CRISISTABLETOP
Modern data center infrastructure representing the information technology sector
← Exercise library

CISA.GOV CTEP · SOFTWARE & SUPPLY CHAIN

CISA Information Technology Sector

An employee installs a compromised application, attackers enter the development environment, and the organization unknowingly ships malware to customers. Data theft, financial manipulation, internal encryption, lawsuits, and media scrutiny follow.

3 HRSuggested duration11Participant roles9Scenario stages
Stock photography via Unsplash

EXERCISE PURPOSE

Assess and improve enterprise resilience to a major cyber incident affecting an information-technology company and its customers.

Malware introduced through a third-party application and propagated to customers in a software update

DECISION PRESSURE

Questions the team must answer together

The facilitator releases facts in stages. Participants should identify the decision owner, the authority being used, the information still needed, the immediate action, and the next escalation point.

01

What can reach build, signing, and release systems?

02

Can the organization identify every customer and artifact receiving a compromised build?

03

Who can suspend distribution and direct customers to disconnect?

04

How are internal response and customer incident support coordinated?

05

What proof is required before a corrected release is trusted?

INSIDE THE EXERCISE

A scenario that changes as the response develops

The template is already populated with public injects, facilitator-only context, discussion prompts, private role messages, and a final hotwash.

  1. Day 1
    Module 1

    IT-sector supply-chain alert

    CISA warns that state-sponsored actors are targeting software and firmware companies and their customers, compromising products to gain access to critical-infrastructure networks.

  2. Day 12
    Module 1

    Developer downloads third-party application

    A software-development employee downloads an application from an official third-party vendor website and installs it successfully.

  3. Day 20
    Module 1

    Software update released to customers

    The organization publishes a software update and urges customers to install it promptly.

  4. Day 30
    Module 1

    Outbound traffic to foreign address

    An employee detects a high volume of data leaving organizational servers for an unauthorized IP address in a foreign country.

  5. Day 31 · Morning
    Module 2

    Customers report exfiltration and financial manipulation

    Customers using the new release report large unauthorized transfers. Some also report altered financial data and redirected bank payments. Every known victim installed the recent update.

  6. Day 31 · Afternoon
    Module 2

    Internal systems encrypted

    Investigators discover that core databases, files, and programs are encrypted. Operations stop, developers cannot work, and support teams cannot troubleshoot customer reports.

  7. Day 33
    Module 2

    Customers threaten suit; reporters call

    Customers threaten legal action over sensitive-data loss and reporters ask the organization to comment.

PARTICIPANTS

Bring the decision-makers who would own the real event

Assign people to functions, not titles alone. If one person owns several functions, keep the roles distinct during discussion so conflicts and handoffs remain visible.

Incident CommanderChief Information Security OfficerIT Operations LeadSecure Software Development LeadProduct Security or PSIRT LeadGeneral CounselCustomer Success LeadCommunications LeadThird-Party Risk LeadBusiness Continuity LeadExecutive Sponsor

REAL-WORLD INCIDENTS

Ground the exercise in events teams can recognize

Use these cases during planning or the prebrief. They are factual anchors, not scripts. Adapt the scenario to the organization’s technology, industry, geography, contracts, regulators, and risk profile.

LEGAL, REGULATORY & STANDARDS LENS

Authorities worth testing against the scenario

Applicability depends on the organization and facts. Use counsel and subject-matter owners to tailor deadlines, thresholds, privileges, preservation, reporting, and communications.

PRACTITIONER PERSPECTIVES

Law-firm and security-professional guidance

External perspectives help the design team challenge internal assumptions. They do not replace organization-specific legal or technical advice.

EXPECTED OUTPUT

Finish with an improvement plan, not a score.

  • Secure-development escalation criteria
  • Build and release containment decisions
  • Customer identification and support procedures
  • Legal and disclosure workstreams
  • A trust-restoration and corrective-release plan
Start with this exerciseRead the facilitator guide