Ransomware / Double Extortion
Operation Iron Horizon
Ransomware has hit the production network of a major manufacturing plant, causing physical safety shutdown loops and threatening lateral propagation to adjacent sites.
Setting: Global manufacturing conglomerate, ~340 sites, 40 countries, OT/IT-converged plants
Objectives
- Contain the ransomware's lateral spread across OT/IT boundaries before it reaches a second site.
- Coordinate executive, legal, and technical response without losing stakeholder trust.
- Determine appropriate regulatory disclosure timing under SEC and multi-jurisdiction requirements.
- Restore operations securely without reintroducing the same architectural exposure.
Four Roles, Four Vantage Points
Each participant sees only what their role would realistically know — the exercise is as much about getting the right information to the right person in time as it is about the technical response.
Chief Information Security Officer
You are the CISO. Your focus is business continuity, board communications, cyber insurance coordination, and strategic escalation.
SOC Incident Commander
You are the SOC Lead. Your focus is SIEM monitoring, indicator correlation, containment scoping, and forensic log preservation.
Chief Compliance Officer
You are the GRC Chief. Your focus is SEC materiality disclosure, GDPR/multi-jurisdiction reporting clocks, and regulatory alignment.
VP of Infrastructure & Recovery
You are the VP of Infrastructure. Your focus is network isolation, backup recovery verification, Purdue model security, and system rebuilds.
Five Acts
2
Containment & Isolation
4
Governance & Materiality
A Real Decision, Illustrated
This is the actual first decision the Chief Information Security Officer faces in Act 1 — no two playthroughs go the same way after this.
How do you coordinate the initial command response?
-
Declare a P1 corporate incident immediately, spin up the crisis bridge, and notify executive leadership.
Leadership is engaged early, but panic spreads across departments.
-
Skip the formal crisis bridge and call the CEO directly for unilateral authority to act fast.
You get instant authority, but the rest of the leadership team learns about the incident secondhand and starts working around you instead of with you.
-
Instruct the SOC to verify the scope quietly before escalating to avoid unnecessary panic.
You gain a brief window of quiet, but lose valuable containment response time.
What You Get At The End
Every completed run generates an After-Action Report — executive summary, full decision timeline, performance scoring mapped to NIST CSF 2.0, and a concrete improvement plan. See a sample report (PDF).