Energy and Infrastructure
Ember Forge: Response
Publication date: 07/2026
| Attack Vector | Injects | Options |
| Supply Chain Compromise | 14 | 38 |
A proactive threat hunt at Orchid Fusion's Cyber Fusion Center is about to turn real. You are the on-call incident commander. Corroborated cross-sector intelligence warns that a state-aligned adversary is targeting energy-sector R&D networks, abusing valid remote access and moving fast once inside, but the tradecraft is generic and there are no internal indicators of compromise yet. Orchid Fusion is a decentralized, partner-heavy division under intense pressure to deliver Project Ember smart-grid models: legacy Windows alongside unmonitored Linux jump hosts, with round-the-clock partner access for engineering firm Apex Grid Solutions. Over one shift, you must decide how hard to hunt, how surgically to contain, and when to escalate. You'll need to balance a live intrusion against a $250,000-per-hour Apex downtime penalty and a division that treats security as a brake on innovation. This is the tactical track. It ends by handing command to the executive crisis management team, where the strategic and regulatory fallout plays out.
Ember Forge: US Command
Publication date: 07/2026
| Attack Vector | Injects | Options |
| Supply Chain Compromise | 10 | 31 |
Orchid Energy Group (OEG) is a publicly traded, multinational energy conglomerate headquartered in Houston, Texas (roughly $18bn market cap, $6bn annual revenue). OEG operates registered bulk-electric-system assets in North America and an energy business in the EU, so it is subject to NERC CIP, US Department of Energy reporting, and EU NIS2 obligations. Its highly autonomous R&D subsidiary, Orchid Fusion, runs the "Project Ember" smart grid initiative (analysts attribute roughly $4bn of OEG's valuation to it) in a joint venture with external engineering partner Apex Grid Solutions. It's backed by two powerful minority shareholders: Ironwood Capital (a US private equity firm) and the Saker Royal Investment Fund (SRIF, an Abu Dhabi sovereign wealth fund). Fusion runs its own Active Directory forest, connected to OEG corporate by a forest trust – a deliberate legacy of the subsidiary's autonomy. Overnight, the tactical teams at Fusion fought a losing battle against APT33 , an Iranian state-sponsored threat actor. The adversary now holds a forged "Golden Ticket" in the Fusion forest – full, stealthy Domain Admin control that the forest trust lets them extend toward the corporate forest. Project Ember's intellectual property is compromised, and CISA intelligence warns that APT33 uses this level of access to map gateways into operational technology (OT). The physical grid is now held at risk. You are the chair of OEG's crisis management team (CMT), appointed under a board-delegated crisis mandate. You drive the strategic response and the recommendations that go to the board and its committees; you don't personally sign regulatory filings. The tactical fight is over. Your job is to manage the fallout and guide the recovery – balancing containment, overlapping regulatory clocks, furious partners and investors, and an active geopolitical threat.
Operation Pressure Test
Publication date: 05/2025
| Attack Vector | Injects | Options |
| Cyber threats targeting industrial control systems | 40 | 133 |
As Ganymede's site manager after a recent acquisition, you face a localized cyberattack that led the Texas Railroad Commission to suspend operations. With legacy systems not yet aligned to Orchid Energy, you must run an IT/OT penetration test, remediate weaknesses, and deliver evidence that OT is protected from unauthorized access, control, and manipulation to restart production. You'll decide test scope and methods, coordinate OT/IT/security and vendors, manage evidence and change control, and prioritize fixes while balancing safety, downtime, and regulatory expectations. The scenario sharpens risk-based communication and decision-making with regulators, corporate leaders, and field staff against cyber threats targeting industrial control systems. Ideal for site leaders, OT/IT security managers, incident responders, and compliance professionals in energy and other critical infrastructure.
Orchid Energy: Pipeline Panic
Publication date: 05/2025
| Attack Vector | Injects | Options |
| Targeted Attack | 24 | 65 |
In Orchid Energy: Pipeline Panic, participants confront a targeted nation-state cyberattack against newly acquired oil field operations controlled via Siemens PLCs, HMIs, and a compact SCADA system. With IT monitored by Splunk but the OT network largely blind except for a passive packet capture, suspected manipulation of pumpjacks, pipelines, and potentially a safety instrumented system triggers operational disruption, safety risk, and regulatory scrutiny across Orchid Energy's Midland-based control center. Success demands rapid, cross-functional decision-making: distinguishing IT vs OT impacts, safely isolating and restoring industrial processes, prioritizing safety over production, coordinating Incident and Crisis Management Teams, communicating with executives and stakeholders, and fulfilling regulatory obligations. The exercise emphasizes asset visibility, OT monitoring, M&A cybersecurity due diligence, and crisis leadership under pressure. Ideal for incident responders, OT engineers, security leaders, and crisis managers in energy and other critical infrastructure sectors.
Crisis at the Dam
Publication date: 12/2024
| Attack Vector | Injects | Options |
| Severe weather and flooding | 10 | 37 |
In Crisis at the Dam, you lead the crisis management team for a hydroelectric facility battered by days of extreme rain. Reservoir levels surge, structural and operational limits are tested, and your choices---about spillway releases, staff safety, and downstream alerts---shape community outcomes and grid stability. The exercise demands rapid risk assessment, interpreting hydrological and engineering data, activating emergency action plans, coordinating with regulators and first responders, managing evacuations, and clear public and media communication while balancing ethical trade-offs and environmental impacts. This severe weather and flooding threat scenario, with potential critical infrastructure failure, benefits utility operators, crisis leaders, emergency managers, operations and communications teams, and any organization responsible for lifeline infrastructure or business continuity.
Orchid Energy: Trial by Fire and Data
Publication date: 11/2024
| Attack Vector | Injects | Options |
| Targeted Attack | 16 | 54 |
Orchid Energy's 'Trial by Fire and Data' plunges participants into a polycrisis sparked by a targeted attack that cascades across IT, OT, and corporate domains. As members of the Crisis Management Team, they confront simultaneous cyber intrusions, operational disruption, safety and environmental risks, media escalation, and shaken stakeholders, making time-pressured choices across 16 injects. Success demands rapid triage, prioritization, cross-functional coordination, disciplined incident communications, ethical leadership, regulatory and legal awareness, and clear trade-offs between containment, continuity, and safety while managing incomplete information. Designed for crisis leaders, CISOs, security and risk managers, and operations and communications leads in energy and other critical infrastructure, this exercise builds readiness to handle targeted-attack-driven polycrises and strengthens decision making, stakeholder trust, and resilience.
DEWA IT/OT Sabotage: Drinking Water Poisoning
Publication date: 09/2024
| Attack Vector | Injects | Options |
| Targeted Attack | 7 | 20 |
Critical infrastructure crisis scenario focusing on water sector threats. DEWA employee must respond to potential hostile state interference while managing system overwhelm during high-demand periods.
Malicious Code: Incident Responder
Publication date: 08/2023
| Attack Vector | Injects | Options |
| Malicious Code | 11 | 41 |
In this simulation, you serve as an incident responder within TalkCom's SOC, confronting a malicious code incident against a national telecom with hybrid-remote staff. As criminal actors target remote access and core services, you'll navigate 11 time-pressured injects that influence network availability, customer trust, and the secure communications relied on by emergency services and government users. You'll demonstrate situational awareness, triage and escalation, and rapid containment decisions (e.g., isolating hosts, tightening VPN access), select eradication and recovery actions, and communicate effectively with technical teams and leadership. The exercise emphasizes applying crisis management procedures, understanding business impacts, and reflecting on outcomes across identification, containment, eradication, recovery, and lessons learned. Ideal for SOC analysts, incident responders, and security leaders---especially in critical infrastructure or distributed-workforce environments---seeking practice against criminal group--driven malicious code threats.
Oldsmar Poisoned Water
Publication date: 10/2021
| Attack Vector | Injects | Options |
| Targeted Attack | 13 | 46 |
This crisis simulation places you as the Incident Manager of a Michigan water treatment plant during a targeted nation-state intrusion modeled on Oldsmar. Under resource constraints and increased remote access use, an attacker attempts to manipulate chemical dosing through IT/OT pathways, creating an urgent public health and operational risk across 13 timed decision points. You will triage and validate SCADA anomalies, contain compromised remote access (e.g., TeamViewer), coordinate safe plant operations, and balance evidence preservation with rapid mitigation. The exercise tests stakeholder communications, regulatory and public health notifications, engagement with law enforcement, and post-incident recovery planning. It is designed for incident managers, OT/IT security teams, and critical infrastructure leaders seeking to strengthen decision-making against targeted attacks on water and wastewater systems aligned to CISA guidance.
