EXERCISE PURPOSE
Examine cyber resilience and third-party response capabilities during a significant supply-chain incident.
Long-dwell compromise of a managed service provider platform and downstream customer environments
CISA.GOV CTEP · THIRD-PARTY & OPERATIONAL RISK
After public warnings about an MSP software compromise, the organization adopts a new MSP. Six months later, access fails, critical operations stop, and investigators find that the MSP platform may have carried malicious code for two years.
EXERCISE PURPOSE
Long-dwell compromise of a managed service provider platform and downstream customer environments
DECISION PRESSURE
The facilitator releases facts in stages. Participants should identify the decision owner, the authority being used, the information still needed, the immediate action, and the next escalation point.
What warning would cause a vendor reassessment or access restriction?
Can every vendor connection, credential, system, and data flow be identified and revoked?
Who can delay a signed vendor update based on supply-chain risk?
Can the business operate and administer systems without the MSP?
What evidence supports rebuilding, replacing, or reconnecting the vendor platform?
INSIDE THE EXERCISE
The template is already populated with public injects, facilitator-only context, discussion prompts, private role messages, and a final hotwash.
CISA and the FBI respond to global ransomware attacks against MSPs and downstream customers through a vulnerable remote-monitoring platform. The software is shut down and critical services across many sectors are disrupted. The organization is not currently affected.
The organization contracts with a trusted MSP. Its platform is installed and updated without intrusion-detection alerts.
Data from several sector partners appears on the dark web. Some of those partners recommended the new MSP.
IT authorizes installation of a functionality update from the MSP on a critical system.
Six months later, employees cannot sign in. The help desk is overwhelmed, and the MSP help desk cannot be reached.
Employees still cannot access the network and business-critical systems are significantly affected.
An independent cybersecurity company reports that the MSP platform was compromised and may have placed malware on customer systems for up to two years. It recommends identifying and eradicating the malicious code.
PARTICIPANTS
Assign people to functions, not titles alone. If one person owns several functions, keep the roles distinct during discussion so conflicts and handoffs remain visible.
REAL-WORLD INCIDENTS
Use these cases during planning or the prebrief. They are factual anchors, not scripts. Adapt the scenario to the organization’s technology, industry, geography, contracts, regulators, and risk profile.
The attack demonstrated how remote-management tooling can amplify harm through MSP and customer ecosystems.
SolarWinds Orion compromise↗The response required rapid inventory, disconnection, threat hunting, credential work, and rebuilding trust in affected environments.
CrowdStrike outage and concentration risk↗Although not a cyberattack, the outage is a strong exercise analogue for automated vendor updates, systemic concentration, and manual recovery at scale.
LEGAL, REGULATORY & STANDARDS LENS
Applicability depends on the organization and facts. Use counsel and subject-matter owners to tailor deadlines, thresholds, privileges, preservation, reporting, and communications.
The source collection for CISA Tabletop Exercise Packages covering ransomware, insider threats, phishing, supply-chain compromise, and sector incidents.
NIST Cybersecurity Supply Chain Risk Management↗Use it to compare procurement, technical, contractual, monitoring, and incident-response decisions.
EU DORA↗For covered financial entities, DORA makes third-party failure and continuity testing a central operational-resilience issue.
PRACTITIONER PERSPECTIVES
External perspectives help the design team challenge internal assumptions. They do not replace organization-specific legal or technical advice.
Recommends regular vendor assessments, clear incident protocols, contractual expectations, and exercises involving suppliers.
CrowdStrike tabletop exercise guidance↗Security-practitioner guidance emphasizing realistic injects, tailored scenarios, decision-making, communications, and coordination.
EXPECTED OUTPUT