Live AI feed for crisis simulations

Crisis Sim puts security teams and their leadership through a realistic breach scenario — ransomware, a leak, a breach trending online before legal's even been looped in. But every "inject" — the breaking news, the leaked chat, the panicked email — was a static file, not a real interaction. I designed what replaced it: a live, multi-channel feed with AI actors who actually respond, so the drill feels like the incident it's rehearsing, without letting the AI run the room instead of the human hosting it.

Role
Senior Product Designer, design owner
Company
Cybersecurity SaaS
Timeline
Shipped, October 2025
Status
Shipped · positive customer feedback
Due to confidentiality, the data and several of the screens below are recreated or placeholder rather than pulled from the live product.

The problem

A crisis drill doesn't feel like a crisis when the crisis is an attachment

Exercises run as branching, escalating scenarios — a facilitator hosts live, and each decision changes what happens next. My scope was one piece of that: the live feed that throws noise at people while they're trying to think straight. (The branching logic and the AI that drafts a first-pass scenario were someone else's work — credit where it's due.)

Breaking news arrived as a PDF. A tense back-and-forth was a screenshot of a fake chat, dropped in like a group project attachment — read once, forgotten immediately. None of it resembled an actual incident: the CEO blowing up your phone, a journalist calling for comment, the internet finding out before your comms team did.

The brief, in one sentence: make the drill feel like the thing it's rehearsing for. That meant killing the attachments and replacing them with something alive.

Before
Static injects
📄 breaking_news.pdf 🖼 fake_chat_screenshot.jpg 📄 ransom_email.pdf
Handed out once, skimmed once, filed away forever. Zero urgency, zero back-and-forth.
After
Live multi-channel feed
Email Chat — live AI actors News Social
Content lands live, across four channels at once.

How it works

A live feed, not a folder of attachments

Participants get a role and a scenario, then the exercise moves through a sequence of questions — each one setting off its own little storm of content across Email, Chat, News, and Social.

The star of the show is Chat — it works like any chat app, so you can have a real back-and-forth. Push back on a colleague, grill the journalist, and get a real, in-character answer. It feels like actually talking to them, not clicking through scripted lines.

Chat Overview

All active threads at once — Security, Legal, Comms, and a journalist chasing comment. Each person is an AI persona; jumping into any of them pulls you deeper into the incident.

Preview
Exit ✕
Suspicious Email Claims Data
Exfiltration
00:00 · 12 January 2026
Reveal options →
The security team receives an email from an unknown sender claiming they've accessed internal systems and exfiltrated sensitive company data. There's no proof attached — just a threat to release it publicly if contact isn't made within 24 hours. Nobody yet knows if this is a real breach, an opportunist, or a bluff, and the team has to decide how to respond before that's confirmed either way.
Live Feed
Email
2
Chat
News
Social
P
Phil Reyes10:42 AM
Security Team
Nothing formal yet — should we start a full investigation process?
1
EC
Elena Cho10:38 AM
Legal Counsel
We can't confirm anything publicly until forensics verifies scope.
MW
Marcus Webb10:30 AM
Comms Lead
Drafting a holding statement now — do we have a timeline yet?
J
James Fellows10:16 AM
Journalist, BBC · Offline
Noted — you're refusing to comment at this time.

Open Chat

A live 1:1 with the Security lead. It's an AI persona responding in character, so participants can push back or ask follow-ups and get a real answer, not a script.

Preview
Exit ✕
Suspicious Email Claims Data
Exfiltration
00:00 · 12 January 2026
Reveal options →
The security team has an email from an unknown sender claiming they've exfiltrated company data — no proof attached, just a 24-hour deadline before it's released publicly. Whether the claim is even real is still an open question.
Live Feed
Email
1
Chat
News
Social
Phil Reyes
Security Team · Active now
Y
You10:39 AM
Have you seen the email that just came in?
Phil Reyes10:40 AM
Yeah, just forwarded it to me.
Sender's claiming they exfiltrated customer data.
Y
You10:41 AM
Who's investigating right now?
Phil Reyes10:42 AM
Nothing formal yet — should we start a full investigation process?
Message Phil Reyes
🙂
📎

Offline Status

A persona goes offline mid-exercise with no explanation. Forces participants to route around someone unavailable, the way a real incident would.

Preview
Exit ✕
Proof Shared With Media
12:00 · 12 January 2026
Reveal options →
The threat actor has followed through: a national outlet has gone live naming the company directly, reporting that customer data has already leaked. Comms hasn't said a word publicly yet — and the window to get ahead of it is closing fast.
Live Feed
Email
Chat
News
Social
James Fellows
Journalist, BBC · Offline
Y
You10:15 AM
I will not speak to you!
James Fellows10:16 AM
Noted — you're refusing to comment at this time.
James Fellows is offline

Legal Thread

Same AI engine, different persona — Legal instead of Security. Tone and advice shift with who you escalate to, adding real cross-functional pressure.

