All scenarios
OT / ICS
Industrial control-system compromise
An attacker reaches SCADA and PLC systems. Manage safety-critical processes, physical impact and the friction between IT security and operations-technology teams.
Free to use for your own tabletop, no email gate.
Scenario brief

The threat
A compromised engineering workstation gives the adversary a path to the control network. Setpoints drift, a safety instrumented system trips, and the plant faces a genuine physical-safety decision, not just a data one.
Key injects
- 01A PLC heartbeat is lost on a critical line; the interlock trips.
- 02Operations wants to keep running; security wants to isolate.
- 03Sensor readings look manipulated: can they be trusted?
- 04A regulator asks whether public safety is at risk.
What's assessed
- Safety-first decision-making under adversarial conditions
- IT/OT authority and escalation clarity
- Trustworthiness of telemetry and manual fallback
- Public-safety communication
Exercise objectives
- Reach a documented safe-state decision (run, degrade or shut down) within 45 minutes, with safety explicitly outranking uptime.
- Resolve the IT-security-versus-operations conflict through one accountable decision-maker instead of a standoff.
- Assess which telemetry can still be trusted and move affected lines to manual or local control where needed.
- Have the regulator briefing (KRITIS/NIS2 reporting chain) and a public-safety statement ready before the exercise closes.
Roles at the table
- ●Crisis team lead · Keeps safety, security and operations in one decision loop; owns the log and the clock.
- ●IT / SOC · Scopes the path from the engineering workstation into the control network; hunts persistence without breaking operations.
- ●OT engineering lead · Knows what the PLCs, interlocks and the safety instrumented system actually do, and what manual control really means.
- ●Communications · Public-safety wording, workforce information and the line to press and neighbours.
- ●Legal / regulatory · KRITIS/NIS2 reporting chain, liability of a restart decision, evidence preservation.
- ●Plant management (executive) · Carries the run/stop decision and its production cost; the safety veto ends every debate.
Discussion prompts
- 01The safety system tripped once. Do you trust it to trip again, and would you bet a life on it?
- 02Operations wants to restart; security cannot rule out persistence in the control network. Who wins, on what evidence?
- 03Which sensor readings do you still trust once manipulation is on the table, and what does your manual fallback actually look like?
- 04A regulator asks whether public safety is at risk. What do you say when the honest answer is 'we don't know yet'?
- 05Engineering workstations bridge IT and OT. Who owns them today, and who should?
- 06If you isolate the plant network, what fails silently with it: interlocks, historians, remote maintenance?
Suggested timeline
- 00:00–00:25Loss of PLC heartbeat, interlock trip: first situation picture
- 00:25–01:05Safe-state decision: run, degrade or shut down, safety holds the veto
- 01:05–02:00Telemetry trust, manual control, persistence hunt vs. operations
- 02:00–02:40Regulator and public-safety communication (KRITIS/NIS2 chain)
- 02:40–03:00Hot wash: restart preconditions and decision review