SCENARIO CATALOG

149 scenarios. 15 series. Every one grounded in a real incident.

What you see here is the catalog: the situation each scenario puts your team in and the real events it is built from. The injects, decision points, and scoring live inside the platform — that's the part your team experiences live.

MFG · DISCRETE & PROCESS MANUFACTURING

Manufacturing33 scenarios

Ransomware reaching the floor, untrusted CNC/manufacturing data, quality-record integrity, vendor remote access, insider risk, controlled data, and an agentic-AI capstone — the founding OT Crucible library.

OTC-MFG-00160 min

BLACK FORGE

Ransomware meets the factory

A precision manufacturer begins experiencing enterprise system disruption consistent with a ransomware event. Engineering and production data systems become partially unavailable, and the team must decide what to isolate, whether production can continue, whether manufacturing data can be trusted, how customer commitments are handled, and what a trustworthy return to production requires.

Grounded in · 2019 ransomware at Norsk Hydro forced manual plant operations across 170 sites worldwide

OTC-MFG-00260 min

GHOST TOOLPATH

Can you trust the part?

A manufacturing engineer discovers unexplained differences between authorized and production versions of manufacturing information — CAD, CAM, CNC programs, work instructions, or process parameters. Participants must decide whether machines keep operating, which files are trustworthy, what production lots are potentially affected, and how known-good manufacturing data is restored.

Grounded in · Stuxnet manipulated industrial control logic while reporting normal operation to operators

OTC-MFG-00360 min

FALSE PASS

When quality data cannot be trusted

Conflicting measurements or unexpected modifications appear in quality-system information. Physical product may or may not be affected. Can product ship? Which lots require reinspection? How far backward does the investigation go, and who communicates with customers?

Grounded in · The 2017 Kobe Steel falsified quality-data scandal triggered recalls and requalification across aerospace and automotive customers

OTC-MFG-00460 min

REMOTE HAND

The vendor connection

Suspicious activity appears associated with a remote-support pathway used by an equipment vendor or integrator. The scenario does not presume vendor guilt — participants must manage uncertainty, account governance, and isolation decisions without losing the support their machines depend on.

Grounded in · The 2013 Target breach began with credentials stolen from an HVAC vendor's remote access

OTC-MFG-00560 min

NIGHT SHIFT

The insider problem

Credential misuse surfaces on the off-shift. It could be a malicious insider, a compromised employee credential, or an accidental action — the scenario does not reveal which. Participants must investigate without premature attribution while operations continue.

Grounded in · Maroochy Shire (2000): a disgruntled ex-contractor used insider knowledge to release sewage 46 times before being caught

OTC-MFG-00660 min

DEAD PANEL

Loss of view, loss of control

Operators experience degraded or inconsistent visibility into one or more manufacturing cells. Participants must determine whether physical processes remain trustworthy, whether manual operation is appropriate, what local indications to trust, and how IT and OT investigate without worsening conditions.

Grounded in · The 2015 Ukraine grid attack included operators watching their own HMIs being driven by someone else

OTC-MFG-00760 min

LOCKED CELL

Automation without confidence

A robotic or automated work cell begins exhibiting unexpected behavior or becomes unavailable after suspicious digital activity. Safety coordination is central: machine state, cell entry, restart authority, and production continuity all collide.

Grounded in · Honda (2020) halted plants worldwide after OT-aware ransomware reached production networks

OTC-MFG-00860 min

BROKEN BACKUP

Recovery is not a button

Following containment of an incident, the organization discovers that recovery assumptions differ across enterprise IT, manufacturing systems, controllers, machine configurations, engineering files, and quality systems. What does 'restored' actually mean, and what must be validated before production resumes?

Grounded in · Maersk rebuilt 45,000 PCs and 4,000 servers after NotPetya; recovery hinged on one domain controller that survived by luck

OTC-MFG-00990 min

POISONED UPDATE

Trusted supply chain, untrusted outcome

A trusted industrial technology update becomes the focus of an investigation after anomalous behavior appears across customer environments. Participants coordinate with the supplier, weigh update rollback against support obligations, and manage uncertainty across the installed base.

Grounded in · SolarWinds (2020): a trusted vendor's signed update became the intrusion vector for thousands of organizations

OTC-MFG-01060 min

SHADOW ERP

When business systems stop the factory

Core business systems become unavailable while physical production equipment remains fully functional. The exercise explores how digitally dependent modern production really is: scheduling, releases, shipping, identity, and logistics without the systems that normally carry them.

Grounded in · Clorox (2023): an IT-side incident disrupted order processing and left shelves empty for months

OTC-MFG-01190 min

CASCADE

Cyber + infrastructure failure

A cyber incident and a power/facility disruption arrive together — or do they? The cause remains uncertain: cyber, physical, coincidental, or combined. The exercise tests decision-making under ambiguity and degraded communications.

Grounded in · The 2003 Northeast blackout grew from a software failure in grid alarm systems into a cascading infrastructure collapse

OTC-MFG-012120 min

IRON TEMPEST

The capstone

An advanced multi-site crisis combining an industrial cyber incident with a critical customer commitment and a supplier failure. Executive crisis management, product integrity, recovery, and communications under sustained pressure — combining lessons from the series without unrealistic disaster stacking.

Grounded in · NotPetya (2017) remains the costliest cyber event on record, halting manufacturers and shippers worldwide as collateral damage

OTC-MFG-01360 min

BROKEN CHAIN

The supplier is down. The crisis is yours.

Your single-source supplier is down with ransomware. Nothing of yours is compromised — and the crisis is entirely yours anyway: material runway, emergency second-sourcing, customer flow-downs, and the question of how connected you really are to a company in the middle of an incident.

Grounded in · Toyota halted all 14 Japanese plants after a cyberattack on supplier Kojima Industries

OTC-MFG-01460 min

GRAY MARKET

Provenance under pressure

Emergency re-sourcing during a shortage invites counterfeit risk: brokered components with uncertain provenance reach receiving inspection, and the paperwork is almost perfect. Traceability, incoming verification, and disposition decisions collide with a production schedule that needed those parts yesterday.

Grounded in · A U.S. Senate Armed Services investigation documented ~1 million suspect counterfeit electronic parts in the defense supply chain

OTC-MFG-01560 min

EXPORT HOLD

Compliance at line speed

An overnight export-control and sanctions update makes a supplier relationship, a software dependency, and a customer shipment suddenly uncertain. Compliance freeze versus production, controlled-technical-data handling under pressure, and the exposure inventory nobody built until the morning they needed it.

Grounded in · The October 2022 U.S. semiconductor export controls forced manufacturers to halt shipments and re-verify licenses overnight

OTC-MFG-01660 min

SILENT PRIME

Downstream of someone else's breach

Your prime contractor discloses a breach that may have exposed your shared technical data and the portal credentials you use with them. You are downstream of someone else's incident — with obligations flowing both directions, a shared-data inventory nobody maintains, and a customer you cannot simply isolate.

Grounded in · The 2023 MOVEit mass exploitation exposed data of thousands of organizations through one vendor's product

OTC-MFG-01790 min

FAR HARBOR

The war is far away. The disruption isn't.

A regional conflict overseas closes shipping lanes and air-freight corridors while hacktivist activity targets your sector at home. Inbound material reroutes, outbound commitments slip, the threat posture rises, and employees bring the world's anxiety onto the plant floor.

Grounded in · The Viasat KA-SAT attack at the start of the Ukraine invasion knocked out remote monitoring for ~5,800 German wind turbines

OTC-MFG-01860 min

DARK GRID

Production in the brownout

Rolling blackouts arrive with a regional energy crisis — and with an unverified report of cyber activity in the utility sector. Power rationing, safe production cycling, generator scheduling, and protecting OT equipment through dirty power, all without ever learning whether the rumor was true.

Grounded in · The 2015 and 2016 Ukraine grid attacks caused real outages for hundreds of thousands of customers

OTC-MFG-01960 min

FALSE FLAG

The documents look real. Are they?

A social-media account begins publishing what it claims are leaked internal documents alleging quality fraud at your plant. Some details are accurate, some are wrong, and one document nobody can immediately disprove. Authenticity verification, media pressure, customer calls, and employee trust — all at once, all on the clock.

Grounded in · Citizen Lab documented 'tainted leaks' — stolen documents altered before release to carry a false story

OTC-MFG-02090 min

LONG HARVEST

Nothing is down. Everything is taken.

A government agency notifies you that your design data was found in an unrelated investigation — exfiltrated, it appears, months ago. Nothing is broken, nothing is encrypted, production hums along. The crisis is entirely about what was taken, who must be told, and what it means to respond to an incident that ended before you knew it began.

Grounded in · The 2014 U.S. indictment of five PLA officers documented years-long economic espionage against U.S. manufacturers

OTC-MFG-02160 min

CLOSED PORT

Ninety days to leave the cloud

Your cloud business-suite provider announces it is suspending service in your region within ninety days, citing a foreign court ruling and new sanctions guidance. Nothing is compromised — everything is leaving. Data gravity, migration under deadline, continuity of the systems your factory quietly depends on, and the vendor-exit playbook nobody wrote.

Grounded in · 2022 sanctions saw major software and cloud vendors suspend services in Russia within weeks

OTC-MFG-02260 min

MUSTER POINT

Half the crew, twice the phish

A public-health wave cuts plant staffing by forty percent in a week — and a phishing surge arrives to meet the temporary workers, loaned crews, and exhausted supervisors covering the gaps. Running lean safely while the human layer of your security is at its thinnest.

Grounded in · CISA and NCSC documented the surge of pandemic-themed phishing exploiting the 2020 disruption

OTC-MFG-02360 min

LAST SHIFT

When trust walks out the door

A valued engineer has resigned to join a competitor, and monitoring flags bulk access to design folders in their final week. The deliberate-insider counterpart to the ambiguity of an unattributed anomaly: access-revocation timing, HR and legal choreography, evidence discipline, and the discipline of treating a person as innocent while protecting the company as if they are not.

Grounded in · A GE engineer was convicted of stealing turbine trade secrets accumulated over years of employment

OTC-MFG-02460 min

CLEAR TEXT

The spill and the cover-up reflex

An engineer emails a controlled technical-data package to the wrong supplier contact — and a well-meaning colleague deletes the email before anyone can assess what actually went out. The recovery is a discipline test: contain without destroying the record, scope honestly, classify what truly spilled, notify per counsel's review, sanitize per policy, and fix the process that put the wrong recipient one keystroke away.

Grounded in · Level One Robotics (2018) exposed 157GB of automaker data — NDAs, schematics, plant layouts — via an open transfer server

OTC-MFG-02560 min

COLD START

Securing the line's first breath

A new production line is being commissioned — integrator laptops on the network, temporary remote access wide open, default credentials on fresh equipment — when an anomaly appears on a device that is not in the asset inventory yet. Securing the birth of a line, where every insecure default is a decision nobody remembers making.

Grounded in · TSMC (2018): one unpatched new tool brought a WannaCry variant into fabs, costing ~$170M

OTC-MFG-02660 min

FIELD DAY

The laptop that left the country

An engineering laptop goes missing — or is briefly out of its owner's sight during an inspection — while traveling to a high-risk region. What was on it, what it could still reach, and an exposure assessment nobody can complete precisely turn a lost device into a decision about trust, access, and controlled data.

Grounded in · DarkHotel espionage targeted traveling executives through hotel networks for years

OTC-MFG-02760 min

WIRE BRUSH

The invoice that wasn't

The deposit for a new machining center is wired — to the wrong account, via a hijacked supplier email thread so convincing nobody thought to call. Payment-fraud response, verification callbacks, the bank-and-counsel clock, and the supplier master-data governance that would have stopped it before the money moved.

Grounded in · FBI IC3 reporting puts cumulative business email compromise losses in the tens of billions of dollars

OTC-MFG-02890 min

SPLIT BRAIN

Whose incident is it now?

Mid-acquisition integration: the newly acquired plant has a flat network, unknown OT hygiene, and incident indicators surface during the identity cutover weekend. Two IT cultures, one legal entity, and the question of whose incident-response plan governs a plant that is legally yours and operationally a stranger's.

Grounded in · Marriott discovered a breach that had lived inside acquired Starwood systems since 2014

OTC-MFG-02960 min

GLASS JAW

When you can't trust the safety layer's eyes

An IT incident raises a question nobody can quickly close: were the systems that support safety-adjacent monitoring touched? The safety hardware is intact — but confidence in what it is telling you is not. Policy-level run and stop decisions when the layer you trust to warn you is itself in question, with OEM verification as the road back.

Grounded in · TRITON/TRISIS (2017) targeted a petrochemical plant's safety instrumented systems

OTC-MFG-03060 min

MUSEUM PIECE

End of support, start of exposure

The vendor ends support for the controller and operating-system family running your critical cells — the same week an industry advisory reports active exploitation of that very platform. Compensating controls, isolation, and replacement economics collide on a timeline set by someone else, for equipment that still makes good parts every day.

Grounded in · WannaCry (2017) stopped production at automakers running unsupported, unpatched Windows

OTC-MFG-03190 min

SECOND SITE

Continuity versus control

A fire closes your plant; the customer cannot wait; a contract manufacturer can start next week. Emergency capacity transfer means sharing controlled technical data at speed with a partner whose environment you have never assessed — business continuity and data governance in direct, urgent collision.

Grounded in · The 2020 telework surge forced emergency expansion of remote access, with security racing behind

OTC-MFG-03260 min

OPEN MIC

The voice on the phone

The shift supervisor takes a call from a voice that sounds exactly like the CEO, demanding an urgent, out-of-process shipment release. Impersonation-era authority discipline: out-of-band verification, a culture where 'let me call you back' is always safe, and the harder lesson that lands when the voice turns out to have been real.

Grounded in · The 2023 MGM Resorts intrusion began with a phone call impersonating an employee to the help desk

OTC-MFG-03390 min

QUICKSILVER

The attack that moves faster than the meeting

An intrusion unfolds at a tempo and scale no human team could match: containment moves are countered within minutes, and convincing messages — from staff, customers, and even your own security vendor — arrive faster than anyone can verify them. The exercise is not about outrunning the adversary. It is about changing the game: pre-delegated authority, out-of-band trust, and knowing when to stop typing and isolate.

Grounded in · DARPA's 2016 Cyber Grand Challenge demonstrated fully autonomous, machine-speed attack and defense

WTR · DRINKING WATER & WASTEWATER UTILITIES

Water & Wastewater8 scenarios

Chemical-dosing manipulation, mass PLC lockouts, insider access, sewage releases, ransomware, and falsified SCADA — grounded in Oldsmar, Aliquippa, the 2026 multi-state PLC wave, Maroochy Shire, American Water, and Volt Typhoon pre-positioning.

OTC-WTR-00160 min

CAUSTIC TIDE

When the dose becomes the danger

On a routine night shift, a community surface-water treatment plant finds chemical dosing setpoints driven far outside the safe band — caustic/pH first, then chlorine — with feed pumps acting on values no operator entered and a change history that cannot cleanly attribute the edits to a console operator or a remote session. As distribution residual and pH begin to drift, the team must force manual dosing, decide whether already-dosed water warrants a public advisory, determine when to notify the primacy agency and EPA, and separate a malicious change from operator or instrument error.

Grounded in · Oldsmar, FL water treatment facility chemical-dosing manipulation: a workstation setpoint for sodium hydroxide (caustic) was driven from roughly 100 ppm to 11,100 ppm before an operator noticed and reverted it.

OTC-WTR-00260 min

DROWNED SIGNAL

Locked out of your own controllers

A community water system loses automated control when programmable controllers across its treatment plant and pumping/lift stations reject operator passwords and drop off the SCADA network — level, pump, and chemical-dosing automation gone and monitoring untrusted. As peer utilities across the state report the same thing within hours and the state's water ISAC asks for status, the team must stand up manual operations, weigh a precautionary boil-water advisory with the plant effectively blind, coordinate with CISA, EPA, and the primacy agency on a suspected coordinated campaign, and decide how to safely restore trustworthy control.

Grounded in · July 2026 multi-state PLC lockout wave affecting 30+ community water systems (CISA Water and Wastewater Systems alert; advisory AA26-097A)

OTC-WTR-00360 min

SCARLET BEACON

The screen is defaced; the water is fine — now prove both

A remote booster and pressure-regulation station's internet-reachable controller is defaced with a political message and stops responding to normal control; pressure setpoints are frozen and crews must run the station by hand. The device matches a class of internet-exposed water-sector controllers named in recent federal advisories, and media are already framing it as "a hack of the water supply." The team must move to safe local/manual pressure control, correct contamination panic with honest messaging, inventory and reduce other exposed OT, report to the primacy agency, FBI, CISA, and the water ISAC, and restore the device to a trusted state while preserving evidence — all with no confirmed impact to drinking-water quality.

