CRISISTABLETOP
Professionals reviewing information together in a conference room
← Exercise library

CISA.GOV CTEP · INSIDER RISK

CISA Insider Threat Tabletop Exercise

A known hardware vulnerability, an accidental PII disclosure, and a hostile termination converge when the former employee joins a vendor and an attacker uses an unauthorized administrator account to destroy critical files.

3 HRSuggested duration10Participant roles13Scenario stages
Stock photography via Unsplash

EXERCISE PURPOSE

Examine cyber resilience in response to an insider-based cyber incident involving accidental disclosure, contentious termination, vendor access, and destructive misuse.

Malicious and unintentional insiders exploiting technical, personnel, and supply-chain weaknesses

DECISION PRESSURE

Questions the team must answer together

The facilitator releases facts in stages. Participants should identify the decision owner, the authority being used, the information still needed, the immediate action, and the next escalation point.

01

Who combines HR, physical-security, vendor, and cyber signals?

02

What monitoring is lawful, proportionate, documented, and technically useful?

03

When can access be limited before the facts are complete?

04

How will the team preserve evidence without alerting a suspected actor?

05

Who decides whether to notify individuals, customers, insurers, or law enforcement?

INSIDE THE EXERCISE

A scenario that changes as the response develops

The template is already populated with public injects, facilitator-only context, discussion prompts, private role messages, and a final hotwash.

  1. Day 1
    Module 1

    Known microprocessor vulnerability

    CISA releases information about frequently exploited CVEs. IT identifies a vulnerability in widely deployed microprocessors that may expose sensitive data.

  2. Day 2
    Module 1

    Replacement will take a year

    IT determines that the vulnerable microprocessors must be replaced. Cost and operational constraints produce a year-long replacement strategy.

  3. Day 8
    Module 1

    PII sent to external recipients

    An employee inadvertently emails PII belonging to the organization, customers, or clients to several external contacts.

  4. Day 9 · Morning
    Module 1

    Workplace conduct escalation

    During a meeting about the disclosure, a highly competent employee loudly berates a colleague. HR previously warned that another incident would result in termination.

  5. Day 9 · Afternoon
    Module 1

    Contentious termination

    Senior management terminates the employee for misconduct. The employee reacts angrily and warns management, “You will be sorry.”

  6. Day 13
    Module 2

    Replacement delay expands

    Replacement begins, but high demand for hardware extends the projected completion time from one year to 18 months.

  7. Day 23
    Module 2

    Former employee joins key vendor

    A key vendor reveals that it hired the terminated employee and promises that the person will not attend meetings with the organization.

PARTICIPANTS

Bring the decision-makers who would own the real event

Assign people to functions, not titles alone. If one person owns several functions, keep the roles distinct during discussion so conflicts and handoffs remain visible.

Incident CommanderChief Information Security OfficerIT Operations LeadHuman Resources LeadGeneral CounselPrivacy OfficerVendor Risk LeadBusiness Continuity LeadCommunications LeadExecutive Sponsor

REAL-WORLD INCIDENTS

Ground the exercise in events teams can recognize

Use these cases during planning or the prebrief. They are factual anchors, not scripts. Adapt the scenario to the organization’s technology, industry, geography, contracts, regulators, and risk profile.

LEGAL, REGULATORY & STANDARDS LENS

Authorities worth testing against the scenario

Applicability depends on the organization and facts. Use counsel and subject-matter owners to tailor deadlines, thresholds, privileges, preservation, reporting, and communications.

PRACTITIONER PERSPECTIVES

Law-firm and security-professional guidance

External perspectives help the design team challenge internal assumptions. They do not replace organization-specific legal or technical advice.

EXPECTED OUTPUT

Finish with an improvement plan, not a score.

  • A multidisciplinary insider-risk escalation path
  • Improved joiner-mover-leaver controls
  • Clear privacy and investigation boundaries
  • Tested vendor-access revocation
  • Evidence and communication protocols
Start with this exerciseRead the facilitator guide