EXERCISE PURPOSE
Examine the organization's ability to prevent, detect, investigate, contain, and recover from a fraudulent remote-worker infiltration while coordinating cybersecurity, employment, privacy, sanctions, export, contractual, law-enforcement, insurance, communications, and governance decisions.
A fraudulent remote IT employee uses a stolen identity, a U.S.-based laptop farm, remote-access tooling, and deceptive payment channels to obtain trusted access, copy sensitive information, generate revenue for the DPRK, and extort the employer after discovery.