Grounded in · Municipal Water Authority of Aliquippa, Pennsylvania — defacement of an internet-exposed Unitronics pressure-control PLC and forced manual operation (November 25, 2023); joint CISA advisory AA23-335A.

OTC-WTR-00490 min

HOLLOW BADGE

When access outlives the person

After hours, a remote session using the credentials of someone who should no longer have had access disables the monitoring-and-protection platform at the hub of a water plant's control network, and disinfection quietly stops while the alarms that should have caught it stay silent. The team must run the plant blind on manual control, revoke every remote path and hunt the stale accounts nobody tracked, restore disinfection and decide whether the lapse is reportable, preserve evidence with HR, legal, and law enforcement, and answer the hardest question of all: when is it safe to trust the network again?

Grounded in · Discovery Bay, California water treatment facility remote-access incident (2021; former contract-operator employee charged 2023)

OTC-WTR-00590 min

BLACKWATER SURGE

The screens say the wells are fine. The creek says otherwise.

Across the wastewater collection system, lift and pump stations start behaving on their own: lead and lag pumps cycle out of sequence, high-wet-well alarms never annunciate, and untreated sewage begins escaping toward a creek — while the SCADA overview shows every level comfortably normal and no active alarms. Ground truth from the field flatly contradicts the screen, and operators stop trusting anything the telemetry tells them. This is a defender exercise about operating a collection system by hand when you cannot believe your instruments, reporting a sanitary sewer overflow to the state and EPA on the clock, warning the public away from contaminated water, and deciding how much of the control system to treat as compromised. Threat is represented only through what the team observes; the exercise contains no offensive technique of any kind.

Grounded in · Maroochy Shire, Queensland, Australia — SCADA-enabled sewage releases (2000)

OTC-WTR-00660 min

PAPER DAM

The enterprise is locked; the plant runs on paper

A large water utility discovers its enterprise network was encrypted overnight — the customer portal, billing, and email are down, and early indicators suggest customer data was stolen. Treatment is reported unaffected, but confidence in the IT/OT boundary is low. The team must decide on precautionary OT isolation, whether treatment can run islanded on manual control, securities and breach-notification duties, a no-shutoff customer-service posture, and how to recover without reinfecting the one network that stayed healthy.

Grounded in · American Water Works cyberattack — the largest US water utility took its customer portal and billing offline and filed an SEC 8-K, with OT/treatment reported unaffected.

OTC-WTR-007120 min

PATIENT DELTA

The intruder that has been here longer than your logs.

A routine threat hunt at a drinking-water utility surfaces something patient: valid-credential administrative access that appears to have been quietly living in enterprise IT for a very long time, using ordinary admin tools rather than malware, and probing toward the control network. Nothing is broken. No dose has drifted, no pump has stopped, no notice has gone out. But no one can prove the PLC logic and setpoints that keep the water safe were never touched, and the logs do not reach back far enough to say when it began. The team must decide whether to slam the door now or scope quietly first, how to re-validate control integrity under assume-breach without endangering supply, what it owes CISA, the EPA, and the state given 'no current impact,' and how to run a utility that may be carrying a sleeper set to wake on its worst day.

Grounded in · CISA Advisory AA24-038A — PRC state-sponsored Volt Typhoon actors using living-off-the-land techniques to pre-position in U.S. critical infrastructure IT networks, including Water and Wastewater Systems, with dwell times reported up to roughly five years to enable later disruption of operational technology.

OTC-WTR-00890 min

GLASS CURRENT

Every screen reads normal. Nothing else does.

Operators start the shift to a control room that looks perfectly healthy — tank levels, turbidity, chlorine residual, and flow all sitting comfortably in range — until a routine round and a lab grab sample say otherwise. The displays and the historian no longer match the physical process, and the same values auto-populate the monthly compliance report due to the primacy agency. The team can no longer tell which numbers are real. This exercise is about establishing independent ground truth, reporting with integrity when the record itself is suspect, deciding whether distrust of your own instruments justifies protecting the public, and defining what it takes to trust the screens again.

Grounded in · CISA joint advisory AA26-097A (2026): Iranian-affiliated cyber actors observed manipulating data displayed on HMI and SCADA displays across US critical infrastructure, including the water and wastewater sector.

PWR · GENERATION, TRANSMISSION & DISTRIBUTION

Electric Power & Grid9 scenarios

Substation breaker attacks, pre-positioning, DER/inverter manipulation, timing/PMU spoofing, generator damage, loss of view, ransomware, and supply-chain compromise — grounded in Ukraine/Industroyer, the Aurora test, sPower, Nova Scotia Power, GridEx, and SolarWinds.

OTC-PWR-00190 min

SEVERED PHASE

No dispatcher touched a breaker. The territory is going dark anyway.

During the coldest evening peak of the winter, a regional transmission control center watches high-voltage breakers at multiple substations report open in rapid succession with no dispatch command issued. HMI states conflict, remote re-close commands appear to send but never take, and load pockets go dark across the service territory while the EMS picture can no longer be trusted. This is a defender exercise about operating substations by hand when the control center has lost remote command and visibility, prioritizing restoration among critical load pockets under stability and load-shed constraints, deciding when to declare a Reportable Cyber Security Incident to E-ISAC and DOE versus treating it as equipment malfunction, and communicating with the public about cause and restoration while SCADA integrity is unverified. The threat is represented only through what the team observes; the exercise contains no offensive technique of any kind.

Grounded in · Ukraine power grid attack — coordinated high-voltage substation breaker openings (December 23, 2015)

OTC-PWR-002120 min

PATIENT SHADOW

The intruder positioned for the day you can least afford it.

A closely held federal intelligence tip and a quiet internal hunt surface something patient at an electric utility: valid-credential administrative access that appears to have been living in corporate IT for months, using ordinary admin tools rather than malware, moving along jump-host paths that reach toward the control-system boundary. Nothing is broken. No relay has tripped, no load has been lost, no EMS alarm has fired, and no notice has gone out. But no one can prove the protective-relay settings, RTU configurations, and EMS logic that keep the grid stable were never touched, and the logs do not reach back far enough to say when it began. During a period of elevated geopolitical tension, the team must decide whether to evict now or map the footprint first, how hard to sever IT/OT interconnections and vendor remote access without harming operations, what it owes the E-ISAC, CISA, the FBI, and DOE given 'no current impact,' and how to run a grid that may be carrying an intruder set to wake on its worst day.

Grounded in · CISA Advisory AA24-038A — PRC state-sponsored Volt Typhoon (also tracked as VOLTZITE) actors using living-off-the-land techniques to pre-position in the IT networks of U.S. critical infrastructure, including the Energy Sector, with dwell times reported up to roughly five years to enable later disruptive or destructive attacks against operational technology.

OTC-PWR-00390 min

PHANTOM HARVEST

The solar fleet curtails and returns in unison — and no operator gave the command.

Across a distribution utility's feeders, large blocks of aggregated rooftop solar and battery storage begin curtailing to near-zero and re-energizing in unison — a coordinated, multi-substation swing that no dispatcher, DERMS operator, or Volt/VAR scheme commanded — producing voltage swings, reverse-power-flow alarms, and a frequency wobble on an interconnection already running tight in a heat wave. The commands appear to originate from a virtual-power-plant aggregator's cloud portal the utility neither owns nor can fully trust, and that portal keeps reporting the fleet as 'healthy' while the utility's own relays say otherwise. This is a defender exercise about operating a grid rich in distributed energy when you cannot believe the cloud telling you what your generation is doing: whether to force-disconnect tens of megawatts of untrusted DER or ride through and localize, how to hold voltage and frequency (and whether to shed load) while the fleet is untrusted, how to coordinate with an aggregator and inverter OEM whose telemetry you distrust, and how to report to the reliability coordinator and regulators and speak to prosumers. Threat is represented only through what the team observes; the exercise contains no offensive technique of any kind.

Grounded in · NIST IR 8498, Cybersecurity for Smart Inverters: Guidelines for Residential and Light Commercial Solar Energy Systems (2024)

OTC-PWR-00490 min

FALSE MERIDIAN

The clocks disagree, and a healthy line pays for it.

Across the transmission control center the wide-area situational-awareness picture stops making sense: synchrophasor phase angles drift apart between substations, time-stamped event records no longer line up between stations, and a line-current-differential scheme misoperates and trips a healthy 345 kV line on nothing but a drifting clock. Operators can no longer trust the wide-area displays, the EMS state estimator that leans on the same timing, or the protection that depends on it — and they cannot yet tell whether they are seeing GNSS interference, a satellite-timing outage, or clocks failing on their own. This is a defender exercise about operating and protecting a transmission system when the time reference underneath your instruments is suspect: switching protection to time-independent backup settings and deciding at which substations, deciding how far to trust state-estimation and PMU-derived controls, characterizing and escalating an ambiguous cause to the Reliability Coordinator, interconnection neighbors, the E-ISAC, and federal reporting, and returning to trusted timing without repeating the misoperation. The threat is represented only through what the team observes; the exercise contains no offensive technique of any kind.

Grounded in · Documented dependence of synchrophasors (PMUs) and GPS/GNSS-synchronized protective relays on unauthenticated civil satellite timing, and the published research corpus on GPS spoofing and timing disruption causing protective-relay misoperation and corrupted power-system state estimation.

OTC-PWR-00590 min

RESONANT FRACTURE

The breakers are hammering the machine. The screen swears no one told them to.

At a bulk-electric-system generating station, the protective relays and breaker controls on a loaded unit begin issuing rapid, unexpected close and reclose actions while operators in the turbine hall hear abnormal machine noise and feel vibration, and the control room lights up with shaft-torque, vibration, and mechanical-stress alarms. The credible outcome, if it continues, is catastrophic physical destruction of the generator or its step-up transformer. This is a defender exercise about deciding whether to emergency-trip and lose generation the grid is leaning on versus attempt a controlled diagnosis, protecting on-site personnel near a machine that may fail without warning, deciding how much of the automated protection and control logic to trust when it may itself be acting against the machine, and recovering long-lead assets while handling OEM, insurer, and NERC/DOE notification if damage occurs. The cause is represented only through what the team observes; the exercise contains no offensive technique of any kind.

Grounded in · Idaho National Laboratory 'Aurora' Generator Test (2007)

OTC-PWR-00660 min

BLIND HORIZON

Generation runs; the control room can't see it

A renewables operator's control center repeatedly loses communications with dozens of remote wind and solar sites in short, recurring blackout windows. Turbines and inverters keep producing, but for stretches at a time dispatchers cannot see live telemetry or send commands to two-thirds of the fleet — a rolling loss of view they cannot yet explain. The team must decide whether to keep operating blind or dispatch crews and curtail assets to a known-safe state, tell a genuine perimeter-device fault apart from a deliberate denial-of-view while communications flap, judge whether the recurring disruption crosses NERC and DOE reporting thresholds and Reliability-Coordinator/market obligations, and choose whether to fail communications over to an alternate path and how far to trust a vendor patch — all through observable effects, without reproducing any technique.

Grounded in · March 2019 sPower (Utah) grid disruption — a perimeter networking device at a wind and solar operator repeatedly rebooted, cutting the operator's control center off from roughly 500 MW of generation in recurring sub-five-minute windows; widely reported as the first cyber-related event to cause a reportable 'disruption' on the US bulk electric system.

OTC-PWR-00760 min

COLD LEDGER

Ransomware freezes the meters, not the grid

A mid-size electric utility is hit overnight by an enterprise ransomware event that encrypts corporate systems and appears to have exfiltrated customer data, while smart-meter reads stop flowing and billing halts. Generation and transmission are unaffected, but the boundary between IT and grid control is unproven. Leadership must decide whether to pre-emptively isolate the operations network, how to handle a ransom demand under sanctions law, how and when to notify customers and overlapping regulators, how to keep billing running without its systems, and what must be proven true before declaring recovery.

Grounded in · 2025 Nova Scotia Power ransomware attack and data breach: the utility disclosed a ransomware incident that disrupted smart-meter (AMI) reads and billing, exposed the personal information of approximately 280,000 customers, and publicly stated it did not pay the ransom, citing sanctions law.

OTC-PWR-00890 min

ASHEN DAWN

Restoring a dark grid when no one can yet say if it was cyber

A fast cascade has collapsed a large portion of the Interconnection and left the utility's footprint dark. As black-start units and cranking paths are marshalled, control-system anomalies that could be ordinary blackout data loss — or tampering — cannot be attributed. The team must sequence energization and load pickup without re-energizing into a compromised or unstable system, allocate scarce black-start resources across entities and borders, communicate with the public and government before attribution is known, and meet reliability-coordinator, DOE, and E-ISAC reporting obligations while the facts are still emerging.

Grounded in · NERC GridEx VII (2023) combined cyber-physical grid exercise

OTC-PWR-00960 min

TAINTED KEYSTONE

A trusted vendor update becomes the way in

A network performance-monitoring and configuration-management platform deployed across the utility is revealed to have shipped a compromised software update, potentially opening footholds that reach toward the management of OT systems. There is no confirmed operational impact, but the trust boundary with a key vendor is now in question. The team must scope the exposure across IT and any OT reach, decide whether to sever vendor remote access and management tooling against the cost of losing monitoring and vendor support, report to NERC, E-ISAC, DOE, and the state regulator while joining an industry-wide extent-of-condition review, and rebuild remote-access and vendor-risk governance for the long term.

Grounded in · 2020 SolarWinds Orion supply-chain compromise

OIL · UPSTREAM, MIDSTREAM & DOWNSTREAM PETROLEUM

Oil, Gas & Pipelines8 scenarios

Safety-instrumented-system integrity, pipeline billing/custody shutdowns, gas-compression loss of view, terminal ransomware, leak-detection ambiguity, overpressure protection, and destructive wipers — grounded in Colonial, TRITON, Shamoon, AA20-049A, European terminals, PIPEDREAM, and Enbridge.

OTC-OIL-00160 min

SILENT SENTINEL

When the last line of defense can no longer be trusted to act.

During routine overnight operation, the safety-instrumented system protecting a refinery's high-pressure hydrocracker executes a full unit trip that no process condition explains, and follow-up diagnostics show the safety controller reporting internal states engineering cannot reconcile with the physical plant. With the last-line protective layer no longer demonstrably trustworthy, the team must decide whether to hold the unit in a safe shutdown or restart for throughput, how long operating on independent and manual protection layers is defensible, when and how to notify the controls vendor and CISA/TSA without prematurely alleging an attack, and whether to preserve the suspect safety controller for forensics or reflash it to get back online.

Grounded in · 2017 TRITON/TRISIS safety-instrumented-system incident at a petrochemical facility (Petro Rabigh, Saudi Arabia), in which malformed logic on a Triconex safety controller produced an unexplained process trip that engineers could not initially reconcile.

OTC-OIL-00260 min

BLIND METER

A healthy pipeline you can't account for

Extortion malware has encrypted the enterprise scheduling, ticketing, and billing environment of a major refined-products pipeline. The pipeline controls are healthy and product is still flowing, but the operator can no longer measure custody volumes or invoice deliveries. The team must decide whether to keep pumping product it cannot account for or shut a technically sound line, whether and how to engage the extortionists and who is authorized to decide, how to explain a self-imposed shutdown to markets and the public, and what measurement and custody assurance must be restored before product moves again.

Grounded in · Colonial Pipeline ransomware attack (DarkSide), May 2021 — a ransomware compromise of enterprise IT and billing systems, not the pipeline's operational controls, led to a roughly six-day precautionary shutdown of the largest U.S. refined-products pipeline and regional fuel shortages across the Southeast and Mid-Atlantic.

OTC-OIL-00360 min

DARK CONSOLE

The plant runs; the control room has gone dark

A commodity ransomware infection crosses a weak IT/OT boundary at a natural-gas compression station and encrypts every operator HMI, the data historian, and both polling servers — blinding the control room while the compressor units keep running on unaffected PLCs and safety-instrumented systems. Controllers still have local control but no window into the plant, and must decide how long they can safely run blind versus executing a controlled shutdown while control is still assured, how aggressively to sever the OT network from a still-burning corporate network at the cost of remote monitoring and historian data, whether to rebuild the full historian/HMI layer from aging backups or stand up temporary local monitoring first, and what condition should trigger escalation from a single-site response to a coordinated, pipeline-wide shutdown — all while TSA, PHMSA, and environmental reporting clocks may already be running. The threat appears only as observable effects — ransom notes, encrypted servers, a spreading loss of view — never as any technique or attacker how-to.