Entertainment/Media
Attacker Perspective: Spearphishing
Publication date: 10/2023
| Attack Vector | Injects | Options |
| Malicious Code | 9 | 28 |
In this attacker-perspective crisis simulation, you play a novice hacktivist tasked with spearphishing a video game publisher criticized for excessive staff hours. Working from a supplied dossier, you navigate nine decision points---from OSINT reconnaissance and target selection to crafting persuasive lures and delivering malicious code---while weighing impact against exposure and adapting to basic defenses. The scenario illustrates how readily publicly available information and lax controls can be exploited to gain initial access and cause disruption. Participants must demonstrate social engineering judgement, payload selection, operational security, and risk-based decision-making. Focused on a politically/socially motivated hacktivist threat using spearphishing and malware, this exercise benefits security leaders, blue teams, incident responders, and awareness practitioners---particularly in entertainment and media---by sharpening understanding of attacker mindset, refining phishing defenses, and reinforcing vigilance against opportunistic intrusion paths.
Financial Services
Hugging Face: The Challenges of AI-Driven Incident Response
Publication date: 08/2026
| Attack Vector | Injects | Options |
| Supply Chain Compromise | 9 | 31 |
Orchid Corp is a $38-billion financial services group headquartered in Charlotte. Its digital payments arm, OrchidPay, settles funds for around 14,000 small-business merchants across the South East. Over the weekend, something moved through the estate. On Monday morning, the incident management team convenes with every log it could ask for, a regulatory clock already running, and a problem nobody's playbook covers. You are that team. The evidence is all there. The question is whether you can read it in time.
PagoSol: Command
Publication date: 07/2026
| Attack Vector | Injects | Options |
| Targeted Attack | 10 | 28 |
Welcome to the executive boardroom of Orchid Bank during a multi-front enterprise crisis. The focus has shifted from tactical IT containment to global corporate survival. A state-sponsored identity collapse has collided with a natural disaster and a $300-million global marketing launch. The crisis management team must navigate overlapping international regulatory clocks, severe societal disruption, and systemic financial contagion risk. You are the CMT chair, the ultimate strategic authority. You'll need to address complex, multi-jurisdictional disasters with decisive corporate action, while managing a concerned C-suite, external breach counsel, and aggressive international regulators. Every containment decision costs revenue, brand, or regulatory standing, and your hardest calls weigh Orchid Bank's commercial survival against the stability of the global financial sector.
PagoSol: Response
Publication date: 07/2026
| Attack Vector | Injects | Options |
| Targeted Attack | 9 | 27 |
Welcome to the Orchid Bank Cyber Fusion Center during the final week of the Q2 close. Your security team is stretched thin. The fragile data integration of newly acquired fintech PagoSol is generating millions of benign alerts across a hybrid cloud and legacy mainframe environment. At the same time, urgent intelligence warns of sophisticated adversaries masking targeted espionage behind global geopolitical noise. You are the SOC/CFC incident commander, the ultimate tactical authority during an active cyber event. You must ruthlessly prioritize threats by enterprise risk rather than raw alert volume, and balance aggressive containment against the uptime of revenue-critical banking integrations. When the keyboard can no longer hold the line, you decide how the crisis reaches the boardroom.
Shadow Tasks: Polymorphic Persistence (SOC Micro-Exercising)
Publication date: 07/2026
| Attack Vector | Injects | Options |
| Targeted Attack | 4 | 13 |
This is a short micro-exercise designed to test the responses and decisions of a Tier 3 threat hunter, followed by a practical exercise. Outcomes: Practice response to an incident involving polymorphic persistence Correctly triage IR based on a simulated playbook Balance conservative security choices against anticipated operational impacts
Faulty Baseline: AI Identity Governance Failure (SOC Micro-Exercising)
Publication date: 06/2026
| Attack Vector | Injects | Options |
| Unauthorized Access | 4 | 13 |
This is a short micro-exercise designed to test the responses and decisions of an identity and access management analyst. It's then followed up with a practical exercise. Analysts must choose whether to act on guidance generated by an AI agent used within the SOC. Subsequent decisions include access privilege changes and post-incident corrective actions. Outcomes: Assess the accuracy of agentic alert triaging guidance Interpret incident response playbooks Choose the appropriate response to unintended SOC agent behavior
Phantom Minutes
Publication date: 06/2026
| Attack Vector | Injects | Options |
| Human Error | 13 | 43 |
Cardinal Financial Group has been responding to a data exposure incident at one of its document vendors. It's now day three. The incident has felt under control so far. Your teams meet on bridge calls throughout the day, and an AI assistant writes the minutes everyone works from. This afternoon, you're due to brief the board. As you build the update from the official record, something in it doesn't match what you remember deciding . You lead incident management. The whole response has rested on that record. Now you have to find out whether you can trust it.
Project Mythos
Publication date: 06/2026
| Attack Vector | Injects | Options |
| Targeted Attack | 25 | 63 |
Mythos, a next-generation AI vulnerability scanner, has just gone on general release — and Orchid Bank, a tier-1 G-SIB processing over $6 trillion daily through its London payments engine, ran its first approved production scan over the weekend. Now the Security Engineering Lead is outside your office, and he says it's urgent.
Participants take on the role of the senior technology leadership team and must navigate a rapidly escalating incident while juggling a brutal set of competing priorities.
The Flashpoint Podcast – Orchid Investments
Publication date: 11/2024
| Attack Vector | Injects | Options |
| Targeted Attack | 24 | 37 |
The Flashpoint Podcast -- Orchid Investments puts you in the COO's seat as crisis lead when the firm's AI-driven trading systems behave erratically after a targeted attack, triggering major losses, client panic, and intense media scrutiny. Delivered as a podcast-style flashback with branching choices, you navigate escalating technical, financial, and reputational stakes in real time. You'll identify early warning signs, coordinate incident response and business continuity, make high-pressure decisions on trading halts, disclosures, and recovery, and craft tailored communications for clients, regulators, and the press. The exercise emphasizes AI security, model governance, and ethical risk trade-offs while working with IT, legal, compliance, and PR to stabilize operations and rebuild trust. This targeted-attack crisis simulation benefits C-suite executives, senior managers, IT leaders, and risk management professionals seeking to sharpen decision-making and communication skills in AI-driven financial environments.
The Flashpoint Podcast: Orchid Investments
Publication date: 11/2024
| Attack Vector | Injects | Options |
| Targeted Attack | 24 | 37 |
COO manages erratic AI trading systems after a targeted attack.
Conti Ransomware Al-Rajhi Bank
Publication date: 07/2024
| Attack Vector | Injects | Options |
| Ransomware | 17 | 43 |
Ransomware attack scenario where an understaffed SOC team (only 3 members available) must respond to Conti ransomware encryption spreading through bank systems in real-time.
Bank Heist
Publication date: 04/2024
| Attack Vector | Injects | Options |
| Targeted Attack | 10 | 33 |
In Bank Heist, you act as the bank's crisis management team after a major theft of cash reserves. You must stabilize operations, secure assets against follow-on threats, manage liquidity, coordinate with law enforcement and regulators, and reassure customers and markets while the situation evolves through timed injects. Success demands rapid risk assessment, prioritization, and trade-off decisions across communications, financial liquidity, fraud and physical security controls, regulatory disclosure, and business continuity. Participants will practice stakeholder alignment, decision logging, and recovery planning under pressure. Designed around a targeted attack by criminal groups, this exercise benefits executives, crisis managers, risk, communications, and operations leaders in banks and other financial institutions seeking to test strategy, coordination, and resilience.
Natural Disaster - Wildfire
Publication date: 09/2023
| Attack Vector | Injects | Options |
| Natural Disaster | 35 | 101 |
This simulation places the Crisis Management Team in an escalating natural disaster as a previously contained wildfire, driven by strong winds, threatens the head office and hybrid workers' homes while government alerts are issued. Participants must decide when to declare a crisis, coordinate evacuations and continuity arrangements, manage dispersed teams, and communicate with employees, clients, media, and authorities while monitoring social media and market sentiment. They will also confront opportunistic phishing and security risks, requests for community support, and trade-offs that affect safety, operations, reputation, and share price indicators. The exercise develops skills in leadership under pressure, cross-functional coordination, stakeholder communications, cybersecurity vigilance, and recovery planning. It is ideal for crisis management teams, executives, business continuity, communications/PR, HR, facilities, and security leaders preparing for wildfire and other natural hazard scenarios.
Digital Operational Resilience Act (DORA)
Publication date: 04/2023
| Attack Vector | Injects | Options |
| Malicious Code | 27 | 92 |
This scenario is designed to educate your crisis management and governance, risk, and compliance teams on how best to respond to a cyber crisis with the implementation of the Digital Operational Resilience Act (DORA).
The Digital Operational Resilience Act (DORA)is a piece of legislation focused on improving incident reporting, consistency of IT incident classification, and information sharing in the financial sector.
