CISO report: EX-2026-03 Ransomware with reputation extortion
Corvid Manufacturing Group. Appendix to the executive summary. Answers three questions: were we ready, how did the first hour go, and what is still open.
Incident arc What a CISO expects to see in each phase, against what the exercise showed. Exercise clock starts at the extortion note.
✓ Met
~ Partial
✕ Missed
? Needs discussion
F1 Opens the finding
GV.RR Standard reference
Repeated incidents Gap categories found again in this exercise, and the prior action meant to close each one
Team gaps by disposition Where the team agrees, where the record needs more, and where people disagree
ConfidenceAllHighMediumLowShowAll issuesRepeat issuesNew this exerciseClear
Open items, not in the approved report Findings that did not pass review. Tracked by the facilitator; not shown to the board or insurer as fact.
Key incidents against security standards Moments in the exercise matched to the framework, rule or technique they fall under
Decisions needed from leadership
Fictional organization and exercise. Standards mapping is illustrative and is not legal advice. References: NIST SP 800-61 Rev. 3 (April 2025) and NIST CSF 2.0 categories; SEC Form 8-K Item 1.05; MITRE ATT&CK Enterprise techniques; CIRCIA (CISA final rule expected September 2026, not yet confirmed in effect).