Grounded in · CISA advisory AA20-049A (February 2020): ransomware at a U.S. natural-gas compression facility encrypted operator HMIs, the data historian, and polling servers after crossing an inadequately segmented IT/OT boundary; controllers lost their view of the plant while the PLCs and safety systems were unaffected, and the operator executed a deliberate, controlled shutdown lasting roughly two days before restoring operations from backups.

OTC-OIL-00460 min

IRON BERTH

Ransomware jams the berths

Ransomware disables the terminal-management and vessel-loading systems at a coastal petroleum terminal. Berths cannot schedule or automatically load, tankers and barges back up on the tide, and the team must decide whether to load by hand at added safety and measurement risk, whether to declare force majeure and reallocate cargoes, how to coordinate with the port authority, customs, vessel operators and customers during an information blackout, and what to restore first before automated loading can be trusted again.

Grounded in · January–February 2022 ransomware attacks on Oiltanking/Mabanaft, SEA-Invest and Evos disrupted vessel loading and scheduling across roughly 17 oil terminals in the Amsterdam-Rotterdam-Antwerp region and Germany, forcing several operators to declare force majeure.

OTC-OIL-00590 min

PHANTOM BARREL

The flow computers and the tanks tell two different stories, and every barrel is money.

At a custody-transfer interconnect, the flow computer on one meter run begins writing net-standard-volume totals that no longer reconcile with the receiving terminal's tank gauging or the counterparty's downstream receipt meters, and the gap widens custody day over custody day. The pipeline itself looks perfectly normal — pressures, flows, and line balance are all ordinary — yet the calibration constants and meter factor on the flow computer are not what the master measurement records say, the change carries no work order, and the device's own stored history presents the altered values as if they were always in effect. This is a defender exercise about protecting custody-measurement integrity when volumes equal money, allocation, tax, and royalty, and the team cannot yet tell tampering from instrument drift from an unlogged configuration error: deciding whether to keep transacting on suspect measurement or place the meter run in dispute and revert to manual proving and witnessed gauging, deciding when and how far to notify counterparties, shippers, auditors, regulators, tax authorities, and security bodies, establishing a trustworthy volume of record for settlement while the investigation is open, choosing between freezing the flow computer for forensics and correcting it to resume accurate measurement, and defining what it will take to trust automated custody measurement again. The threat is represented only through what the team observes; the exercise contains no offensive technique of any kind.

Grounded in · The custody-measurement dimension of the 2021 Colonial Pipeline incident, in which the compromise reached the flow-computer and billing systems that turn metered volumes into money — set against the API 21.1 (electronic liquid measurement) and API 1164 (pipeline SCADA security) custody-measurement control regime, under which volumes at transfer points equal payment, allocation, and tax liability.

OTC-OIL-00660 min

SLACK LINE

When the pipeline's own data can't tell a leak from a slack line.

A crude-oil transmission control room faces a pressure excursion whose SCADA and leak-detection indications contradict each other: some point to a possible release, others to a benign 'slack line' column-separation transient — and the anomalous readings could equally reflect a data-integrity problem rather than a physical one. Under time pressure and commercial expectation, the team must decide whether to keep the line shut in and treat it as a spill or restart, when to notify the National Response Center and warn the community, how to obtain independent field confirmation when the instruments cannot be trusted, and what known-good evidence must exist before the pipeline returns to service.

Grounded in · 2010 Enbridge Line 6B crude-oil pipeline rupture into Talmadge Creek and the Kalamazoo River near Marshall, Michigan, in which control-room staff interpreted alarms as column separation and restarted a ruptured line, releasing over a million gallons of crude.

OTC-OIL-00760 min

COLD FLARE

When you can't trust the trip

At an upstream sour-gas processing plant on a normal day shift, compressor anti-surge and overpressure-protection PLCs begin showing set-points and readings no operator commanded, and the emergency-shutdown system reports itself healthy while field measurements disagree. With production nominated downstream and a rural community at the fenceline, the team must judge whether the ESD can still be relied on to protect the plant — deciding whether to invoke a manual emergency shutdown and blowdown now or keep operating while investigating, how to verify overpressure and ESD integrity when the very systems reporting status may be affected, how to weigh production deferment and flaring against the safety risk of continuing, and how to engage the controls vendor and regulators while preserving evidence on potentially manipulated controllers.

Grounded in · CISA/DOE/NSA/FBI joint Cybersecurity Advisory AA22-103A on the PIPEDREAM/INCONTROLLER ICS attack toolkit, reported as purpose-built to scan for, compromise, and manipulate PLCs and OPC UA servers of the kind common in oil-and-gas and gas-processing environments.

OTC-OIL-00890 min

SALTED EARTH

The business is gone. The plants are still running. Now run them for a month.

A destructive wiper sweeps an integrated oil company overnight, rendering tens of thousands of corporate workstations and servers unbootable in a matter of minutes. Email, the ERP, procurement, cargo and refinery scheduling, the laboratory-information system, and document management are simply gone, while hydrocarbon production and its control systems — refinery DCS, pipeline SCADA, compressor stations, terminal loading, upstream gas processing, and the safety-instrumented systems beneath them — sit on isolated networks, untouched and still running, but cut off from every business function that normally feeds them. This is a defender exercise about keeping crude and product moving safely for days or weeks with no enterprise IT, rebuilding an entire endpoint estate from bare metal while working out which backups can still be trusted, communicating and authenticating instructions when normal channels are destroyed, and deciding whether to curtail perfectly healthy production because the business cannot schedule, invoice, procure, or move the barrels it makes. The threat is represented only through what the team observes; the exercise contains no offensive technique of any kind.

Grounded in · 2012 Shamoon (Disttrack) destructive-wiper attack on Saudi Aramco

RAI · PASSENGER, FREIGHT & TRANSIT RAIL

Rail & Transit8 scenarios

Third-party dispatch outages, fare-system ransomware, passenger-info defacement, unauthenticated emergency braking, comms sabotage, ticketing takedowns, signalling integrity, and IT/OT boundary tests — grounded in DSB/Supeo, SFMTA, Iranian railways, Poland RADIOSTOP, Deutsche Bahn, Belarus/Ukrzaliznytsia, and the NY MTA breach.

OTC-RAI-00160 min

SILENT DISPATCH

One app dark, a nation's trains stopped

A cloud-hosted operations app that train crews depend on for real-time speed restrictions and engineering-works notices goes dark after its third-party supplier isolates its own systems following a suspected security event. With no authoritative source of movement-critical information, crews across the network have no safe basis to proceed and trains begin stopping — even though nothing on the railway itself was touched. The team must decide whether to run a reduced service under manual degraded working or suspend service, how to authorise the movement of already-running and stranded trains, what evidence proves it is safe to resume normal working, and how to coordinate the supplier's incident response, regulatory reporting and passenger communications throughout.

Grounded in · November 2022 Danish State Railways (DSB) service halt: DSB trains stopped across Denmark for several hours on 5 November 2022 after Supeo, a third-party IT subcontractor, took its own servers offline in response to a suspected cyberattack. Drivers rely on an application supplied by that subcontractor to access safety-critical operational information such as speed restrictions and engineering-works notices; with the application unavailable, crews had no authoritative basis to run trains, and no railway control or signalling system was itself attacked.

OTC-RAI-00260 min

OPEN GATE

Open the gates, lose the ledger

A large urban transit agency begins experiencing enterprise-IT and fare-collection back-office disruption consistent with a ransomware event, while trains keep running on a separate signalling network. To keep passengers moving with the integrity of back-office systems unknown, the team must weigh opening the fare gates and switching off ticket machines — forgoing revenue and losing visibility into ridership and payment data — against holding the line, decide how far to isolate the fare and enterprise environment from operational and SCADA networks, judge whether payment or personal data may be affected and what notifications follow, and define the known-good criteria and public messaging before fare collection is trusted again. Threat activity is shown only as observable effects.

Grounded in · November 2016 SFMTA (San Francisco Muni) ransomware incident, in which the transit agency opened its fare gates and switched off ticket machines for a weekend so riders could keep moving while it protected operations, declined to pay the ransom, and restored affected systems from its own backups.

OTC-RAI-00360 min

FALSE BOARD

Every board is lying

Across a busy commuter railway, passenger-information displays, automated station announcements, and the operator's own app, website, and social channels begin showing fabricated delay and cancellation messages plus a bogus 'service disruption — call this number' notice, while real-time train-tracking readouts turn unreliable. Crowds surge on platforms and at gatelines, passengers flood a phone number that is not the railway's, and station staff cannot immediately tell whether train operations are actually affected or only the information layer. The team must decide whether to take passenger-information systems and announcements offline and revert to manual information, how to authoritatively counter the false messages across every public channel at once, how to manage crowding and platform safety, and how to establish whether signalling and train control are affected or only the information layer — engaging law enforcement, regulators, and the press accordingly, then restoring trustworthy passenger information.

Grounded in · July 2021 Iranian railways passenger-information incident: station departure boards were defaced with fabricated delay and cancellation messages and a phone number posted as a complaints line, causing widespread confusion and crowding while actual train movements were not affected.

OTC-RAI-00460 min

PHANTOM BRAKE

Unauthorized stop commands over the air

Trains across a busy passenger corridor suffer repeated, unexplained emergency-brake applications consistent with unauthorized stop commands reaching them over a legacy train-radio channel that cannot authenticate the source of a broadcast stop. Signallers and drivers cannot tell a malicious activation from a genuine emergency, forcing extremely conservative operation on a critical line. The team must decide whether to keep running under speed and headway restrictions, when to declare an incident and stand up a safe manual-working fallback, how to balance passenger safety against shutting a critical corridor, and when to treat the source as malicious and involve the regulator and law enforcement.

Grounded in · In August 2023, more than twenty trains across Poland were brought to unexpected halts when unauthorized broadcast emergency-stop signals were injected over an unauthenticated analog train-radio channel; national authorities treated it as sabotage and two suspects were arrested.

OTC-RAI-00560 min

SEVERED SIGNAL

Redundant rail comms fail as one

Across a busy region during the morning peak, the railway's nominally redundant radio and transmission network fails almost simultaneously, cutting voice and data between the control centre, lineside signalling, and trains. Controllers lose contact with trains still moving, and the team must choose a safe degraded method of working, decide how to hold trains they cannot reach, judge whether the cause is cyber, physical, or both, and define what must be true before the region returns to normal — all while the evidence is still forming.

Grounded in · October 2022 sabotage of Deutsche Bahn's GSM-R railway communications, in which two deliberately severed redundant cables halted rail traffic across northern Germany for about three hours.

OTC-RAI-00660 min

LOCKED LEDGER

A targeted attack empties the ticket office while the trains keep rolling

During a period of heightened geopolitical tension, a targeted attack takes down a national rail operator's enterprise estate overnight: online and station ticketing, seat reservations, crew rostering and freight documentation are all unavailable, and data appears to have been stolen. Trains keep running because signalling, interlockings and train radio sit behind a separate operations boundary, but the morning peak is building with no way to sell or validate tickets, and a public claim of responsibility carrying false safety assertions is about to break. Leadership must decide whether to keep running on manual ticketing or free travel versus curtailing service, whether and how to segregate the signalling domain from the compromised enterprise side, how to sustain crews and freight on manual records, and how to handle attacker claims and disinformation while meeting mandated national CERT and regulator reporting timelines.

Grounded in · January 2022 Belarusian Railway hacktivist attack: a hacktivist group disrupted the railway's ticketing and enterprise IT systems as a publicly announced political act amid regional tension, while deliberately leaving train-control automation alone so services could keep moving safely.

OTC-RAI-00760 min

BLIND INTERLOCK

The picture that keeps trains apart can no longer be trusted

Dispatchers and signallers begin seeing intermittent, inconsistent indications from the signalling and interlocking control system — signal aspects and track-occupancy readings that no longer match what field staff and drivers report. The team can no longer trust the picture that governs how trains are kept apart, and must decide whether to keep operating on the automated signalling picture or revert immediately to manual absolute-block working, how far to throttle throughput to preserve safe separation while diagnosis continues, how to independently establish true field state and isolate the affected system without endangering trains, and what evidence and assurance must exist before signalling indications can be trusted again. The threat appears only as observable effects — untrustworthy indications — with no attacker technique, exploit, or how-to.

Grounded in · Documented rail-signalling and control-command vulnerability reporting, together with ENISA railway-sector guidance and CLC/TS 50701, which identify control-command and signalling (CCS) as the rail sector's crown-jewel operational technology whose integrity underpins safe train separation.

OTC-RAI-00860 min

HELD LINE

The tip says they've been inside for weeks — now prove the trains are safe

A credible external tip reveals that an intruder has held access to a transit agency's enterprise IT for weeks through a remote-access appliance. Trains are running normally and the train-control side shows nothing wrong, and leadership must decide how much to disrupt service to prove that with confidence — how aggressively to isolate IT from OT and cut remote access, what forensic scope demonstrates the vital systems are clean, how to contain credentials and remote access across the enterprise, and when and on what evidence to tell riders, the board and regulators there was no operational impact.

Grounded in · In April 2021, the New York Metropolitan Transportation Authority (MTA) was breached through a zero-day vulnerability in a Pulse Secure remote-access appliance; the MTA reported, and a subsequent forensic review found, that the intrusion did not affect the systems controlling train operations, that no employee or customer information was compromised, and that no data was lost.

MAR · PORTS, TERMINALS & VESSELS

Maritime & Ports9 scenarios

Terminal-operating-system ransomware, carrier wipers, GNSS/AIS spoofing, tampered ship-to-shore cranes, cargo-data integrity, cruise/port extortion, shipboard OT, strategic-port takedowns, and reefer cold-chain — grounded in Maersk/NotPetya, Nagoya, DP World, Port of Seattle, ZPMC cranes, and Shahid Rajaee.

OTC-MAR-00160 min

TIDE LOCK

The terminal operating system goes dark

Ransomware freezes the terminal operating system that runs gate-in/gate-out, yard planning and vessel load sequencing across a deep-water container port. Operators are locked out, trucks queue onto public roads, cranes stand idle with empty work queues, and staff have no digital record of which container sits where. The team must decide whether to keep gates open on manual and paper processing or suspend landside operations to contain the incident, whether to sever the terminal's internet and vendor links and accept a full operational halt, whether to divert or re-berth inbound vessels, and how and when to notify the National Response Center and Coast Guard, carriers and trucking customers, before choosing what to restore first and how to trust the container map again.

Grounded in · In July 2023 a ransomware attack attributed to LockBit 3.0 on the Nagoya United Terminal System (NUTS) - the shared terminal operating system for the Port of Nagoya, Japan's busiest container port - halted container loading and unloading across all terminals for roughly three days, stopping truck gate transactions and forcing a reversion to manual handling.

OTC-MAR-00260 min

SEVERED HAWSER

The line went dark worldwide overnight; the ships still came.

A top-tier global ocean carrier that also runs its own container terminals wakes to a destructive malware event that has wiped its enterprise environment on every continent overnight. Booking, EDI/EDIFACT messaging, bill-of-lading issuance, and manifest exchange are gone, so vessels arrive at berth with no electronic cargo data and terminals cannot confirm what to load or discharge. The team must establish global command with its own communications dark, keep priority cargo moving on manual booking and paper manifests, choose between restoring from a fragile surviving backup and a clean bare-metal rebuild, manage disclosure to shippers, insurers, customs, and the markets, and verify the integrity of restored bookings before ever loading a ship on them.

Grounded in · The June 2017 NotPetya destructive-malware event spread globally overnight and halted Maersk and APM Terminals across roughly 76 terminals, forcing weeks of manual and paper operations while a wiped global environment was rebuilt, at an estimated USD 200-300 million impact.

OTC-MAR-00360 min

FALSE FIX

The harbor's own map turns against it

During a busy flood-tide window, inbound vessels and the harbor's traffic picture stop agreeing with reality: ECDIS and AIS place ships ashore or circling, phantom contacts populate the dredged channel, GNSS integrity alarms sound on bridges, and pilots and Vessel Traffic Service see conflicting tracks. The team must decide whether to keep moving vessels on radar and visual means or hold the fleet at anchor, whether to restrict or close the channel and stand down pilotage and how to sequence the fleet, how to warn mariners without triggering unsafe improvisation, and when and to whom to report the interference — all while radar and human eyes remain the only trusted picture.

Grounded in · 2017 Black Sea mass GPS/GNSS spoofing, in which roughly twenty vessels' AIS positions were displaced miles inland, 'teleporting' ships ashore while radar and visual references stayed correct.

