OTC-MFG-00160 min
BLACK FORGE
Ransomware meets the factory
A precision manufacturer begins experiencing enterprise system disruption consistent with a ransomware event. Engineering and production data systems become partially unavailable, and the team must decide what to isolate, whether production can continue, whether manufacturing data can be trusted, how customer commitments are handled, and what a trustworthy return to production requires.
Grounded in · 2019 ransomware at Norsk Hydro forced manual plant operations across 170 sites worldwide
OTC-MFG-00260 min
GHOST TOOLPATH
Can you trust the part?
A manufacturing engineer discovers unexplained differences between authorized and production versions of manufacturing information — CAD, CAM, CNC programs, work instructions, or process parameters. Participants must decide whether machines keep operating, which files are trustworthy, what production lots are potentially affected, and how known-good manufacturing data is restored.
Grounded in · Stuxnet manipulated industrial control logic while reporting normal operation to operators
OTC-MFG-00360 min
FALSE PASS
When quality data cannot be trusted
Conflicting measurements or unexpected modifications appear in quality-system information. Physical product may or may not be affected. Can product ship? Which lots require reinspection? How far backward does the investigation go, and who communicates with customers?
Grounded in · The 2017 Kobe Steel falsified quality-data scandal triggered recalls and requalification across aerospace and automotive customers
OTC-MFG-00460 min
REMOTE HAND
The vendor connection
Suspicious activity appears associated with a remote-support pathway used by an equipment vendor or integrator. The scenario does not presume vendor guilt — participants must manage uncertainty, account governance, and isolation decisions without losing the support their machines depend on.
Grounded in · The 2013 Target breach began with credentials stolen from an HVAC vendor's remote access
OTC-MFG-00560 min
NIGHT SHIFT
The insider problem
Credential misuse surfaces on the off-shift. It could be a malicious insider, a compromised employee credential, or an accidental action — the scenario does not reveal which. Participants must investigate without premature attribution while operations continue.
Grounded in · Maroochy Shire (2000): a disgruntled ex-contractor used insider knowledge to release sewage 46 times before being caught
OTC-MFG-00660 min
DEAD PANEL
Loss of view, loss of control
Operators experience degraded or inconsistent visibility into one or more manufacturing cells. Participants must determine whether physical processes remain trustworthy, whether manual operation is appropriate, what local indications to trust, and how IT and OT investigate without worsening conditions.
Grounded in · The 2015 Ukraine grid attack included operators watching their own HMIs being driven by someone else
OTC-MFG-00760 min
LOCKED CELL
Automation without confidence
A robotic or automated work cell begins exhibiting unexpected behavior or becomes unavailable after suspicious digital activity. Safety coordination is central: machine state, cell entry, restart authority, and production continuity all collide.
Grounded in · Honda (2020) halted plants worldwide after OT-aware ransomware reached production networks
OTC-MFG-00860 min
BROKEN BACKUP
Recovery is not a button
Following containment of an incident, the organization discovers that recovery assumptions differ across enterprise IT, manufacturing systems, controllers, machine configurations, engineering files, and quality systems. What does 'restored' actually mean, and what must be validated before production resumes?
Grounded in · Maersk rebuilt 45,000 PCs and 4,000 servers after NotPetya; recovery hinged on one domain controller that survived by luck
OTC-MFG-00990 min
POISONED UPDATE
Trusted supply chain, untrusted outcome
A trusted industrial technology update becomes the focus of an investigation after anomalous behavior appears across customer environments. Participants coordinate with the supplier, weigh update rollback against support obligations, and manage uncertainty across the installed base.
Grounded in · SolarWinds (2020): a trusted vendor's signed update became the intrusion vector for thousands of organizations
OTC-MFG-01060 min
SHADOW ERP
When business systems stop the factory
Core business systems become unavailable while physical production equipment remains fully functional. The exercise explores how digitally dependent modern production really is: scheduling, releases, shipping, identity, and logistics without the systems that normally carry them.
Grounded in · Clorox (2023): an IT-side incident disrupted order processing and left shelves empty for months
OTC-MFG-01190 min
CASCADE
Cyber + infrastructure failure
A cyber incident and a power/facility disruption arrive together — or do they? The cause remains uncertain: cyber, physical, coincidental, or combined. The exercise tests decision-making under ambiguity and degraded communications.
Grounded in · The 2003 Northeast blackout grew from a software failure in grid alarm systems into a cascading infrastructure collapse
OTC-MFG-012120 min
IRON TEMPEST
The capstone
An advanced multi-site crisis combining an industrial cyber incident with a critical customer commitment and a supplier failure. Executive crisis management, product integrity, recovery, and communications under sustained pressure — combining lessons from the series without unrealistic disaster stacking.
