CRISISTABLETOP
Rows of infrastructure racks in a large data center
← Exercise library

CRISIS TABLETOP ORIGINAL · THIRD-PARTY & OPERATIONAL RISK

Critical Vendor Outage

A strategic vendor becomes unavailable across regions. The provider cannot give a reliable restoration estimate, contractual remedies do not restore service, customers and regulators demand evidence, and a possible subcontractor compromise forces the organization to choose between risky partial recovery and an expensive migration.

2.5 HRSuggested duration10Participant roles12Scenario stages
Stock photography via Unsplash

EXERCISE PURPOSE

Test operational continuity, contract enforcement, customer and regulatory commitments, security coordination, failover, recovery, and strategic vendor decisions during a major third-party disruption.

A critical cloud provider suffers a prolonged outage complicated by weak transparency, possible data compromise, subcontractor failure, and an untested exit plan

DECISION PRESSURE

Questions the team must answer together

The facilitator releases facts in stages. Participants should identify the decision owner, the authority being used, the information still needed, the immediate action, and the next escalation point.

01

Which services fail first and who can activate workarounds?

02

Can the organization administer or recover critical systems without the vendor?

03

Do contract rights yield useful evidence, assistance, or transition support?

04

When does a service outage become a security, privacy, or disclosure event?

05

What conditions justify risky restoration, emergency replacement, or termination?

INSIDE THE EXERCISE

A scenario that changes as the response develops

The template is already populated with public injects, facilitator-only context, discussion prompts, private role messages, and a final hotwash.

  1. Tuesday · 08:05
    Module 1 · Outage and continuity

    Critical service becomes unavailable

    Users cannot access the organization’s strategic cloud platform. Automated monitoring shows failures in two regions, but the vendor status page reports only minor performance degradation.

  2. Tuesday · 08:45
    Module 1 · Outage and continuity

    No restoration estimate

    The vendor confirms a significant incident but will not provide a cause, scope, or restoration estimate. It asks customers not to open duplicate support tickets and promises another update in four hours.

  3. Tuesday · 09:30
    Module 1 · Outage and continuity

    Workarounds reach capacity

    Manual intake and spreadsheets keep priority work moving, but queues are growing quickly. Some teams begin copying production data into unsanctioned tools and personal accounts.

  4. Tuesday · 10:40
    Module 1 · Outage and continuity

    Customers invoke commitments

    Three major customers invoke contractual continuity and notification provisions. One demands an executive bridge and a written restoration estimate within an hour. Another threatens to suspend transactions and seek damages.

  5. Tuesday · 12:15
    Module 1 · Outage and continuity

    Failover is not ready

    The architecture team says an alternate provider could support the service, but credentials, data replication, licensing, network routes, and customer validation are incomplete. An emergency migration may take 24 to 72 hours and could lose recent transactions.

  6. Tuesday · 14:00
    Module 2 · Security, recovery, and exit

    Possible security incident disclosed

    The vendor reports that the outage began after suspicious activity in a management environment. It cannot yet rule out unauthorized access to customer data or administrative functions.

  7. Tuesday · 15:20
    Module 2 · Security, recovery, and exit

    Subcontractor failure revealed

    The vendor says a previously undisclosed infrastructure subcontractor is central to the incident. The subcontractor is not responding to the organization and the vendor will not provide its investigation report.

PARTICIPANTS

Bring the decision-makers who would own the real event

Assign people to functions, not titles alone. If one person owns several functions, keep the roles distinct during discussion so conflicts and handoffs remain visible.

Incident CommanderChief Information OfficerGeneral CounselProcurement and Vendor Risk LeadBusiness Continuity LeadChief Information Security OfficerPrivacy OfficerCustomer Operations LeadCommunications LeadExecutive Sponsor

REAL-WORLD INCIDENTS

Ground the exercise in events teams can recognize

Use these cases during planning or the prebrief. They are factual anchors, not scripts. Adapt the scenario to the organization’s technology, industry, geography, contracts, regulators, and risk profile.

LEGAL, REGULATORY & STANDARDS LENS

Authorities worth testing against the scenario

Applicability depends on the organization and facts. Use counsel and subject-matter owners to tailor deadlines, thresholds, privileges, preservation, reporting, and communications.

PRACTITIONER PERSPECTIVES

Law-firm and security-professional guidance

External perspectives help the design team challenge internal assumptions. They do not replace organization-specific legal or technical advice.

EXPECTED OUTPUT

Finish with an improvement plan, not a score.

  • A dependency and concentration-risk map
  • Usable vendor escalation and evidence requests
  • Validated continuity and exit assumptions
  • Customer and regulator communications triggers
  • Contract and architecture improvement priorities
Start with this exerciseRead the facilitator guide