OTC-MAR-00460 min

HARBOR MIRROR

Undocumented modems on the crane fleet

A scheduled equipment audit at a major container terminal turns up undocumented cellular modems and unexplained remote-access connections wired into the ship-to-shore crane fleet, and crane telemetry shows movements and outbound data no operator initiated — leaving the terminal unable to say whether its cranes have been tampered with. The team must decide whether to take suspect cranes out of service and halt throughput or keep lifting under heightened monitoring, whether and how to sever vendor remote-access and cellular links entangled with warranty and safety interlocks, how to handle the national-security dimension and mandatory reporting to the USCG, FBI and CISA, and what to tell longshore labor, operators and the public about the safety of lifting over people and cargo, before proving what "clean" means and returning the fleet to service.

Grounded in · In September 2024 a joint U.S. House Homeland Security Committee and Select Committee on the CCP report warned that PRC-manufactured ship-to-shore cranes — roughly 80% of the STS cranes at U.S. ports, largely built by ZPMC — carried undocumented cellular modems and remote-access pathways, citing the FBI's 2021 discovery of undocumented devices on a ZPMC crane shipment at the Port of Baltimore; the concern drove USCG MARSEC Directive 105-5 issued under Executive Order 14116.

OTC-MAR-00560 min

BROKEN SEAL

The terminal is back online, but its cargo data can no longer be trusted

Days after an intrusion is found in a container terminal's environment, the terminal operating system, gate and yard automation are rebuilt from backups and operations resume - but the restored data can no longer be trusted. Gate-release authorizations, container-to-vessel load lists and dangerous-goods (IMDG) stowage records may have been silently altered, so no one can be certain a hazardous box is classified, released and stowed correctly, and the first checks against physical placards and carrier records come back wrong. With vessels alongside and demurrage clocks running, leadership must decide whether to halt loading until dangerous-goods and load data are independently reconciled or keep the vessels moving, how to verify stowage and gate-release decisions against a trusted out-of-band source of truth, which known-good snapshot to restore to and how to establish what was altered and when, and how to notify the USCG, customs/CBP and carriers given the cargo-security and safety-of-stowage stakes. The exercise turns on the difference between an operation that is running again and data that can actually be trusted.

Grounded in · July 2023 Port of Nagoya ransomware attack: Japan's largest port had its unified terminal operating system knocked offline by a ransomware attack, halting container loading and unloading across terminals for roughly two days and forcing a fallback to manual handling before systems were restored from backups.

OTC-MAR-00660 min

PALE LANTERN

Ransomware darkens the terminal on turnaround day while passengers' data goes up for auction

On the busiest cruise turnaround morning of the season, ransomware with data theft cripples a port authority that runs a cruise terminal and shares its enterprise campus with an airport: passenger check-in, boarding-pass validation, baggage handling and display systems all fail as twelve thousand guests cross the quay, while attackers threaten to auction the stolen personal data of tens of thousands of passengers, crew and staff. The ships and their bridge systems remain safe, but the shoreside terminal is dark, the crowd is building, and the clocks — an extortion deadline and multi-jurisdiction breach-notification duties — are already running. Leadership must move and process crowds safely by manual means, decide whether to pay the extortion demand or refuse and absorb prolonged exposure, meet breach-notification obligations to tens of thousands of individuals and regulators, and communicate in a way that preserves trust and prevents panic while the facts are still emerging.

Grounded in · August 2024 Rhysida ransomware attack on the Port of Seattle: the attack disrupted the Port's shared airport and seaport systems — including passenger display boards, check-in kiosks, ticketing, baggage handling and the website — during peak summer travel; the Port refused to pay the roughly USD 6 million ransom demand, and later confirmed that data was stolen and notified about 90,000 people that their personal information was affected.

OTC-MAR-00760 min

DRIFTING COMPASS

An inbound ship the bridge can no longer trust

An inbound laden container vessel reports her integrated bridge, propulsion and steering controls behaving erratically — alarms that will not clear, control responses the bridge team did not command, and ballast and engine readings that no longer agree with the engine room — while she closes a narrow, tidal channel with a berth booked within hours. Ship and shore must decide whether she continues under her own power, holds at anchor or takes tugs and refuses the berth; when to declare to port state control, the flag state, class and the National Response Center and treat her as a potential floating hazard; how to isolate and segregate the bridge and machinery-control networks without losing essential navigation and propulsion; how to coordinate harbor traffic and emergency response around a partially controllable ship; and what must be proven before the helm can be trusted again.

Grounded in · IACS Unified Requirements E26 (cyber resilience of ships) and E27 (cyber resilience of on-board systems and equipment) apply to newbuildings contracted on or after 1 July 2024, formalizing class-society expectations that shipboard operational technology — the integrated bridge, propulsion, steering-gear and machinery-control networks — be designed to be segregated, monitored and recoverable.

OTC-MAR-00860 min

STILL WATER

A strategic port seizes up all at once

During a period of heightened geopolitical tension, the terminal operating system, gate and yard automation, appointment and port-community systems at a strategic container port fail simultaneously — vessels hold in the anchorage, drayage trucks gridlock the causeway and access roads, and cargo stops moving in both directions. Attribution is unclear and national authorities warn of possible follow-on activity against other ports. The team must decide whether to fall back to manual traffic control and continue limited operations or suspend the port to contain and investigate, how to coordinate with the U.S. Coast Guard, CISA and the FBI given possible nation-state involvement, whether and when to make external and geopolitical attribution statements, and when to invoke force majeure and how to prioritize strategic and time-critical cargo through a prolonged outage — all before deciding what must be proven before automated vessel, truck and cargo flow can be trusted again.

Grounded in · In May 2020 a cyberattack on Iran's Shahid Rajaee port terminal at Bandar Abbas crashed the systems that regulate the movement of vessels, trucks and goods at roughly the same time, causing days of severe backups on the waterways and access roads and halting the flow of cargo.

OTC-MAR-009120 min

COLD ANCHOR

The board says the cargo is cold. The yard says otherwise.

Across the reefer yard, the platform that is supposed to prove the cold chain held goes dark and begins reporting temperatures that do not match the boxes — and the terminal can no longer prove the cold chain held for thousands of pharmaceutical and perishable containers. As shippers demand documented proof or pre-emptively reject cargo, the team must decide whether to trust the data, revert to labor-intensive manual temperature rounds, or quarantine what it cannot verify; how to establish defensible independent proof of integrity for high-value loads; how to handle mounting commercial and legal exposure with shippers, insurers and receivers; and how to contain and recover the monitoring and power systems without going blind to the reefers still under power. The exercise is not about catching an intruder. It is about operating, proving integrity, and protecting cargo when the system of record can no longer be believed.

Grounded in · Ransomware disrupted the Nagoya United Terminal System and halted container-handling operations at the Port of Nagoya, Japan for roughly two days in July 2023.

CHM · PETROCHEMICAL, SPECIALTY & CONSUMER CHEMICALS

Chemical & Process Safety8 scenarios

Safety-instrumented-system trust, alarm floods, loss of cooling on reactive materials, toxic-release detection ambiguity, unexplained safety-logic changes, batch/recipe integrity, precautionary shutdown, and overpressure/relief assurance — grounded in TRITON/TRISIS, BP Texas City, Arkema Crosby, Bayer CropScience, Clorox, and Colonial.

OTC-CHM-00160 min

HOLLOW GUARDIAN

When the last line of defense can't be trusted

On a running petrochemical unit, the safety instrumented system and emergency-shutdown logic begin faulting and resetting, and the safety controller's diagnostics no longer reconcile with field devices. With the process at hazardous conditions, operators can no longer confirm the last-line trips will actuate on demand, and the team must decide whether to keep running on uncertain protection, how to independently verify what is real, who may declare a safety function unavailable, whom to notify, and what must be proven before the guardian is trusted again.

Grounded in · TRITON/TRISIS (2017): the first known malware to target a process safety system — a Triconex safety instrumented system at a Middle East petrochemical facility — which caused the safety controller to fault and the plant to trip to a safe state; the activity was attributed by Dragos to the XENOTIME group.

OTC-CHM-00260 min

PAPER STORM

The board is lying and the tower is filling

During a unit restart the control room is overwhelmed by a sustained alarm flood while some HMI values freeze or contradict one another, and operators must decide what to believe as a distillation column trends toward overfill. The team must establish command, verify the true process state against field readings, choose whether to reduce rates or shut the unit, decide when to invoke abnormal-situation and emergency operating procedures, and determine who can declare the control system untrustworthy for safe operation — then handle notification, reporting, and a trustworthy restart.

Grounded in · CSB investigation of the 2005 BP Texas City refinery explosion, in which alarm and instrumentation deficiencies and an overfilled raffinate splitter tower contributed to an explosion and fire that killed 15 workers and injured many more.

OTC-CHM-00360 min

FEVER TANK

When the cold can't be trusted

At a specialty-chemical plant that stores organic peroxides and other temperature-sensitive reactive materials in refrigerated cold-storage banks, an OT disruption degrades the monitoring and control that keep the material cold: temperature indications go stale, jitter, and disagree with handheld probes, a high-temperature alarm is found silently shelved, and backup-cooling and emergency-power status can no longer be taken at face value — all while at least one bank of peroxide is warming toward the temperature at which decomposition feeds itself. With a rural community at the fenceline, the team must judge whether the readings that keep the material safe can still be believed and act conservatively despite green screens, whether to emergency de-inventory the at-risk material or hold it in place, when to trigger community shelter-in-place or evacuation and notify the LEPC and agencies, and — if cooling cannot be assured — whether to stop fighting for the save and manage a controlled decomposition or burn behind defensive lines, all while preserving evidence on potentially manipulated controllers.

Grounded in · The 2017 Arkema Crosby, Texas incident, in which Hurricane Harvey floodwater disabled site power and the refrigeration and backup power keeping organic peroxides cold; the unrefrigerated peroxides self-decomposed and ignited, roughly 205 nearby residents were evacuated and 21 responders sought medical attention, and the remaining material was ultimately allowed to decompose and burn.

OTC-CHM-00460 min

PALE VAPOR

Conflicting alarms, an uncertain siren, and a life-safety call on ambiguous release data.

During a suspected toxic-gas release from a reactive semi-batch process, the plant's fixed detection grid returns conflicting and dropped readings — some point detectors alarm while adjacent open-path monitors read clear and others go to no-data — and the automated community-notification system's status is uncertain. The team must reach and hold a safe process state, decide whether to declare a release and trigger shelter-in-place on ambiguous data, choose between automated and manual public warning, settle who owns the release declaration, and sequence NRC, EPA, OSHA, and LEPC notifications under regulatory clocks. The underlying threat appears only as observable effects on the monitoring and notification systems; no offensive technique is depicted.

Grounded in · U.S. Chemical Safety Board investigation of the August 28, 2008 runaway-reaction explosion in a pesticide residue-treater (waste) vessel at Bayer CropScience in Institute, West Virginia, which killed two workers at a site that also stored methyl isocyanate; investigators cited insufficient air monitoring and control-room human-factors deficiencies among the contributing factors.

OTC-CHM-00590 min

PHANTOM PATCH

A change to the safety system that no one can account for — and a unit waiting to restart

During a unit turnaround, verification of the safety instrumented system finds that its program no longer matches the approved baseline, and the change records cannot fully account for it. With the restart window closing, participants must decide whether the discrepancy is a management-of-change failure, a security incident, or both; whether to start on an unverified safety configuration or hold for full re-validation and proof testing; how to restore a safety baseline they can actually prove is known-good; and what remote-access and engineering-workstation posture the unit will live under. The threat appears only as observable effects — never technique.

Grounded in · TRITON/TRISIS malware targeting a safety instrumented system at a petrochemical facility, activity attributed to the group Dragos tracks as XENOTIME; the safety controller's application was altered and the SIS ultimately tripped the process to a safe state, which is how the intrusion was discovered.

OTC-CHM-00660 min

SOUR BATCH

When the batch record can't be trusted

At a specialty and consumer-chemical plant, an overnight enterprise-IT compromise leaves the systems that hold recipes, setpoints, electronic batch records, historian trends, and lab results returning data no one can fully trust — while exothermic reactors keep running on the setpoints those systems delivered. Finished lots made during the uncertainty window are of uncertain conformance, and some have already shipped. The team must decide whether to keep producing on unverified recipes or halt, whether to trust the electronic batch record or revert to manual verification and independent sampling, whether to release, hold, or recall the affected product, and what to disclose to customers and regulators about product assurance — and when.

Grounded in · The August 2023 cyberattack on Clorox, a major consumer- and chemical-products manufacturer, which disrupted its production and order-processing systems, forced a reversion to slower manual processes, and caused product shortages and a quarterly loss.

OTC-CHM-00760 min

GRACEFUL TRIP

The business is down; the reactor is not

Enterprise ransomware has crippled the corporate IT estate of a continuous specialty-chemicals plant — email, ERP, production scheduling, the LIMS lab system, and the long-term historian archive are all encrypted — while the process control network running an exothermic, chlorine-fed reaction shows no confirmed impact and every DCS console and the safety-instrumented system still respond normally. With degraded visibility into the business systems that surround the process and genuine uncertainty about whether the IT/OT boundary held, leadership must decide whether to keep a hazard-laden continuous process running or execute a precautionary controlled shutdown to a safe state — knowing the shutdown and the eventual restart are themselves high-risk evolutions. The team must judge which control and safety systems can be trusted and independently verified to bring the plant down and hold it there, how to staff and sequence a safe-state transition with manual-operation readiness, and what 'known-good' and safe-to-restart must mean — and who signs it — before the process is re-energized.

Grounded in · The May 2021 Colonial Pipeline ransomware attack, in which a compromise of the company's IT and billing systems led the operator to proactively shut down pipeline operations even though the operational systems were not confirmed to be affected, resulting in a roughly six-day outage of the largest U.S. fuel pipeline.

OTC-CHM-00860 min

CHOKED FLARE

When the last line of relief can't be trusted

On a normal day shift at a high-pressure reaction and separation unit handling toxic and flammable intermediates, the indications for the plant's final overpressure-protection and emergency-disposal path — relief headers, knockout drum, elevated flare, caustic scrubber, and blowdown — begin to disagree with each other, and one monitoring point on the flare header reads a value the process cannot physically produce. The safety-instrumented system reports the relief functions armed and healthy, but with the disposal-path instruments no longer trustworthy the team cannot confirm that overpressure protection and the safe-disposal route will actually perform if a reactor or column demands them. Participants must decide whether to proactively cut rates and depressure the unit or hold production while the relief path is uncertain, whether to trust the flare and relief instrumentation or stage independent field verification of the disposal route, whether loss of confidence in the final protective layer mandates an immediate emergency shutdown, and how to weigh flaring against air-permit thresholds and community exposure while meeting OSHA PSM, EPA RMP, and CSB-informed notification duties — all without the offensive technique behind the anomalies ever being shown or resolved.

Grounded in · The U.S. Chemical Safety Board investigation of the March 2005 BP Texas City refinery disaster, in which an ISOM raffinate splitter was overfilled and overheated, relief valves lifted to a blowdown drum and stack that discharged flammable liquid and vapor to the atmosphere rather than to a flare, and the resulting vapor cloud ignited and killed fifteen workers.

AGR · PROCESSING, COOPERATIVES, COLD CHAIN & LIVESTOCK

Agriculture & Food8 scenarios

Multi-plant protein shutdowns, harvest-timed grain-cooperative outages, connected-equipment lockout and guidance drift, cold-chain record integrity, welfare-critical livestock controllers, pasteurization/CCP integrity, distribution collapse, and irrigation/fertigation tampering — grounded in JBS, NEW Cooperative, John Deere/Melitopol, Americold, Dole, and Schreiber Foods.

OTC-AGR-00160 min

STOCKYARD HUSH

Ransomware halts the kill floor and the inspection that lets it run

A multi-plant protein processor loses plant-floor scheduling, weigh/label, and refrigeration-monitoring systems at the start of day shift across several federally inspected establishments. Kill floors and packaging lines sit idle, USDA in-plant inspection cannot lawfully proceed, chilled and frozen inventory loses temperature telemetry, and live-haul trucks keep arriving with animals that have nowhere to go. Leadership must establish command across sites, decide whether to cease production or run on paper at reduced speed, manage arriving live animals and a growing cold-chain backlog against welfare and spoilage, set a ransom posture and retailer/consumer messaging as grocery supply tightens, and define what must be provably true before resuming without shipping mislabeled or temperature-compromised product.

Grounded in · May 2021 JBS ransomware attack: a ransomware incident forced JBS, the world's largest meat processor, to halt operations at 13 plants and all of its JBS-owned U.S. beef facilities, disrupting a significant share of North American beef and pork capacity, before the company paid an approximately $11 million ransom - the largest documented production halt in the protein sector.