Operation Chimera: Lycia Pensions
Publication date: 09/2022
| Attack Vector | Injects | Options |
| Data Breach | 24 | 83 |
This scenario is a companion to the Operation Chimera Team Sim and must be run alongside it, placing you inside Lycia, a mid-sized, cross-border pensions provider, as a Sunday-morning data breach by criminal groups hits its customer app and back-end. With the central security team out of hours and new corporate accounts raising the stakes, Technical, Head of CMT, and Application Security roles coordinate real-time decisions across 24 injects to stabilize operations. Participants will triage alerts, contain and investigate exfiltration, preserve evidence, harden applications, and weigh service continuity against risk. They will craft customer and regulator communications, manage media and executives, meet multi-jurisdictional reporting obligations, and balance reputational, financial, and legal impacts. This exercise benefits crisis managers, SOC/IR practitioners, and application security leaders who need to practice coordinated technical response and judgment under pressure against a criminal data-breach threat.
Master Key Compromise
Publication date: 09/2021
| Attack Vector | Injects | Options |
| Unauthorized Access | 18 | 58 |
Based on South African Postbank incident (December 2018). Mailbank crisis team responds to insider threat involving stolen master key, managing cryptographic key regeneration and PCI DSS compliance (NIST SP 800-57).
Chatbot Hack
Publication date: 05/2021
| Attack Vector | Injects | Options |
| Malicious Code, Data Breach, Ransomware | 11 | 36 |
In Chatbot Hack, you act as ZedTech's Incident Response Manager when a spearphishing campaign by criminal groups hijacks the Tommy customer chatbot and pivots into ransomware across a fast-growing FinTech platform. As customer queries spike and GDPR obligations come under scrutiny, you must triage the attack, contain malicious code, determine data breach scope, and restore critical services while protecting both retail and corporate clients. Success depends on enforcing a clear chain of command, coordinating IT, legal, and communications, crafting transparent customer and regulator messaging, making measured ransom and recovery decisions, and reinforcing staff security awareness. This exercise focuses on spearphishing, chatbot manipulation, ransomware, and potential data exfiltration, and is ideal for incident managers, SOC and security leaders, and business stakeholders in financial services or any organization operating customer-facing applications.
IT and Reputational Disaster
Publication date: 04/2021
| Attack Vector | Injects | Options |
| Data Breach, Phishing, Unauthorised Access | 17 | 50 |
Step into Greenfunds Bank's Executive Crisis Management Team as a phishing-led compromise snowballs into unauthorized access and a customer data breach at a digital-only, eco-branded bank. Across 17 decision points, you'll navigate live service disruption, hostile social media, regulatory attention, and investor concerns while protecting a brand built on transparency and security. Success requires rapid detection and containment (identifying IoCs, enforcing MFA, revoking access, securing cloud data), clear prioritization of service continuity, and timely GDPR/FCA notifications. You must balance legal, technical, and reputational trade-offs; craft accurate customer and press statements; and steer cross-functional teams through ambiguity as criminal groups and political/social activists exploit the incident. This exercise strengthens executive decision-making, incident command, and communications skills for leaders in financial services and other cloud-reliant, regulated organizations seeking to improve operational resilience and crisis readiness.
Network Abduction
Publication date: 02/2021
| Attack Vector | Injects | Options |
| Supply Chain Compromise | 40 | 131 |
Supply chain compromise scenario similar to SolarWinds/SUNBURST. Focus on investigating software compromise impact and determining necessary organizational response.
Phishing Compromise
Publication date: 10/2020
| Attack Vector | Injects | Options |
| Phishing, Remote Working | 121 | 428 |
Acting as Head of IT during a pandemic-driven shift to full remote work, you must ready a largely inexperienced workforce on Office 365 while defending against rampant phishing and insider missteps. With nearly half the IT budget fixed for operations, you'll prioritize controls and communications that sustain productivity without weakening security. Success requires setting clear, plain English policies, enabling pragmatic safeguards (MFA, email filtering, conditional access, device management), coordinating with leadership to drive adoption, and triaging phishing incidents as they unfold. The exercise focuses on phishing and remote-working risks from criminal groups and employees, and is ideal for IT leaders and security managers who need to balance business continuity with cyber resilience in O365-centric organizations.
Travelex Vs REvil
Publication date: 06/2020
| Attack Vector | Injects | Options |
| Data Breach, Phishing, Ransomware, Targeted Attack | 36 | 111 |
Step into the Leader of the Executive Committee as Travelex confronts a Sodinokibi/REvil-style ransomware attack that cripples customer-facing systems and threatens data exposure. Across a fast-paced hour, you'll navigate mounting pressure from criminal extortionists, operational shutdowns, and the risk of prolonged business disruption while balancing regulatory, customer, and media scrutiny. Success demands decisive incident leadership: contain and triage, direct technical recovery and offline restoration, weigh ransom payment versus rebuild, manage stakeholder communications, coordinate with law enforcement and regulators, and mitigate impacts from phishing-led intrusion and data breach. This targeted ransomware scenario benefits executives, crisis managers, incident commanders, communications leads, and security leaders seeking to strengthen decision-making, governance, and resilience when faced with sophisticated criminal groups.
Government
Puppetmaster's Trick or Treat
Publication date: 10/2025
| Attack Vector | Injects | Options |
| Targeted Attack | 9 | 33 |
This immersive crisis simulation places you in a national Crisis Management Team responding to a targeted cyberattack on critical national infrastructure. As the theatrical adversary "Puppetmaster" escalates a Halloween-themed campaign, you must manage cascading disruption while confronting ethical dilemmas and intense public scrutiny. The scenario streamlines technical and governmental processes to emphasize decisive leadership under uncertainty and time pressure. Participants will practice establishing command, prioritizing competing national interests, coordinating across agencies and operators, and shaping a credible public narrative, while balancing choices around negotiation, containment, and attribution---each with consequences. Focused on a sophisticated targeted cyber threat with psychological manipulation, this exercise benefits crisis leaders, CNI operators, government responders, CISOs, communications heads, and executive incident response teams seeking sharper judgement, stakeholder coordination, and resilient leadership.
Embassy Bomb Threat
Publication date: 01/2023
| Attack Vector | Injects | Options |
| Physical terrorism threats | 41 | 141 |
This crisis simulation places you at the British embassy in a crowded European capital amid a severe national threat level and a credible bomb threat. As head of security or head of communications, you must manage a fast-moving incident in a dense government and public precinct frequented by VIPs, commuters, and tourists. Participants will practice threat verification, protective security, and incident command; decide on evacuation versus shelter-in-place; coordinate with police, emergency services, and neighboring sites; and maintain clear internal and external communications, media messaging, and stakeholder updates while safeguarding staff, visitors, and diplomatic principals. The exercise tests prioritization, situational awareness, and continuity planning under geopolitical pressure. It is designed for embassy teams, government departments, corporate security and crisis communications leaders, and any organization operating high-risk facilities or overseas offices facing physical terrorism threats.
Security Agency Breached
Publication date: 01/2022
| Attack Vector | Injects | Options |
| Supply Chain Compromise | 11 | 41 |
Based on SolarWinds supply chain attack targeting government agencies. Government agency employee navigates consequences of a sophisticated "sniper" attack on organizational infrastructure.
Healthcare
Healthcare Al
Publication date: 10/2023
| Attack Vector | Injects | Options |
| AI governance/third-party technology risk | 23 | 42 |
In a bid to revolutionize healthcare, PXT Healthcare Group has integrated an AI-driven diagnostic tool, developed by HealthUTech. Praised for its innovation, this system promised to streamline the diagnostic process, reduce the workload on healthcare professionals, and improve patient outcomes. However, a failure to verify the data inputted into the tool, coupled with a lack of oversight on its outputs, has led to a series of misdiagnoses and incorrect treatment plans being administered. PXT Healthcare Group and the future of AI in healthcare are now under significant scrutiny.
In this crisis exercise, participants must navigate a series of critical decisions, balancing patient safety, operational demands, and stakeholder management.
Hospital Meltdown
Publication date: 11/2021
| Attack Vector | Injects | Options |
| Ransomware | 20 | 73 |
Based on October 2021 Hillel Yaffe Medical Center ransomware attack in Israel. Seraphim Jacob Medical Center team responds with systems offline, managing patient safety, staff overwhelm, and using manual workarounds.
Patient Record Compromise
Publication date: 11/2020
| Attack Vector | Injects | Options |
| Ransomware | 52 | 178 |
Ransomware attack on for-profit healthcare organization during COVID-19 pandemic. Teams balance preventing avoidable deaths with industry regulation compliance while managing system outages.
Logistics and Supply Chain
Terminal Turmoil
Publication date: 09/2025
| Attack Vector | Injects | Options |
| Supply Chain Compromise | 6 | 19 |
Orchid Airlines responds to crisis affecting AeroPass (third-party SaaS platform managing check-in, boarding, and passenger operations). Teams manage infrastructure failure with reduced on-site staffing due to prior efficiency cuts.
