INCIDENT SIMULATION LAB

Interactive Tabletop Exercise & Incident Simulator

Facilitate high-impact crisis simulations for executive leadership, legal counsel, and technical response teams. Every scenario is reverse-engineered from primary court indictments, SEC disclosures, and verified forensic filings.

Select Scenario:
Case Dossier Blueprint: Change Healthcare (UnitedHealth Group)

Healthcare Clearinghouse Ransomware & National Outage

Actor: ALPHV / BlackCat Ransomware Affiliates Estimated Loss: $872 Million+ direct response costs

Simulation Overview: An adversary acquires valid credentials to an internet-facing remote portal lacking MFA. Within days, the threat actor exfiltrates 6 terabytes of health records, deploys ransomware across core transaction databases, and demands $22 million, halting nationwide prescription processing.

Target Sector:
Healthcare & Financial Services
Initial Entry Vector:
Compromised Citrix Gateway credentials lacking multi-factor authentication (MFA)

Phased Crisis Injects (5 Phases)

Click inject cards to toggle details or review role-specific prompts
1

Initial Detection & Portal Anomaly

T+00:00 (Incident Discovery)

Inject Incident Narrative: At 02:14 UTC, automated endpoint monitoring detects suspicious PowerShell commands spawning from a Citrix session. Within 20 minutes, anomalous outbound traffic is flagged toward an unclassified external IP address in Europe.

Technical Evidence & Artifacts Discovered:
> Process spawn: cmd.exe -> powershell.exe -enc ...
> Data exfiltration via Megasync tool
> Log source: Citrix NetScaler / Gateway authentication logs
Role-Specific Facilitation Prompts:
Technical Incident Response
  • How rapidly can you isolate the Citrix gateway without severing connectivity for emergency clinical staff?
  • What forensic artifacts are immediately preserved before server reboot or container termination?
Legal & Regulatory Compliance
  • Does this initial exfiltration trigger mandatory HIPAA reporting clocks (60 days) or state breach alerts?
  • Should external incident response and forensic retainers be placed under formal attorney-client privilege?
Executive Leadership & Board
  • What is the emergency threshold for halting commercial transaction clearing operations?
  • Who has the authority to activate the external crisis management and cyber insurance team?
Communications & Public Relations
  • What is our initial holding statement if partner pharmacies begin reporting failed transactions?
  • How do we handle off-the-record journalist inquiries asking if our systems are down?
2

Mass Volume Encryption & Service Outage

T+04:30 (Active Ransomware Deployment)

Inject Incident Narrative: System administrators find VMware ESXi hypervisors and production databases encrypted with .ALPHV extensions. A digital ransom note demands 350 Bitcoin ($22M). Core claim validation and pharmacy clearing portals fail completely.

Technical Evidence & Artifacts Discovered:
> Ransom note: RECOVER-README.txt placed in /vmfs/volumes
> ESXi command-line wiper script execution
> Volume shadow copies deleted via vssadmin
Role-Specific Facilitation Prompts:
Technical Incident Response
  • Are clean, immutable, out-of-band backups available, and when were they last tested for restoration velocity?
  • Can core claims processing be failed over to an isolated disaster recovery environment safely?
Legal & Regulatory Compliance
  • Does negotiating or communicating with this specific threat group present OFAC sanctions liability?
  • What are our legal contractual liabilities to hospital networks unable to process emergency payroll or drugs?
Executive Leadership & Board
  • Under what conditions, if any, will the executive leadership consider authorizing a ransom payment?
  • How does the board evaluate the trade-off between days of national health disruption versus ransom refusal?
Communications & Public Relations
  • How do we communicate with thousands of dependent healthcare providers without triggering panic?
  • Do we launch a dedicated status microsite completely off corporate infrastructure?
3

Double Extortion & Dark Web Leak Site Timer

T+24:00 (Extortion & Data Leak Threat)

Inject Incident Narrative: The ransomware syndicate publishes sample patient records containing SSNs, medical diagnoses, and banking details on their Tor leak site, setting a 72-hour countdown before the full 6TB archive is auctioned.