Grounded in · NotPetya (2017) remains the costliest cyber event on record, halting manufacturers and shippers worldwide as collateral damage
OTC-MFG-01360 min
BROKEN CHAIN
The supplier is down. The crisis is yours.
Your single-source supplier is down with ransomware. Nothing of yours is compromised — and the crisis is entirely yours anyway: material runway, emergency second-sourcing, customer flow-downs, and the question of how connected you really are to a company in the middle of an incident.
Grounded in · Toyota halted all 14 Japanese plants after a cyberattack on supplier Kojima Industries
OTC-MFG-01460 min
GRAY MARKET
Provenance under pressure
Emergency re-sourcing during a shortage invites counterfeit risk: brokered components with uncertain provenance reach receiving inspection, and the paperwork is almost perfect. Traceability, incoming verification, and disposition decisions collide with a production schedule that needed those parts yesterday.
Grounded in · A U.S. Senate Armed Services investigation documented ~1 million suspect counterfeit electronic parts in the defense supply chain
OTC-MFG-01560 min
EXPORT HOLD
Compliance at line speed
An overnight export-control and sanctions update makes a supplier relationship, a software dependency, and a customer shipment suddenly uncertain. Compliance freeze versus production, controlled-technical-data handling under pressure, and the exposure inventory nobody built until the morning they needed it.
Grounded in · The October 2022 U.S. semiconductor export controls forced manufacturers to halt shipments and re-verify licenses overnight
OTC-MFG-01660 min
SILENT PRIME
Downstream of someone else's breach
Your prime contractor discloses a breach that may have exposed your shared technical data and the portal credentials you use with them. You are downstream of someone else's incident — with obligations flowing both directions, a shared-data inventory nobody maintains, and a customer you cannot simply isolate.
Grounded in · The 2023 MOVEit mass exploitation exposed data of thousands of organizations through one vendor's product
OTC-MFG-01790 min
FAR HARBOR
The war is far away. The disruption isn't.
A regional conflict overseas closes shipping lanes and air-freight corridors while hacktivist activity targets your sector at home. Inbound material reroutes, outbound commitments slip, the threat posture rises, and employees bring the world's anxiety onto the plant floor.
Grounded in · The Viasat KA-SAT attack at the start of the Ukraine invasion knocked out remote monitoring for ~5,800 German wind turbines
OTC-MFG-01860 min
DARK GRID
Production in the brownout
Rolling blackouts arrive with a regional energy crisis — and with an unverified report of cyber activity in the utility sector. Power rationing, safe production cycling, generator scheduling, and protecting OT equipment through dirty power, all without ever learning whether the rumor was true.
Grounded in · The 2015 and 2016 Ukraine grid attacks caused real outages for hundreds of thousands of customers
OTC-MFG-01960 min
FALSE FLAG
The documents look real. Are they?
A social-media account begins publishing what it claims are leaked internal documents alleging quality fraud at your plant. Some details are accurate, some are wrong, and one document nobody can immediately disprove. Authenticity verification, media pressure, customer calls, and employee trust — all at once, all on the clock.
Grounded in · Citizen Lab documented 'tainted leaks' — stolen documents altered before release to carry a false story
OTC-MFG-02090 min
LONG HARVEST
Nothing is down. Everything is taken.
A government agency notifies you that your design data was found in an unrelated investigation — exfiltrated, it appears, months ago. Nothing is broken, nothing is encrypted, production hums along. The crisis is entirely about what was taken, who must be told, and what it means to respond to an incident that ended before you knew it began.
Grounded in · The 2014 U.S. indictment of five PLA officers documented years-long economic espionage against U.S. manufacturers
OTC-MFG-02160 min
CLOSED PORT
Ninety days to leave the cloud
Your cloud business-suite provider announces it is suspending service in your region within ninety days, citing a foreign court ruling and new sanctions guidance. Nothing is compromised — everything is leaving. Data gravity, migration under deadline, continuity of the systems your factory quietly depends on, and the vendor-exit playbook nobody wrote.
Grounded in · 2022 sanctions saw major software and cloud vendors suspend services in Russia within weeks
OTC-MFG-02260 min
MUSTER POINT
Half the crew, twice the phish
A public-health wave cuts plant staffing by forty percent in a week — and a phishing surge arrives to meet the temporary workers, loaned crews, and exhausted supervisors covering the gaps. Running lean safely while the human layer of your security is at its thinnest.
Grounded in · CISA and NCSC documented the surge of pandemic-themed phishing exploiting the 2020 disruption
OTC-MFG-02360 min
LAST SHIFT
When trust walks out the door
A valued engineer has resigned to join a competitor, and monitoring flags bulk access to design folders in their final week. The deliberate-insider counterpart to the ambiguity of an unattributed anomaly: access-revocation timing, HR and legal choreography, evidence discipline, and the discipline of treating a person as innocent while protecting the company as if they are not.