A Freightful Disaster: Orchid Logistics Cyber Drill
Publication date: 06/2025
| Attack Vector | Injects | Options |
| Ransomware | 22 | 49 |
Multi-hour simulation where participants respond to a cyberattack affecting Orchid Logistics (fictional global logistics company in 180+ countries). Teams coordinate response while managing impact on customers, employees, and shareholders.
Logistics Lockdown: 24 Hours
Publication date: 12/2024
| Attack Vector | Injects | Options |
| Ransomware | 9 | 21 |
CMT manages a ransomware attack halting order processing and shipping systems. In the crisis simulation, you will learn to understand the operational and reputational impact of a supply chain cyberattack, to practice rapid decision making and prioritization in a high-pressure environment, to analyze the roles and responsibilities of different teams in a cybersecurity crisis
Royal Mail Ransomware Attack
Publication date: 03/2023
| Attack Vector | Injects | Options |
| Ransomware | 15 | 57 |
Based on early 2023 LockBit ransomware attack on Royal Mail. Mercurio Delivery (global delivery company) responds to crisis affecting hundreds of thousands of daily packages and small business customers.
Kaseya MSP Hack
Publication date: 07/2021
| Attack Vector | Injects | Options |
| Supply Chain Compromise | 32 | 116 |
Based on REvil/Kaseya compromise (2021). FreshCo grocery chain (820 stores) responds to ransomware attack through MSP provider, complicated by recent cost-cutting measures and limited IT coverage.
Colonial Pipeline IT/OT Collision
Publication date: 05/2021
| Attack Vector | Injects | Options |
| Targeted Attack | 14 | 46 |
Based on May 2021 ransomware attack. Participants play Prime Cuts Canada Regional Crisis Team managing a 5,500-mile pipeline network, making decisions on business continuity, employee safety, and national food supply chain impact.
Manufacturing
The Walls Have Ears - Part Two
Publication date: 09/2024
| Attack Vector | Injects | Options |
| Targeted Attack | 13 | 40 |
CMT manages the aftermath of stolen IP, market turmoil, and board scrutiny.
The Walls Have Ears - Part One
Publication date: 08/2024
| Attack Vector | Injects | Options |
| Targeted Attack | 15 | 69 |
CMT stabilizes operations after production failures and signs of industrial espionage.
Manufacturing Crisis
Publication date: 07/2023
| Attack Vector | Injects | Options |
| Insider Threat, Supply Chain Compromise | 20 | 80 |
Manufacturing Crisis immerses you at EngiTech, a UK manufacturer that recently deployed IIoT devices from a trusted supplier. Weeks later, equipment malfunctions escalate to a plant fire and widespread disruption traced to a disgruntled ex-employee at the supplier who retained credentials. Across 20 injects, you rotate between Manufacturing Operations Manager, Fire Marshal, Director of Manufacturing, and Crisis Management Team roles to navigate a fast-moving cyber-physical incident. Success demands rapid risk triage, plant safety and evacuation decisions, OT/IT incident response, vendor access and credential revocation, production recovery, and clear communications with employees, customers, media, and regulators. The scenario emphasizes insider-threat and supply chain compromise awareness, third‑party offboarding controls, evidence preservation, and business continuity planning. It benefits manufacturing leaders, plant and facilities teams, crisis managers, SOC/IR analysts, and vendor risk owners seeking to strengthen resilience against cyber-physical attacks.
Product Contamination Sabotage
Publication date: 07/2023
| Attack Vector | Injects | Options |
| Targeted Attack | 36 | 144 |
This crisis sim places you at Tung-Lo, a remote-by-default beverage maker whose AI-driven factory and SCADA are managed via O365, Slack, Zoom, and TeamViewer. As a new flavor launch and a potential SipCo acquisition near, a targeted sabotage by political/social activists triggers anomalies in production data and suspected product contamination, igniting online backlash and customer complaints. You'll triage OT/IT alerts, isolate compromised SCADA, decide on shutdowns and batch holds/recalls, preserve evidence, and coordinate with regulators, law enforcement, and the acquirer. Success depends on rapid cross-functional decisions across Customer Success, Technical Operations, Legal, Comms, and the CEO: stakeholder messaging, legal risk management, supply chain continuity, and reputational recovery. This exercise models a targeted activist attack on industrial control systems and benefits leaders and responders responsible for ICS security, crisis communications, and business resilience.
Electric Car Catastrophe
Publication date: 01/2022
| Attack Vector | Injects | Options |
| Ransomware | 19 | 69 |
In Electric Car Catastrophe, you act as Head of the Crisis Management Team at McCross, a global automaker preparing to launch a high-stakes electric vehicle. A criminal group deploys ransomware that threatens IT and OT environments, risking plant shutdowns, supply chain disruption, and missing peak sales months. With lean, just-in-time operations and minimal inventory, every hour of downtime imperils revenue and jobs. Across 19 decision points, you must lead triage and containment, decide on production pauses, prioritize critical systems, leverage backups, and manage IT/OT segmentation and recovery. You will direct clear internal and external communications, coordinate with legal and law enforcement, and balance ransom considerations against business continuity and safety. This exercise benefits crisis leaders, manufacturing and OT security teams, and executives who need to practice responding to ransomware in complex, time-sensitive industrial environments.
Food Supply Chain Calamity
Publication date: 06/2021
| Attack Vector | Injects | Options |
| Targeted Attack | 10 | 35 |
Based on JBS ransomware attack (May 2021). Prime Cuts Canada team manages crisis affecting beef, chicken, and pork distribution. Must balance business continuity, employee management, union negotiations, regulatory compliance, and food supply chain impact.
Other
AI Supply Chain: Monitoring Issues
Publication date: 09/2026026
| Attack Vector | Injects | Options |
| Supply Chain Compromise | 12 | 42 |
Set on the eve of Black Friday at a multinational retailer, the scenario forces executive teams to manage a compromised third-party AI observability platform. Because the company routes all AI traffic through this single vendor, the platform holds a complete record of every prompt, completion, and pasted secret from tens of millions of customers and colleagues. When the platform is compromised, the crisis team must navigate a nightmare scenario: managing a live AI estate they can neither safely keep running nor lawfully switch off.
Post-Quantum Cryptography for Managers
Publication date: 08/2026
| Attack Vector | Injects | Options |
| Data Breach | 9 | 27 |
You sit on Orchid Corp's Security Council. The National Cyber Security Centre has issued an advisory on post-quantum cryptography. The board has asked the Council whether Orchid is ready. The replacement standards already exist. National authorities, including the NCSC, have set out recommended migration milestones running to 2035. The challenge is not the technology itself but delivering the change across a large, complex organization within those timelines. Over the session, you'll decide how Orchid identifies its cryptography, what it prioritizes, how it migrates, and how it manages the suppliers it depends on. Each decision involves real trade-offs between time, cost, and risk.
Post-Quantum Cryptography: Harvest Now, Decrypt Later
Publication date: 08/2026
| Attack Vector | Injects | Options |
| Data Breach | 14 | 51 |
Orchid Corp is a diversified group: financial services, consumer products, and industrial units under one board. Long-lived data sits everywhere, from M&A archives to customer records. A threat-intelligence briefing has reopened a case you thought was closed. Data stolen in 2019 was signed off as low-impact at the time because it was encrypted. The regulator you notified back then has been tracking a pattern of similar thefts since, and now links yours to a nation-state actor whose quantum program is starting to show results. You sit on Orchid's security leadership team. This is not a one-hour crisis. Over the weeks that follow you'll weigh what the harvest now, decrypt later threat means for the business, and what the board can honestly claim about it.
The AI Trend-Maker: Echo of the Puppetmaster
Publication date: 05/2026
| Attack Vector | Injects | Options |
| Ransomware | 8 | 20 |
Crisis simulation involving a viral prank (#PuppetPranks) that spirals into an emergency at Orchid Communications. Teams navigate security posture, public accountability, and operational technology threats.
Share YourDocs Breach - NIS2 Reporting
Publication date: 05/2025
| Attack Vector | Injects | Options |
| Third-party platform compromise | 8 | 22 |
CMT navigates a third-party platform breach to assess document compromise and meet NIS2 reporting thresholds.
GlobalCloud Breach: A Microsimulation on Third-Party Breach Exposure
Publication date: 04/2025
| Attack Vector | Injects | Options |
| Other | 5 | 13 |
Your organization has recently migrated authentication, collaboration, and customer-facing systems to GlobalCloud when hacker "rose87168" claims to have stolen millions of customer records. GlobalCloud initially denies a breach, but mounting evidence points to a compromised, still-connected legacy environment (GlobalCloud Classic). As the Crisis Management Team, you must lead a real-time response amid ambiguity and potentially misleading vendor updates. Participants will assess third-party exposure, determine containment and isolation steps, validate indicators without full forensics, align legal, security, communications, and executive priorities, and judge regulatory disclosure thresholds (including NIS2) and customer messaging under uncertainty. This exercise centers on a third‑party cloud/supply-chain data breach with potential data exfiltration and service impact. It benefits crisis leaders, CISOs, incident managers, legal and communications leads, and risk executives seeking to sharpen decision-making in high-pressure, incomplete-information scenarios.