OTC-AGR-00290 min

AMBER SILO

Harvest won't wait, and the scale house just went dark.

At the peak of harvest, a member-owned grain cooperative loses its electronic scale tickets, grain-accounting, dryer HMIs and blend/load-out automation all at once. Trucks stack to the county road, the continuous-flow dryers run full and blind, and settlement, load-out and seed/fertilizer dispatch to member farms stall in the tightest moisture-and-margin window of the year. The team must keep people safe around the dryers and dust, keep grain moving, keep members whole, and decide who else needs to know — all while the timing suggests the week was chosen on purpose.

Grounded in · September 2021 ransomware attack on NEW Cooperative during peak harvest (BlackMatter ransomware, reported $5.9M ransom demand), disrupting grain scheduling, accounting and feed/logistics systems for a major U.S. grain cooperative.

OTC-AGR-00390 min

PALE MERIDIAN

The lines on the screen and the rows in the field no longer agree.

In the middle of the planting window, a large row-crop operation running RTK-guided tractors, planters, and self-propelled sprayers finds that the technology it plants by can no longer be trusted. Guidance terminals report position drift and refuse to arm planter and sprayer sections, some lock to a vendor-authentication error and go dark, a subset of the fleet can be immobilized remotely from somewhere the team does not control, and the as-applied maps coming off the machines no longer match what is actually on the ground. This is a defender exercise about operating a farm when the guidance, telematics, and records underneath the fleet are suspect: deciding whether to keep planting and spraying on untrusted guidance or revert to manual and lose the agronomic window, whether to disconnect the fleet from OEM telematics and cellular to regain local control at the cost of support and updates, whether to trust or fully re-verify the season's as-applied and prescription records that input-cost, compliance, and yield accounting all depend on, and whether to escalate to the OEM and dealer or pursue independent recovery of locked machines — all while notifying state regulators, the FBI/IC3, and the Food and Ag-ISAC. The threat is represented only through what the team observes; the exercise contains no offensive technique of any kind.

Grounded in · May 2022 Melitopol case in which GPS-equipped John Deere farm machinery removed from a dealership in occupied Ukraine was remotely locked and tracked, rendering the stolen equipment inoperable by its new holders.

OTC-AGR-00460 min

FROST LEDGER

When the cold chain loses its memory.

A third-party temperature-controlled warehouse and distribution network loses warehouse-management, order-fulfillment, and refrigeration-telemetry visibility at the start of shift. Dock doors and automated racking cannot release loads for pickup, and operators can no longer confirm whether hundreds of cold rooms holding meat, produce, dairy, and pharmaceuticals stayed in range - the temperature history itself is now in doubt. The team must decide whether to release product it cannot vouch for or hold it and cause stockouts and spoilage, stand up a manual cold chain across hundreds of rooms, notify customers and health authorities, and rebuild a temperature record it can defend to regulators and auditors.

Grounded in · November 2020 ransomware attack on cold-storage and logistics giant Americold that disrupted operations, inventory management, and order fulfillment across temperature-controlled warehouses and blocked customer pickups, occurring while the company was reported to be in discussions to store COVID-19 vaccines.

OTC-AGR-00560 min

DARK BROODER

Fans idle, dashboards green.

On a network of contract poultry and swine barns, the automated environmental controllers that run ventilation, heating, feed, and water begin reporting conditions that don't match the barns and stop obeying setpoint changes, while the alarm auto-dialers fall silent — just as a heat front moves in. With remote telemetry no longer trustworthy, the team must decide whether to dispatch crews to force barns onto manual control, whether to believe any reading or alarm, how to keep animals fed and watered, when to escalate to veterinary intervention or humane depopulation, whom to notify, and what evidence must exist before barns return to trustworthy automated control.

Grounded in · September 2021 BlackMatter ransomware intrusion at NEW Cooperative, an Iowa grain and animal-agriculture cooperative, which disrupted enterprise systems reported to be tied to livestock feed scheduling and the broader soft supply of grain, feed, and protein.

OTC-AGR-00660 min

PHANTOM BATCH

When the record can't prove the kill step

At a Grade A dairy and beverage processor, an overnight enterprise-IT compromise leaves the systems that hold pasteurization and clean-in-place monitoring values, electronic batch records, and critical-control-point (CCP) records returning data that no longer agrees with itself. Some logged HTST pasteurization temperatures look individually plausible but cannot be reconciled with the independent chart recorder or with product already shipped, and the team can no longer prove which finished lots met their CCPs. They must decide whether to keep filling while record integrity is unproven and stand up a trusted parallel monitoring path, whether to recall or hold lots whose CCP records are unverifiable, when and how widely to notify FDA and USDA FSIS, and how to reconstruct an authoritative record set for regulators and customers — all before anyone can prove what happened.

Grounded in · A loss of integrity in the electronic critical-control-point (CCP) and batch records that a dairy and beverage processor relies on to prove pasteurization and clean-in-place were performed correctly — the class of failure in which logged HTST pasteurization temperatures and CIP monitoring readings look individually plausible yet can no longer be reconciled with one another, with the independent chart recorder, or with product already shipped, so the plant cannot demonstrate which finished lots met their CCPs. No single named public incident cleanly matches this event, but the underlying risk is one regulation already treats as real: FDA's FSMA Preventive Controls rule (21 CFR Part 117) and HACCP require continuous CCP monitoring backed by verified, reviewable records, and NIST SP 1800-10 addresses exactly this class of ICS record- and process-integrity risk in manufacturing.

OTC-AGR-00760 min

EMPTY SHELF

When the orders stop and the shelves empty

A national foodservice and fresh-produce distributor loses its order-management, warehouse, and transportation-routing systems overnight to a suspected ransomware event. Restaurant and grocery orders can no longer be received or picked, dozens of refrigerated trailers sit unassigned in the yard, and highly perishable produce, dairy, and portioned proteins begin aging against a same-day clock while the automated cold-chain temperature log goes blind. As the team improvises manual order intake, sets allocation priorities across thousands of customers, and decides what aging inventory to divert, hold, or write off, it learns that customer and employee data may also have been taken — opening a second crisis on a different clock, with its own regulators and notification duties. Participants must keep product moving and food safe, communicate honestly with retailers, restaurants, and consumers as shelves empty, and run the operational-recovery and data-breach-notification tracks in parallel without letting either fail.

Grounded in · The February 2023 ransomware attack on Dole, one of the largest fresh-produce companies, which forced it to shut down systems and temporarily halt North American production and shipments, producing visible salad-kit and packaged-produce stockouts on grocery shelves.

OTC-AGR-00860 min

BITTER FURROW

The dose nobody entered

On an irrigated fresh-produce and fertigation operation at peak harvest, the SCADA controlling pump stations, irrigation zones, and inline fertilizer/chemical injection shows setpoints and dosing rates that don't match what operators entered, with flow and injection readings that don't agree with each other. It is unclear whether crop water and nutrient/chemical application were altered in a way that affects food safety, and the change history cannot cleanly separate a console edit from a remote session. The team must decide whether to stop irrigation or run manual-only after independently verifying dosing, judge whether affected produce is safe to harvest and sell, notify FDA and state authorities under FSMA, and prove the dosing and flow instrumentation can be trusted before believing any reading.

Grounded in · September 2021 intrusions into U.S. grain-cooperative operations reported during harvest season, in which the affected systems were described as including those controlling crop irrigation alongside grain and feed operations.

BLD · SMART BUILDINGS, BAS/BMS & DATA-CENTER OT

Buildings & Data Centers9 scenarios

Data-hall cooling/power telemetry integrity, smart-building BAS persistence, bricked KNX controllers, vendor remote-access pivots, cloud access-control compromise, hospital environmental-monitoring trust, winter heating loss, colocation management-plane ransomware, and internet-exposed BMS patch governance — grounded in Trane/Vertiv, VoltRuptor, KNXlock, Target/Fazio, Verkada, Lappeenranta, and WebCTRL.

OTC-BLD-00160 min

HOT AISLE

The dashboards read cool. The hot aisle is cooking.

Overnight in a multi-tenant colocation data hall, the cooling and power controls begin behaving erratically — chiller supply-water setpoints drift, CRAH units report conflicting temperatures on adjacent aisles, and one UPS bank shows an unexpected 'output off' while the racks it feeds stay powered — as hot-aisle temperatures climb toward thermal-shutdown thresholds and hardware-damage risk for tenant equipment. With the BMS and power telemetry no longer trustworthy, the team must decide whether to trip a controlled shutdown or failover to protect hardware or ride it out, whether to isolate the BMS/UPS management network mid-incident and lose remote monitoring, whether temperature and power readings can be trusted enough to shed load on, when to invoke tenant SLA breach notifications and escalate to the equipment OEM, and what evidence must exist before the hall returns to trustworthy automated control.

Grounded in · In 2025-2026, Claroty's Team82 disclosed unauthenticated vulnerabilities in widely deployed data-center equipment — Trane Tracer SC+ HVAC/BMS controllers and Vertiv Liebert UPS network management cards — documented in CISA ICS advisories ICSA-25-140-10 and ICSA-26-071-01, describing conditions that could lead to loss of control over cooling and power on these commonly BMS- and internet-reachable devices.

OTC-BLD-00260 min

PHANTOM FLOOR

The building says it's fine. You can't tell if it's lying.

A multi-tenant smart-building operator watches unexplained changes ripple across building-automation points in several buildings — lighting and access schedules toggling, HVAC modes flipping, clean gaps in the historian, and 'known-good' controllers whose firmware can no longer be verified — with no ransom note and no way to tell whether configurations were altered or the monitoring itself is lying. The team must decide whether to declare BAS integrity unknown and revert to a trusted baseline, how to keep buildings safe and occupiable on instruments they don't trust, whether to attribute publicly on only a working hypothesis, and when to disclose to tenants and regulators under NIS2 with the facts still uncertain.

Grounded in · ENISA Threat Landscape 2025 documented VoltRuptor, ICS-specific malware with built-in persistence and anti-forensics capabilities, attributed to the destructive threat cluster ENISA tracks as the 'Infrastructure Destruction Squad'.

OTC-BLD-00360 min

COLD KEY

The building locked itself, and no one has the key

Across a mixed-use commercial campus, hundreds of KNX field devices stop responding on the same morning — lighting, blinds, and HVAC actuators go dark, and a small edge data hall loses its cooling-control integration. The controllers appear locked by their own protective key, which facilities staff no longer hold. There is no ransom demand and no clear extortion, and no quick path to restore short of device-by-device recovery or full re-commissioning. The team must keep an occupied building safe and usable, choose a recovery path with honest downtime, decide whether to engage law enforcement and insurers, and fix the key-custody and vendor-handover gap that made this possible.

Grounded in · Limes Security 'KNXlock' — hundreds of a client's KNX building-automation devices bricked via the standard's own BCU protective-key feature, frequently with no ransom demand, leaving lighting, blinds, and HVAC actuators unresponsive and recoverable only device-by-device or through re-commissioning.

OTC-BLD-00460 min

SERVICE ENTRANCE

When the vendor with the keys gets breached

A facilities-services vendor that holds standing remote-maintenance access to your building-automation and HVAC systems reports it has been breached. Odd-hours logins are now visible through the vendor's channel to controllers that cool live data halls, and the team cannot immediately tell legitimate maintenance from an intruder pivoting toward building and corporate networks. Participants must decide whether to cut or watch the vendor's access, whether building-to-enterprise segmentation is actually holding, who else to warn, and what evidence and reporting the moment demands, all while the data halls still need cooling.

Grounded in · 2013 Target data breach that originated from HVAC/refrigeration vendor Fazio Mechanical's stolen remote-access credentials

OTC-BLD-00560 min

GLASS HOUSE

When you can't trust the locks or the cameras

A facilities operator learns its cloud-managed access-control and camera platform has been compromised at the provider, exposing live and archived footage and letting door schedules and badge permissions be overridden across a portfolio that includes a hospital and a school. With no reliable way to know which doors are truly secured, the team must decide whether to fall back to manual door control and posted guards, whether the uncertainty warrants a partial lockdown, how to meet privacy and breach-notification duties for exposed footage of patients, students, and staff, and how to hold the provider accountable while keeping physical security running.

Grounded in · March 2021 Verkada breach: attackers obtained super-admin access to roughly 150,000 cloud-managed cameras plus door and badge override at hospitals, schools, jails, and enterprises via a compromised provider support server.

OTC-BLD-00660 min

NEGATIVE PRESSURE

When the building can't tell you the truth about the air

A hospital's building automation system begins reporting anomalous, self-clearing, and possibly falsified conditions on the air-handling that maintains negative-pressure isolation rooms, operating-room humidity, and pharmacy clean-room cascades. Alarms are inconsistent and clinical staff cannot independently confirm whether containment and sterile environments are actually being held. The team must decide whether to fall back to manual verification and portable units — possibly relocating patients — how far to escalate infection control while integrity is unverifiable, what and when to report to health and accreditation authorities, and how to communicate with patients and the public without causing undue alarm.

Grounded in · March 2021 breach of a cloud-managed physical-security camera platform that exposed live and archived feeds inside hospitals, clinics, and other facilities.

OTC-BLD-00760 min

HARD WINTER

Heat goes down in a deep freeze

A property operator running heating and hot water for a portfolio of residential and mixed-use buildings loses its building-automation controllers to a repeating power-cycle failure during a deep sub-zero freeze. Radiators go cold, hot water disappears, and the automatic frost protection dies with the controllers, putting pipes hours from bursting and vulnerable residents at real risk. The team must protect people and pipes while controls are down, choose between central recovery and dispatching crews building-by-building, meet municipal and duty-of-care obligations, and set honest expectations for residents facing a second freezing night, all before deciding what "restored" really means.

Grounded in · In November 2016 in Lappeenranta, Finland, a distributed denial-of-service flood drove Fidelix building-automation controllers into an endless reboot loop, knocking out the systems that managed heating and hot water in at least two apartment buildings during sub-zero weather until responders isolated the affected traffic and restored control.

OTC-BLD-00860 min

SHARED FLOOR

The floor is up, the company is down

A commercial colocation data-center operator is struck by ransomware across its corporate and management systems. Power and cooling to customer cages keep running on autonomous field controllers, but the customer portal, provisioning, billing, DCIM/BMS monitoring and cloud-managed badge access go dark, and some operational, financial and facility data appears to have been stolen. Colocation customers demand to know whether their equipment and data are affected, and the team must communicate a running facility against impacted corporate systems, decide whether degraded monitoring justifies advising fail-over, meet breach- and data-centre incident-reporting obligations, and handle SLA credits — all without over- or under-stating risk.

Grounded in · Equinix NetWalker ransomware attack (September 2020), reportedly accompanied by an extortion demand of roughly $4.5M, in which the provider's corporate and internal systems were affected while colocation and interconnection services to customers were reported to continue operating.

OTC-BLD-00960 min

OPEN GATEWAY

An emergency advisory meets a portfolio of occupied buildings

A commercial real-estate operator learns that the building-management server product standardized across hundreds of occupied sites has a critical, unauthenticated exposure, and that some BMS front-ends are reachable from the public internet. The team must triage emergency patching and isolation across live, revenue-generating buildings without breaking HVAC, cloud-managed access control, data-hall cooling, or life-safety; determine whether the exposure was already abused before deciding whether this is patching or incident response; coordinate a national BMS integrator's remote-maintenance channel; and communicate a hard-to-bound exposure window to owners, tenants, and regulators. Threat activity appears only as observable effects; no offensive technique is presented.

Grounded in · CISA ICS advisory ICSA-25-324-01 (November 2025) for the Automated Logic WebCTRL Premium Server, describing CVE-2024-8525 (unrestricted file upload) and CVE-2024-8526 (redirection) in a widely deployed building-management server product, with a vendor-released fixed version urged for immediate mitigation.

MED · HOSPITALS, PHARMA GMP & MEDICAL DEVICES

Healthcare & Pharma9 scenarios

GMP production loss and batch disposition, electronic-record integrity, aseptic environmental-monitoring trust, vaccine cold-chain, hospital EHR/downtime, third-party clearinghouse dependency, connected medical-device drift, DSCSA serialization, and blood-bank/pathology integrity — grounded in Merck/NotPetya, Change Healthcare, UHS, Ireland HSE, Ascension, Synnovis, and Cencora.

OTC-MED-00160 min

STERILE HALT

When the batch record can't be trusted

A sterile-injectables plant loses its DCS, MES, and process historian at once on the morning shift: controllers drop offline, in-process aseptic and lyophilization batches stall mid-phase, environmental monitoring of the aseptic core goes dark, and no one can confirm which lots were at which step when everything froze. The team must decide who owns the hold/shutdown call under GMP, how to disposition lots whose electronic batch records can no longer be trusted, when to declare the line down amid a drug shortage and notify FDA and customers, and what evidence must exist to return the line to a validated state. The defining question is not 'is it down?' but 'can we still trust the record, the dose, and the cold chain?'

