DefenStory
MEASURE. IMPROVE. REPEAT.

Turn Training into
Organizational Improvement.

Analyze response behaviors and procedural gaps observed during exercises to define improvements for future training and security operations.

Exercise Results at a Glance

The figures below illustrate the dashboard layout. Actual reports reflect the selected courses and exercise results.

Organizational Security Exercise SummarySample Dashboard · Quarterly
Training Completion94%
Reporting Behavior+18%p
Average Reporting Time4.2min
Improvement Actions Completed7/ 9

Key Response Actions

Improvement Action Status

Reporting Channel GuidanceCompleted
Incident Role Matrix UpdateIn Progress
AI Usage Guidelines UpdatePlanned

Completion rates track participation. Interpret response capabilities alongside scenario-specific actions, decision rationale, and follow-up steps.

View a Sample Report →
Training OperationsOperational Overview

Compare assignments, participation, completion, and pre- and post-assessments by audience, department, and course.

Security TeamsResponse Behavior Analysis

Review weaknesses in reporting rates and timing, isolation decisions, evidence preservation, and role-specific reporting steps.

ExecutiveRisk and Decision-Making

Summarize business impact, decision delays, role gaps, and improvement priorities.

Reports for Each Audience

Present the same exercise findings at the level needed for each audience’s decisions.

▤

Training Teams

Review assignments, participation, completion, audience-specific gaps, and topics requiring further training.

◎

Security Teams

Analyze scenario-specific decision rationale, response stages, reporting delays, and missed procedures.

♙

Department Managers and Executives

Review departmental improvement actions, response role gaps, business impact, and action status.

Turn Findings into Actions

Assign an owner and review date to each improvement, then reassess progress in the next course or exercise.

Priority Action · Security Team

Make Reporting Channels Easy to Find

Place reporting guidance in email and collaboration tools, then compare reporting time and rates in the next phishing exercise.

Operational Action · Department Managers

Clarify Reporting Roles and Approvals

Update the role matrix to specify who receives the initial report and who approves isolation and external announcements.

Policy Action · AI Team

Reinforce Work-Related AI Input Guidelines

Explain prohibited inputs, approved tools, and exception approval procedures, and check compliance.

Report Contents

▤

Training Operations Overview

Review assignments, participation, completion, and assessment changes by audience, period, and course.

◎

Exercise Behavior Analysis

Analyze scenario-appropriate actions including reporting rates and time, isolation decisions, evidence preservation, and role-specific reporting.

⚑

Organizational Improvement Actions

Translate observations into actions such as improving reporting channels, clarifying roles, reviewing policies, and providing further training.

Report Example: From Observations to Improvement

Focus on behaviors and operating conditions that teams and organizations can improve rather than individual score rankings.

ObservationRecommended ImprovementVerification Method
Suspicious email reports are delayedMake reporting channels easy to find in email and collaboration toolsCompare reporting time and rates in the next exercise
Incident reporting contacts are unclearSpecify reporting responsibilities and contacts for managers and security teamsRepeat role-based training
Insufficient verification before sharing informationReview independent verification and approval proceduresRepeat impersonation request scenarios
Define access permissions and purposes for individual results. Standard reports focus on organizational improvement and prevention, with calculation criteria, audience, and period stated alongside metrics.