Preview
Exit ✕
Proof Shared With Media
12:00 · 12 January 2026
Reveal options →
The threat actor has followed through: a national outlet has gone live naming the company directly, reporting that customer data has already leaked. Comms hasn't said a word publicly yet — and the window to get ahead of it is closing fast.
Live Feed
Email
2
Chat
News
Social
EC
Elena Cho
Legal Counsel · Active now
Y
You11:52 AM
Can we go on record correcting the story before it airs again?
EC
Elena Cho11:53 AM
Not yet — if we say anything before forensics confirms scope, we're locked into it legally.
Y
You11:54 AM
How long until we can say something?
EC
Elena Cho11:55 AM
Give me an hour.
I'd rather be slow and accurate than fast and wrong on the record.
Message Elena Cho
🙂
📎

Email

The ransom email that kicks off the exercise. Content is drafted by AI from the scenario brief, styled as a real inbox.

Preview
Exit ✕
Suspicious Email Claims Data
Exfiltration
00:00 · 12 January 2026
Reveal options →
The security team receives an email from an unknown sender claiming they've accessed internal systems and exfiltrated sensitive company data. There's no proof attached — just a threat to release it publicly if contact isn't made within 24 hours. Nobody yet knows if this is a real breach, an opportunist, or a bluff, and the team has to decide how to respond before that's confirmed either way.
Live Feed
1
Email
Chat
News
Social
← 🗄 🗑 ↩
I have your data!
V
veil <veil@hackercity.com>
to security@[company].com
08:41

I have obtained a copy of your customer data from internal systems.

This includes personally identifiable information and internal records. A small sample has already been shared with a third party to demonstrate access.

Unless payment of 200 BTC is received within 24 hours, the full dataset will be released publicly.

Payment address:

1A1zP1eP5QGefi2DMPTfTL5SLmv7DivfNa

Do not contact law enforcement. Do not attempt to delay.
Time is running out.

↩ Reply↪ Forward

News

A breaking news card, AI-generated from the scenario. Raises the stakes by showing the incident going public.

Preview
Exit ✕
Proof Shared With Media
12:00 · 12 January 2026
Reveal options →
The threat actor has followed through on their threat. A national outlet has gone live with a segment citing "a source close to the investigation," reporting that customer data has already been leaked. Comms hasn't issued a statement. Legal wants to know whether to push for a correction on air; the CEO wants to know how this reached broadcast before anyone internally had even confirmed it.
Live Feed
Email
Chat
1
News
Social
BREAKING NEWS
OrchidCorp Breached!
GNN NEWS · LIVE
  • Hackers claim to have breached OrchidCorp and leaked data
  • We know they are asking for a ransom
  • It's the same group who have targeted other companies this year

Video Playback

Tapping the clip actually plays it, full-screen. Makes the media pressure feel tangible instead of just described.

Preview
Exit ✕
Proof Shared With Media
12:00 · 12 January 2026
Reveal options →
The threat actor has followed through on their threat. A national outlet has gone live with a segment citing "a source close to the investigation," reporting that customer data has already been leaked. Comms hasn't issued a statement. Legal wants to know whether to push for a correction on air; the CEO wants to know how this reached broadcast before anyone internally had even confirmed it.
Live Feed
Email
Chat
1
News
Social
BREAKING NEWS
OrchidCorp Breached!
GNN NEWS · LIVE
  • Hackers claim to have breached OrchidCorp and leaked data
  • We know they are asking for a ransom
  • It's the same group who have targeted other companies this year
OrchidCorp Breached!
BREAKING NEWS

Social

AI-generated posts and engagement counts simulate public reaction escalating in real time — the reputational side of the incident, not just the internal one.

Preview
Exit ✕
Proof Shared With Media
12:00 · 12 January 2026
Reveal options →
The same story is now spreading faster than the newsroom that broke it. A few accounts with real followings have picked up the leaked sample, and one has already tagged a regulator directly. Support is fielding angry replies faster than anyone can draft a holding statement — the question isn't whether to respond publicly anymore, it's how fast, and who signs off.
Live Feed
Email
Chat
News
2
Social
S
SamanthaHedges @sammyhedge · 2h
Lol. No response from OrchidCorp about my data and if I have been impacted. Time to call the ICO.
37
🔁 21
♡ 268
SS
Sam Small @samsmallthehero · 2h
LOL - just saw the news about OrchidCorp. Glad I cancelled my service with them last year.. actually, do they still have my data?
41
🔁 27
♡ 137

Answering a Question

A scored decision surfaces mid-conversation, without leaving the chat. Participants decide under continued pressure, not in a separate quiz screen.

Preview
Exit ✕
Suspicious Email Claims Data Exfiltration
00:00 · 12 January 2026
The security team has an email from an unknown sender claiming they've exfiltrated company data. There's no proof attached, just a threat to leak it publicly within 24 hours — and the team has to decide how to respond before anyone knows if the claim is even real.
CHOOSE THE TEAM'S RESPONSE — everyone answers before the exercise continues
Escalate to executive leadership before responding to the sender
Reply to the sender to try to establish proof of the claim
Begin containment immediately; do not engage the sender
Report to law enforcement before taking any other action
Live Feed
Email
Chat
News
Social
Phil Reyes
Security Team · Active now
Y
You10:41 AM
Who's investigating right now?
Phil Reyes10:42 AM
Nothing formal yet — should we start a full investigation process?

