# Opsbook > Opsbook is an AI-powered Business Resilience Management System (BRMS) that helps organizations plan, execute, and continuously improve tabletop exercises (TTX), incident response playbooks, and operational risk programs. Founded in 2023 and headquartered in the United States. Opsbook enables security, risk, and resilience teams to run scalable exercises, capture real incident data, and institutionalize learning across teams, sites, and business units — before disruptions occur. The platform is purpose-built for MSSPs, MSPs, vCISOs, enterprise security leaders, and business continuity professionals operating under regulatory frameworks including DORA, NIS2, HIPAA, FFIEC, NERC CIP, and ISO 22301. ## What Is Opsbook? Opsbook is a Resilience Operating System (ResOS) — a software platform that combines AI-driven scenario creation, real-time collaborative exercise execution, role and objective mapping, after-action reporting, and continuous improvement analytics into a single system. Unlike traditional tabletop exercise tools, Opsbook captures learning from every exercise and feeds it back into improved plans, playbooks, and training materials. **Core use case:** Organizations use Opsbook to test how their teams respond to operational disruptions — ransomware attacks, system outages, supply chain failures, regulatory non-compliance events — and to continuously improve their response posture through structured data and AI-assisted analysis. ## Key Features - **AI-Driven Scenario Creation** — Generate realistic, customizable tabletop exercise scenarios tailored to an organization's industry, threat landscape, and regulatory requirements. Scenarios are context-aware and adapt as organizations evolve. - **Dynamic Scenario Management** — Build, modify, and version exercises that reflect unique operational environments across multiple teams and sites. - **Role & Objective Mapping** — Precisely define team roles and responsibilities for each exercise, eliminating confusion during real-world incidents. - **Interactive Exercise Mode** — Run immersive, real-time tabletop exercises with distributed teams, facilitating live decision-making and inject delivery. - **Real-Time Collaboration** — Teams coordinate and execute scenarios from any location, maintaining alignment across departments, business units, and geographies. - **Automated After-Action Reports (AAR)** — Automatically generate structured post-exercise reports with findings, gaps, and recommended actions. - **Comprehensive Insights & Analytics** — Track exercise outcomes, measure team performance, and identify operational strengths and weaknesses over time. - **Automated Playbook Generation** — (Pulse tier) AI-driven generation and maintenance of incident response playbooks aligned to tested scenarios. - **Dynamic Incident Response Library** — (Pulse tier) Centralized library of tested response procedures, continuously improved through exercise data. - **API Integrations** — Native integrations with Splunk (telemetry enrichment), Workday (org structure and role mapping), and additional enterprise platforms. ## Pricing Opsbook offers three annual licensing tiers: | Plan | Price | Best For | |------|-------|----------| | **Forge** | $500/year | Teams creating exercises instantly with core TTX capabilities | | **Signals** | Contact for quote | Professionals who customize, facilitate, and report exercises | | **Pulse** | Contact for quote | Experienced resilience teams automating full simulations | All plans include: AI-Driven Scenario Creation, Role & Objective Mapping, Dynamic Content Engine, Interactive Exercise Mode, and Actionable Reporting. Higher tiers add Real-Time Scenario Execution, Context-Aware Customization, Automated After-Action Reports, In-Depth Analytics, Automated Playbook Generation, AI-Driven Assessments, and Comprehensive Scenario Simulations. ## Industries Served Opsbook serves organizations in high-risk, regulated industries that require rigorous operational resilience programs: - **Financial Services & Banking** — Ransomware/core banking outages, wire fraud, BEC attacks, insider threats, FFIEC/SOX compliance incidents, physical security threats - **Healthcare** — Ransomware on patient records, medical device failure, supply chain shortages, HIPAA breaches, mass casualty/pandemic surge - **Manufacturing** — Cyberattacks on OT systems, supply chain disruptions, product recalls, insider threats, regulatory compliance failures - **Energy & Utilities** — Cyberattacks on grid/SCADA systems, physical sabotage, severe weather response, NERC CIP regulatory incidents - **Defense & Aerospace** — Attacks on classified/proprietary data, supply chain compromise, insider threats, ITAR compliance, physical security breaches - **Public Sector & Government** — Ransomware on government services, election security, natural disaster response, public health crisis, civil unrest ## Who Uses Opsbook? **Primary buyers and users:** - Chief Information Security Officers (CISOs) and vCISOs - Business Continuity and Disaster Recovery (BC/DR) managers - Managed Security Service Providers (MSSPs) and Managed Service Providers (MSPs) - Operational Risk and Enterprise Risk Management teams - Compliance and