It designs incident-response tabletop exercises and prints the paper that runs them — facilitator guides, inject cards, participant briefs and capture sheets. A discussion-based exercise is paper-first once it starts; this makes the paper. No server, no account, no telemetry.
Eight handouts, print-ready — including one inject per page and a bound facilitator pack, with every read-aloud wrapped in EXERCISE labels so a simulated message cannot be mistaken for a real one
Write the scenario once, run it anywhere — define [COMPANY], [ERP SYSTEM] and the rest as variables; every read-aloud and handout fills them in, and unresolved tokens are flagged before you print
Sixteen ready-to-run scenarios — ten at SMB scale (account takeover, wire fraud, ransomware, lost laptop, vendor breach, website outage, insider data theft, help-desk social engineering, a misdirected email, exposed cloud storage) and six Advanced/Enterprise (domain-wide ransomware with double extortion, long-dwell targeted intrusion, software supply-chain compromise, identity-provider takeover, privileged-admin sabotage, man-in-the-middle token theft)
Three stages, one exercise — Plan (objectives, scenario, injects, participants), Run (checklist, run-of-show clock, print centre) and Learn (hotwash, findings, improvement actions)
Findings become someone else's work — improvement actions link to the finding they answer and export to PumaRisk as that risk's treatment plan, instead of dying in a document
Exports for the room and the record — a PowerPoint deck from the live presentation view, an Excel workbook of the exercise, and a blank build-your-own template
Programs hold the reusable parts — an org profile and stakeholder roster shared across every exercise in the program, plus metrics across them
New here, read Method — it condenses the facilitator's craft.
Running one
A tabletop is a facilitated, discussion-based walkthrough of a hypothetical incident. Nobody touches a keyboard. It tests whether your people, plans and decisions hold up — not whether your technology works — and confusion in the room is the exercise working.
1 · Plan: write objectives you could fail — "confirm who can authorise a ransom decision out of hours" is testable; "improve readiness" is not. Everything downstream is judged against these in the Learn stage.
2 · Plan: start from a scenario, then make it yours — pick from the library and replace the variables with your systems and your vendors. A scenario about somebody else's business gets discussed politely and teaches nothing.
3 · Plan: pitch injects at decisions, not at packets — a cross-functional room includes Legal, Comms and Finance. The most common way a tabletop fails is being too technical for the people whose decisions actually matter.
4 · Run: set the no-fault rule out loud, first — this is an exercise, not a test. Say it, then protect it every time someone starts defending themselves instead of thinking.
5 · Run: work the loop — present an inject, ask an opening question, let discussion run, probe the gap, capture it, release the next inject. "Walk me through what happens next." "Legal, what obligations have we triggered?" "Who authorises that, and what does it break downstream?" "You said restore from backup — when was that last tested?"
6 · Run: hold your expertise back — the trap for technical facilitators is answering their own questions. The moment you do, the room stops thinking and waits for you. Let silence do the work, and use "let's capture that and move on" to protect time.
7 · Learn: guard 20–30 minutes for the hotwash — reactions, what worked, what was hard, results against each objective, top three fixes. Never let the scenario eat the debrief; this is where the lessons are actually locked in.
8 · Learn: give every finding an owner — link improvement actions to findings and hand them to PumaRisk. An exercise with no follow-through is theatre with a scribe.
Going deeper
For the formal evaluation framework behind the after-action report, see FEMA's HSEEP Exercise Evaluation Guides. For ready-made scenario packages to adapt, see CISA's Tabletop Exercise Packages (CTEPs). Links in the README.
PumaTTX's data model is the eight reusable templates, mapped onto the lifecycle:
A · Planning Checklist → Run stage (phased, checkable).
B · Invitation & Pre-Read → Plan brief + the Participant Brief handout.
C · Scenario Builder → Plan → Scenario.
D · Inject Card → Plan → Injects, and the Inject Card handouts.
E · Run-of-Show → Run → Run-of-Show, and its handout.
F · Hotwash Capture → Learn → Hotwash, and the blank capture sheet.
G · After-Action Report → Learn → Findings + Improvement plan + summary; exports to Markdown/RTF/PDF.
H · Improvement Actions & Program Metrics → Learn → Improvement actions + the Program metrics view.
Framework vocabulary (HSEEP; NIST SP 800-61 / CSF 2.0) is noted on the AAR for auditors — the quality of the conversation matters more than the diagram you cite.
Where your exercises live
Every program is stored in your browser's sessionStorage, on this device and this browser only. Nothing is uploaded anywhere.
This is the whole database. If you clear site data, use a private window, switch browsers, or lose the device, your exercises are gone. Back up regularly with Export (or ⌘/Ctrl+S).
Clear all local data
Danger zone. This erases every PumaTTX program in this browser. Export a backup first.
PumaTTX is a lightweight, portable, offline Tabletop Exercise (TTX) generator that runs entirely in your local browser. Build your scenarios in the app and it will generate a paper-based run packet, complete with facilitator guides and handouts.
This tool is provided as-is, with no warranties or guarantees. It is not professional advice. By using it you accept full responsibility for any outcomes that result from your use.
About PumaWorx
PumaWorx is a suite of offline, single-HTML productivity apps that run entirely in your local browser. The entire suite is a personal, open source vibecoding project.
This is an offline single-HTML app. No data goes to or from the internet — there is no server, no account, no sync, and no telemetry. Your exercises live in your web browser's sessionStorage — on this device, in this browser, and nowhere else.
Your data is YOUR responsibility.
If you clear site data, use a private/incognito window, switch browsers, or lose this device, your exercises are gone. Back up regularly with Export in the topbar — it produces a single .pumapack file with every program and exercise.
Press ? any time for help and the facilitator's method.