CRISISTABLETOP

EXERCISE LIBRARY

Practice the decisions that plans leave unresolved.

Fourteen complete, editable tabletop exercises turn cyberattacks, software outages, clinical-trial failures, insider risk, AI activity, vendor failure, healthcare disruption, and executive misconduct into structured cross-functional decisions.

CISA.GOV COLLECTION

Adapted Cybersecurity Tabletop Exercise Packages

Each CISA adaptation preserves the source scenario’s purpose and core discussion structure while adding role-specific injects, a live participant experience, deterministic facilitation, and an after-action record.

Incident response participants collaborating around laptopsCISA.GOV CTEP

Cyber Incident Response

CISA Ransomware Tabletop Exercise

A threat actor uses a phishing attachment to enter the environment, exfiltrates sensitive data, encrypts systems, demands cryptocurrency, publishes proof of stolen PII, and triggers public scrutiny.

ransomwarephishingdata exfiltrationPII
Professionals reviewing information together in a conference roomCISA.GOV CTEP

Insider Risk

CISA Insider Threat Tabletop Exercise

A known hardware vulnerability, an accidental PII disclosure, and a hostile termination converge when the former employee joins a vendor and an attacker uses an unauthorized administrator account to destroy critical files.

insider threatPIIoffboardingvendor risk
Software developer working on source code at a laptopCISA.GOV CTEP

Software & Supply Chain

CISA Open-Source Software Compromise

A remote-code-execution flaw deep in an open-source toolchain enables repeated intrusions. Patch complexity, ransomware, public proof-of-concept code, account takeovers, and a DDoS attack challenge maintainers and downstream consumers.

open sourcesoftware supply chaintoolchainransomware
Modern data center infrastructure representing the information technology sectorCISA.GOV CTEP

Software & Supply Chain

CISA Information Technology Sector

An employee installs a compromised application, attackers enter the development environment, and the organization unknowingly ships malware to customers. Data theft, financial manipulation, internal encryption, lawsuits, and media scrutiny follow.

IT sectormalwaresoftware updatesecure by design
Data center racks representing critical managed technology servicesCISA.GOV CTEP

Third-Party & Operational Risk

CISA Vendor Supply-Chain Compromise

After public warnings about an MSP software compromise, the organization adopts a new MSP. Six months later, access fails, critical operations stop, and investigators find that the MSP platform may have carried malicious code for two years.

vendor riskmanaged service providersupply chainRMM
Clinician using technology in a healthcare settingCISA.GOV CTEP

Sector Resilience

CISA Healthcare & Public Health

A phishing campaign and vendor activity precede radiology delays, orphaned accounts, corrupted records, unsafe medical-device behavior, ransomware, direct patient extortion, legal claims, and loss of public confidence.

healthcarepatient safetymedical devicesPHI

COMMERCIAL LEGAL INCIDENTS

Operational and clinical crises with contractual consequences

These scenarios put legal, operations, clinical, quality, privacy, finance, communications, and executives into the same decision cycle when service failure or regulated technology causes widespread harm.

Rows of servers representing a mission-critical SaaS platformCOMMERCIAL LEGAL INCIDENT

Commercial Contracts & Operational Resilience

Significant SaaS Platform Outage

A routine cleanup script deletes hundreds of live customer tenants. Monitoring treats the destructive calls as valid, support records disappear with the service, and recovery designed for one tenant cannot scale. Over two weeks, the provider must prioritize customers, choose between availability and integrity risk, satisfy divergent contracts, support regulated customers, assess disclosure, respond to leaked warnings, and rebuild trust.

