Live AI feed for crisis simulations
Crisis Sim puts security teams and their leadership through a realistic breach scenario — ransomware, a leak, a breach trending online before legal's even been looped in. But every "inject" — the breaking news, the leaked chat, the panicked email — was a static file, not a real interaction. I designed what replaced it: a live, multi-channel feed with AI actors who actually respond, so the drill feels like the incident it's rehearsing, without letting the AI run the room instead of the human hosting it.
The problem
A crisis drill doesn't feel like a crisis when the crisis is an attachment
Exercises run as branching, escalating scenarios — a facilitator hosts live, and each decision changes what happens next. My scope was one piece of that: the live feed that throws noise at people while they're trying to think straight. (The branching logic and the AI that drafts a first-pass scenario were someone else's work — credit where it's due.)
Breaking news arrived as a PDF. A tense back-and-forth was a screenshot of a fake chat, dropped in like a group project attachment — read once, forgotten immediately. None of it resembled an actual incident: the CEO blowing up your phone, a journalist calling for comment, the internet finding out before your comms team did.
The brief, in one sentence: make the drill feel like the thing it's rehearsing for. That meant killing the attachments and replacing them with something alive.
How it works
A live feed, not a folder of attachments
Participants get a role and a scenario, then the exercise moves through a sequence of questions — each one setting off its own little storm of content across Email, Chat, News, and Social.
The star of the show is Chat — it works like any chat app, so you can have a real back-and-forth. Push back on a colleague, grill the journalist, and get a real, in-character answer. It feels like actually talking to them, not clicking through scripted lines.
Chat Overview
All active threads at once — Security, Legal, Comms, and a journalist chasing comment. Each person is an AI persona; jumping into any of them pulls you deeper into the incident.
Exfiltration
Open Chat
A live 1:1 with the Security lead. It's an AI persona responding in character, so participants can push back or ask follow-ups and get a real answer, not a script.
Exfiltration
Offline Status
A persona goes offline mid-exercise with no explanation. Forces participants to route around someone unavailable, the way a real incident would.
Legal Thread
Same AI engine, different persona — Legal instead of Security. Tone and advice shift with who you escalate to, adding real cross-functional pressure.
The ransom email that kicks off the exercise. Content is drafted by AI from the scenario brief, styled as a real inbox.
Exfiltration
I have obtained a copy of your customer data from internal systems.
This includes personally identifiable information and internal records. A small sample has already been shared with a third party to demonstrate access.
Unless payment of 200 BTC is received within 24 hours, the full dataset will be released publicly.
Payment address:
Do not contact law enforcement. Do not attempt to delay.
Time is running out.
News
A breaking news card, AI-generated from the scenario. Raises the stakes by showing the incident going public.
- Hackers claim to have breached OrchidCorp and leaked data
- We know they are asking for a ransom
- It's the same group who have targeted other companies this year
Video Playback
Tapping the clip actually plays it, full-screen. Makes the media pressure feel tangible instead of just described.
- Hackers claim to have breached OrchidCorp and leaked data
- We know they are asking for a ransom
- It's the same group who have targeted other companies this year
Social
AI-generated posts and engagement counts simulate public reaction escalating in real time — the reputational side of the incident, not just the internal one.
Answering a Question
A scored decision surfaces mid-conversation, without leaving the chat. Participants decide under continued pressure, not in a separate quiz screen.
Answering, Live
Same decision mechanic, triggered from the news feed instead of chat — shows any channel can interrupt with a call to make.
Behind the scenes
Building the crisis drill — without writing code
Built inside the same tool used to construct the branching exercise itself: see the whole flow at a glance, attach feed items to an inject, schedule when they fire, and — for Chat — write the prompt that defines how an AI persona behaves.
Before this existed, the closest thing in the builder was a plain file-upload field. Same static problem the participant was stuck with, just one floor up the building.
Persona Builder
Where a facilitator configures an AI persona before the drill — role, tone, behavior — controlling which characters show up and how they act.
Inject
✕Key decisions
Two problems every live AI experience runs into
Live AI feeds can go wrong easily. These patterns aren't unique to this feature — they can show up anywhere AI runs inside a live, human-hosted experience.
How do you give a human real control over something meant to feel autonomous?
Familiarity is more important than ever.
Outcome
Where it landed
User interviews were run with facilitators and participants after launch. Both described it as more tense, more real, more fun to interact with, and more urgent than the format it replaced.