New · MSP & Advisory Partner Whitepaper

Download the whitepaper
Partner Program · MSPs, MSSPs & Advisory Firms

A recurring delivery line you don’t have to build.

Breachday gives every client a fully isolated, white-labeled instance — live facilitation, real-time response capture, branded audit-ready reporting — priced per client slot on a single annual agreement.

Why clients are asking now

Compliance is forcing the issue — four mandates, one gap

Four regulatory and audit forces are independently pushing clients toward tested, not just written, incident response and continuity plans.

PCI DSS 4.0

Requirement 12.10 explicitly requires annual incident response plan testing with documented results.

SOC 2

Auditors increasingly expect tabletop evidence for the Security and Availability criteria — not just a policy binder.

SEC Item 1.05 / Reg S-K Item 106

Public registrants must be able to assess and disclose material incidents within four business days. No team does that cold.

ISO 22301

Requires a documented BIA and an active exercise program — not a one-time plan.

The gap advisors keep hitting: clients need a tested plan on a recurring cadence, but running one manually — deck, room, write-up — consumes senior consultant hours that don’t scale across a client book.

The platform

A facilitator-led tabletop, captured as it happens

A facilitator runs the room from a live console. Participants join from their own device with a short room code and respond to scenario injects as they’re released — every action, vote, and observation captured automatically.

The exercise itself becomes the deliverable: the same session a client runs in the room is the artifact an auditor reviews.

  • No participant accounts or installs — join from any device with a room code.
  • Custom role seats per client — Incident Commander, Legal, Comms, IT, executive, or any role the org chart requires.
  • Live inject delivery on a phase-based timeline; freeform, vote, and confidence-slider response types.
  • Scenario library built on real-world public breaches plus CISA CTEP-aligned sector templates.
  • Automatic after-action reporting — timeline, attributed responses, vote tallies, observations, linked BC assets — exported as a branded PDF.
  • Lessons-learned tracker so clients close the loop on what the exercise surfaced.

How it works

The same flow in every client org

Only the branding changes. Run it the same way for every client on your roster.

  1. 01

    Design the scenario

    Choose a default or CTEP-based template, or clone and customize for the client’s environment. Tag the IT assets and BIA processes the exercise will touch.

  2. 02

    Launch the exercise

    Open the room with one click and share the room code. No client-side installs and no accounts to provision.

  3. 03

    Join the room

    Stakeholders join from any device, pick a display name, and claim a role seat.

  4. 04

    Run the scenario

    Release injects on the timeline; capture votes, freeform responses, and live facilitator observations as the room works the incident.

  5. 05

    Review the report

    Generate the after-action report — timeline, decisions, vote tallies, lessons learned — branded with the client’s or the partner firm’s logo.

One exercise, four audit trails

Compliance mapping

Run one scenario with a client and hand the same report to four assessors. Each card shows the controls a Breachday after-action report speaks to.

SOC 2

Most common

  • CC7.3Evaluating security events
  • CC7.4Responding to security incidents
  • CC7.5Recovery from identified events
  • A1.2 / A1.3Availability & environmental BCM

PCI DSS 4.0

Annual requirement

  • 12.10.1IR plan exists, reviewed, tested
  • 12.10.2Annual testing & documented results
  • 12.10.4Personnel trained on IR duties
  • 12.10.5IR plan covers all required elements

SEC Cyber Disclosure

Public companies

  • Item 1.054-day material incident readiness
  • Item 106(b)Cyber risk management disclosure
  • Item 106(c)Board oversight & management role
  • Materiality drillsLegal / finance / comms rehearsal

ISO 22301

BCM standard

  • Clause 8.2BIA & risk assessment
  • Clause 8.5Exercise program & testing
  • Clause 9.1Performance evaluation
  • Clause 10Continual improvement & lessons learned

Breachday is not a substitute for legal or audit advice. Control mappings are guidance for compliance teams, and the client’s auditor has the final say.

White-labeled, fully isolated

Each client is a complete, isolated Breachday organization

Every client slot is a full organization — its own users, data, scenarios, and reports — running the complete Pro-tier feature set under the partner firm’s brand.

The partner sets what they charge their own clients. Breachday powers the platform behind it.

  • White-labeled PDF reports carrying the partner firm’s branding, not Breachday’s.
  • Fully isolated client orgs — complete data and user separation between clients.
  • Pro-tier features in every client org: CISA CTEP templates, IT asset register, BIA, and unlimited crisis communication plans.
  • Partner portal for cross-client member and organization management.
  • Seed scenarios pre-installed in every client org from day one.
  • Priority support and consultant-style scenario and template cloning across the client base.
  • Dedicated customer success manager at 50+ client slots.

The model

Per-slot, annual, volume-discounted

  • Annual billing only, priced per client slot.
  • 10-slot minimum to start.
  • Per-slot rate steps down as slot count grows; dedicated CSM at 50+ slots.
  • 14-day onboarding with seed scenarios pre-installed in every client org — included at every tier.

Partner pricing

Talk through slot pricing on a walkthrough

Per-slot rates step down with volume and are quoted against your current client roster — not published on a public table.

Get partner pricing

Built by a practitioner

Built and operated by a working GRC analyst

Breachday is built and actively operated by someone who sits in the same audits your clients do. That shows up in the product: scenario content that reads like a real incident, reports built to satisfy an actual auditor, and a roadmap driven by what compliance teams are asked for.

Where Breachday’s SOC 2 stands: Breachday has not yet completed its own SOC 2 audit; Type II certification is on the roadmap and completed reports will be shared on request. Until then, the platform runs on infrastructure providers (Supabase, Vercel) that maintain their own SOC 2 certifications.

Security posture

  • Data encrypted at rest (AES-256 via Supabase) and in transit (TLS 1.2+, HSTS enforced) across every plan tier.
  • Optional data protection mode on Plus and Pro — ephemeral, auto-purged session data for sensitive scenarios.
  • Row-level tenant isolation — client organizations never see one another’s data, a structural requirement for any multi-client deployment.
  • Two-factor authentication required for every app user; room access needs a code plus a separate password.
  • Runs on infrastructure providers (Supabase, Vercel) that maintain their own SOC 2 certifications — an evidentiary bridge while Breachday completes its own SOC 2 Type II attestation.

Getting started

See it running before you commit

The fastest way to evaluate the partner program is to see it running: pick one client relationship, run a live 30-minute scenario together, and look at the after-action report it produces.

  1. 01Book a partner walkthrough — a live demo of the facilitator console, the participant join flow, and a sample audit-ready report.
  2. 02Choose a starting slot count (10-slot minimum) based on your current client roster.
  3. 03Onboard over a 14-day period with seed scenarios already installed in every client org.
  4. 04Roll out white-labeled tabletop exercises as a standing line item across your engagements.
Book a partner walkthrough