Interactive Tabletop Exercise & Incident Simulator
Facilitate high-impact crisis simulations for executive leadership, legal counsel, and technical response teams. Every scenario is reverse-engineered from primary court indictments, SEC disclosures, and verified forensic filings.
Healthcare Clearinghouse Ransomware & National Outage
Simulation Overview: An adversary acquires valid credentials to an internet-facing remote portal lacking MFA. Within days, the threat actor exfiltrates 6 terabytes of health records, deploys ransomware across core transaction databases, and demands $22 million, halting nationwide prescription processing.
Phased Crisis Injects (5 Phases)
Initial Detection & Portal Anomaly
T+00:00 (Incident Discovery)Inject Incident Narrative: At 02:14 UTC, automated endpoint monitoring detects suspicious PowerShell commands spawning from a Citrix session. Within 20 minutes, anomalous outbound traffic is flagged toward an unclassified external IP address in Europe.
- How rapidly can you isolate the Citrix gateway without severing connectivity for emergency clinical staff?
- What forensic artifacts are immediately preserved before server reboot or container termination?
- Does this initial exfiltration trigger mandatory HIPAA reporting clocks (60 days) or state breach alerts?
- Should external incident response and forensic retainers be placed under formal attorney-client privilege?
- What is the emergency threshold for halting commercial transaction clearing operations?
- Who has the authority to activate the external crisis management and cyber insurance team?
- What is our initial holding statement if partner pharmacies begin reporting failed transactions?
- How do we handle off-the-record journalist inquiries asking if our systems are down?
Mass Volume Encryption & Service Outage
T+04:30 (Active Ransomware Deployment)Inject Incident Narrative: System administrators find VMware ESXi hypervisors and production databases encrypted with .ALPHV extensions. A digital ransom note demands 350 Bitcoin ($22M). Core claim validation and pharmacy clearing portals fail completely.
- Are clean, immutable, out-of-band backups available, and when were they last tested for restoration velocity?
- Can core claims processing be failed over to an isolated disaster recovery environment safely?
- Does negotiating or communicating with this specific threat group present OFAC sanctions liability?
- What are our legal contractual liabilities to hospital networks unable to process emergency payroll or drugs?
- Under what conditions, if any, will the executive leadership consider authorizing a ransom payment?
- How does the board evaluate the trade-off between days of national health disruption versus ransom refusal?
- How do we communicate with thousands of dependent healthcare providers without triggering panic?
- Do we launch a dedicated status microsite completely off corporate infrastructure?
Double Extortion & Dark Web Leak Site Timer
T+24:00 (Extortion & Data Leak Threat)Inject Incident Narrative: The ransomware syndicate publishes sample patient records containing SSNs, medical diagnoses, and banking details on their Tor leak site, setting a 72-hour countdown before the full 6TB archive is auctioned.
- Can we independently verify the scope of stolen data using firewall and NetFlow exfiltration volume logs?
- How do we verify whether the adversary maintains persistent backdoor webshells or secondary access tokens?
- Does the publication of sample records convert this incident into a confirmed breach under state and federal law?
- What are our immediate disclosure obligations to state Attorneys General and the HHS Office for Civil Rights?
- If an extortion negotiator is engaged, what guarantees exist that the stolen records will actually be deleted?
- What is our stance if a rival affiliate surfaces claiming they also hold a copy of the stolen data?
- How do we address public inquiries about compromised patient records and potential identity theft support?
- What resources (call center, credit monitoring) must be prepared prior to public statement release?
SEC 8-K Disclosure & Mandatory Regulatory Clocks
T+72:00 (Regulatory Clocks & SEC 8-K)Inject Incident Narrative: The company reaches Day 4 of disruption. Total operational losses and response costs cross $100M. The board determines the incident is material to public shareholders. The SEC 4-business-day 8-K Item 1.05 clock expires.
- What technical details can be safely shared with CISA and FBI without exposing ongoing defense vulnerabilities?
- Is the forensic investigation sufficiently mature to definitively state the threat vector in regulatory filings?
- Does the company qualify for a National Security or Public Safety delay under DOJ guidelines for SEC Form 8-K?
- How do we manage class action litigation preservation notices already received from plaintiffs counsel?
- How do we prepare for investor earnings calls and potential Congressional subpoena inquiries?
- What bridge financing or emergency liquidity is required to support critical partners during the downtime?
- How do we align SEC disclosures with customer FAQs to prevent inconsistent public statements?
- Who is authorized to speak publicly to avoid contradictory statements cited in subsequent securities lawsuits?
Post-Mortem, Root Cause & Policy Overhaul
T+30 Days (Remediation & Governance Debrief)Inject Incident Narrative: Systems have reached 95% restoration. Forensic examination confirms a single unpatched Citrix portal without MFA was the root cause. Congressional hearings and multiple regulatory investigations are formally launched.
- What automated architecture prevents any external asset from being deployed without mandatory phishing-resistant MFA?
- How is network micro-segmentation verified between payment clearing systems and general corporate networks?
- What cybersecurity representations and warranties in vendor contracts must be updated immediately?
- How do we coordinate responses to the SEC Division of Enforcement and state AG multi-state taskforces?
- What structural changes are required in board-level cybersecurity oversight and reporting cadences?
- How are executive compensation metrics tied to verifiable cybersecurity remediation milestones?
- How do we rebuild enterprise trust and retain critical healthcare network partnerships long-term?
- What long-term transparency reports will demonstrate our enhanced defensive posture to the market?