Grounded in · A GE engineer was convicted of stealing turbine trade secrets accumulated over years of employment
OTC-MFG-02460 min
CLEAR TEXT
The spill and the cover-up reflex
An engineer emails a controlled technical-data package to the wrong supplier contact — and a well-meaning colleague deletes the email before anyone can assess what actually went out. The recovery is a discipline test: contain without destroying the record, scope honestly, classify what truly spilled, notify per counsel's review, sanitize per policy, and fix the process that put the wrong recipient one keystroke away.
Grounded in · Level One Robotics (2018) exposed 157GB of automaker data — NDAs, schematics, plant layouts — via an open transfer server
OTC-MFG-02560 min
COLD START
Securing the line's first breath
A new production line is being commissioned — integrator laptops on the network, temporary remote access wide open, default credentials on fresh equipment — when an anomaly appears on a device that is not in the asset inventory yet. Securing the birth of a line, where every insecure default is a decision nobody remembers making.
Grounded in · TSMC (2018): one unpatched new tool brought a WannaCry variant into fabs, costing ~$170M
OTC-MFG-02660 min
FIELD DAY
The laptop that left the country
An engineering laptop goes missing — or is briefly out of its owner's sight during an inspection — while traveling to a high-risk region. What was on it, what it could still reach, and an exposure assessment nobody can complete precisely turn a lost device into a decision about trust, access, and controlled data.
Grounded in · DarkHotel espionage targeted traveling executives through hotel networks for years
OTC-MFG-02760 min
WIRE BRUSH
The invoice that wasn't
The deposit for a new machining center is wired — to the wrong account, via a hijacked supplier email thread so convincing nobody thought to call. Payment-fraud response, verification callbacks, the bank-and-counsel clock, and the supplier master-data governance that would have stopped it before the money moved.
Grounded in · FBI IC3 reporting puts cumulative business email compromise losses in the tens of billions of dollars
OTC-MFG-02890 min
SPLIT BRAIN
Whose incident is it now?
Mid-acquisition integration: the newly acquired plant has a flat network, unknown OT hygiene, and incident indicators surface during the identity cutover weekend. Two IT cultures, one legal entity, and the question of whose incident-response plan governs a plant that is legally yours and operationally a stranger's.
Grounded in · Marriott discovered a breach that had lived inside acquired Starwood systems since 2014
OTC-MFG-02960 min
GLASS JAW
When you can't trust the safety layer's eyes
An IT incident raises a question nobody can quickly close: were the systems that support safety-adjacent monitoring touched? The safety hardware is intact — but confidence in what it is telling you is not. Policy-level run and stop decisions when the layer you trust to warn you is itself in question, with OEM verification as the road back.
Grounded in · TRITON/TRISIS (2017) targeted a petrochemical plant's safety instrumented systems
OTC-MFG-03060 min
MUSEUM PIECE
End of support, start of exposure
The vendor ends support for the controller and operating-system family running your critical cells — the same week an industry advisory reports active exploitation of that very platform. Compensating controls, isolation, and replacement economics collide on a timeline set by someone else, for equipment that still makes good parts every day.
Grounded in · WannaCry (2017) stopped production at automakers running unsupported, unpatched Windows
OTC-MFG-03190 min
SECOND SITE
Continuity versus control
A fire closes your plant; the customer cannot wait; a contract manufacturer can start next week. Emergency capacity transfer means sharing controlled technical data at speed with a partner whose environment you have never assessed — business continuity and data governance in direct, urgent collision.
Grounded in · The 2020 telework surge forced emergency expansion of remote access, with security racing behind
OTC-MFG-03260 min
OPEN MIC
The voice on the phone
The shift supervisor takes a call from a voice that sounds exactly like the CEO, demanding an urgent, out-of-process shipment release. Impersonation-era authority discipline: out-of-band verification, a culture where 'let me call you back' is always safe, and the harder lesson that lands when the voice turns out to have been real.
Grounded in · The 2023 MGM Resorts intrusion began with a phone call impersonating an employee to the help desk
OTC-MFG-03390 min
QUICKSILVER
The attack that moves faster than the meeting
An intrusion unfolds at a tempo and scale no human team could match: containment moves are countered within minutes, and convincing messages — from staff, customers, and even your own security vendor — arrive faster than anyone can verify them. The exercise is not about outrunning the adversary. It is about changing the game: pre-delegated authority, out-of-band trust, and knowing when to stop typing and isolate.
Grounded in · DARPA's 2016 Cyber Grand Challenge demonstrated fully autonomous, machine-speed attack and defense