IncidentKitBuild Your Exercise

Scenario Catalog

Every scenario is built from a carefully written, human-reviewed base template, then tailored by AI to your organization type, size, and selected roles.

Ransomware

This exercise walks the team through a ransomware event: files across shared systems become inaccessible, a ransom note appears, and the organization must decide how to respond under time pressure. Participants practice detection and escalation, business continuity decisions, stakeholder communication, and the many decisions that surround a ransom demand — without ever discussing payment mechanics or negotiation tactics as facts to rely on.

Exercise objectives include:

  • Practice recognizing and escalating early signs of a ransomware event
  • Exercise the decision chain for isolating affected systems and preserving evidence
  • Rehearse internal and external communication under uncertainty
  • Clarify who owns the decision about engaging law enforcement, insurers, and outside counsel

NIST CSF touchpoints: Govern, Detect, Respond, Recover

Build a Ransomware Exercise

Business Email Compromise (BEC)

This exercise explores a business email compromise: an attacker impersonates a trusted executive or vendor to manipulate an employee into redirecting a payment or disclosing sensitive information. Participants practice verification discipline, financial-control decisions, and cross-department coordination under social pressure.

Exercise objectives include:

  • Practice verifying unusual payment or data requests before acting
  • Exercise the decision chain for freezing or attempting to recall a payment
  • Clarify escalation paths when a request appears to come from leadership
  • Rehearse coordination between finance, IT, and leadership

NIST CSF touchpoints: Govern, Protect, Detect, Respond

Build a Business Email Compromise (BEC) Exercise

Third-Party / Vendor Breach

This exercise examines how the organization responds when a key third-party vendor discloses that their own systems — which touch the organization's data — have been compromised. Participants practice vendor-risk decisions, data-impact assessment, and communication with customers or partners who may also be affected.

Exercise objectives include:

  • Practice assessing what data and processes depend on the affected vendor
  • Exercise the decision chain for suspending or continuing vendor access
  • Clarify contractual and communication obligations toward the vendor
  • Rehearse communication with any customers or partners who may be affected

NIST CSF touchpoints: Govern, Identify, Respond

Build a Third-Party / Vendor Breach Exercise

Insider Data Theft

This exercise addresses a sensitive scenario: signs suggest an employee or contractor may be taking sensitive data before leaving the organization. Participants practice careful, fair investigation steps, coordination between HR/legal/IT, and decisions that balance protecting the organization with treating the individual fairly while facts are still emerging.

Exercise objectives include:

  • Practice a measured, fact-based approach to a sensitive personnel-related security concern
  • Exercise the coordination between HR, legal, and IT/security
  • Clarify decision authority for access suspension and evidence preservation
  • Rehearse discretion and confidentiality throughout the process

NIST CSF touchpoints: Govern, Protect, Detect

Build a Insider Data Theft Exercise

Lost or Stolen Device

This exercise walks through a common, high-frequency event: an employee's laptop or phone with access to company systems is lost or stolen in public. Participants practice fast triage, remote-wipe and access-revocation decisions, and proportional communication — most such events are low-impact, but the team needs a calm, repeatable process.

Exercise objectives include:

  • Practice fast, calm triage of a lost or stolen device report
  • Exercise the decision chain for remote wipe, password resets, and access revocation
  • Clarify what data or access the device actually exposed
  • Rehearse proportional communication — most cases don't need company-wide alarm

NIST CSF touchpoints: Protect, Detect, Respond

Build a Lost or Stolen Device Exercise