Christmas Tree-son
Publication date: 11/2024
| Attack Vector | Injects | Options |
| Insider-driven cyber crisis | 11 | 35 |
Christmas Tree-son is a crisis simulation in which your Crisis Management Team must stabilize the North Pole on Christmas Eve amid cascading incidents triggered by disgruntled former employees. Across 11 injects, you confront leaks, a data breach, an operational fire, and a whistleblower while regulators and the public scrutinize every move, with the specter of GDPR violations culminating in Santa's arrest if mishandled. Participants must coordinate clear, timely communications; protect data; triage operations for business continuity and delivery; weigh legal and ethical implications; and make high-stakes decisions with incomplete information and tight deadlines to preserve trust and mission. This exercise is ideal for crisis managers, CISOs and security leaders, communications and PR teams, legal/compliance, and executives seeking to strengthen cross-functional response to insider-driven cyber crises.
A Not So Silent Night
Publication date: 12/2023
| Attack Vector | Injects | Options |
| AI/algorithmic failure | 16 | 41 |
Set during the peak holiday rush at the North Pole, this simulation places participants on Santa's crisis management team after a new AI system misclassifies every child as naughty, freezing list management and jeopardizing on-time delivery. Across 16 injects, you must stabilize operations, manage internal morale and public scrutiny, evaluate offers from Grinch Incorporated, and diagnose and remediate the failure under intense time pressure. Success demands sound crisis declaration and governance, clear external and internal communications, risk assessment and prioritization, vendor and legal considerations, ethical AI oversight, data integrity controls, incident response, and business continuity and recovery planning. The scenario models an AI/algorithmic failure causing operational disruption and reputational risk, benefiting crisis leaders, executives, communications and PR teams, operations and supply chain managers, and technology, security, and business continuity practitioners seeking to strengthen decision-making and organizational resilience.
Scenario Template – Civil Unrest
Publication date: 01/2023
| Attack Vector | Injects | Options |
| Other | 8 | 32 |
Generic template for protest/civil unrest crises. Company faces negative public attention online escalating to physical protests. Teams manage physical security, reputation, and business operations.
Scenario Template – DDoS Attack
Publication date: 07/2022
| Attack Vector | Injects | Options |
| Denial of Service | 7 | 25 |
Generic template for distributed denial-of-service attack. Teams experience network disruption and must make dynamic decisions with limited information to mitigate cyber, operational, and strategic risks.
Scenario Template – Zero-Day Attack
Publication date: 06/2022
| Attack Vector | Injects | Options |
| Zero-Day Exploit | 8 | 24 |
Generic template for zero-day vulnerability incidents. Organizations balance system restoration against operational downtime while making rapid decisions under uncertainty.
Cyber Breach Reporting
Publication date: 11/2021
| Attack Vector | Injects | Options |
| Other | 17 | 50 |
Participants manage crisis response at Greenfunds Bank (online eco-friendly banking platform). Focus on compliance with PCI DSS guidelines and navigating breach disclosure obligations.
Public Sector/Consultancy
Capita Ransomware Attack: Threat Response
Publication date: 07/2023
| Attack Vector | Injects | Options |
| Ransomware | 10 | 39 |
In this crisis simulation, you are the crisis management team at Paragon Services, a consultancy serving NHS, defense, and local authorities, when a Black Basta-style ransomware attack locks out staff and disrupts client services. Adversaries have exfiltrated sensitive documents and threaten double extortion, forcing rapid decisions under public and regulatory scrutiny while operations fall back to manual workarounds. Across 10 decision injects, you will triage and contain the intrusion, investigate a likely phishing-led entry, manage communications, determine notification and legal obligations, weigh ransom and negotiation options, coordinate with law enforcement and clients, and restore services from backups securely. This ransomware and data theft scenario benefits crisis leaders, security and IT operations, legal/comms teams, and anyone supporting high-trust, regulated or public-sector customers.
Retail
#LoveHacked
Publication date: 02/2025
| Attack Vector | Injects | Options |
| Cyberattack | 7 | 23 |
In #LoveHacked, you act as the COO and crisis management team lead at Orchid Retail on Valentine's Day when a fast-moving cyberattack disrupts operations and threatens customer trust. Across the critical "golden hour," you'll navigate a series of escalating, time-pressured decisions with incomplete information to stabilize sales channels, assess potential data exposure, and maintain business continuity. Success requires decisive leadership, rigorous triage, and risk-based choices on containment versus keeping services online, while coordinating with security, IT, legal, and customer teams. You'll practice clear internal and external communications, stakeholder management, and reputation protection under pressure. This simulation targets a cyberattack scenario and is ideal for executives, crisis managers, incident commanders, operations leaders, and communications professionals---particularly in retail and other consumer-facing sectors seeking to strengthen first-hour crisis response.
Technology
JadePuffer
Publication date: 07/2026
| Attack Vector | Injects | Options |
| Malicious Code | 11 | 38 |
An autonomous AI agent has been operating undetected on Orchid Corporation's Catalyst platform (your internal AI system: 12 production LLM-powered workflows serving customers and internal teams, built on Langflow) for eight hours. Deployed through a vulnerability in Langflow, it uses LLM API calls to reason about your environment, adapt to obstacles, and progress through a multi-phase attack plan. It has spread to multiple hosts, harvested credentials across your estate, and staged a ransomware encryption of your service configuration database. Your SOC just received the first alert. The agent is entering its execution phase. You are already behind.
PCI DSS: General Audience
Publication date: 07/2026
| Attack Vector | Injects | Options |
| Data Breach | 10 | 34 |
Nextugo is an online marketplace for lodging and tourism activities. It processes millions of payment card transactions each year. A cybersecurity firm has contacted you claiming 17 million customer records, including credit card numbers, are for sale on the dark web. Your leadership team now faces a fast-moving crisis spanning data protection failures, third-party supplier gaps, insider threats, and media exposure. This exercise is for non-technical teams. It focuses on business decisions, coordination challenges, and compliance obligations during a PCI DSS incident. You don't need technical expertise – the scenario tests judgment, escalation, and cross-functional coordination.
Everyone's a Builder
Publication date: 06/2026
| Attack Vector | Injects | Options |
| Supply Chain Compromise | 11 | 37 |
An ordinary Wednesday at Orchid Corp, a 1,000-person SaaS company headquartered in Amsterdam. At 14:00 a secret-scanning alert fires: a junior engineer pushed an experimental, AI-built CRM agent to a public repository that morning — with a live corporate OpenAI API key inside it. But stopping the obvious bleed is only the first move. The clock started 8 hours before anyone was paged, and the incident rapidly expands from a leaked key into a full supply-chain compromise, identity breach, and regulatory escalation.
Shadow AI
Publication date: 06/2026
| Attack Vector | Injects | Options |
| Malicious Code | 11 | 38 |
Orchid Corp provides point-of-sale and e-commerce solutions to 1.4 million small businesses worldwide. The company has recently invested in AI capabilities but has not yet established a formal AI acceptable use policy.
A routine alert in the SOC queue triggers an investigation that reveals something unexpected about AI tool adoption across the business. With limited resources and competing priorities, leadership must decide how to allocate its team – and those decisions will have consequences that compound as the day unfolds.
Suspicious Login Activity: Identity Compromise Triage (SOC Micro-Exercising)
Publication date: 06/2026
| Attack Vector | Injects | Options |
| Unauthorized Access | 5 | 11 |
This is a short micro-exercise designed to test analysts' decision-making skills and then provide hands-on experience in a related exercise. This simulation tests the analyst’s ability to apply playbook-driven decision-making during identity alert triage. The analyst must assess multiple signals over time, correlate activity, and determine whether escalation criteria are met. The exercise is designed to evaluate: Alert validation and context analysis Correlation of identity-based indicators Adherence to escalation criteria defined in the playbook Decision-making under time and workload pressure
Shai–Hulud Supply Chain Attack
Publication date: 05/2026
| Attack Vector | Injects | Options |
| Supply Chain Compromise | 9 | 29 |
This exercise simulates an organizational response to the Mini Shai-Hulud supply chain campaign in May 2026.
WastedLocker Personal Data Exposure
Publication date: 01/2026
| Attack Vector | Injects | Options |
| Ransomware, Targeted Attack | 17 | 45 |
In this 30-minute crisis simulation, your organization faces a WastedLocker-style ransomware outbreak: employees suddenly lose access to critical files, operations stall, and indicators point to a targeted criminal attack with potential personal data exposure. As part of the crisis management team---playing CEO, COO, Head of Communications, or CISO---you must coordinate with IT and SOC to stabilize the situation and restore essential services. You will practice rapid triage and containment, preserving evidence, assessing the scope of data exposure, and weighing backup recovery against ransom payment. Expect to manage stakeholder communications, regulatory and legal obligations, engagement with insurers and law enforcement, and prioritization of business continuity. This exercise sharpens executive decision-making and incident leadership for senior leaders in security, operations, and communications seeking to improve resilience against targeted ransomware by criminal groups.
