Train for the CISO seatand the job after it.
You work through 17 years of incidents modelled on breaches that actually happened, then you have to defend your calls to a board and sit a mock interview that grills you on the rules in your own region. It's about as close to the job as you can get before someone hands you the job.
$9 a week, $29 a month, or $99 for the year. Cancel whenever you like.
Which seat are you in?
Same product, three different first moves. Pick the one that sounds like Monday morning.
You want the CISO job — or the interview for it.
Score yourself first, then drill the mock interview until your incident story, budget defense, and regulatory answers are automatic.
Start with the free scorecard →You run security — and the board runs you.
Rehearse the worst day before it happens: live incidents graded against your country's regulators, and a board-report coach for the write-up.
Take a War Room run →You build and review the systems.
Threat-model on an infinite canvas with an AI copilot, blueprint architectures with live control coverage, and scan what you ship.
Open the architect studios →A quick look inside.
Six surfaces, five seconds each. Every scenario is fictional — inspired by real-world incidents.
Isolate the runner and burn the release window — or trust the WAF rule and ship? You have 42 seconds.
Three things you can only get good at by doing them
Reading about incident command is not the same as running one at 2am. So we let you run one.
Three security-architect studios
Infinite-canvas tools with an AI copilot: you draw, it proposes, you dispose — then export. Threat modeling, architecture design and design review, each on its own canvas.
Five security tools, included
Five is the promise — we built them, we use them ourselves, and they come with every subscription. There's more in the box on top of that (AI BOM, a country-aware resume review, and AI SVS as it ships), but the five are what you're paying for.
npm/PyPI trust, typosquat distance, and CVE check.
Static prompt-injection & jailbreak detection.
Static audit of your MCP server config.
Adversarial probes against your model endpoint.
Chrome extension permission + risk scoring.
Turn a manifest into an AI bill of materials.
Country-tailored AI critique of your resume.
AI verification standard — in development.
More ways to practice
Everything on PlayCISO, in one place.
Survive a $4M budget cut, beat your peers on the weekly board.
Face hostile reporters after a breach — live, on the podium.
A 2-minute readiness scorecard that shows where you stand.
Live avatar interviewer, country-aware, 7 roles.
8-dimension reference architectures to study.
Fast security mini-games — breach, patch runner, SOC.
See real board reports and critiques before you pay.
The threat pulse
week 2026-W36What we're watching — the incidents shaping what the War Room throws at you. From the weekly PlayCISO briefing.
China-linked Fire Ant hijacks Cisco routers to steal credentials
Hackers tied to China compromised Cisco IOS XR routers and TACACS authentication servers, siphoning credentials and quietly wiping the logs that would have shown them. The campaign shows how routers themselves have become a favorite hiding spot for long-term espionage.
Source →Aurora ransomware crew uses Cursor AI to breach 10 targets
Operators of the Aurora ransomware were caught using SpaceX's Cursor AI coding assistant to move through victim networks during attacks on at least ten targets. It's a clear sign that even small ransomware teams now lean on generative AI to speed up intrusions.
Source →Berlin refuses to pay hackers who stole state network data
Berlin's government confirmed an extortion attempt after attackers stole data from the city's administrative network in August and walked away with more than initially believed. Officials have publicly ruled out paying the ransom.
Source →Subscribers get this every week — with the AI developments and the one stat worth repeating. Take the free scorecard and it lands in your inbox.
Everything inside
The whole product on one screen. Green means free right now; everything else comes with any plan.
- War Room simulator17 years of incidents, graded by a board
- Board Report coachGenerate, write live, or get critiqued
- Mock interviewAI avatar · 7 roles × 7 countries
- Press conferenceFace the journalists after the breach
- Threat Model StudioDraw or paste a URL → STRIDE map
- Architecture StudioBlueprints with live control coverage
- Design Review WorkbenchRFC in, triaged findings out
- Org DesignerTeam, budget, KPIs, JDs — from scratch
- Attack Path SimulatorWatch a breach move, hop by hop
- Risk RegisterEvery studio's risks, board-ready
- Cyber PMO10 project packs: case → plan → RAID
- 5 security scannersPackages, prompts, MCP, models, extensions
- Resume reviewCountry-tuned, ATS-aware critique
- AI BOMCycloneDX inventory of your AI stack
- 120+ diagrams8-dimension interactive walkthroughs
- CISO-readiness scorecard2 minutes, score + 30-day plan
- Watch a run + make a callGet graded on one live decision
- 25 templatesArtefacts, policies, processes, audit
- Cyber Arcade5 games that teach real security
- Sample outputsSee what you get before paying
- Live statsReal activity, updated live
Every plan is the whole thing
There's no stripped-down tier. Go weekly if an interview is next week, monthly if you're building up over time, yearly if you're in this for the long haul. You get the same product whichever you pick.