All scenarios
Banking & Finance
SWIFT compromise & data exfiltration
Fraudulent transfers and customer-data theft under a DORA clock. Handle regulators, customer notification, fraud investigation and market exposure at once.
Free to use for your own tabletop, no email gate.
Scenario brief

The threat
Anomalous SWIFT messages and a spike in card-not-present fraud reveal a deep intrusion. The DORA major-incident clock starts, the supervisor expects an initial report, and the market is watching the share price.
Key injects
- 01Treasury flags outbound transfers that no one authorised.
- 02The supervisor opens the DORA initial-notification window.
- 03A journalist has a screenshot of an internal incident channel.
- 04Fraud volumes climb as customers report drained accounts.
What's assessed
- DORA notification timing and content quality
- Fraud containment vs. service continuity trade-offs
- Customer-notification and market-disclosure judgement
- Coordination across fraud, legal and comms
Exercise objectives
- Classify the incident under DORA and have the initial report drafted inside the exercise window: due 4 hours after classification as major, at the latest 24 hours after awareness.
- Stop fraudulent outflows without unilaterally taking core payment services down.
- Run fraud, legal, treasury and communications on one decision cadence with a single log.
- Prepare customer notification and market communication that survive next-morning scrutiny.
Roles at the table
- ●Crisis team lead · Runs the cadence across fraud, IT, legal and comms; arbitrates when clocks collide.
- ●IT / SOC forensics · Traces the intrusion behind the SWIFT anomalies; protects evidence while systems stay up.
- ●Fraud & payments operations · Freezes suspicious flows and coordinates with correspondent banks and card schemes.
- ●Communications / investor relations · Customer lines, press response and the market's reading of every word.
- ●Legal & compliance · Owns the DORA reporting clock (4 h / 24 h, 72 h, 1 month) and the GDPR duties running in parallel.
- ●Executive board member · Approves service shutdowns, disclosure and spending; answers to the supervisor.
Discussion prompts
- 01The DORA clock starts at classification, not at certainty. When do you call the incident 'major', and who signs that call?
- 02Do you cut SWIFT connectivity while transfers are still moving? Price an hour of downtime against one more fraudulent batch.
- 03Customers post screenshots of drained accounts. Confirm, deny or stay silent, and for how long?
- 04A journalist quotes your internal incident channel. What changes in the next thirty minutes?
- 05In the 72-hour intermediate report, what matters more: completeness, or candour about what you still don't know?
- 06DORA and GDPR notifications run in parallel. Who makes sure the supervisor and the data-protection authority hear the same story?
Suggested timeline
- 00:00–00:20Anomalous SWIFT messages and fraud spike: triage, first freezes
- 00:20–01:00Classification call: DORA major-incident decision starts the clock (4 h / 24 h)
- 01:00–01:50Containment vs. continuity: payment services, correspondent banks, schemes
- 01:50–02:35Initial report drafted; customer and market lines aligned
- 02:35–03:00Hot wash: report quality, decision latency, 72-hour and 1-month follow-ups