Home Capabilities Security Focus Areas Reports Events Team Insights R&D Contact Client Portal
Cyberpert R&D
PublicationPublic research note

Cyber Range Scenario Pack: Ransomware Pressure and Supplier Access

A scenario pack for exercising ransomware pressure, supplier uncertainty, legal decisions, and executive communication.

A scenario pack for exercising ransomware pressure, supplier uncertainty, legal decisions, and executive communication.

Scenario premise

The exercise begins with suspicious supplier remote access, anomalous authentication, partial encryption in a business unit, and a threat actor claiming data exposure.

The scenario intentionally creates uncertainty: logs are incomplete, the supplier is slow to respond, backups are available but identity trust is unclear, and customer-facing services are under pressure.

Participant roles

The pack includes SOC, infrastructure, IAM, supplier management, legal, communications, executive leadership, insurance, and business continuity roles.

Each role receives different information, forcing the organization to practice evidence sharing, escalation, and decision discipline.

Inject library

Injects include media inquiry, customer concern, supplier denial, privileged-account anomaly, backup-restoration conflict, regulator notification question, insurance language review, and law-enforcement coordination.

Technical injects can be mapped to ATT&CK techniques, but the core learning objective is institutional decision quality.

Result

The output is a scenario structure organizations can adapt for executive tabletop, SOC coordination, supplier-risk review, and ransomware readiness assessment.

Scoring focuses on decision latency, evidence completeness, restoration sequencing, communication discipline, and after-action closure.

Exercise design reference

CCDCOE Locked Shields demonstrates that cyber exercises are strongest when they combine technical defence, legal reasoning, strategic communication, and leadership pressure. This scenario pack adapts that logic for organizations that need ransomware and supplier-risk rehearsal.

The scenario begins with suspicious supplier access, anomalous authentication, partial encryption, uncertain data exposure, and public pressure. Participants do not receive perfect facts; they must build a defensible operating picture under uncertainty.

Scoring criteria

Scoring covers evidence completeness, decision latency, containment authority, supplier coordination, restoration sequencing, legal escalation, regulator readiness, message consistency, and after-action ownership.

The expected output is not only a better tabletop. It is a prioritized improvement backlog for identity controls, supplier access, logging, communication approvals, and recovery dependencies.