Financial fraudadvanced
Authorised by the CFO
A perfectly-written invoice email harvests one payroll clerk's credentials. Two days later 23 employees' bank details point at three accounts, €340,000 has left on a single signature, and the CFO who authorised it by phone was on a plane at the time. Teams work an integrity incident with a recall window measured in hours.
Manufacturing & Engineering · 3 injects · 13 decisions · ~95 min
Ransomwareintro
Nordwind Standstill
Ransomware detonates in a German logistics operator's warehouse management system on a Friday evening. Trucks are queuing, the backup story is unclear, and NIS2 gives you 24 hours to file an early warning. Teams decide what to shut down, what to restore, and what to report.
Logistics & Transport · 2 injects · 5 decisions · ~55 min
Credential theftintermediate
Operation Shadow Harvest
A spear-phishing email at a mid-sized MSSP turns into stolen client credentials. Teams triage, investigate, contain and decide who to tell — while the clock runs and every client environment the MSSP manages is downstream of the blast radius.
Managed Security Service Provider (MSSP) · 3 injects · 12 decisions · ~90 min