Grounded in · Merck & Co.'s 2017 NotPetya destructive-malware outage, which crippled a top-tier pharmaceutical manufacturer's global systems (est. US$870M+) and disrupted production.

OTC-MED-00260 min

TRUE COPY

When the batch record no longer reconciles

Quality discovers that timestamps and audit-trail entries in the electronic batch records and LIMS for several released and in-process lots no longer reconcile — some readings appear altered, some missing — and no one can yet say whether it is a system fault, a sync error, or tampering. The team must decide whether the integrity doubt triggers a hold or recall of already-released lots and how far back the ALCOA investigation must reach, how to preserve audit trails for both the QA investigation and a possible regulatory inquiry without further disrupting production, what to tell FDA/EMA and customers about records of uncertain integrity and when, and how to re-establish a trusted golden record baseline and prove going-forward data integrity.

Grounded in · 2017 NotPetya attack — Merck (Merck & Co.) global manufacturing and IT outage

OTC-MED-00360 min

STILL AIR

When the clean room can't prove the air is clean

During an overnight aseptic fill of a small-volume sterile injectable already on the national drug-shortage list, the environmental monitoring system (EMS) and building-management system (BMS) for the Grade A/B suite begin showing impossible, frozen, and internally inconsistent readings — non-viable particle counts, room-to-room differential-pressure cascades, and HEPA airflow can no longer be trusted — while vials keep filling behind the RABS glass. The team cannot tell whether the room is truly in control or only reported to be, and must decide whether to stop the fill and scrap a shortage drug or finish and quarantine it, whether operators may safely intervene in the aseptic zone with monitoring blind, how to disposition product made during the window of untrusted data, what and when to report to regulators, and when the suite can be requalified and returned to service. The defining question is not "is it down?" but "can we still trust the record, the dose, and the cold chain?" Threat activity is shown only through observable effects and integrity uncertainty; no offensive technique detail is ever presented.

Grounded in · The June 2017 NotPetya cyberattack, which spread globally from Ukraine and disrupted major multinationals including the pharmaceutical manufacturer Merck & Co., halting production and knocking out facility and control systems across sites.

OTC-MED-00460 min

COLD DECK

The freezers are full. The record is empty.

A health-system central pharmacy and specialty-distribution hub wakes to a cold-chain monitoring platform that has flatlined and gone silent across vaccine freezers, biologic refrigerators, and refrigerated courier (reefer) loads — with excursion alarms that never paged and no reliable way to tell which product actually saw a temperature excursion. The team must decide how to verify true temperature history when the record itself cannot be trusted, whether to quarantine or release potentially degraded vaccines and biologics against genuine patient-supply need, whom to notify among downstream providers, patients, and regulators, and how to re-earn trust in monitoring before accepting new stock.

Grounded in · 2017 NotPetya attack — global loss of a major vaccine manufacturer's production and operational technology (Merck)

OTC-MED-005120 min

PAPER WARD

The ward runs on paper now — and the record you need is the one you cannot reach.

Across a regional health system the electronic health record, PACS imaging, the laboratory and blood-bank systems, the pharmacy and electronic medication administration record, and the internal phones all go dark at once. The emergency department goes on ambulance diversion, clinicians revert to paper orders, and at the bedside no one can reliably pull allergies, medication histories, or prior imaging. Nothing about the building has changed — the ORs, the ventilators, the analyzers still run — but the record, the result, and the dose can no longer be taken on trust, and the outage may last not hours but weeks. PAPER WARD puts the team inside that reality: whether to divert and curtail services or run degraded, how to keep medication administration, transfusion, and ventilated patients safe on paper, what to tell patients, staff, referring providers, and the public without overstating what is known, and how to bring labs, pharmacy, and imaging back first and safely. The scenario depicts only observable effects and never any attacker technique.

Grounded in · Universal Health Services ransomware attack (September 2020): a Ryuk ransomware event took clinical and enterprise systems offline across roughly 400 UHS facilities in the United States, forcing hospitals and clinics onto paper records and manual processes for weeks and prompting ambulance diversion and delayed care while systems were rebuilt.

OTC-MED-00660 min

CLEARING HOUSE

Everything works. Nothing functions.

A national claims-and-prescription clearinghouse that the health system depends on abruptly goes offline. Pharmacies cannot adjudicate or fill many prescriptions, prior authorizations stall, and provider payments stop — yet nothing inside the organization's own EHR, pharmacy systems, or network shows any sign of compromise. The team must keep dispensing medications and delivering care without the transaction backbone, decide whether to sever connectivity to a partner it cannot clear, judge how long it can absorb halted reimbursement, and define what evidence proves the partner is safe to reconnect. Threat activity appears only as observable effects; no offensive technique is ever depicted.

Grounded in · February 2024 ransomware attack on Change Healthcare (ALPHV/BlackCat), which took the largest US medical-claims and pharmacy-transaction clearinghouse offline for weeks, halting prescription adjudication, prior authorizations, and provider payments nationwide and threatening provider solvency.

OTC-MED-00760 min

BEDSIDE DRIFT

When you can't trust the dose the pump displays

At a large acute-care teaching hospital, biomedical and clinical engineering flags that a fleet of networked smart infusion pumps — and a couple of imaging and lab-analyzer systems on the same clinical network — are misbehaving: unexpected reboots, drug-library and configuration drift, and displayed values that do not reconcile with manual checks at the bedside. The connected devices sit on the same hospital network that an enterprise-IT security event has put in doubt, and no one can yet confirm whether the devices' settings, doses, and results can still be trusted. The team must decide whether to pull suspect devices from service and lose clinical capacity or keep using them under manual verification, how to confirm dose and configuration when the devices themselves may be unreliable, whether the situation meets thresholds for FDA and manufacturer notification and a coordinated advisory, and how to safely patch or re-image a device fleet without interrupting active patient care. Throughout, the defining question is not "is it down?" but "can we still trust the dose, the setting, and the result?"

Grounded in · The U.S. FDA medical-device cybersecurity regime — the FD&C Act Section 524B cybersecurity requirements for cyber devices, together with FDA's premarket and postmarket cybersecurity guidance, under which device manufacturers and health-delivery organizations coordinate on device vulnerabilities and the FDA and manufacturers issue medical-device safety communications and advisories.

OTC-MED-00860 min

BLIND SERIAL

The serial numbers you can no longer trust

A national pharmaceutical distributor's serialization and product-verification platform goes intermittently unavailable, and its recent traceability records turn out to be internally inconsistent. A pallet of saleable returns cannot be verified, early signals suggest possibly counterfeit or diverted product is entering the channel, and several affected drugs are already in national shortage. The team must decide whether to quarantine unverifiable product or release it to protect supply, how to meet DSCSA suspect- and illegitimate-product investigation and notification duties, what to disclose to trading partners, FDA, and patients, and how to restore a trustworthy traceability system and reconcile the data gap — the defining question being not whether the system is down, but whether the record, the dose, and the cold chain can still be trusted.

Grounded in · 2024 Cencora (formerly AmerisourceBergen) data incident at a distributor handling roughly 20% of U.S. pharmaceuticals

OTC-MED-00960 min

CROSS MATCH

Blood tests you can no longer trust

Across a multi-hospital pathology partnership, the shared laboratory information system and its connected analyzers become unavailable and, worse, of doubtful accuracy, just as blood typing, cross-match, and urgent diagnostics are needed for transfusions and time-critical decisions. The team must keep transfusion and diagnostics safe without trusted results, decide what care to curtail and how to protect a shrinking blood supply, communicate honestly about degraded diagnostics without causing panic, and define how to validate results and instruments before the lab is believed again. The defining question is not only whether the systems are down, but whether the record, the dose, and the cross-match can still be trusted.

Grounded in · June 2024 ransomware attack on Synnovis, a pathology services provider (attributed in reporting to the Qilin group), which disrupted pathology and blood-transfusion services for major London NHS trusts, forcing cancelled operations and procedures, critical-incident declarations, and urgent public appeals for O-negative blood.

MIN · SMELTERS, UNDERGROUND & OPEN-PIT MINES, TAILINGS

Mining & Metals9 scenarios

Molten-smelter loss of view, underground hoist/ventilation/gas trust, autonomous-haulage positioning integrity, tailings-dam telemetry, remote-operations-centre multi-site failure, known-good restart of hazardous plant, environmental-permit monitoring, extortion/disinformation, and automated heavy-haul rail/port control — grounded in Aurubis, Norsk Hydro, Copper Mountain, Sibanye-Stillwater, EVRAZ, Nucor, Brumadinho/GISTM, and WA autonomous-haulage findings.

OTC-MIN-00160 min

COLD HEARTH

Running a molten smelter blind

Overnight, a cyber incident takes enterprise IT dark across an integrated copper-and-aluminium smelter and its captive mine, and the central control room's furnace, converter, casting and off-gas HMIs freeze on last-known values, leaving crews to run continuously-fed molten furnaces blind on immersion-thermocouple and pyrometer readings. Because a smelter cannot simply be stopped without risking a freeze-up or an uncontrolled tap, leadership must decide whether to hold the furnaces hot on degraded manual control with too few experts or execute a controlled banking that risks days of restart, whether to fully isolate OT from IT and go completely blind or preserve limited historian and emissions-monitoring visibility, when to declare force majeure to concentrate suppliers and metal customers, and what evidence is needed to trust HMIs and setpoints enough to return furnaces to automatic control - all while the mine's ventilation, gas and dewatering telemetry, the tailings-dam instrumentation and the stack-emissions monitoring run in the dark. Threat activity is shown only through observable effects - loss of visibility, integrity and remote control - never any offensive technique.

Grounded in · The October 2022 cyberattack on Aurubis, Europe's largest copper producer, which forced the company to isolate its IT systems and disconnect from the internet while keeping its Hamburg smelter and its environmental-protection facilities running on manual, degraded operation to protect people and the process.

OTC-MIN-00260 min

DEEP CAGE

People underground, instruments you can't trust

During a deep underground metal mine's back shift, the SCADA supervising the man-hoist, primary ventilation fans, gas monitoring and dewatering pumps begins showing frozen, stale and contradictory values shortly after a corporate ransomware event, and the control room can no longer confirm that displayed shaft, airflow and water readings reflect reality. With crews underground, the surface team must decide what it can still trust: whether to withdraw people on a hoist it cannot fully verify or hold and verify first, how to run hoisting, ventilation and dewatering on independent mechanical safeguards, when a mine emergency is declared and the regulator notified, and what evidence is required before automatic control is trusted and the mine re-manned.

Grounded in · Copper Mountain Mining Corporation shut down its mill and switched to manual processes following a ransomware attack affecting its control and IT systems.

OTC-MIN-00360 min

BLIND CONVOY

The pit's own map stops matching the ground

During the early-morning shift at an open-pit mine running a driverless haulage fleet, the control room stops being able to trust what its screens show: autonomous haul trucks and production drills report positions that jump off the haul roads and snap back, health telemetry freezes and resumes, real trucks and 'ghost' icons swap places, and the team can no longer be confident that displayed locations match the ground the machines are actually on. Manned light vehicles, a water cart, and a grader share those same haul roads, and a near-miss is reported at a give-way intersection that exists in the system but is faint on the ground after recent re-sheeting. The team must decide whether to trip the autonomous fleet to a controlled safe stop and halt production or keep hauling under heightened separation rules, whether to permit any manned vehicles inside autonomous zones while position integrity is uncertain, how to re-establish a trusted positioning baseline before resuming, and when to report a potential safety event to the mines regulator — all while the only trusted picture is the one people can see with their own eyes.

Grounded in · WA Mines Safety Significant Incident Report No. 226 (2025), documenting a collision in which an autonomous haul truck struck a manned water cart where the control-system route was not delineated on the ground, an injury-causing mismatch between the machine's digital picture and the physical roadway.

OTC-MIN-00460 min

QUIET BASIN

The dam's own instruments stop telling the truth

A high-consequence tailings storage facility above a downstream village finds its real-time monitoring — piezometers, inclinometers, pond level, and pump status — returning readings that conflict with each other and with the last manual survey, and the Engineer of Record can no longer certify that phreatic levels and embankment movement are within safe limits. The cause is unknown and could be instrument fault, a communications failure, or deliberate manipulation of the monitoring data. With a community inside the dam-break inundation zone and automated alarms firing on numbers no one trusts, the team must decide whether to evacuate on possibly-false alarms, whether to keep depositing while effectively blind, how to obtain independent ground-truth fast enough to matter, and what to tell the regulator, the Engineer of Record, and the community, and when.

Grounded in · Brumadinho tailings-dam (Dam I, Corrego do Feijao) failure — on 25 January 2019 the upstream-raised tailings dam near Brumadinho, Brazil collapsed without effective warning, killing roughly 270 people and destroying facilities and communities downstream.

OTC-MIN-00560 min

THIN TETHER

One control room loses its grip on many distant mines at once

A single remote operations centre supervising several mines, a smelter and an automated rail-to-port chain more than a thousand kilometres away loses trustworthy visibility and control of multiple sites at the same time. Screens across the video wall go blank or freeze on stale values, and operators cannot confirm whether the commands they issue are still reaching autonomous haulage fleets, fixed plant, hoisting, ventilation and rail. Every site runs a deliberately thin on-site crew because the operating model assumes the control room is in charge, so the team must decide whether to safe-state every affected site at once or triage which can keep running, whether skeleton crews can safely take manual control they rarely exercise, how to prioritise scarce field responders across sites hundreds of kilometres apart, and when to invoke mutual-aid and notify regulators across several jurisdictions.

Grounded in · In July 2024, Sibanye-Stillwater disclosed a cyber incident that took IT systems offline across its global operations at the same time, disrupting business systems at multiple sites simultaneously rather than at a single location.

OTC-MIN-00660 min

KNOWN GOOD

You can restart, or you can prove it's safe to — not both today

The enterprise-wide intrusion is contained and the underground mine, concentrator and smelter are cold and ready to restart — but no one can yet prove that the PLC logic, control-loop setpoints, metallurgical recipes and safety-instrumented configurations in the live controllers are unchanged from before the event, because the master baseline lived on a workstation in the affected zone. With a concentrate and anode backlog mounting, offtake shipments slipping, and the board demanding a date, the team must decide what "known-good" has to mean before it re-energises heavy, hazardous plant — and how to verify, sequence, communicate and codify it.

Grounded in · Copper Mountain Mining precautionarily shut down its mill after a ransomware attack, specifically to determine the attack's effect on its control systems (December 2022).

OTC-MIN-00760 min

GREY STACK

A smelter that cannot prove it is within its permit limits — and an extortion note that says the numbers were never real.

During an overnight IT incident at a copper smelter, the continuous environmental monitoring that proves the plant is within its permit limits — stack SO2 and particulate, effluent pH, suspended solids, and dissolved metals at the river outfall, and tailings piezometer telemetry — becomes unreliable, and the compliance dashboard keeps showing green within-limit tiles the team can no longer trust. An extortion note then claims the monitoring data was altered for weeks before it ever reached the regulator, a claim the plant can neither confirm nor disprove. The team must decide whether to reduce or halt production to stay demonstrably within limits, stand up independent manual sampling with defensible chain-of-custody, self-report a monitoring gap to the environmental regulator before anything is confirmed, and communicate honestly to a community asking whether it was exposed. The threat appears only as its observable effects on monitoring and reporting systems; no offensive technique is depicted.

Grounded in · The October 2022 cyberattack and IT outage at Aurubis, Europe's largest copper producer, during which the company took systems offline yet emphasised that production and environmental-protection facilities were kept running, including manually, so that operations and emissions controls continued while enterprise systems were isolated.

OTC-MIN-00860 min

OPEN SEAM

Extortion, fakes, and the fight to stay believed

A mining and metals company is named on an extortion group's leak site claiming to hold employee, community, and commercial data, and samples begin to appear. As the leak spreads, fabricated internal messages and a fake 'company statement' circulate while the mine, smelter, and export chain keep running normally. The team must decide whether and how to engage the actor, who may authorise any payment, whom to notify and when, and how to prove which words are genuinely the company's — all while balancing transparency against union, securities-disclosure, and legal constraints.

Grounded in · 2024 Sibanye-Stillwater data breach claimed by the RansomHouse extortion group, which leaked data on roughly 7,258 employees.