Technical Evidence & Artifacts Discovered:
> Published proof-pack on onion site with 20 sample patient dossiers
> Proof of exfiltration verified via hash comparison
> Direct extortion email sent to Chief Executive Officer personal phone
Role-Specific Facilitation Prompts:
Technical Incident Response
  • Can we independently verify the scope of stolen data using firewall and NetFlow exfiltration volume logs?
  • How do we verify whether the adversary maintains persistent backdoor webshells or secondary access tokens?
Legal & Regulatory Compliance
  • Does the publication of sample records convert this incident into a confirmed breach under state and federal law?
  • What are our immediate disclosure obligations to state Attorneys General and the HHS Office for Civil Rights?
Executive Leadership & Board
  • If an extortion negotiator is engaged, what guarantees exist that the stolen records will actually be deleted?
  • What is our stance if a rival affiliate surfaces claiming they also hold a copy of the stolen data?
Communications & Public Relations
  • How do we address public inquiries about compromised patient records and potential identity theft support?
  • What resources (call center, credit monitoring) must be prepared prior to public statement release?
4

SEC 8-K Disclosure & Mandatory Regulatory Clocks

T+72:00 (Regulatory Clocks & SEC 8-K)

Inject Incident Narrative: The company reaches Day 4 of disruption. Total operational losses and response costs cross $100M. The board determines the incident is material to public shareholders. The SEC 4-business-day 8-K Item 1.05 clock expires.

Technical Evidence & Artifacts Discovered:
> Materiality determination formalized in audit committee minutes
> Draft Form 8-K Item 1.05 prepared for filing
> CIRCIA / CISA notification packet submitted
Role-Specific Facilitation Prompts:
Technical Incident Response
  • What technical details can be safely shared with CISA and FBI without exposing ongoing defense vulnerabilities?
  • Is the forensic investigation sufficiently mature to definitively state the threat vector in regulatory filings?
Legal & Regulatory Compliance
  • Does the company qualify for a National Security or Public Safety delay under DOJ guidelines for SEC Form 8-K?
  • How do we manage class action litigation preservation notices already received from plaintiffs counsel?
Executive Leadership & Board
  • How do we prepare for investor earnings calls and potential Congressional subpoena inquiries?
  • What bridge financing or emergency liquidity is required to support critical partners during the downtime?
Communications & Public Relations
  • How do we align SEC disclosures with customer FAQs to prevent inconsistent public statements?
  • Who is authorized to speak publicly to avoid contradictory statements cited in subsequent securities lawsuits?
5

Post-Mortem, Root Cause & Policy Overhaul

T+30 Days (Remediation & Governance Debrief)

Inject Incident Narrative: Systems have reached 95% restoration. Forensic examination confirms a single unpatched Citrix portal without MFA was the root cause. Congressional hearings and multiple regulatory investigations are formally launched.

Technical Evidence & Artifacts Discovered:
> Comprehensive enterprise MFA mandate implemented across 100% of external gateways
> Zero-trust network architecture migration timeline
> Third-party security audit report finalized
Role-Specific Facilitation Prompts:
Technical Incident Response
  • What automated architecture prevents any external asset from being deployed without mandatory phishing-resistant MFA?
  • How is network micro-segmentation verified between payment clearing systems and general corporate networks?
Legal & Regulatory Compliance
  • What cybersecurity representations and warranties in vendor contracts must be updated immediately?
  • How do we coordinate responses to the SEC Division of Enforcement and state AG multi-state taskforces?
Executive Leadership & Board
  • What structural changes are required in board-level cybersecurity oversight and reporting cadences?
  • How are executive compensation metrics tied to verifiable cybersecurity remediation milestones?
Communications & Public Relations
  • How do we rebuild enterprise trust and retain critical healthcare network partnerships long-term?
  • What long-term transparency reports will demonstrate our enhanced defensive posture to the market?