All scenarios
Manufacturing

Production-line ransomware

Ransomware halts the line and jumps the IT/OT boundary. Balance supplier communications, quality-assurance impact and regulatory reporting while fighting to keep production running.

Free to use for your own tabletop, no email gate.

Scenario brief

Production-line ransomware, Manufacturing

The threat

A phishing foothold in corporate IT escalates into a domain-wide ransomware deployment that reaches the plant network. Production control systems go dark, orders back up, and the attacker threatens to leak stolen design files unless paid.

Key injects

  • 01EDR flags mass file encryption spreading toward the OT DMZ.
  • 02The line stops; a shift supervisor calls for guidance on safe shutdown.
  • 03A key customer demands a delivery guarantee within the hour.
  • 04The attacker posts a countdown on their data-leak site.

What's assessed

  • IT/OT segmentation decisions under time pressure
  • Supplier and customer communication discipline
  • Ransom decision governance and legal sign-off
  • Evidence capture for regulatory notification

Exercise objectives

  • Decide on IT/OT segmentation within 30 minutes of the first inject, with production, safety and delivery impact weighed on the record.
  • Stand up a working crisis organisation (roles, decision authority, reporting cadence) inside the first hour.
  • Have the 24-hour early warning to the competent authority (NIS2-style reporting) drafted before the exercise ends.
  • Hold a consistent customer and supplier line while the ransom demand is still open.

Roles at the table

  • Crisis team lead · Owns cadence, decision log and escalations; keeps the room on decisions instead of diagnosis.
  • IT / SOC lead · Containment options, forensic preservation, and the honest answer to 'is it still spreading?'
  • OT / plant operations · Safe-shutdown and manual-operation options; speaks for what the line can actually still do.
  • Communications · Holding statements for customers, suppliers and press; one story across every channel.
  • Legal / data protection · Ransom legality, contract penalties, notification duties and evidence discipline.
  • Executive sponsor · Ransom stance, spending authority and the final call when functions disagree.

Discussion prompts

  • 01Would you disconnect the OT network on suspicion alone, and who has the authority to stop production for days?
  • 02Your backups are encrypted or unverified. At what point does paying become a board-level option, and who says the word first?
  • 03A key customer demands a delivery guarantee within the hour. What do you promise while the blast radius is still unknown?
  • 04The attacker leaks a sample of stolen design files. Does that change your negotiation stance, or your notification duties?
  • 05Who briefs the works council and the shift teams, and what happens when a worker posts a photo of the ransom note?
  • 06Could you produce the decision log a regulator or insurer will ask for next week?

Suggested timeline

  • 00:00–00:20Detection & alarm: EDR alert, first triage, crisis team convenes
  • 00:20–01:00Containment: IT/OT isolation decision, safe shutdown, backup status
  • 01:00–02:00Escalation peak: customer pressure, leak-site countdown, ransom stance
  • 02:00–02:40Reporting & comms: early warning drafted, customer and press lines aligned
  • 02:40–03:00Hot wash: decisions reviewed against the timestamped log

Run this scenario with your team.