Self-Run Tabletop Exercise · Free

The breach that starts with someone else's software

A 90-minute incident response rehearsal your team can run in a conference room. No software, no consultants, no preparation beyond printing it. Adapted from OPERATION DANGER CLOSE, a facilitated exercise built from a real 2023 event.

PDF, 3 pages. No email required. Print it and go.

Run time
60 to 90 minutes
Group size
5 to 30 participants
Format
Discussion-based, no laptops
Who attends
IT, risk, legal, operations
You need
A room, a whiteboard, a timer
You leave with
A documented test and named owners
Why this scenario

Most institutions rehearse their own failure. Almost none rehearse someone else's.

Ransomware on your own network. An outage in your own data center. Those get tested. Far fewer teams rehearse the morning a trusted third-party product becomes the way in, when the vendor controls the fix and you control none of it.

That is also where examiners press. Not whether you have a plan, but whether you tested it, who was in the room, and what you did about what you found.

Hold this in mind

Your first priority is not stopping the attacker. It is keeping the business running while you stay in control.

What's inside

Five phases, one Saturday that gets worse

A fictional regional bank runs everything through a file transfer product from a vendor it has never thought twice about. Each phase gives the room a situation and three questions. Read, huddle, report back. Same rhythm every time.

1

Panic

Saturday, 6:00 AM

The vendor announces a flaw being exploited worldwide. No patch. Your analyst is at home and the CEO is already awake.

2

Control

Saturday, noon

Still no evidence you were hit. Someone wants to pull the product offline now. That freezes loan closings and Tuesday's payroll.

3

Confirmed

Sunday into Monday

Forensics finds unauthorized software on your server and files copied out Friday night. Scope unknown, and people are tired.

4

Obligations

Tuesday

Roughly 95,000 customers are in those files. A criminal group posts you on its leak site demanding $3 million. A reporter emails.

5

Recovery

The following week

The server is rebuilt. Forensics runs for months, but leadership wants a preliminary report now.

The reveal

Save this for the end

The bank is invented. The rest is drawn from the public record, mapped line by line with sources so the room can check the work.

Four seats, and nobody spectates

Chief Executive

Owns final approval and outside stakeholders. Gives decisions, not instructions.

Incident Commander

Owns execution and keeping the institution open. Defines the incident in one sentence.

CISO

Owns the security program. Turns the technical picture into a risk decision.

Legal & Comms

Owns obligations, clocks, regulators. Tracks what is reported, to whom, by when.

Take the kit

Three pages. Print one copy for the facilitator and one per team. The last page is the reveal, so hold it back until the room is done arguing. Nothing to fill in, and nothing to sign up for.

Get the kit
OPERATION DANGER CLOSE

The facilitated version goes further.

The self-run kit uses an invented bank and a generic vendor. The facilitated exercise uses yours. Same five phases, rewritten around your actual third parties, your charter, and the regulators who actually examine you.

Built by a former OCC and NYDFS IT examiner, from the perspective of the person who eventually asks how you tested this.

Scope a session

Live injects

New facts land mid-exercise. Decisions get tested against information the room did not have five minutes ago.

Your vendors

The scenario is rewritten around the third parties you actually depend on, and the ones you have never assessed.

Your clocks

Notification deadlines scoped to your charter and primary regulator, not a generic list.

A written after-action report

Findings, gaps, and named owners in a document your board and your examiners can read.