Ransomware / Double Extortion

Operation Iron Horizon

Ransomware has hit the production network of a major manufacturing plant, causing physical safety shutdown loops and threatening lateral propagation to adjacent sites.

Setting: Global manufacturing conglomerate, ~340 sites, 40 countries, OT/IT-converged plants

Objectives

Four Roles, Four Vantage Points

Each participant sees only what their role would realistically know — the exercise is as much about getting the right information to the right person in time as it is about the technical response.

Chief Information Security Officer
You are the CISO. Your focus is business continuity, board communications, cyber insurance coordination, and strategic escalation.
SOC Incident Commander
You are the SOC Lead. Your focus is SIEM monitoring, indicator correlation, containment scoping, and forensic log preservation.
Chief Compliance Officer
You are the GRC Chief. Your focus is SEC materiality disclosure, GDPR/multi-jurisdiction reporting clocks, and regulatory alignment.
VP of Infrastructure & Recovery
You are the VP of Infrastructure. Your focus is network isolation, backup recovery verification, Purdue model security, and system rebuilds.

Five Acts

1
Ingestion & Triage
2
Containment & Isolation
3
The Pivot
4
Governance & Materiality
5
Recovery & Debrief

A Real Decision, Illustrated

This is the actual first decision the Chief Information Security Officer faces in Act 1 — no two playthroughs go the same way after this.

How do you coordinate the initial command response?

What You Get At The End

Every completed run generates an After-Action Report — executive summary, full decision timeline, performance scoring mapped to NIST CSF 2.0, and a concrete improvement plan. See a sample report (PDF).

Solo and multiplayer tabletop exercises are free to run.

Run This Exercise Free