🎉 New here? Use code WELCOME10 for 10% off any plan at checkout
NEWSActive Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin TokensNEWSGoogle Patches Pixel Modem Flaw Amid Signs of Limited Targeted ExploitationNEWSKREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session TokensBLOGVTAI: VirusTotal’s Free API for AI Agents, ExplainedBLOGShould Your Coding Agent Auto-Scan Every Download? A VTAI Rollout ChecklistBLOGFree Security-Scanning APIs for AI Agents: VTAI and the AlternativesBLOGPentAGI: What an Autonomous AI Pentesting Agent Means for Your Security ProgramTOOLSCompress a PDF or MP4 free, no signupTOOLS140+ free cybersecurity APIs, curated weeklyTOOLS120+ interactive architecture diagramsNEWSee everything PlayCISO has shippedAD SLOTAdvertise here — put your brand in front of thousands of security leadersNEWSActive Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin TokensNEWSGoogle Patches Pixel Modem Flaw Amid Signs of Limited Targeted ExploitationNEWSKREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session TokensBLOGVTAI: VirusTotal’s Free API for AI Agents, ExplainedBLOGShould Your Coding Agent Auto-Scan Every Download? A VTAI Rollout ChecklistBLOGFree Security-Scanning APIs for AI Agents: VTAI and the AlternativesBLOGPentAGI: What an Autonomous AI Pentesting Agent Means for Your Security ProgramTOOLSCompress a PDF or MP4 free, no signupTOOLS140+ free cybersecurity APIs, curated weeklyTOOLS120+ interactive architecture diagramsNEWSee everything PlayCISO has shippedAD SLOTAdvertise here — put your brand in front of thousands of security leaders
Rehearsal for the hot seat

Train for the CISO seatand the job after it.

You work through 17 years of incidents modelled on breaches that actually happened, then you have to defend your calls to a board and sit a mock interview that grills you on the rules in your own region. It's about as close to the job as you can get before someone hands you the job.

$9 a week, $29 a month, or $99 for the year. Cancel whenever you like.

17 years · 3 companies · 7 countries
Country-aware for🇦🇺Australia🇨🇦Canada🇮🇳India🇶🇦Qatar🇸🇦Saudi Arabia🇸🇬Singapore🇺🇸United States

Which seat are you in?

Same product, three different first moves. Pick the one that sounds like Monday morning.

A quick look inside.

Six surfaces, five seconds each. Every scenario is fictional — inspired by real-world incidents.

SIEM Live Feed · Zoomify AI · Y700:42
criticalOutbound C2 beacon from build-runner-04 — MCP tool call chain originated from support-bot session
highAnomalous token grant: service account escalated to org-admin 14 min ago
infoGC asking for a call. CEO wants a one-liner for the board thread.

Isolate the runner and burn the release window — or trust the WAF rule and ship? You have 42 seconds.

Play an incident

Three things you can only get good at by doing them

Reading about incident command is not the same as running one at 2am. So we let you run one.

Five security tools, included

Five is the promise — we built them, we use them ourselves, and they come with every subscription. There's more in the box on top of that (AI BOM, a country-aware resume review, and AI SVS as it ships), but the five are what you're paying for.

Enjoying PlayCISO so far?

The threat pulse

week 2026-W38

What we're watching — the incidents shaping what the War Room throws at you. From the weekly PlayCISO briefing.

Signal 1

Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens

Attackers are actively exploiting a critical WSO2 API Manager flaw that lets them forge admin tokens and bypass JWT verification. This could give them full control over affected API gateways.

Source →
Signal 2

Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation

Google fixed a high‑severity privilege‑escalation bug in the Pixel cellular modem that was already being used in targeted attacks. The patch closes CVE-2026-58704, CVSS 8.0.

Source →
Signal 3

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

A newly documented Brazilian banking malware, KREMLIN, injects into Chrome and Edge to harvest login details and session tokens. It has been active since at least May 2025.

Source →

Subscribers get this every week — with the AI developments and the one stat worth repeating. Take the free scorecard and it lands in your inbox.

Everything inside

The whole product on one screen. Green means free right now; everything else comes with any plan.

Practice the seat
Architect studios
Tools & knowledge
Free — no signup

Every plan is the whole thing

There's no stripped-down tier. Go weekly if an interview is next week, monthly if you're building up over time, yearly if you're in this for the long haul. You get the same product whichever you pick.

Weekly
$9/wk
Monthly
$29/mo
Yearly
$99/yr
Choose your plan
Cancel any time 7 bonus days on every plan No free tier