Exercises / EX-2026-03 Ransomware with reputation extortion / Debrief home
View as

EX-2026-03 Ransomware with reputation extortion

Organization Corvid Manufacturing Group Run 2026-09-10, 09:00 to 13:05 PT Participants 11 Agents 5 (adversary, journalist, regulator, general counsel, customer) Facilitator Sam Okafor
Review in progress
Decision timeline
Within required windowLate or out of sequenceNot performed in exerciseContext event, not assessed
Findings by gap category Recurrence compares with EX-2026-01 (Q1 2026)
Recommended next exercise Generated from open gaps and overdue actions
Fictional exercise. Organization, participants, transcript and findings are invented for a design case study. Gap categories follow the four recurring incident response gaps described on The Cyber Security Matters Podcast, Ep 74 (June 2026), plus communication breakdown and capability gap from the Founding Product Lead job description. Required windows come from the fictional organization's plan; where the plan is silent, expected behavior follows NIST SP 800-61 and IBM Cost of a Data Breach 2026 findings.
All categories Decision authority Notification order Containment vs recovery Tribal knowledge Communication breakdown Capability gap Any confidence High Medium Low Any state New Reviewed Needs attention Repeated from Q1
#CategoryFindingConfidenceEvidenceState
No findings match these filtersClear a filter to see the rest of the set. Rejected findings stay in the record and can be restored.
Evidence
Confidence computed from the evidence
Recommendation
Review history
    Click any marker, label or row to see the required behavior, what happened, and the linked finding.
    Decision timeline, EX-2026-03
    Within required windowLate or out of sequenceNot performed in exerciseContext event, not assessed
    Events Required window is from the organization's plan or, where the plan is silent, from NIST SP 800-61 and IBM 2026 findings
    ClockEventActorRequired behaviorResultFinding
    Findings submitted for approval Rejected findings are excluded. Low-confidence findings appear only with a facilitator override.
    CISO comment

    Executive summary: EX-2026-03 Ransomware with reputation extortion

    Corvid Manufacturing Group. Exercise run 2026-09-10. 11 participants across Security, IT, Legal, Communications, Finance, Operations and the executive team. 5 adaptive agents.
    Top recommendations Approved findings, ordered by confidence, repeated gaps first
      Evidence appendix Participant attribution is hidden for executive readers
      The CISO report is shared with the facilitator, the CISO and executive readers.
      Switch the view to see it.

      CISO report: EX-2026-03 Ransomware with reputation extortion

      Corvid Manufacturing Group. Appendix to the executive summary. Answers three questions: were we ready, how did the first hour go, and what is still open.
      Incident arc What a CISO expects to see in each phase, against what the exercise showed. Exercise clock starts at the extortion note.
      ✓ Met ~ Partial ✕ Missed ? Needs discussion F1 Opens the finding GV.RR Standard reference
      Repeated incidents Gap categories found again in this exercise, and the prior action meant to close each one
      Team gaps by disposition Where the team agrees, where the record needs more, and where people disagree
      ConfidenceAllHighMediumLowShowAll issuesRepeat issuesNew this exerciseClear
      Open items, not in the approved report Findings that did not pass review. Tracked by the facilitator; not shown to the board or insurer as fact.
        Key incidents against security standards Moments in the exercise matched to the framework, rule or technique they fall under
        Decisions needed from leadership
          Fictional organization and exercise. Standards mapping is illustrative and is not legal advice. References: NIST SP 800-61 Rev. 3 (April 2025) and NIST CSF 2.0 categories; SEC Form 8-K Item 1.05; MITRE ATT&CK Enterprise techniques; CIRCIA (CISA final rule expected September 2026, not yet confirmed in effect).
          All actions Open Overdue Done Carried from Q1 Pending approval
          Remediation actions Each approved recommendation becomes an owned action. Open Q1 actions explain the gaps that repeated.
          IDActionOwnerGap categoryDueStatusSource
          No actions match this filterClear the filter to see every action.
          Fictional actions. New actions are generated from EX-2026-03 recommendations and become open when the CISO publishes the approved after-action report; until then they show as pending approval. Q1 actions come from the prior exercise EX-2026-01.
          Readiness trend is shared with the facilitator, the CISO and executive readers.
          Switch the view to see it.
          Corvid Manufacturing Group, last three exercises. The view a CISO takes to the board and an account lead brings to renewal.
          Trend by exercise One measure per chart. Latest exercise highlighted.
          Gap categories across exercises Count of findings per category. Red marker: category also found in the exercise before.
          Account health Vendor side only, not shown to the customer. Leading indicators for renewal on 2027-02-01.
          Fictional organization and exercises. Scenario difficulty rose in EX-2026-03 (adaptive adversary plus reputation extortion), so finding count alone is not a readiness measure; recurrence, closure and decision latency are.
          A point of view on where this product can go, built from public sources. Not a company roadmap.
          The loop this slice starts Each turn of the loop makes the next exercise cheaper, more targeted and more valuable to renew
          Simulate→Debrief and evidence→Remediate→Measure readiness→Target the next exercise↻
          Three horizons
          How I would own the customer after the sale
          Sources: The Cyber Security Matters Podcast Ep 74 (June 2026) for the data-set thesis and the automated pen testing analogy; the Founding Product Lead job description for regulator and insurer demand; IBM Cost of a Data Breach Report 2026 for cost of delay and noncompliance. Benchmarks and integrations below are proposals, not claims about any existing product.