EXERCISE PURPOSE
Assess and improve enterprise resilience to a major cyber incident affecting an information-technology company and its customers.
Malware introduced through a third-party application and propagated to customers in a software update
CISA.GOV CTEP · SOFTWARE & SUPPLY CHAIN
An employee installs a compromised application, attackers enter the development environment, and the organization unknowingly ships malware to customers. Data theft, financial manipulation, internal encryption, lawsuits, and media scrutiny follow.
EXERCISE PURPOSE
Malware introduced through a third-party application and propagated to customers in a software update
DECISION PRESSURE
The facilitator releases facts in stages. Participants should identify the decision owner, the authority being used, the information still needed, the immediate action, and the next escalation point.
What can reach build, signing, and release systems?
Can the organization identify every customer and artifact receiving a compromised build?
Who can suspend distribution and direct customers to disconnect?
How are internal response and customer incident support coordinated?
What proof is required before a corrected release is trusted?
INSIDE THE EXERCISE
The template is already populated with public injects, facilitator-only context, discussion prompts, private role messages, and a final hotwash.
CISA warns that state-sponsored actors are targeting software and firmware companies and their customers, compromising products to gain access to critical-infrastructure networks.
A software-development employee downloads an application from an official third-party vendor website and installs it successfully.
The organization publishes a software update and urges customers to install it promptly.
An employee detects a high volume of data leaving organizational servers for an unauthorized IP address in a foreign country.
Customers using the new release report large unauthorized transfers. Some also report altered financial data and redirected bank payments. Every known victim installed the recent update.
Investigators discover that core databases, files, and programs are encrypted. Operations stop, developers cannot work, and support teams cannot troubleshoot customer reports.
Customers threaten legal action over sensitive-data loss and reporters ask the organization to comment.
PARTICIPANTS
Assign people to functions, not titles alone. If one person owns several functions, keep the roles distinct during discussion so conflicts and handoffs remain visible.
REAL-WORLD INCIDENTS
Use these cases during planning or the prebrief. They are factual anchors, not scripts. Adapt the scenario to the organization’s technology, industry, geography, contracts, regulators, and risk profile.
CISA directed federal agencies to disconnect affected Orion products after malicious code was distributed through trusted software updates.
3CX DesktopApp compromise↗A trojanized communications application enabled multi-stage downstream compromise.
MOVEit exploitation↗Mass exploitation of internet-facing file-transfer software drove widespread customer, notice, and vendor-coordination work.
LEGAL, REGULATORY & STANDARDS LENS
Applicability depends on the organization and facts. Use counsel and subject-matter owners to tailor deadlines, thresholds, privileges, preservation, reporting, and communications.
The source collection for CISA Tabletop Exercise Packages covering ransomware, insider threats, phishing, supply-chain compromise, and sector incidents.
SEC cybersecurity incident disclosure rules↗Public companies must assess materiality and disclose material incidents on Form 8-K Item 1.05 within four business days after the materiality determination, subject to the rule’s limited delay process.
NIST SP 800-161 Rev. 1 Update 1↗Test software-supply-chain governance, critical suppliers, provenance, monitoring, response, and recovery.
PRACTITIONER PERSPECTIVES
External perspectives help the design team challenge internal assumptions. They do not replace organization-specific legal or technical advice.
EXPECTED OUTPUT