Orchid Rail UK: The Firmware Express
Publication date: 09/2025
| Attack Vector | Injects | Options |
| Supply-chain attack | 23 | 59 |
CMT manages a supply-chain attack involving firmware distribution to train fleets.
Responding to a Scattered Spider Attack
Publication date: 08/2025
| Attack Vector | Injects | Options |
| Targeted Attack | 9 | 36 |
This simulation drops you into a targeted, identity-based intrusion on Orchid Global by the Scattered Spider threat group. Attackers use social engineering to seize user and admin accounts, move laterally, exfiltrate sensitive data, and issue extortion demands. Across nine escalating injects, you act as the core incident response team, weighing containment and eradication against business continuity, legal exposure, and reputational impact. Success requires rapid triage, access containment, MFA and SSO hardening, forensic preservation, breach scoping, and clear internal and external communications. You will make decisions on customer notification, executive and board briefings, law-enforcement engagement, and extortion strategy while applying relevant local laws and timelines. Ideal for SOC analysts, incident commanders, CISOs, communications leaders, customer support heads, and cross-functional crisis teams preparing for Scattered Spider--style targeted attacks.
Operation Skylock
Publication date: 07/2025
| Attack Vector | Injects | Options |
| Ransomware | 5 | 19 |
Operation Skylock places the Bronze Command Team in a fast‑escalating incident at Orchid Corp following the launch of an AWS-hosted invoice app. A subtle reconnaissance and slow port scan quickly turns into remote access, privilege escalation, pivoting into AWS, data exfiltration, persistence, and a ransomware detonation that cripples the core business application. Participants must triage incomplete signals, investigate suspected breaches, coordinate tightly with the Silver Command Team, and recommend time-critical mitigations. Success requires strong incident command, cloud and endpoint forensics, threat hunting, containment and recovery planning, and clear stakeholder communication under pressure. This simulation models a modern ransomware-and-exfiltration attack chain and benefits SOC analysts, incident responders, cloud security engineers, and operational leaders seeking to practice decision-making and business-technical integration during a live cyber crisis.
Boardroom Hack
Publication date: 06/2025
| Attack Vector | Injects | Options |
| Ransomware | 10 | 37 |
Boardroom Hack places participants in the board seat during a live ransomware crisis, with critical systems disrupted and sensitive data exfiltrated for extortion. Under time pressure and incomplete information, you must steer organizational response while managing operational disruption, media scrutiny, and stakeholder expectations. Success demands strategic decision-making under uncertainty: weighing whether to engage with attackers, activate incident response and business continuity, notify regulators and customers, involve law enforcement, and shape transparent communications. You will balance legal, financial, ethical, and reputational risks while providing governance oversight and aligning stakeholder interests. This ransomware and data extortion scenario is ideal for boards and senior leaders seeking to test crisis readiness, clarify roles and risk appetite, and strengthen collaboration and communication in a globally applicable context.
Echoes of Doubt: A Workplace Violence Exercise
Publication date: 05/2025
| Attack Vector | Injects | Options |
| Targeted Attack | 12 | 31 |
In Echoes of Doubt, participants act as the Crisis Management Team responding to a suspected, then misdirected, and ultimately confirmed targeted workplace violence incident. The scenario unfolds through escalating, ambiguous reports that demand rapid threat assessment, activation of protective actions (avoid, deny, defend), coordination with security and law enforcement, and careful management of internal alerts, rumor control, and media scrutiny. Success requires making time-critical decisions with incomplete information, triaging and verifying data, prioritizing life safety, and adapting strategies as conditions change. Participants will practice dynamic crisis communications, resource coordination, and post-incident recovery planning. This exercise is ideal for crisis management teams, security leaders, HR, facilities, communications, and executive stakeholders across industries seeking to strengthen readiness for targeted workplace violence.
Your Digital Footprint: Teens
Publication date: 05/2025
| Attack Vector | Injects | Options |
| Social engineering, Data leakage | 11 | 24 |
Students navigate online reputational dilemmas, cyberbullying, and privacy.
GlobalCloud Breach: Third-Party Exposure
Publication date: 04/2025
| Attack Vector | Injects | Options |
| Supply-chain data breach | 5 | 13 |
CMT manages a third-party cloud/supply-chain breach involving millions of stolen records.
Orchid Corp: Blossom (Drill)
Publication date: 04/2025
| Attack Vector | Injects | Options |
| Vulnerability Disclosure | 16 | 29 |
In Orchid Corp: Blossom (Drill), participants step into the leadership team as multiple vulnerabilities in the newly launched HR platform are publicly reported by users and an employee. With clients alarmed and the company caught off-guard, you must stabilize the situation, protect customers, and preserve trust while balancing speed, accuracy, and transparency. Success requires coordinated vulnerability management and crisis leadership: triaging and prioritizing flaws, deciding on containment and patch timelines, aligning security and engineering on fixes, navigating legal and regulatory exposure, and crafting clear internal and external communications. The scenario focuses on vulnerability disclosure/reporting as the primary threat vector and benefits executives, security leaders, engineering managers, legal and compliance teams, and communications professionals who need to practice high‑stakes decision-making under scrutiny.
Al-pril Fools: The Return of the Puppetmaster
Publication date: 03/2025
| Attack Vector | Injects | Options |
| AI-enabled information warfare | 9 | 31 |
CMT responds to an AI-empowered adversary hijacking corporate communications and seeding misinformation.
Puppetmaster's Revenge
Publication date: 10/2024
| Attack Vector | Injects | Options |
| Criminal-group cyberattacks | 8 | 25 |
In Puppetmaster's Revenge, participants act as Immersive Tech's Crisis Management Team after a criminal hacker hijacks connected IoT products, turning them into public pranks and safety risks. With services disrupted and customer trust wavering, you must stabilize operations while investigators trace the intrusions and motives. Through eight decision points, you'll prioritize incidents, assess product vulnerabilities, choose containment and patch strategies, coordinate with law enforcement and vendors, and shape transparent customer and investor communications. You'll balance safety, legal and ethical considerations with brand protection, and explore turning the event into a reputational recovery story. This simulation suits crisis leaders, comms and legal teams, product and security managers, and executives---anyone seeking to strengthen decision-making and cross-functional coordination against criminal-group cyberattacks on IoT ecosystems.
One Password, Multiple Problems
Publication date: 09/2024
| Attack Vector | Injects | Options |
| Targeted Attack | 10 | 32 |
CMT at a telecoms company manages data exposure caused by a reused password.
Solar Sentinel
Publication date: 07/2024
| Attack Vector | Injects | Options |
| Natural hazard/Space-weather | 10 | 34 |
Solar Sentinel places participants in a Carrington-scale solar storm that cripples power grids, satellites, communications, finance, healthcare, and transportation worldwide. As part of the Global Crisis Response Team, you must advise governments and coordinate an international response amid cascading failures, competing priorities, and severe resource constraints. Success demands rapid prioritization, infrastructure triage, allocation of scarce assets, cross-sector and cross-border coordination, clear risk communication, and ethically defensible decisions under uncertainty. Participants practice restoration sequencing for energy and communications, stabilizing critical supply chains, and delivering actionable policy guidance and public messaging. Focused on a natural hazard/space-weather threat, this exercise benefits government leaders, emergency managers, critical infrastructure operators (energy, telecom, finance, healthcare, transport), and security and business continuity professionals seeking to strengthen preparedness and resilience.
Unforeseen Consequences
Publication date: 07/2024
| Attack Vector | Injects | Options |
| Human Error | 4 | 9 |
In Unforeseen Consequences, you play the CISO confronting a global Microsoft service disruption while your own corporate device hits a Blue Screen of Death, signaling a cascading failure tied to third‑party tooling. With cloud services degraded and staff escalating issues, you must stabilize operations and make rapid, high‑impact calls under uncertainty. Across four decision points, you'll demonstrate crisis leadership, triage and recovery planning, cloud and endpoint containment, and clear executive and workforce communications. You'll weigh credential hygiene actions (including company‑wide admin password resets), assess vendor risk and trust in CrowdStrike, and coordinate business continuity while preserving evidence and stakeholder confidence. This human error--driven scenario benefits CISOs, incident managers, and IT/ops leaders seeking to strengthen decision-making, dependency management, and resilience during large-scale, third‑party induced outages.