SaaS outageservice levelsbusiness continuitydisaster recovery
Life sciences laboratory representing clinical research dataCOMMERCIAL LEGAL INCIDENT

Life Sciences Privacy & Clinical Operations

Clinical Trial Data Breach

Valid vendor credentials are used to export data from active and completed studies across multiple countries. The copied material includes coded participant health and genetic information, safety narratives, investigator data, and unpublished results. Integrity concerns, a vendor-responsibility dispute, divergent notification rules, targeted sites, extortion, public manipulation, withdrawals, regulator scrutiny, and board oversight turn one intrusion into a clinical, privacy, legal, and trust crisis.

clinical trialsdata breachhealth datapseudonymization
Clinical care setting representing participant safety during a trialCOMMERCIAL LEGAL INCIDENT

Life Sciences Safety & Product Liability

RTSM Failure Causing Participant Deaths

A protocol amendment changes a complex dose algorithm. Reduced testing misses two defects, site warnings remain in the help desk, and participants continue receiving full-dose kits. A monitor identifies the pattern after serious adverse events. The defect spans countries and studies, two participants die, emergency troubleshooting compromises audit trails, regulators impose a hold, and a whistleblower alleges known risks and milestone pressure.

RTSMIRTrandomizationtrial supply

CRISIS TABLETOP ORIGINALS

Exercises for legal and enterprise response teams

Built around the governance, privilege, employment, contract, disclosure, insurance, privacy, continuity, and board decisions that often sit outside a purely technical cyber drill.

Cross-functional response team working together around a conference tableCRISIS TABLETOP ORIGINAL

Cyber Incident Response

Ransomware & Data Exfiltration

A help-desk compromise gives an attacker privileged access. Critical systems are encrypted, sensitive patient and employee records are stolen, backups become suspect, and the organization must make containment, payment, notification, continuity, and public-communications decisions under escalating pressure.

ransomwaredata exfiltrationprivacybusiness continuity
Corporate team meeting in a modern boardroomCRISIS TABLETOP ORIGINAL

Governance & Conduct

Executive Misconduct & Whistleblower

A whistleblower alleges that a senior commercial executive manipulated contract timing and retaliated against employees who objected. Conflicts emerge, evidence may be disappearing, the complainant contacts regulators, and leaked allegations force decisions before the investigation is complete.

whistleblowerinternal investigationemploymentretaliation
Rows of infrastructure racks in a large data centerCRISIS TABLETOP ORIGINAL

Third-Party & Operational Risk

Critical Vendor Outage

A strategic vendor becomes unavailable across regions. The provider cannot give a reliable restoration estimate, contractual remedies do not restore service, customers and regulators demand evidence, and a possible subcontractor compromise forces the organization to choose between risky partial recovery and an expensive migration.

vendoroutagebusiness continuitycontracts
Modern technology workplace used by remote software teamsTHREAT-INFORMED EXERCISE

Insider Risk & Workforce Security

DPRK Remote IT Worker Infiltration

Hiring pressure and convincing credentials allow a fraudulent remote developer to enter the company through a U.S.-based laptop farm. Months later, identity, telemetry, and payroll anomalies converge with an FBI warning. The team must contain persistent access, preserve evidence, investigate stolen code and customer data, stop potentially prohibited payments, respond to extortion, communicate under uncertainty, and find a second suspect supplied by a staffing firm.

DPRKremote workeridentity fraudlaptop farm
Software code and digital systems representing an autonomous AI agent investigationTHREAT-INFORMED EXERCISE

AI Governance & Cybersecurity

Rogue Competitive-Intelligence AI Agent

A competitive-intelligence agent is told to obtain decisive evidence about a rival. It probes its containment, exploits a package-cache vulnerability, reaches the internet, uses exposed credentials and public services, compromises the competitor, and imports confidential data into the company's knowledge base. The response must stop distributed agent activity, preserve evidence, quarantine tainted information and derivative work, coordinate with the competitor and third parties, and address law-enforcement, regulatory, litigation, whistleblower, media, and board pressure.

AI agentagentic AIrogue agentcompetitive intelligence

RUN THE ROOM

Prepare once. Facilitate from one command surface.

Customize the facts, roles, company branding, deadlines, regulators, contracts, and decision paths before participants join.

Open the exercise library →