OTC-MIN-00960 min

HEAVY HAUL

Driverless ore trains, automated ports, and control you can no longer trust

A major iron-ore exporter's remote operations centre loses trustworthy supervisory control over its fleet of driverless heavy-haul ore trains and its automated port stockyard, stackers, reclaimers and shiploaders at once. Loaded consists stall across the network — some near public level crossings — and ship loading halts with booms over occupied berths, while level-crossing and berth safety interlocks can no longer be confirmed and demurrage and export commitments keep running. The team must decide whether to bring the whole chain to a controlled safe stop and block exports or run degraded under manual and heightened controls, how to protect public crossings and berths while positioning is uncertain, how to prioritise scarce manual crews across rail, stockyard and shiploading, and how to manage customer, shipping and force-majeure exposure — then define what a trustworthy, safety-assured return to autonomous operation requires. The defining question is not "is it stopped?" but "can we trust where every train and boom is, and who is protected?"

Grounded in · The deployed, in-service automation of the world's largest autonomous (driverless) heavy-haul iron-ore railway moving ore several hundred kilometres to port, together with highly automated port ore-handling — stockyard stackers, bucket-wheel reclaimers and automated shiploaders — all supervised from a remote operations centre far inland.

AVN · AIRPORTS, AIRLINES & AIR NAVIGATION

Aviation & Airports9 scenarios

Common-use passenger-processing outages, single-vendor systemic failures, hold-baggage screening integrity, fuel-farm telemetry, GNSS/RNAV position trust, flight-data/surveillance degradation, datalink/NOTAM integrity, terminal building-automation, and third-party PII extortion — grounded in Collins/MUSE, CrowdStrike, Sea-Tac/Rhysida, Colonial jet fuel, Finnair/Tartu GNSS, the FAA NOTAM ground stop, and SITA.

OTC-AVN-00160 min

PAPER HORIZON

The morning the shared platform went dark

On a peak travel morning, the shared common-use passenger-processing platform that every carrier at a hub airport depends on becomes unavailable. Check-in kiosks and bag-drop stop returning reservations, bag-tag printers fall idle, boarding-gate readers and the flight-information displays freeze, and staff fall back to handwritten boarding passes and whiteboards as queues overrun the terminal. The team must decide who commands an incident that originates inside a third-party vendor, whether to declare manual operations and deliberately cap terminal throughput or keep waiting on restoration, when to cancel or consolidate flights versus absorb rolling delays, how to set a single passenger-communication cadence across airport, airlines and the regulator, and what a trustworthy return to shared operations requires.

Grounded in · September 2025 Collins Aerospace ARINC MUSE/cMUSE ransomware disruption to shared common-use passenger-processing systems, which forced Heathrow, Brussels, Berlin, Dublin and Cork to revert to manual check-in and boarding.

OTC-AVN-00260 min

GLASS CASCADE

One vendor's update, every hub at once

Ninety minutes before the first departure bank, a routine overnight update from the carrier's aviation-IT provider silently disables departure control, crew scheduling and weight-and-balance across the entire network — and every hub degrades in the same instant. The failure is not malicious; it is a trusted dependency breaking, and the carrier cannot fix code it does not own. The Integrated Operations Control Center must decide whether to trigger an enterprise-wide manual recovery now or wait for the vendor's fix and risk a deeper schedule collapse, how to prioritize which flights, crews and hubs are restored first while keeping crews legal and inside fatigue limits, whether to pre-emptively cancel a defined block of the schedule to reset operations rather than chase a runaway backlog, and how to communicate externally and to regulators when the root cause sits with a third party it does not control.

Grounded in · The 19 July 2024 CrowdStrike faulty-update outage, in which a routine update to a widely used platform crashed core aviation IT worldwide; the carrier most affected cancelled roughly 7,000 flights over five days as departure control, crew tracking and related systems went down together.

OTC-AVN-00360 min

SORTER DRIFT

The sorter forgets which bag goes where — and whether it was screened

During the morning departure bank at a major hub, the automated hold-baggage handling system begins misrouting and mis-sorting bags: tote destinations no longer match the printed tags, diverters fire early or not at all, and transfer bags pile up at the wrong make-up carousels. At the same time the interface to in-line hold-baggage screening starts dropping decisions, so a growing share of bags reach make-up with no recorded screened-or-rejected result — and operators can no longer confirm that every bag loaded was actually screened. The team must decide whether to keep loading aircraft under degraded screening assurance or hold every affected departure for manual re-screening, whether the misrouting is a controls fault or an integrity compromise of the baggage OT/PLC network and whether to isolate it, how far to cut throughput so manual sortation and screening stay safe and sustainable, and when and how to notify the TSA and aviation-security regulator of a screening-integrity gap — all while manual sortation and hand reconciliation are the only trusted process left.

Grounded in · The August 2024 ransomware attack on the Port of Seattle / Seattle-Tacoma International Airport, which disrupted airport systems and forced airlines into manual baggage handling, leaving passengers and mis-sorted bags stranded during a prolonged recovery.

OTC-AVN-00460 min

DRY HYDRANT

The tanks won't add up and the pipeline won't deliver

A hub airport's fuel farm loses trust in its automated tank-gauging and hydrant-dispensing telemetry just as the pipeline feeding it cuts deliveries. With fuel quantity and on-spec quality data in doubt and only days of on-site storage, the team must decide whether to fuel on manual dips and paper tickets or halt, how to ration verified fuel and whether to tanker in or add en-route fuel stops, when to cut the schedule to the fuel that can actually be confirmed, and how to coordinate with the supplier and carriers — then define what evidence lets automated fueling resume.

Grounded in · In May 2021, a ransomware attack forced the shutdown of the Colonial Pipeline, the largest US refined-fuels pipeline, cutting jet-fuel deliveries to major aviation hubs including Atlanta, Charlotte, and Raleigh-Durham that hold only a few days of on-site storage; American Airlines temporarily added refueling stops to some long-haul flights out of Charlotte to manage the supply squeeze. The airport fuel farms and hydrant-dispensing systems these hubs depend on are SCADA/OT-controlled.

OTC-AVN-00560 min

GHOST FIX

The map in the sky stops telling the truth

During a heavy morning arrival bank, inbound aircraft begin reporting sudden GNSS position jumps and lost RNAV guidance: GPS-based approaches become unusable, receiver integrity alarms sound on flight decks, ADS-B tracks jump across the controllers' surveillance display, and several inbounds divert as the position data can no longer be trusted. The team must decide whether to suspend GNSS-dependent approaches and cut the arrival rate or continue on ground-based procedures with mitigations, how to manage diversions and holding as inbound aircraft burn fuel and alternates fill, how to advise crews and issue NOTAMs about the interference without amplifying confusion, and — once the interference looks deliberate rather than local — when and to whom to escalate, all while radar and ground-based aids remain the only trusted picture.

Grounded in · In April 2024, Finnair suspended flights to Tartu, Estonia for roughly a month after GPS interference near the airport caused two inbound flights to abort their approaches and divert, because the destination relied on GPS-based approach procedures.

OTC-AVN-00660 min

HOLLOW SKY

The airport's own picture stops telling the truth

During a busy morning bank, a hub airport's flight-data and surveillance picture stops agreeing with reality: a core flight-data processing system becomes unavailable while controller displays show phantom and duplicate targets that cannot be reconciled with real traffic, cutting usable separation capacity and putting a ground stop on the table. The team must decide whether to halt or throttle traffic to preserve safe separation or run reduced operations on reversionary procedures, who owns the fault-versus-attack determination between the airport, the ANSP, and the FAA, how long controllers can safely sustain manual procedures before capacity must be cut further, and what to tell airlines and the public during a flow halt whose cause is still unknown — all while radar and pilot position reports remain the only fully trusted picture.

Grounded in · The 11 January 2023 failure of a single FAA National Airspace System component (the NOTAM system), which triggered the first nationwide ground stop of departures since 11 September 2001 and disrupted thousands of flights.

OTC-AVN-00760 min

CROSSED SIGNAL

When the messages can't be trusted

Operations, dispatch, and flight crews at a busy hub begin receiving datalink and NOTAM/briefing messages — clearances, notices, and weather — that do not match authoritative sources, throwing the trustworthiness of routine operational communications into doubt. With no outage to point to and the morning departure bank loading, the team must decide whether to declare these channels untrusted and revert to authenticated voice and primary sources, how crews verify a legitimate message from a fabricated one under time pressure, whether to hold departures until integrity is confirmed, and how and when to warn the ANSP, the regulator, and other operators. The threat appears only as observable effects; no technique is examined.

Grounded in · Documented aviation concerns about the integrity of operational datalink and NOTAM/briefing information — situations in which crews and dispatchers have had to weigh whether a routine electronic message, notice, or weather product truly reflects authoritative information.

OTC-AVN-00860 min

STUCK BRIDGE

When the terminal itself is the outage

Passenger boarding bridges freeze at multiple gates while the terminal's building-automation systems - HVAC, lighting, access control and fire-detection panels - throw cascading anomalies, and gate operations gridlock during the morning departure bank even though check-in, departure control and the flight systems are all healthy. The constraint is the physical terminal itself. The team must decide how to board affected gates - air-stairs, apron buses and manual bridge operation, or closing the gates outright - whether the fire and access-control anomalies compromise life-safety enough to restrict areas or evacuate part of the concourse, whether to isolate the terminal OT network from IT to contain the anomalies at the cost of all automation, and how to re-bank a peak wave of flights onto a shrunken pool of usable gates and stands before defining what must be proven before automated gate and life-safety systems can be trusted again.

Grounded in · In August 2024 the Port of Seattle - which operates Seattle-Tacoma International Airport (SEA) - was hit by a ransomware attack (later attributed to the Rhysida group) and responded by isolating and taking a range of systems offline as a precaution; airport operations were disrupted for days, with flight-information displays, baggage, check-in and Wi-Fi affected and staff reverting to manual processes, and the Port later reported the data breach impacted roughly 90,000 people.

OTC-AVN-00960 min

OPEN MANIFEST

A vendor's breach, your passengers, your name

A third-party provider that runs common-use passenger processing and holds passenger data for most of the industry discloses a breach and an extortion demand with a countdown. The airport and its resident carriers held none of the data themselves, yet must own the fallout: when to notify passengers and regulators before the vendor has scoped the loss, whether engaging the extortion sits with them or the vendor, whether to keep processing passengers on the vendor's platform or cut over, and how to keep one consistent message across the many operators the same vendor serves.

Grounded in · February 2021 SITA passenger-processing breach — a common-use provider serving roughly 90% of the industry, in which Air India confirmed about 4.5 million passengers and ten years of data were exposed.

LOG · DISTRIBUTION, 3PL, FREIGHT & PORTS

Logistics & Warehousing9 scenarios

Warehouse-automation safe-state, WMS inventory/routing integrity, cold-chain and ammonia refrigeration, AMR/AGV fleet safety, SaaS-dependency outages, customs/documentation lockouts, terminal-operating-system halts, telematics/ELD hours-of-service, and carrier extortion — grounded in Blue Yonder, Americold, Ocado Andover, Expeditors, Royal Mail, Nagoya, DP World, ORBCOMM, Toll, and KNP.

OTC-LOG-00160 min

STILL BELT

The automation control layer stops answering mid-peak

A regional grocery and general-merchandise distribution center is midway through its overnight outbound wave at the height of peak season when the warehouse execution layer that orchestrates its conveyors, cross-belt sorter and high-bay AS/RS stops responding all at once. Belts halt with totes jammed at the merges, both storage-and-retrieval cranes park mid-aisle with pallets still on their forks, pick-to-light faces across the ambient and chilled modules go dark, and operators cannot tell whether the automation is safely stopped or holding stored energy on inclines and raised carriages. With hundreds of store deliveries due to depart at 06:00, the team must decide whether to declare a controlled safe-state shutdown or keep partial lanes running, whether to switch to manual pick/pack and re-slot labor or hold and divert inbound trailers to protect SLAs, when and how to grant the automation integrator, OEM and hosted-WMS vendor scoped remote access without widening exposure, and what to tell stores and key accounts about OTIF while root cause is still unknown - before choosing what to restore first and how to trust the inventory record and the automation again.

Grounded in · In November 2024 a ransomware attack on Blue Yonder - a supply-chain management software provider whose systems help orchestrate warehouse, inventory and fulfilment operations for major retailers - disrupted its managed-services environment and visibly interrupted goods flow for customers including the UK grocer Morrisons, whose warehouse and ordering systems for fresh and produce lines were affected across hundreds of stores.

OTC-LOG-00260 min

CROSSED LADING

When the records lie, not the servers

A regional third-party logistics distribution center finds parcels and pallets arriving at the wrong dock doors and loading onto the wrong outbound trucks. Handheld scans, the WMS location master, and printed shipping labels disagree, and the team cannot yet say whether inventory records, sortation routing, or the label print stream is the corrupted source — including for food, pharma, and dangerous-goods consignments. Participants must decide whether to trust or quarantine the location master and revert to a known-good snapshot, whether to halt outbound shipping or verify by hand at the dock, whether to interdict loads already dispatched, and whom to notify when controlled goods may already be mis-routed.

Grounded in · The November 2024 ransomware attack on Blue Yonder, a supply-chain management SaaS provider, which disrupted warehouse and logistics operations for numerous retail and grocery customers dependent on its platform.

OTC-LOG-003120 min

THAW POINT

Every room reads a perfect set-point. The probe in your hand — and the ammonia plant — say otherwise.

Across a fourteen-room 3PL cold store, the refrigeration-monitoring dashboards freeze and begin reporting implausibly steady set-points while calibrated spot checks show product cores drifting — and the team can no longer tell which zones are genuinely in-spec or prove the cold chain held for tens of thousands of pallets of food and pharmaceutical product. At the same time the anhydrous-ammonia refrigeration plant's HMI turns erratic, so no one can confirm the refrigeration process itself is operating safely under OSHA Process Safety Management. As customers demand FSMA traceability and documented temperature history, product must be held or shipped, the ammonia plant safe-stated or trusted, and regulators, insurers and customers notified — all while the monitoring platform, the ammonia HMI and the warehouse systems share infrastructure that cannot be cleanly isolated without going blind. The exercise is not about catching an intruder. It is about operating safely, proving integrity, and protecting product and people when the system of record can no longer be believed.

Grounded in · Cold-storage and logistics giant Americold suffered a network breach in November 2020 (with a further ransomware incident in 2023) that took inventory, fulfillment and customer-facing systems for its temperature-controlled 3PL operations offline.

OTC-LOG-00460 min

BLIND FLEET

When the floor can't trust its own robots

A high-throughput fulfilment centre's autonomous robot fleet — AMRs, AGVs, and grid-bots — begins behaving erratically: missed protective stops, a charging-bay thermal fault, and bots clustering and colliding near human pickers, while the fleet-management console can no longer confirm whether safety interlocks and stop functions are still trustworthy. The team must choose between a fleet-wide stop and zone-by-zone isolation, set fire and evacuation thresholds, decide whether to send people among stopped-but-possibly-live robots, and define what it takes to re-trust the fleet and resume automated operation.

Grounded in · 2019 Ocado Andover automated-warehouse fire (Andover, UK)

OTC-LOG-00560 min

TENANT DARK

Your cloud goes dark and the recovery clock isn't yours.

A high-volume third-party logistics operator loses access to the outsourced, vendor-hosted WMS/TMS SaaS its distribution centers run on. The platform goes dark with no restoration ETA, dashboards freeze, RF and voice picking stop, and the DCs revert to paper while a third party the operator cannot direct controls the recovery clock. The team must decide whether to invoke contractual continuity or wait, which goods flows to sustain or sacrifice on manual processes, how far to trust and repeat the vendor's public statements, and when a third-party outage becomes a solvency-level decision.

Grounded in · The November 2024 Blue Yonder ransomware attack, whose private-cloud outage disrupted the outsourced supply-chain and workforce SaaS relied on by major companies and cascaded to Starbucks workforce and pay operations and to UK grocers Morrisons and Sainsbury's.

OTC-LOG-00660 min

BONDED SILENCE

When the paperwork stops, the border closes

A global freight forwarder and customs broker loses the platforms that produce customs entries, dispatch dockets, and cross-border labels — whether from a self-imposed containment shutdown or encrypted docket systems. Cargo sits in a bonded yard while demurrage and detention clocks run, and the team must decide whether to disconnect to contain, how to stand up scarce manual filing capacity, which perishable, hazmat, and medical consignments clear first, and what to tell shippers, carriers, and the customs authority while recovery time is unknown.

Grounded in · Expeditors International shut down most of its global operating systems in February 2022 following a targeted cyberattack, and for roughly three weeks could not book freight, manage shipments, or clear customs, leaving cargo stranded worldwide.