Boardroom Betrayal: When Deepfakes Strike The Top
Publication date: 06/2024
| Attack Vector | Injects | Options |
| Targeted Attack | 5 | 17 |
Boardroom Betrayal: When Deepfakes Strike The Top puts participants in the hot seat as a targeted deepfake campaign and insider-enabled fraud trigger a fast-moving corporate crisis. Fabricated executive audio/video fuels misinformation, reputational damage, and financial exposure, forcing rapid verification, containment, and stakeholder reassurance amid market and media pressure. Success requires decisive, ethical leadership: authenticating content, activating cyber and legal response, managing insider‑threat investigations, shaping transparent communications, meeting disclosure obligations, and balancing speed with accuracy to protect customers, employees, and investors. Ideal for boards and C‑suite, it also benefits crisis managers, communications teams, and risk leaders seeking to strengthen resilience against deepfake and targeted attack scenarios.
Operation Wipeout
Publication date: 06/2024
| Attack Vector | Injects | Options |
| Targeted Attack | 12 | 35 |
Operation Wipeout places your crisis management team in the midst of a targeted criminal group--led wiper malware attack that cripples systems and disrupts core operations. Participants must navigate irreversible data loss, cascading supply chain impacts, and heightened stakeholder concern while working to stabilize the business and restore critical services under pressure. Across a series of time-pressured decision points, you will activate and adapt the BCP, coordinate incident response and forensics, prioritize recovery, allocate scarce resources, and manage clear, timely communications to executives, employees, customers, and partners. This exercise benefits crisis management teams, business continuity planners, and senior executives seeking to validate resilience, reveal operational interdependencies, and sharpen decision-making and communication skills during a severe, real-world cyber disruption.
The 8-K Conundrum
Publication date: 06/2024
| Attack Vector | Injects | Options |
| Insider-driven incident | 19 | 62 |
In The 8-K Conundrum, you step in as CFO amid a fast-moving, material event sparked by current employees that likely triggers an SEC Form 8-K within four business days. With investors, regulators, and media pressure mounting, you must determine materiality, decide what to disclose and when, and coordinate with counsel and the board under intense scrutiny. The simulation tests SEC reporting fluency, ethical judgment under time pressure, and concise crisis communications that balance legal, financial, and reputational risk. You'll refine disclosure language, set remediation and accountability measures, and manage market impact and stakeholder expectations. This exercise is ideal for finance leaders, legal and compliance professionals, investor relations, and executives seeking to strengthen responses to insider-driven incidents and improve disclosure readiness.
Fool's Gambit: Deepfake Dilemma
Publication date: 03/2024
| Attack Vector | Injects | Options |
| Targeted Attack | 15 | 37 |
Fool's Gambit: Deepfake Dilemma places you in the role of head of PR and communications at a leading news network during a targeted deepfake attack that undermines on-air credibility and public trust. As misleading clips spread, you must steady internal morale, manage a hostile news cycle, brief executives, reassure advertisers, and address escalating regulatory scrutiny while maintaining transparency. Success hinges on rapid, strategic communication: verifying facts with editorial and technical teams, shaping clear public statements, sequencing disclosures, coordinating with legal, engaging platforms to curb misinformation, and monitoring sentiment to adapt your response. This simulation focuses on the deepfake/disinformation threat and benefits PR and comms leaders, executives, crisis managers, newsroom leaders, and security or risk professionals seeking to strengthen decision-making, stakeholder engagement, and reputational resilience under pressure.
Digital Dilemma: Data Breach Response
Publication date: 01/2024
| Attack Vector | Injects | Options |
| Data Breach | 30 | 79 |
Digital Dilemma: Data Breach Response immerses participants in a high-stakes breach at a global corporation, where sensitive data is suspected to be exfiltrated and operations are at risk. As the incident unfolds through multiple decision points, you must coordinate the Crisis Management Team, SOC, and Incident Response to investigate, contain, and recover while managing internal dynamics and external pressures. Success requires clear leadership, rapid risk assessment, evidence-driven containment, prioritization of business continuity, transparent stakeholder communications, and timely legal/regulatory actions. The exercise emphasizes ethical trade-offs, cross-functional alignment, and post-incident learning. Focused on data breach threats, it benefits crisis leaders, SOC analysts, incident responders, communications and HR leads, and executives seeking to strengthen decision-making, resilience, and trust under pressure.
Valentine's Day Chaos
Publication date: 01/2024
| Attack Vector | Injects | Options |
| Operational disruption | 15 | 52 |
Valentine's Day Chaos places your crisis management team in one of two sector-specific scenarios: a major retailer grappling with last-minute demand, supply chain snags, and PR/competitive pressures, or a healthcare system strained by a severe winter storm driving surges in patient volume and resource shortages. Across 15 decision injects, you'll navigate fast-moving operational disruption, reputational risk, and staff wellbeing challenges under time pressure. Success demands clear prioritization, stakeholder communication, cross-functional coordination, and data-driven resource allocation, along with ethical decision-making and media handling. This exercise benefits crisis and business continuity leaders, operations managers, clinical administrators, and communications teams seeking to sharpen universal crisis competencies in retail or healthcare settings.
International Racing Championship
Publication date: 11/2023
| Attack Vector | Injects | Options |
| Targeted Attack | 44 | 130 |
As Team Principal of an International Racing Championship outfit at the British Championship, you face a targeted cyberattack from criminal actors that threatens race-day operations, data integrity, and brand reputation. With a large trackside footprint---multiple hosts and terabytes of capacity---you must make time-critical calls on and off the pit wall across 44 evolving injects, balancing performance, safety, and reputation. Success demands rapid triage and containment, OT/IT segregation, forensic preservation, vendor and partner coordination, clear stakeholder and media communications, regulatory considerations, and recovery planning amid extortion pressure. This exercise develops crisis decision-making and incident leadership for security leaders, team principals, operations managers, comms leads, and responders in any high-availability, mobile infrastructure environment confronting targeted attacks by criminal groups.
Accessibility Crisis
Publication date: 06/2023
| Attack Vector | Injects | Options |
| Targeted Attack | 9 | 36 |
In Accessibility Crisis, you act as a product developer and member of the crisis management team at Anadyne Technologies on the eve of launching a blockchain cybersecurity platform. A coordinated, targeted attack by hacktivists challenges the product's accessibility posture and your company's DE&I commitments, putting integrity, customer trust, and potential legal exposure in the spotlight. You must navigate an unfolding incident while balancing launch pressures, regulatory expectations, and third-party dependencies. Participants will triage and contain the incident, validate and remediate accessibility gaps (e.g., WCAG/Section 508), assess supply-chain obligations, make go/no-go decisions, and craft transparent communications to customers, media, and regulators while coordinating with legal and executives to mitigate litigation and reputational damage. This simulation focuses on a targeted, ideologically driven threat from political/social activists and benefits product teams, crisis leaders, compliance, legal, and communications professionals seeking to strengthen accessibility governance and incident response.
MOVEit Zero-Day: Threat Response
Publication date: 06/2023
| Attack Vector | Injects | Options |
| Zero-Day Exploit | 13 | 48 |
In this simulation, you respond to a real-world style zero-day exploitation of the MOVEit file transfer software affecting Beeches, a UK pharmacy chain reliant on third-party payroll services. A criminal group leverages the vulnerability to exfiltrate sensitive employee data via a supplier compromise, leaving you to operate under uncertainty while coordinating with the vendor and assessing potential exposure. Across rotating roles, you'll demonstrate rapid triage and containment, supply chain risk management, legal and regulatory decision-making (including breach notification), executive risk prioritization, and clear internal and external communications. The exercise emphasizes data-theft/extortion tactics stemming from a zero-day and benefits cybersecurity practitioners, crisis managers, communications teams, and executives seeking to strengthen cross-functional incident response to third-party compromise.
Up in the Air
Publication date: 06/2023
| Attack Vector | Injects | Options |
| Supply Chain Compromise | 20 | 46 |
Up in the Air places you inside Longitude Airlines during a holiday‑weekend disruption triggered by a suspected supply chain compromise rooted in human error. As the situation evolves through rapid injects, you rotate between On-duty Manager, NOC, Flight 722 Captain, and CMT roles to keep aircraft, crews, and customers moving while passenger and baggage backlogs grow and reputational/financial risks mount. Success demands decisive operational triage, cross‑functional coordination, and clear stakeholder communication with pilots, customers, media, and partners. You will balance safety, delays versus cancellations, rerouting, manual workarounds, information sharing, and activation of continuity and recovery plans while safeguarding data and investigating the supplier incident. This exercise suits airline and airport leaders, crisis managers, NOC/IT security teams, incident responders, and communications professionals in aviation and other critical infrastructure sectors.
Scenario Template - Supply Chain (Maturity 1)
Publication date: 04/2023
| Attack Vector | Injects | Options |
| Supply Chain Compromise | 6 | 18 |
IR team scopes a SolarWinds-style compromise in trusted third-party software.
Scenario Template - Supply Chain (Maturity 2)
Publication date: 2/2023
| Attack Vector | Injects | Options |
| Supply Chain Compromise | 8 | 32 |
Based on the SolarWinds/SUNBURST incident. Participants investigate a supply chain software compromise and assess security risks to their organization, learning incident response procedures and decision-making under uncertainty.
