop exercises and hands-on labs for hospital command staff and IT teams. Your people take a position, decide on a clock as the incident develops, and walk out with a timestamped record of what they actually did.

Built by a working hospital CISO, around HICS, downtime procedures, diversion, and the regulatory clocks that start whether anyone's watching them.

The Crucible exercise board mid-scenario: the Incident Commander's narration for the ransom note inject, the questions to put to the room, and the position board showing which HICS roles have logged a decision. Crucible · Code Dark · inject 03 of 12
12
Injects per exercise
9
HICS command positions
4
Modules, detection to recovery
2h 50m
Simulated incident time
01

Where awareness training stops

Annual training teaches staff to spot a suspicious email. It's silent on how a section chief sequences a decision at 03:00 with half the building running on paper.

02

Healthcare, specifically

HICS command structure. Downtime packets. EMS diversion. Wet-signature policy that quietly stops working at volume. You won't find any of that in generic security content.

03

What you're left holding

Every decision gets timestamped against the inject that prompted it, so what comes out is an after action record you can hand to a surveyor, your carrier, or the board.

What we do

What we build

Most security training produces a completion percentage. This produces a finding you can do something about on Monday.

Early access

Crucible

An interactive tabletop platform for hospital command staff. Everyone joins on their own device, takes a HICS position, and decides in role as the incident develops.

  • Facilitator narration and real artifacts per inject
  • Decisions timestamped and scored against a rubric
  • Hotwash and after action record generated from the session
Available

Hands-on labs

Scored simulators for IT, service desk and SOC teams. The technician does the task instead of answering questions about it, and a control breach scores zero.

  • Caller verification, escalation, ticket intake and triage
  • Built from your own runbooks and verification scripts
  • Per-scenario scoring, with must-do and coaching separated
Available

vCISO and program work

Program build and advisory for organizations that need the function without the headcount. Run by someone who does the job day to day, so the advice comes out of current practice.

  • Security education and awareness program design
  • Incident response program and playbook development
  • Risk assessment and gap analysis support
Crucible · scenario library

Code Dark runs three hours and gets worse.

Twelve injects across four modules at a fictional two-site health system. Command staff hold HICS positions, and every position has decisions of its own to make.

T+0:00Degraded Access31 service desk calls, nobody has said ransomware yetM1
T+0:22Ransom NoteThree failed backup jobs and a fifty-hour-old restore pointM1
T+0:50The Shutdown DecisionContainment costs you badge access and nurse call escalationM2
T+1:05Downtime RealityForty printed packets for a hospital running 148 patientsM2
T+1:18Shift ChangeDay shift arrives untrained into a building that does not workM2
T+1:45The ReporterThe press has it before your own staff doM3
T+2:00Diversion and EMSStaying open harms someone, diverting harms someone elseM3
T+2:15ExposurePatient names on a leak site and a clock nobody was trackingM3
T+2:35The Ransom QuestionThe board is on the phone and asking what you recommendM4
T+2:50Recovery SequencingEvery department wants to be first and root cause is unknownM4
The downtime packet inventory did not match the continuity plan. Authority to grant a clinical policy variance mid-incident was not clearly held by anyone in the room. The sixty-day notification clock started before Command knew the data was exposed. Findings from the Code Dark hotwash. Planted on purpose.

A tabletop everyone passes taught you nothing. These are built so the gaps most hospitals already have surface on their own, which is what turns them into findings instead of somebody's opinion.

Crucible role selection: HICS command positions laid out as cards, color-coded to the standard ICS vest scheme, with taken positions showing who holds them.
Participants claim a command position on join. Colors follow the standard ICS vest scheme, so anyone who's stood up a command center recognizes the board on sight.
October · Cybersecurity Awareness Month

A free healthcare tabletop kit, yours to run.

Everybody gives away phishing tip sheets in October. Astraea is giving away a complete facilitator-ready tabletop built for a hospital, with the scenario, the injects, HICS role cards, narration to read aloud and a hotwash guide. Run it with your own people and keep whatever you find.

See what's in it
Crucible early access

Early access is opening to a few health systems first.

Crucible is still in development. Early access organizations help shape the scenario library and get their first exercise facilitated at no cost. Send a few details about your organization and you'll hear back within a couple of business days.

This is only used to get in touch about Astraea Cyber. No list sales, no newsletter. You can also just write to sprice@astraeacyber.com.