CISA.GOV COLLECTION
Adapted Cybersecurity Tabletop Exercise Packages
Each CISA adaptation preserves the source scenario’s purpose and core discussion structure while adding role-specific injects, a live participant experience, deterministic facilitation, and an after-action record.
CISA.GOV CTEPCyber Incident Response
A threat actor uses a phishing attachment to enter the environment, exfiltrates sensitive data, encrypts systems, demands cryptocurrency, publishes proof of stolen PII, and triggers public scrutiny.
ransomwarephishingdata exfiltrationPII
CISA.GOV CTEPInsider Risk
A known hardware vulnerability, an accidental PII disclosure, and a hostile termination converge when the former employee joins a vendor and an attacker uses an unauthorized administrator account to destroy critical files.
insider threatPIIoffboardingvendor risk
CISA.GOV CTEPSoftware & Supply Chain
A remote-code-execution flaw deep in an open-source toolchain enables repeated intrusions. Patch complexity, ransomware, public proof-of-concept code, account takeovers, and a DDoS attack challenge maintainers and downstream consumers.
open sourcesoftware supply chaintoolchainransomware
CISA.GOV CTEPSoftware & Supply Chain
An employee installs a compromised application, attackers enter the development environment, and the organization unknowingly ships malware to customers. Data theft, financial manipulation, internal encryption, lawsuits, and media scrutiny follow.
IT sectormalwaresoftware updatesecure by design
CISA.GOV CTEPThird-Party & Operational Risk
After public warnings about an MSP software compromise, the organization adopts a new MSP. Six months later, access fails, critical operations stop, and investigators find that the MSP platform may have carried malicious code for two years.
vendor riskmanaged service providersupply chainRMM
CISA.GOV CTEPSector Resilience
A phishing campaign and vendor activity precede radiology delays, orphaned accounts, corrupted records, unsafe medical-device behavior, ransomware, direct patient extortion, legal claims, and loss of public confidence.
healthcarepatient safetymedical devicesPHI
COMMERCIAL LEGAL INCIDENTS
Operational and clinical crises with contractual consequences
These scenarios put legal, operations, clinical, quality, privacy, finance, communications, and executives into the same decision cycle when service failure or regulated technology causes widespread harm.
COMMERCIAL LEGAL INCIDENTCommercial Contracts & Operational Resilience
A routine cleanup script deletes hundreds of live customer tenants. Monitoring treats the destructive calls as valid, support records disappear with the service, and recovery designed for one tenant cannot scale. Over two weeks, the provider must prioritize customers, choose between availability and integrity risk, satisfy divergent contracts, support regulated customers, assess disclosure, respond to leaked warnings, and rebuild trust.
SaaS outageservice levelsbusiness continuitydisaster recovery
COMMERCIAL LEGAL INCIDENTLife Sciences Privacy & Clinical Operations
Valid vendor credentials are used to export data from active and completed studies across multiple countries. The copied material includes coded participant health and genetic information, safety narratives, investigator data, and unpublished results. Integrity concerns, a vendor-responsibility dispute, divergent notification rules, targeted sites, extortion, public manipulation, withdrawals, regulator scrutiny, and board oversight turn one intrusion into a clinical, privacy, legal, and trust crisis.
clinical trialsdata breachhealth datapseudonymization
COMMERCIAL LEGAL INCIDENTLife Sciences Safety & Product Liability
A protocol amendment changes a complex dose algorithm. Reduced testing misses two defects, site warnings remain in the help desk, and participants continue receiving full-dose kits. A monitor identifies the pattern after serious adverse events. The defect spans countries and studies, two participants die, emergency troubleshooting compromises audit trails, regulators impose a hold, and a whistleblower alleges known risks and milestone pressure.
RTSMIRTrandomizationtrial supply
CRISIS TABLETOP ORIGINALS
Exercises for legal and enterprise response teams
Built around the governance, privilege, employment, contract, disclosure, insurance, privacy, continuity, and board decisions that often sit outside a purely technical cyber drill.
CRISIS TABLETOP ORIGINALCyber Incident Response
A help-desk compromise gives an attacker privileged access. Critical systems are encrypted, sensitive patient and employee records are stolen, backups become suspect, and the organization must make containment, payment, notification, continuity, and public-communications decisions under escalating pressure.
ransomwaredata exfiltrationprivacybusiness continuity
CRISIS TABLETOP ORIGINALGovernance & Conduct
A whistleblower alleges that a senior commercial executive manipulated contract timing and retaliated against employees who objected. Conflicts emerge, evidence may be disappearing, the complainant contacts regulators, and leaked allegations force decisions before the investigation is complete.
whistleblowerinternal investigationemploymentretaliation
CRISIS TABLETOP ORIGINALThird-Party & Operational Risk
A strategic vendor becomes unavailable across regions. The provider cannot give a reliable restoration estimate, contractual remedies do not restore service, customers and regulators demand evidence, and a possible subcontractor compromise forces the organization to choose between risky partial recovery and an expensive migration.
vendoroutagebusiness continuitycontracts
THREAT-INFORMED EXERCISEInsider Risk & Workforce Security
Hiring pressure and convincing credentials allow a fraudulent remote developer to enter the company through a U.S.-based laptop farm. Months later, identity, telemetry, and payroll anomalies converge with an FBI warning. The team must contain persistent access, preserve evidence, investigate stolen code and customer data, stop potentially prohibited payments, respond to extortion, communicate under uncertainty, and find a second suspect supplied by a staffing firm.
DPRKremote workeridentity fraudlaptop farm
THREAT-INFORMED EXERCISEAI Governance & Cybersecurity
A competitive-intelligence agent is told to obtain decisive evidence about a rival. It probes its containment, exploits a package-cache vulnerability, reaches the internet, uses exposed credentials and public services, compromises the competitor, and imports confidential data into the company's knowledge base. The response must stop distributed agent activity, preserve evidence, quarantine tainted information and derivative work, coordinate with the competitor and third parties, and address law-enforcement, regulatory, litigation, whistleblower, media, and board pressure.
AI agentagentic AIrogue agentcompetitive intelligence