Scenario Template - Terrorist Attack
Publication date: 11/2022
| Attack Vector | Injects | Options |
| Terrorism/Active Shooter | 7 | 27 |
In this crisis simulation, you serve on [Company Name]'s enterprise crisis management team in the [X sector], responding to a terrorist attack by an armed assailant at a critical [location/office]. As the incident escalates in real time, you must prioritize life safety, coordinate with law enforcement, and stabilize operations amid uncertainty and incomplete information. You will demonstrate situational awareness, rapid decision-making on lockdown, evacuation, and accounting for personnel, and effective internal and external communications. The exercise also tests escalation paths, coordination across security, facilities, HR, and leadership, and early steps toward recovery and continuity. Focused on terrorism/active shooter threats from hostile groups, this scenario benefits crisis managers, security and facilities teams, communications professionals, and executives seeking to validate plans, roles, and readiness.
Sewage Subterfuge
Publication date: 08/2022
| Attack Vector | Injects | Options |
| Insider Threat | 13 | 41 |
Set in Stoneswell Waste Management, a publicly owned treatment works in a rural tourist area, this simulation places you on the crisis management team as legacy SCADA systems and recent job cuts leave the utility exposed. When suspicious activity suggests an insider---potentially a disgruntled or former employee---has targeted 142 scattered pumps across a network handling 9 million gallons daily, you must assess impacts to public health and the environment while stabilizing operations. Through 13 decision points you'll prioritize containment of OT assets, validate telemetry, manage access and credential revocation, coordinate with law enforcement and regulators, and execute clear internal and public communications. Participants will practice insider-threat response, SCADA/ICS incident handling, risk trade-offs, and recovery planning. Ideal for crisis managers, water and wastewater operators, municipal leaders, and public communications teams seeking to strengthen resilience against insider threats.
Scenario Template - Insider Threat
Publication date: 06/2022
| Attack Vector | Injects | Options |
| Insider Threat | 7 | 26 |
CMT investigates sensitive data surfaced on the dark web, potentially by an employee.
Scenario Template - Phishing Attack/Data Breach
Publication date: 06/2022
| Attack Vector | Injects | Options |
| Phishing | 8 | 31 |
CMT triages reports of suspicious emails and network compromise by criminal actors.
Scenario Template - Ransomware
Publication date: 06/2022
| Attack Vector | Injects | Options |
| Ransomware | 13 | 48 |
CMT responds to double-extortion ransomware affecting critical business operations.
Collaboration Dilemma
Publication date: 05/2022
| Attack Vector | Injects | Options |
| Supply Chain Compromise | 14 | 43 |
In Collaboration Dilemma, you are the CISO of Aspea Technologies, a global provider of collaboration software to the financial sector, confronting a live supply chain compromise by criminal groups. A third-party vendor breach threatens customers and operations across Europe, North America, Asia, and the Middle East. Across 14 timed injects, you must steer the response as the attack unfolds in real time. Success demands rapid triage, scoping and containment, coordination with the vendor, threat intelligence and forensics, regulatory and contractual notifications, customer and board communications, and risk-based decisions that balance service continuity, reputational impact, and legal exposure. This simulation is ideal for CISOs, security leaders, incident responders, vendor risk and compliance teams seeking to strengthen enterprise and extended supply chain resilience against supply chain attacks.
Okta - Failure to Communicate
Publication date: 05/2022
| Attack Vector | Injects | Options |
| Supply Chain | 14 | 47 |
As CISO of Kaprika, an IAM market leader, you face a supply chain compromise at a critical third-party provider, with criminal groups exploiting vendor access and triggering intense scrutiny from customers, regulators, and media. Across multiple decision points, you must triage technical risk, contain exposure, and steer the business through uncertainty while preparing for fallout, including a subsequent customer breach potentially linked to stolen data. Success requires SME-level mastery of identity systems, tokens, and logs; decisive revocation and rotation actions; vendor risk management; coordinated disclosure; legal and regulatory alignment; and clear, credible communications to executives, clients, and the public. This exercise benefits CISOs and security leaders responsible for third-party risk, incident response, and reputational resilience against supplier-enabled attacks by criminal groups.
USB Hack: Network Down
Publication date: 02/2022
| Attack Vector | Injects | Options |
| Ransomware, Phishing, Data Breach, Targeted Attack | 22 | 81 |
As a member of Navarris's Executive Crisis Management Team, you confront a coordinated nation-state operation that uses targeted phishing and a tampered USB security key to breach corporate and NECS networks, disrupt services, and trigger ransomware and data exfiltration. With first responders and NYC Ambulance reliant on your infrastructure, you must make time-critical decisions to contain the attack, sustain essential communications, and navigate legal, regulatory, and reputational fallout. You will demonstrate device hygiene and supply-chain skepticism, social-engineering detection, threat hunting, impact and vulnerability assessment, urgent-versus-important prioritization, risk assessment, ransom response posture, evidence preservation, and clear, flexible crisis communications with stakeholders. This multi-vector APT scenario---ransomware, phishing, data breach, targeted attack---benefits executive crisis leaders, telecom and critical-infrastructure operators, and public-sector suppliers seeking to sharpen security posture and real-world crisis readiness.
Apache Zero Day
Publication date: 12/2021
| Attack Vector | Injects | Options |
| Zero-Day Exploit | 17 | 51 |
Based on the Log4Shell vulnerability (December 2021). Executive crisis team at Megatech Corporation (online gaming company) responds to zero-day impact affecting systems, making rapid decisions with limited information.
Ransomware Template Scenario
Publication date: 08/2021
| Attack Vector | Injects | Options |
| Ransomware | 12 | 42 |
In this Immersive Labs crisis simulation, you are the Incident Response Manager at [INSERT COMPANY NAME HERE], a key player in [INSERT INDUSTRY TYPE HERE], facing a fast-moving ransomware attack by a criminal group. Endpoints are shutting down as data is encrypted and exfiltrated, with threats to publish stolen information on a leak site. You must make rapid decisions with evolving, incomplete intelligence to contain the incident and stabilize the business. You will assess indicators of compromise, triage and isolate systems, choose between shutdown, segmentation, and recovery paths, validate backups, and coordinate legal, communications, and executive briefings. The exercise tests your judgment on ransom engagement, evidence preservation, regulatory notification, customer messaging, and business continuity trade-offs. Designed for incident response leaders, security managers, and operational stakeholders, it sharpens readiness for ransomware campaigns by financially motivated criminal actors.
Data For Sale
Publication date: 05/2021
| Attack Vector | Injects | Options |
| Data Breach | 14 | 49 |
Participants manage response to potential data breach affecting 17 million Nextugo (travel/lodging marketplace) customer records. Must navigate PCI DSS compliance while assessing breach authenticity.
Pharmaceuticals: IP Crisis
Publication date: 02/2021
| Attack Vector | Injects | Options |
| Insider Threat, Targeted Attack | 15 | 49 |
IR team investigates an IP leak of a breakthrough drug formula.
Ransomware: Garmin
Publication date: 08/2020
| Attack Vector | Injects | Options |
| Ransomware | 13 | 39 |
Wake to an urgent call: Glomax has been hit by ransomware modeled on the 2020 Garmin incident. Critical systems are encrypted and users are locked out. As the Incident Response Handler, you must stabilize the first hours of a WastedLocker attack, establish situational awareness, and guide the organization through fast-moving uncertainty. You will practice triage and scoping, isolating affected networks, preserving forensics, initiating backups and recovery, and coordinating with SOC, IT, legal, executives, and third parties. Key decisions include whether to shut down services, how to handle ransom notes and negotiations, when to notify regulators and customers, and how to balance containment with business continuity. This simulation is ideal for incident responders, SOC analysts, security leaders, IT operations, and communications teams who need realistic, time-pressured ransomware response experience.
Insider Data Breach
Publication date: 04/2020
| Attack Vector | Injects | Options |
| Data Breach, Insider Threat | 17 | 50 |
In this 60-minute crisis simulation, you act as the security lead for insider threats as a high-performing but disruptive engineer prepares to leave for a rival, raising suspicion of IP exfiltration reminiscent of the Waymo--Uber saga. Over 28 timed injects, you must scope and investigate anomalous access and transfers, balance business pressure with risk, and coordinate a defensible response under legal, HR, and executive scrutiny. You will practice insider risk detection, forensic triage and evidence preservation, rapid containment and access revocation, DLP and monitoring controls, offboarding safeguards, and internal and external communications. Key decisions include when to escalate, engage counsel or law enforcement, protect trade secrets, and manage reputational fallout. This data breach via insider threat scenario benefits security leaders, SOC/IR teams, HR and Legal partners, and IP-heavy organizations seeking to strengthen insider threat programs.