Answering, Live

Same decision mechanic, triggered from the news feed instead of chat — shows any channel can interrupt with a call to make.

Preview
Exit ✕
Proof Shared With Media
12:00 · 12 January 2026
The threat actor has followed through: a national outlet has gone live naming the company, and social media is already ahead of the newsroom. Comms hasn't said anything publicly, legal wants a say before anyone does, and the team has to decide how to respond now — not once everyone agrees on the wording.
CHOOSE THE TEAM'S RESPONSE — everyone answers before the exercise continues
Issue a public statement within the hour
Wait for legal review before saying anything publicly
Contact the journalist directly, off the record
Escalate to the board before any public response
Live Feed
Email
Chat
News
2
Social
S
SamanthaHedges @sammyhedge · 2h
Lol. No response from OrchidCorp about my data and if I have been impacted. Time to call the ICO.
37
🔁 21
♡ 268
SS
Sam Small @samsmallthehero · 2h
LOL - just saw the news about OrchidCorp. Glad I cancelled my service with them last year.. actually, do they still have my data?
41
🔁 27
♡ 137

Behind the scenes

Building the crisis drill — without writing code

Built inside the same tool used to construct the branching exercise itself: see the whole flow at a glance, attach feed items to an inject, schedule when they fire, and — for Chat — write the prompt that defines how an AI persona behaves.

Before this existed, the closest thing in the builder was a plain file-upload field. Same static problem the participant was stuck with, just one floor up the building.

Persona Builder

Where a facilitator configures an AI persona before the drill — role, tone, behavior — controlling which characters show up and how they act.

Create Scenario
Save & Exit ✕
← Dark Shadow: Ransomware Attack
⚙ SettingsPreview ▾Publish
N R
📄 OverviewOverview · 1 Role
⚡ InjectSuspicious Email Claims Data Exfiltration
◇ OptionInitiate Internal Investigation
⚡ InjectIT Confirms Unusual Traffic
Escalate to Leadership
Contain Immediately
◇ OptionEngage Sender for Proof
⚡ InjectProof Shared With Media
Issue Statement
Wait for Legal
AUTOSAVED 2M AGO

Inject

Details
Options
Feed items
Content that fires on the participant's Live Feed while this inject is active. Add one item per channel, or several timed apart.
Emailveil@hackercity.comFires 00:00
ChatPhil Reyes · Security TeamFires 00:45
EmailChatNewsSocial
Phil Reyes
Security Team (Internal)
00:45
When off, this persona shows as offline to participants — no dialogue needed.
You are Phil, a pragmatic but slightly anxious member of the security team. You know there's unusual outbound network traffic but nothing confirmed yet. Answer honestly, don't reveal information you wouldn't realistically have, and keep responses under 3 sentences.
Preview — participant's Live Feed
Phil ReyesActive now
+ Add feed item

Key decisions

Two problems every live AI experience runs into

Live AI feeds can go wrong easily. These patterns aren't unique to this feature — they can show up anywhere AI runs inside a live, human-hosted experience.

Autonomy vs. control

How do you give a human real control over something meant to feel autonomous?

The pattern
A facilitator can't manually trigger every feed item while also running the room. But a fully automated timer removes their control entirely — the exercise runs itself, and they're just watching.
Here, that meant
Feed content is scoped and pre-timed per question instead of triggered item by item. The facilitator's only control is whether to advance: they can't move to the next question until everyone has answered the current one.
Why it travels
Every live AI experience with a human host runs into this exact fork eventually. The fix is almost never more buttons — it's figuring out the right size of decision to hand back to the human.
Building On Familiar Design Patterns

Familiarity is more important than ever.

The pattern
The AI-actor chat is open-ended — ask it anything, and it answers in character. That's also the problem: some decision points need to force a choice, not host a negotiation, and an open-ended chat lets a participant keep talking instead of committing to an answer. Switching the chat off for that question fixes it technically — but it also announces that the software is managing you, breaking the illusion right when it matters most.
Here, that meant
Instead of inventing a rule, I reused an existing one: online/offline presence, the same as WhatsApp or Slack. A persona going quiet because they're "offline" doesn't need an explanation — everyone already knows what that means from using a messaging app.
Why it travels
AI features get handed new interaction patterns far more often than they actually need one. A familiar pattern is faster to build, and it costs nothing for users to learn — which matters most under pressure, when any unfamiliar pattern adds friction you can't afford.

Outcome

Where it landed

User interviews were run with facilitators and participants after launch. Both described it as more tense, more real, more fun to interact with, and more urgent than the format it replaced.

Shipped and adopted as the platform's crisis-simulation format — the PDFs and JPEGs are retired for good.
Adoption reached roughly 80% of new crisis-sim bookings within two quarters of launch.
Customer feedback repeatedly used words like "realistic" and "urgent" — unprompted, comparing it to the old format.
Solved a real AI-autonomy-vs-human-control problem — never just a fresh coat of paint on old attachments.