Insider Threat / IP Theft

Operation Quiet Exit

A senior platform engineer submitted his two-weeks notice yesterday afternoon. Overnight, DLP tooling flagged an unusual bulk clone of the proprietary risk-scoring codebase and an attempted export of a customer PII table, both from his account, outside business hours.

Setting: Meridian Analytics, a mid-size fintech SaaS provider (~600 employees) building a cloud-native trading risk platform

Objectives

Four Roles, Four Vantage Points

Each participant sees only what their role would realistically know — the exercise is as much about getting the right information to the right person in time as it is about the technical response.

Chief Information Security Officer
You are the CISO. Your focus is executive risk decisions, HR/Legal coordination, and protecting the company's IP and reputation.
SOC Incident Commander
You are the SOC Lead. Your focus is DLP alert triage, access log correlation, and real-time monitoring of the insider's activity.
Chief Compliance Officer
You are the GRC Chief. Your focus is evidentiary chain of custody, employment law exposure, and regulatory notification obligations if customer data was exposed.
VP of Platform Engineering
You are the VP of Engineering. Your focus is access revocation, credential rotation, and closing the architectural gap that let this happen.

Five Acts

1
The DLP Alert
2
The Interview
3
The Pivot
4
Response & Containment
5
Recovery & Debrief

A Real Decision, Illustrated

This is the actual first decision the Chief Information Security Officer faces in Act 1 — no two playthroughs go the same way after this.

How do you direct the initial response?

What You Get At The End

Every completed run generates an After-Action Report — executive summary, full decision timeline, performance scoring mapped to NIST CSF 2.0, and a concrete improvement plan. See a sample report (PDF).

Solo and multiplayer tabletop exercises are free to run.

Run This Exercise Free