All scenarios
Retail
E-commerce breach at peak season
Payment-card data stolen during the holiday rush. Meet PCI DSS obligations and customer-notification rules while defending brand reputation and business continuity.
Free to use for your own tabletop, no email gate.
Scenario brief

The threat
A skimmer on the checkout flow exfiltrates card data at the busiest time of year. The acquirer and card schemes get involved, customers notice fraud, and every hour of downtime is measured in lost revenue.
Key injects
- 01The acquirer flags a common point of purchase.
- 02Checkout errors spike as the team debates taking the site down.
- 03A customer thread about fraud goes viral.
- 04Legal asks which jurisdictions require notification.
What's assessed
- PCI containment and forensics engagement
- Downtime vs. revenue trade-off decisions
- Multi-jurisdiction notification judgement
- Brand and customer-trust messaging
Exercise objectives
- Take the site-down decision with an explicit revenue-versus-exposure calculation on the record.
- Engage acquirer, card schemes and a PCI forensic investigator in the right order, at the right time.
- Build the multi-jurisdiction notification matrix (GDPR: 72 hours to the supervisory authority, and further regimes) from a real data inventory.
- Keep customer, social and press responses consistent under viral pressure.
Roles at the table
- ●Crisis team lead · Holds the tempo between trading, security and comms; forces explicit trade-offs.
- ●IT / SOC · Finds and removes the skimmer, preserves evidence, prepares the clean-rebuild option.
- ●E-commerce trading lead · Quantifies revenue impact per hour; owns checkout configuration and rollback.
- ●Communications / social · In-thread replies, press statement, customer email: one voice at viral speed.
- ●Legal / data protection · Notification duties per jurisdiction, acquirer and scheme contracts, PCI DSS evidence.
- ●Executive management · Signs the downtime decision and the customer promise that follows it.
Discussion prompts
- 01Every hour online is peak-season revenue, and possibly more stolen cards. Who owns that trade-off: the CISO or the CFO?
- 02The acquirer named you as the common point of purchase. How long does 'we are investigating' hold?
- 03A fraud thread is going viral. Reply in-thread, publish a statement, or wait for facts: what does each option cost?
- 04In which countries do your card customers actually live, and could legal produce the notification matrix tonight?
- 05The skimmer sat in your checkout for weeks. What do you tell the card schemes about your monitoring?
- 06Would you rebuild the checkout from a clean image rather than trust a cleaned system, at peak load?
Suggested timeline
- 00:00–00:25Acquirer alert: common point of purchase confirmed internally
- 00:25–01:05Containment: site down vs. filtered checkout; forensics engaged
- 01:05–01:50Scoping: which cards, which countries, which duties (GDPR 72 h)
- 01:50–02:35Brand defence: viral thread, press statement, notification plan
- 02:35–03:00Hot wash: trade-offs, evidence quality, PCI follow-up