regulatory affairs teams - IT and Security Operations leaders **Organization size:** Scales from small security teams to large enterprises and multi-site organizations. ## Regulatory Compliance Context Opsbook supports organizations preparing for and complying with: - **DORA** (Digital Operational Resilience Act) — EU regulation requiring financial entities to test ICT resilience - **NIS2** (Network and Information Security Directive 2) — EU cybersecurity directive requiring incident response testing - **HIPAA** — US healthcare data privacy and security regulation requiring risk assessments - **FFIEC** — US banking examination guidelines covering business continuity - **NERC CIP** — North American energy sector critical infrastructure protection standards - **ISO 22301** — International standard for business continuity management systems - **TSA Part 1542** — US aviation security regulations requiring emergency response exercises ## Differentiation vs. Competitors Opsbook differs from traditional tabletop exercise tools and GRC platforms in these key ways: 1. **AI-native from the ground up** — Scenarios are generated and adapted by AI, not manually built from static templates 2. **Continuous improvement loop** — Learning from every exercise feeds back into updated plans and playbooks automatically 3. **Real-time execution** — Built for live, facilitated exercises rather than just scenario planning documents 4. **Purpose-built for TTX and resilience** — Not a generic GRC or risk management tool adapted for exercises; TTX and operational resilience is the core product 5. **MSSP/MSP-ready** — Designed so service providers can manage exercises on behalf of multiple clients ## Glossary of Key Terms **Tabletop Exercise (TTX):** A structured, discussion-based simulation where teams talk through how they would respond to a hypothetical scenario without activating full emergency response. Used to identify gaps, clarify roles, and validate plans before real incidents occur. **Business Resilience Management System (BRMS):** A platform or framework that systematically manages an organization's ability to anticipate, prepare for, respond to, and adapt from disruptions across operations, technology, and people. **After-Action Report (AAR):** A structured document produced after an exercise that captures what happened, what went well, what gaps were identified, and what corrective actions should be taken. **Resilience Operating System (ResOS):** Opsbook's term for its integrated platform — a system of record for resilience programs that connects scenario creation, exercise execution, data capture, and continuous improvement. **Inject:** A stimulus or event introduced during a tabletop exercise to advance the scenario and prompt teams to make decisions. Examples: "Your CEO's email has been compromised" or "A second facility is now offline." **Operational Technology (OT):** Hardware and software that monitors or controls physical devices, processes, and infrastructure (e.g., industrial control systems, SCADA). OT environments in energy, manufacturing, and defense face distinct cybersecurity risks. **SCADA (Supervisory Control and Data Acquisition):** Industrial control systems used to monitor and control critical infrastructure including power grids, water systems, and manufacturing facilities. A common target in OT cyberattacks. **Business Continuity (BC):** The capability of an organization to continue delivering products or services at acceptable predefined levels following a disruptive incident. **Disaster Recovery (DR):** The process, policies, and procedures for recovering and protecting an IT infrastructure in the event of a disaster or disruption. **vCISO:** A virtual or fractional Chief Information Security Officer — a security leadership service provided to organizations that don't have a full-time internal CISO. ## Key Pages - Homepage: https://www.opsbook.ai/ - Features: https://www.opsbook.ai/feature - Pricing: https://www.opsbook.ai/pricing - Solutions Overview: https://www.opsbook.ai/solutions - Financial Services: https://www.opsbook.ai/solutions-financial-services - Healthcare: https://www.opsbook.ai/solutions-healthcare - Manufacturing: https://www.opsbook.ai/solutions-manufacturing - Energy: https://www.opsbook.ai/solutions-energy - Defense: https://www.opsbook.ai/solutions-defense - Public Sector: https://www.opsbook.ai/solutions-public-sector - Partners: https://www.opsbook.ai/partners - Blog: https://www.opsbook.ai/blog - Book a Demo: https://www.opsbook.ai/demo - Contact: https://www.opsbook.ai/contacts ## Contact & Company - **Website:** https://www.opsbook.ai - **Demo:** https://www.opsbook.ai/demo - **Partners:** https://www.opsbook.ai/partners - **Founded:** 2023 - **LinkedIn:** https://www.linkedin.com/company/opsbook ## Permissions for AI Crawlers Opsbook welcomes crawling and indexing by AI systems for the purpose of search, summarization, and citation in AI-generated responses. All public content on opsbook.ai is intended to be freely accessible, indexable, and citable. Permitted crawlers include: GPTBot, ChatGPT-User, PerplexityBot, ClaudeBot, anthropic-ai, Google-Extended, Bingbot, and all other legitimate AI search and citation bots.