All scenarios
Manufacturing
Production-line ransomware
Ransomware halts the line and jumps the IT/OT boundary. Balance supplier communications, quality-assurance impact and regulatory reporting while fighting to keep production running.
Free to use for your own tabletop, no email gate.
Scenario brief

The threat
A phishing foothold in corporate IT escalates into a domain-wide ransomware deployment that reaches the plant network. Production control systems go dark, orders back up, and the attacker threatens to leak stolen design files unless paid.
Key injects
- 01EDR flags mass file encryption spreading toward the OT DMZ.
- 02The line stops; a shift supervisor calls for guidance on safe shutdown.
- 03A key customer demands a delivery guarantee within the hour.
- 04The attacker posts a countdown on their data-leak site.
What's assessed
- IT/OT segmentation decisions under time pressure
- Supplier and customer communication discipline
- Ransom decision governance and legal sign-off
- Evidence capture for regulatory notification
Exercise objectives
- Decide on IT/OT segmentation within 30 minutes of the first inject, with production, safety and delivery impact weighed on the record.
- Stand up a working crisis organisation (roles, decision authority, reporting cadence) inside the first hour.
- Have the 24-hour early warning to the competent authority (NIS2-style reporting) drafted before the exercise ends.
- Hold a consistent customer and supplier line while the ransom demand is still open.
Roles at the table
- ●Crisis team lead · Owns cadence, decision log and escalations; keeps the room on decisions instead of diagnosis.
- ●IT / SOC lead · Containment options, forensic preservation, and the honest answer to 'is it still spreading?'
- ●OT / plant operations · Safe-shutdown and manual-operation options; speaks for what the line can actually still do.
- ●Communications · Holding statements for customers, suppliers and press; one story across every channel.
- ●Legal / data protection · Ransom legality, contract penalties, notification duties and evidence discipline.
- ●Executive sponsor · Ransom stance, spending authority and the final call when functions disagree.
Discussion prompts
- 01Would you disconnect the OT network on suspicion alone, and who has the authority to stop production for days?
- 02Your backups are encrypted or unverified. At what point does paying become a board-level option, and who says the word first?
- 03A key customer demands a delivery guarantee within the hour. What do you promise while the blast radius is still unknown?
- 04The attacker leaks a sample of stolen design files. Does that change your negotiation stance, or your notification duties?
- 05Who briefs the works council and the shift teams, and what happens when a worker posts a photo of the ransom note?
- 06Could you produce the decision log a regulator or insurer will ask for next week?
Suggested timeline
- 00:00–00:20Detection & alarm: EDR alert, first triage, crisis team convenes
- 00:20–01:00Containment: IT/OT isolation decision, safe shutdown, backup status
- 01:00–02:00Escalation peak: customer pressure, leak-site countdown, ransom stance
- 02:00–02:40Reporting & comms: early warning drafted, customer and press lines aligned
- 02:40–03:00Hot wash: decisions reviewed against the timestamped log