CRISISTABLETOP
Data center racks representing critical managed technology services
← Exercise library

CISA.GOV CTEP · THIRD-PARTY & OPERATIONAL RISK

CISA Vendor Supply-Chain Compromise

After public warnings about an MSP software compromise, the organization adopts a new MSP. Six months later, access fails, critical operations stop, and investigators find that the MSP platform may have carried malicious code for two years.

3 HRSuggested duration11Participant roles9Scenario stages
Stock photography via Unsplash

EXERCISE PURPOSE

Examine cyber resilience and third-party response capabilities during a significant supply-chain incident.

Long-dwell compromise of a managed service provider platform and downstream customer environments

DECISION PRESSURE

Questions the team must answer together

The facilitator releases facts in stages. Participants should identify the decision owner, the authority being used, the information still needed, the immediate action, and the next escalation point.

01

What warning would cause a vendor reassessment or access restriction?

02

Can every vendor connection, credential, system, and data flow be identified and revoked?

03

Who can delay a signed vendor update based on supply-chain risk?

04

Can the business operate and administer systems without the MSP?

05

What evidence supports rebuilding, replacing, or reconnecting the vendor platform?

INSIDE THE EXERCISE

A scenario that changes as the response develops

The template is already populated with public injects, facilitator-only context, discussion prompts, private role messages, and a final hotwash.

  1. Day 1
    Module 1

    Global MSP ransomware warning

    CISA and the FBI respond to global ransomware attacks against MSPs and downstream customers through a vulnerable remote-monitoring platform. The software is shut down and critical services across many sectors are disrupted. The organization is not currently affected.

  2. Day 7
    Module 1

    New MSP platform installed

    The organization contracts with a trusted MSP. Its platform is installed and updated without intrusion-detection alerts.

  3. Day 8
    Module 1

    Sector-partner data appears on dark web

    Data from several sector partners appears on the dark web. Some of those partners recommended the new MSP.

  4. Day 10
    Module 1

    MSP update authorized on critical system

    IT authorizes installation of a functionality update from the MSP on a critical system.

  5. Day 182 · Morning
    Module 2

    Organization-wide sign-in failure

    Six months later, employees cannot sign in. The help desk is overwhelmed, and the MSP help desk cannot be reached.

  6. Day 182 · Afternoon
    Module 2

    Critical systems remain unavailable

    Employees still cannot access the network and business-critical systems are significantly affected.

  7. Day 182 · Evening
    Module 2

    MSP compromise disclosed by third party

    An independent cybersecurity company reports that the MSP platform was compromised and may have placed malware on customer systems for up to two years. It recommends identifying and eradicating the malicious code.

PARTICIPANTS

Bring the decision-makers who would own the real event

Assign people to functions, not titles alone. If one person owns several functions, keep the roles distinct during discussion so conflicts and handoffs remain visible.

Incident CommanderChief Information Security OfficerIT Operations LeadThird-Party Risk LeadProcurement LeadGeneral CounselBusiness Continuity LeadBusiness Service OwnerCommunications LeadCyber Insurance LiaisonExecutive Sponsor

REAL-WORLD INCIDENTS

Ground the exercise in events teams can recognize

Use these cases during planning or the prebrief. They are factual anchors, not scripts. Adapt the scenario to the organization’s technology, industry, geography, contracts, regulators, and risk profile.

LEGAL, REGULATORY & STANDARDS LENS

Authorities worth testing against the scenario

Applicability depends on the organization and facts. Use counsel and subject-matter owners to tailor deadlines, thresholds, privileges, preservation, reporting, and communications.

PRACTITIONER PERSPECTIVES

Law-firm and security-professional guidance

External perspectives help the design team challenge internal assumptions. They do not replace organization-specific legal or technical advice.

EXPECTED OUTPUT

Finish with an improvement plan, not a score.

  • An inventory of privileged vendor dependencies
  • Actionable contract and escalation rights
  • Tested degraded-mode operations
  • Provider-isolation and access-revocation procedures
  • Trusted restoration and exit criteria
Start with this exerciseRead the facilitator guide