Concord Lantern

Cyber Incident Response Tabletop Exercise

The namesake: the engagement at Concord's North Bridge, 19 April 1775 — engraved by Amos Doolittle after Ralph Earl.
Christ Church (Old North), Boston, where the two signal lanterns hung for barely a minute on the night of 18 April 1775.
Concord Lantern — Cyber Incident Response Tabletop Exercise.
The namesake: the engagement at Concord's North Bridge, 19 April 1775 — engraved by Amos Doolittle after Ralph Earl.

Buy Concord Lantern

Call for pricing
Request a quote

Every license is a dedicated hosted instance, deployed and kept up to date for you. Nothing to install on any seat.

Scenarios per Plan
4 Scoring Dimensions
100% Plan-Specific
0 Install Required
Audit-Ready Output

About this product

Concord Lantern is not a tabletop discussion. AI-assisted ingestion reads your cyber crisis response plan and maps every step, owner, and deadline into a scoring framework. From there the platform generates unlimited incidents against your plan's scope — ransomware, data breach, insider threat, supply chain — and runs your team through them under a clock that doesn't stop.

Every expected action is measured on four axes, with the role your plan names acting as a gate: an obligation discharged by the wrong person earns none of the points. What comes out is a timestamped, team-attributed record of readiness — usable for internal improvement and for external audit, compliance, and budget justification.

AI Plan Ingestion

Your plan becomes the game engine's ruleset in a guided, reviewable process. No manual configuration, no custom coding — and when the plan is updated, the scoring updates with it.

Infinite Scenario Generation

Unique, realistic incidents calibrated to your plan's scope. Every exercise is fresh, and every scenario tests a different part of the plan.

Real-World Stress Conditions

A live, timed exercise with genuine operational pressure — incomplete information, competing priorities, and a clock that doesn't stop.

Four-Dimensional Scoring

Every expected action measured on accuracy, completeness, timeliness, and sequence.

  • Accuracy — what the team passed on was right
  • Completeness — and it was all of it
  • Timeliness — within the deadline the plan states
  • Sequence — prerequisite actions happened first

Solo, Team, or Hybrid

Run the same plan with a full room, a single analyst, or any mix. Empty seats are filled by AI-driven NPCs with their own personas and response speeds, so one person can rehearse the whole plan without waiting on a room to assemble.

Readiness Certification

An auditable record of team and organizational preparedness — evidence for internal reporting, external audit, regulatory compliance, and budget justification.

  • Timestamped, team-attributed performance record
  • Step-by-step scoring across all four dimensions
  • Gap analysis showing where the plan broke down
  • Exportable certification documents

Continuous Improvement Loop

Re-run after plan updates or identified gaps and track performance over time — the kind of trend evidence that justifies security investment to leadership and boards.

How it works

  1. Ingest Your Plan

    AI-assisted ingestion maps your crisis response plan into the engine's scoring ruleset.

  2. Generate Scenario

    AI creates a realistic incident tailored to your organization's context — infinitely repeatable.

  3. Run the Simulation

    Players execute the plan under pressure: emails, work products, notifications, decisions.

  4. Score & Certify

    The platform measures every action against the plan and produces the certification record.

Who it's for

Enterprise Security Teams

Quarterly readiness drills against your actual IR plan — not generic scenarios — with improvement tracked across exercises for CISO and board reporting.

  • Quarterly and annual readiness exercises
  • New hire and onboarding certification
  • Post-incident plan validation
  • Multi-team coordination exercises

Government & Critical Infrastructure

Meet CISA, NIST, and sector-specific readiness requirements with documented, tested, and scored exercises.

  • NIST CSF and FISMA compliance exercises
  • CISA preparedness framework documentation
  • Sector-specific IR plan testing
  • Interagency coordination simulation

Training & Certification

Offer credentialed cyber crisis response training backed by scored exercise records and objective performance data.

  • CISO and IR team certification
  • University and professional practicums
  • Corporate cyber resilience programs
  • Consultant-delivered readiness assessments

What a license includes

Delivery
Hosted — a dedicated instance provisioned and deployed for your organization.
Client
Any modern browser. Nothing to install, on any seat.
Custom domain
Served on your own hostname with TLS (e.g. woodhull.your-institution.edu).
AI access
An AI subscription (Anthropic or OpenAI) is required for scenario generation.
Updates
Engine and content updates delivered automatically to your instance.
Support
Onboarding, operator training, and email support included with the license.

The name “Concord Lantern”

On the night of 18 April 1775, two lanterns hung for barely a minute in the steeple of Boston's Old North Church — a signal arranged days in advance. By dawn, militia were assembling at muster points assigned months earlier, and the stores at Concord had already been moved to safety. The Concord alarm was a genuine crisis response plan, and none of it counted until the night it was executed under pressure, in the dark, with incomplete information. A plan proves itself the night it is used, not the day it is written.

Read more →