The breach that starts with someone else's software
A 90-minute incident response rehearsal your team can run in a conference room. No software, no consultants, no preparation beyond printing it. Adapted from OPERATION DANGER CLOSE, a facilitated exercise built from a real 2023 event.
- Run time
- 60 to 90 minutes
- Group size
- 5 to 30 participants
- Format
- Discussion-based, no laptops
- Who attends
- IT, risk, legal, operations
- You need
- A room, a whiteboard, a timer
- You leave with
- A documented test and named owners
Most institutions rehearse their own failure. Almost none rehearse someone else's.
Ransomware on your own network. An outage in your own data center. Those get tested. Far fewer teams rehearse the morning a trusted third-party product becomes the way in, when the vendor controls the fix and you control none of it.
That is also where examiners press. Not whether you have a plan, but whether you tested it, who was in the room, and what you did about what you found.
Your first priority is not stopping the attacker. It is keeping the business running while you stay in control.
Five phases, one Saturday that gets worse
A fictional regional bank runs everything through a file transfer product from a vendor it has never thought twice about. Each phase gives the room a situation and three questions. Read, huddle, report back. Same rhythm every time.
Panic
Saturday, 6:00 AMThe vendor announces a flaw being exploited worldwide. No patch. Your analyst is at home and the CEO is already awake.
Control
Saturday, noonStill no evidence you were hit. Someone wants to pull the product offline now. That freezes loan closings and Tuesday's payroll.
Confirmed
Sunday into MondayForensics finds unauthorized software on your server and files copied out Friday night. Scope unknown, and people are tired.
Obligations
TuesdayRoughly 95,000 customers are in those files. A criminal group posts you on its leak site demanding $3 million. A reporter emails.
Recovery
The following weekThe server is rebuilt. Forensics runs for months, but leadership wants a preliminary report now.
The reveal
Save this for the endThe bank is invented. The rest is drawn from the public record, mapped line by line with sources so the room can check the work.
Chief Executive
Owns final approval and outside stakeholders. Gives decisions, not instructions.
Incident Commander
Owns execution and keeping the institution open. Defines the incident in one sentence.
CISO
Owns the security program. Turns the technical picture into a risk decision.
Legal & Comms
Owns obligations, clocks, regulators. Tracks what is reported, to whom, by when.
Take the kit
Three pages. Print one copy for the facilitator and one per team. The last page is the reveal, so hold it back until the room is done arguing. Nothing to fill in, and nothing to sign up for.
Get the kitThe facilitated version goes further.
The self-run kit uses an invented bank and a generic vendor. The facilitated exercise uses yours. Same five phases, rewritten around your actual third parties, your charter, and the regulators who actually examine you.
Built by a former OCC and NYDFS IT examiner, from the perspective of the person who eventually asks how you tested this.
Scope a sessionLive injects
New facts land mid-exercise. Decisions get tested against information the room did not have five minutes ago.
Your vendors
The scenario is rewritten around the third parties you actually depend on, and the ones you have never assessed.
Your clocks
Notification deadlines scoped to your charter and primary regulator, not a generic list.
A written after-action report
Findings, gaps, and named owners in a document your board and your examiners can read.