Every scenario is built from a carefully written, human-reviewed base template, then tailored by AI to your organization type, size, and selected roles.
Ransomware
This exercise walks the team through a ransomware event: files across shared systems become inaccessible, a ransom note appears, and the organization must decide how to respond under time pressure. Participants practice detection and escalation, business continuity decisions, stakeholder communication, and the many decisions that surround a ransom demand — without ever discussing payment mechanics or negotiation tactics as facts to rely on.
Exercise objectives include:
- Practice recognizing and escalating early signs of a ransomware event
- Exercise the decision chain for isolating affected systems and preserving evidence
- Rehearse internal and external communication under uncertainty
- Clarify who owns the decision about engaging law enforcement, insurers, and outside counsel
NIST CSF touchpoints: Govern, Detect, Respond, Recover
Build a Ransomware ExerciseBusiness Email Compromise (BEC)
This exercise explores a business email compromise: an attacker impersonates a trusted executive or vendor to manipulate an employee into redirecting a payment or disclosing sensitive information. Participants practice verification discipline, financial-control decisions, and cross-department coordination under social pressure.
Exercise objectives include:
- Practice verifying unusual payment or data requests before acting
- Exercise the decision chain for freezing or attempting to recall a payment
- Clarify escalation paths when a request appears to come from leadership
- Rehearse coordination between finance, IT, and leadership
NIST CSF touchpoints: Govern, Protect, Detect, Respond
Build a Business Email Compromise (BEC) ExerciseThird-Party / Vendor Breach
This exercise examines how the organization responds when a key third-party vendor discloses that their own systems — which touch the organization's data — have been compromised. Participants practice vendor-risk decisions, data-impact assessment, and communication with customers or partners who may also be affected.
Exercise objectives include:
- Practice assessing what data and processes depend on the affected vendor
- Exercise the decision chain for suspending or continuing vendor access
- Clarify contractual and communication obligations toward the vendor
- Rehearse communication with any customers or partners who may be affected
NIST CSF touchpoints: Govern, Identify, Respond
Build a Third-Party / Vendor Breach ExerciseInsider Data Theft
This exercise addresses a sensitive scenario: signs suggest an employee or contractor may be taking sensitive data before leaving the organization. Participants practice careful, fair investigation steps, coordination between HR/legal/IT, and decisions that balance protecting the organization with treating the individual fairly while facts are still emerging.
Exercise objectives include:
- Practice a measured, fact-based approach to a sensitive personnel-related security concern
- Exercise the coordination between HR, legal, and IT/security
- Clarify decision authority for access suspension and evidence preservation
- Rehearse discretion and confidentiality throughout the process
NIST CSF touchpoints: Govern, Protect, Detect
Build a Insider Data Theft ExerciseLost or Stolen Device
This exercise walks through a common, high-frequency event: an employee's laptop or phone with access to company systems is lost or stolen in public. Participants practice fast triage, remote-wipe and access-revocation decisions, and proportional communication — most such events are low-impact, but the team needs a calm, repeatable process.
Exercise objectives include:
- Practice fast, calm triage of a lost or stolen device report
- Exercise the decision chain for remote wipe, password resets, and access revocation
- Clarify what data or access the device actually exposed
- Rehearse proportional communication — most cases don't need company-wide alarm
NIST CSF touchpoints: Protect, Detect, Respond
Build a Lost or Stolen Device Exercise