OTC-LOG-00760 min

SLACK TIDE

The terminal operating system stalls and the boxes stop moving

The terminal operating system that choreographs quay cranes, yard slots, straddle carriers and the truck gate at a major container gateway fails, and monitoring flags spreading activity. The strange cruelty of it is that the ships alongside can still be discharged on local controls, so import boxes keep landing - but nothing can be located, grounded to a known slot, or gated out. Trucks queue back onto the motorway, the yard climbs toward gridlock, several hundred reefers lose monitoring and need power decisions, dangerous goods cannot be positively located, and a national-scale container backlog builds by the hour. The team must decide whether to disconnect the affected network to contain the incident or keep the gate and yard running on it, whether and at what safe throughput to stand up manual and paper gate and yard operations, how to ration the sliver of remaining capacity across reefer power, hazmat handling and empty repositioning, and how to coordinate with customs, carriers and the national authorities while managing importer and public backlog communications - before choosing what to restore first and how to trust the digital map of the yard again.

Grounded in · In July 2023 a ransomware attack on the Nagoya United Terminal System (NUTS), the shared terminal operating system for the Port of Nagoya - Japan's largest container port - halted container handling across the port's terminals for roughly two and a half days, stopping truck-gate transactions and forcing a reversion to manual handling before a staged recovery.

OTC-LOG-00860 min

PAPER MILES

The telematics platform goes dark and the paper-log clock starts ticking

A ransomware attack on the third-party telematics and electronic-logging platform that a 1,200-truck refrigerated carrier depends on takes it dark: drivers' in-cab ELDs drop into a malfunction state, dispatch loses live asset tracking and reefer temperature telemetry, and the hours-of-service data feed into the transportation management system stops. With no way to see who is legal to drive and a limited paper-log allowance already ticking, the team must decide whether to keep the fleet running on compliant paper logs or park trucks, whether and how to seek an FMCSA hours-of-service waiver, how to reroute and repower reefer and tracked-hazmat loads without live visibility, how to divide ownership between the carrier and its SaaS vendor while keeping customer communications consistent, and finally what must be proven — and what record reconciled — before trusting and reconnecting the platform. The threat appears only as observable effects: frozen dashboards, malfunctioning loggers, blind miles and a compliance clock nobody can pause.

Grounded in · In September 2023 a ransomware attack on telematics provider ORBCOMM knocked out its FleetManager and BlueTree electronic-logging-device (ELD) platforms, cutting off electronic hours-of-service logging and fleet-tracking for trucking customers, forcing drivers back onto paper logs, and prompting the FMCSA to issue an hours-of-service waiver for affected carriers.

OTC-LOG-00960 min

DOUBLE HAUL

Two hundred trucks, no run sheets, and a countdown on the company's data.

A mid-market road-freight carrier arrives Monday to find its transport management, dispatch, finance, and payroll systems locked behind a ransom demand, its backups encrypted, and hundreds of tractors idle in the yard for want of load and routing data. Within a day the intruders publish stolen commercial contracts and employee and customer records on a leak site and couple decryption with a threat to release the data, turning an operational outage into a fight for the company's survival. The team must stand up command with email and dispatch dark, decide whether to run manually or stand the fleet down, govern a pay/no-pay stance with the board, legal, the cyber insurer, and law enforcement, meet breach-notification duties across jurisdictions, sequence recovery between dispatch and finance, and carry an honest going-concern case to lenders and insurers — all represented only through observable operational effects, with no offensive detail.

Grounded in · In 2020 the global logistics operator Toll Group was hit by ransomware twice in roughly three months; the second incident exfiltrated data including commercial agreements and employee information and disrupted deliveries, forcing the company onto manual processes across much of its operation.

SPC · SATELLITE OPERATIONS, GROUND STATIONS & LAUNCH

Space & Ground Segment9 scenarios

Ground-segment ransomware at fleet scale, positive control of the vehicle, ground-station-as-a-service dependency, orbit-determination and conjunction-data integrity, timing infrastructure, imagery-product attestation, mission-planning supply chain, launch-range OT, and storm-plus-intrusion attribution — grounded in Viasat KA-SAT/AcidRain, the Landsat-7/Terra interference reports, SolarWinds, Volt Typhoon, and the 2022 Starlink storm loss.

OTC-SPC-00190 min

SILENT UPLINK

The spacecraft answer every call. The ground does not.

During a regional crisis, ransomware detonates across Auriga SatCom's mission-operations enterprise network while customer terminals across one GEO beam drop by the thousands. The fleet never stops answering — but positive control must be proven, not presumed, while containment at the IT/OT boundary, government and customer communications, teleport-vendor coordination, and the logistics of restoring a downed modem fleet all compete for the same hours. Modeled on the 2022 KA-SAT ground-segment attack, this exercise keeps the battlefield firmly on the ground and asks the room to earn every claim it makes.

Grounded in · AcidRain wiper attack on Viasat KA-SAT ground segment disabled tens of thousands of modems at the onset of the Russia-Ukraine war

OTC-SPC-00290 min

COLD HORIZON

The command counter is two counts high — and no one in this room sent them.

Boreal Imaging, a fictional 40-satellite LEO Earth-observation operator, sees an accepted-command counter increment on BOR-27 that nobody scheduled, logged during a window when a third-party northern ground station has nine minutes of missing session logs. The exercise turns on a single question that owns every module: does the operator still hold exclusive command authority over its fleet, and how would it prove that — to itself, to its insurer, and to its licensing authority? Teams work through validation of the anomaly, a command-link lockdown with real capacity costs, reporting into forensic fog, and the conditions under which normal operations resume.

Grounded in · US-China Economic and Security Review Commission reported command-and-control interference incidents affecting Landsat-7 and Terra (EOS AM-1) via a commercial ground station

OTC-SPC-00390 min

BORROWED SKY

Sixty satellites, forty passes a day, and a vendor who won't say what happened.

Kestrel Orbital flies a 60-satellite constellation almost entirely through PolarNet, a ground-station-as-a-service provider — until PolarNet declares a security incident and suspends its scheduling APIs for every tenant with no explanation. Teams must decide whose incident this is, triage a handful of owned-station passes across a medical-logistics SLA, a defense priority clause, and constellation safety, coordinate with a silent vendor and forty fellow tenants through Space ISAC, and define what evidence is enough to reconnect. The scenario operationalizes the core hybrid-network risk: your mission rides infrastructure you neither own nor can inspect.

Grounded in · AcidRain/KA-SAT showed one shared ground-infrastructure compromise degrading many downstream customers at once

OTC-SPC-00490 min

FALSE EPHEMERIS

The collision-avoidance decision is due — and the orbit data is lying

Halcyon Networks, a fictional operator of a 300-satellite LEO broadband constellation, screens a high-probability conjunction for 04:10 UTC tomorrow — and then discovers its orbit-determination pipeline has been ingesting third-party tracking data that fails cross-checks, with every maneuver-planning product from the past several days now suspect. The team must decide whether to burn on a questionable solution, seek independent screening under a hard orbital clock, or hold and accept the computed risk. The corruption then radiates outward: published ephemerides consumed by neighboring operators, a tracking provider that cannot yet enumerate the damage, and a regulator asking questions. Finally the team must rebuild a trusted orbit-determination baseline and define, in writing, what 'trusted again' means while a launch campaign bears down on the schedule.

Grounded in · ESA maneuvered Aeolus to avoid a Starlink satellite after coordination between operators broke down over a missed correspondence

OTC-SPC-00590 min

DARK PASS

Every pass is scheduled to the second — until the seconds stop agreeing

Aurora Ground Networks, a polar ground-station-as-a-service operator serving 15 customer constellations, watches the GNSS-disciplined timing references at its two arctic sites drift away from truth: passes start late, antennas point where satellites were, and telemetry timestamps poison customer pipelines. The team must decide whether this is regional GNSS interference, failing clock hardware, or deliberate manipulation of the time infrastructure — while choosing between holdover clocks with manual scheduling and suspending the sites outright as customers escalate. The exercise runs the full arc from anomaly triage through degraded-mode operations, third-party validation with national CERT and other operators, and a hardened-timing restoration that has to win back customer trust as well as clock lock.

Grounded in · Documented regional GNSS interference and spoofing episodes have repeatedly disrupted aviation and maritime timing/navigation in the Baltic, Black Sea, and Middle East

OTC-SPC-00690 min

SPLIT FEED

On-time flood maps you can no longer vouch for

During a multi-day flood response, Earth-observation analytics operator Terracast discovers that tiles in its FloodScope inundation products fail checksum verification against their signed manifests, with processing-log gaps and an unexplained service-account session pointing to a compromised product pipeline — while disaster-response agencies build levee and evacuation decisions around its four-hour delivery cadence. The team must decide whether the next delivery window ships annotated as unverified, holds for reprocessing from raw downlink, or ships only re-verified subsets; how to notify agencies and answer a reporter asking whether hackers altered the flood maps; and how to rebuild the pipeline to a known-good state, backfill attestation from the raw archive, and settle what the company can honestly certify, to whom, afterwards.

Grounded in · A 2014 intrusion into NOAA systems forced the agency to take satellite data services offline, interrupting products downstream users depended on

OTC-SPC-00790 min

PATIENT INJECT

Months of trusted updates. Zero alerts. One question: have we ever flown a tainted plan?

Corvid Space Systems learns from a vendor disclosure — and hours later a national advisory — that the mission-planning suite generating every command load it flies shipped compromised updates for months. Nothing has alarmed, which is exactly the problem. Teams must map exposure across consoles and missions, choose an operating mode with real throughput costs, hunt backward through ninety days of flown plans for evidence that may no longer exist, and rebuild to a known-good state with supply-chain requirements that outlive the incident.

Grounded in · The SolarWinds supply-chain compromise (CISA alert AA20-352a) put trojanized vendor updates inside government and critical-infrastructure networks for months undetected

OTC-SPC-00890 min

RANGE HOLD

Thirty-six hours from a customer launch, the range can no longer vouch for itself.

At L-36 hours for a customer launch, Windward Spaceport's configuration monitoring flags unexplained changes across the range's timing distribution, weather instrumentation, and the network feeding the Range Safety Officer's displays. Nothing is broken — and that is the problem: the launch safety case rests on systems whose integrity is suddenly in question. Teams must validate an ambiguity under countdown pressure, structure a scrub/proceed decision with real money on the line, coordinate the regulator, the customer, a national CERT, and neighboring airspace and maritime authorities, and define what 'range green' means before anything flies again. Built for launch-range, spaceport, and ground-segment operators who own safety cases as well as networks.

Grounded in · CISA advisory AA23-144a documented Volt Typhoon pre-positioning inside US critical-infrastructure OT-adjacent networks, including communications and transportation systems

OTC-SPC-00990 min

LONG ECLIPSE

The storm and the intruder arrive on the same night

A severe geomagnetic storm has Loom Dynamics' 1,200-satellite constellation at surge tempo — drag spiking, dozens of spacecraft in safe mode, conjunction screening degraded — when the SOC flags credential misuse inside the constellation-management platform. Now every anomaly has two possible causes, and the team must decide whether to restrict fleet automation and fly a mega-constellation at manual rate, whether to force a credential rotation at the storm's peak, how to separate weather effects from adversary effects with evidence, and what to tell peer operators, the regulator, and a press corps asking whether the satellites are hacked or just weathered. Recovery forces the capstone question: which trust do you rebuild first — automation or identity — and what the storm taught the security model. The threat appears only as observable effects; no technique is examined.

Grounded in · A February 2022 geomagnetic storm caused the loss of 38 newly launched Starlink satellites to atmospheric drag

XSC · MULTI-SECTOR CASCADES & SHARED-DEPENDENCY FAILURES

Cross-Sector Capstones4 scenarios

Larger multi-department capstones where an incident in one sector cascades into others or a shared dependency fails everywhere at once — trusted-vendor global defects, dominant-clearinghouse ransomware, coordinated pre-positioning across lifelines, and fuel-pipeline second-order cascades — grounded in the CrowdStrike outage, Change Healthcare, Volt Typhoon (AA24-038A), and Colonial Pipeline.

OTC-XSC-00190 min

TRUSTED FALLOUT

One trusted update, four lifelines dark at the same minute

Before dawn, a single trusted software vendor pushes a routine content update to the endpoint-security agent that runs on every managed Windows host across the group — and within minutes, servers and workstations reboot-loop simultaneously in airport passenger check-in, a hospital network's patient scheduling, third-party logistics dispatch, and back-office banking and payments. No attacker is required; a fragile shared dependency has failed at global scale, and because every business unit relies on the same platform, none can lean on the others. The multi-department team must keep four lifeline functions running with no cross-support, decide whether simultaneity means a coordinated attack or an ordinary non-malicious defect before it attributes anything, sequence a slow one-machine-at-a-time recovery across interdependent departments with scarce field staff, and speak to customers and the public when its own websites, contact centers, and every peer organization are down too. The exercise evaluates command, continuity, evidence discipline, recovery prioritization, and communications under a simultaneous enterprise-wide IT failure whose cause is, at first, genuinely ambiguous.

Grounded in · The 19 July 2024 global IT outage in which a defective content update pushed by a single trusted endpoint-security vendor caused millions of Windows hosts to fail simultaneously, grounding flights, disrupting hospitals, and halting logistics and banking operations worldwide with no attacker involved.

OTC-XSC-002120 min

SEVERED ARTERY

One shared hub goes dark. Every sector stalls.

A ransomware event takes down Continental Settlement Network, the dominant cross-sector clearing-and-settlement intermediary that authorizes and settles transactions for fuel distribution, freight, healthcare claims, airline ticketing, and card payments across the region. The participating organization — a regional fuel-and-logistics distributor whose own IT and terminal OT show no sign of compromise — suddenly cannot authorize fuel-card transactions, settle carrier load tenders, or collect receivables, while the same outage simultaneously freezes hospital claims, airline settlement, and card payments at retailers everywhere at once. With obligations, payments, and workflows stalled across hundreds of partners it does not control, the team must keep fuel physically flowing to hospitals, the airport, and emergency services on manual and alternate rails, survive a receivables freeze, decide which contractual and regulatory obligations legally pause versus persist, coordinate within a sector ecosystem via mutual aid and government (CISA/sector-ISAC) channels, judge when to declare force majeure, distinguish a non-malicious hub defect from an attack, and define what evidence proves the hub is safe to reconnect. Threat activity appears only as observable effects; no offensive technique, exploit, or attacker method is ever depicted.

Grounded in · February 2024 ransomware attack on Change Healthcare (ALPHV/BlackCat), which took the largest US medical-claims and payment clearinghouse offline for weeks, halting prescription adjudication, prior authorizations, and provider payments nationwide and threatening the solvency of organizations that depended on it.

OTC-XSC-00390 min

QUIET ARSENAL

Pre-positioned access wakes across water, power, and the port at once

During a period of acute geopolitical tension, long-dormant pre-positioned access appears to activate across a coastal region's lifeline sectors in the same window: a water authority's dosing and pump telemetry drift, an electric utility loses remote visibility to substations, and a port's terminal operating system stops moving containers. A regional coordination cell must run unified cross-sector command, prioritize lifeline restoration among competing sectors, coordinate scarce mutual-aid and government partners under simultaneous load, set operating posture as attribution points to a state actor mid-conflict, and speak with one public voice without amplifying panic.

Grounded in · CISA/NSA/FBI joint advisory AA24-038A on PRC state-sponsored 'Volt Typhoon' actors pre-positioning in U.S. critical infrastructure networks across the water and wastewater, energy, transportation, and communications sectors to enable disruptive or destructive effects during a major crisis or conflict (February 2024).

OTC-XSC-00490 min

DRY VALVE

The pipeline no one in the room owned

A cyber incident takes the region's dominant refined-products pipeline offline, and within days the second-order effects — not the pipeline itself — become the crisis: aviation jet-fuel rationing, transport and emergency-service fuel scarcity, and panic buying that empties still-supplied forecourts faster than tank trucks can refill them. This cross-sector capstone puts the players in a Regional Fuel Resilience Coordination Cell of organizations that never touched the pipeline but depend entirely on its output — an international airport, a hospital system, emergency management, fuel logistics, and a state energy office — who must establish authority none of them holds over the others, separate real supply loss from panic-driven demand, prioritize scarce fuel across competing life-safety and lifeline consumers, and communicate scarcity to millions without amplifying it. The threat appears only as observable effects — a precautionary shutdown, dry stations, competing inventory numbers, a restart that is not yet a resupply — never as any technique or attacker how-to, and the exercise deliberately tests coordination across an ecosystem no single participant controls, government and mutual-aid levers that must be pulled through others, and the honest question of who owns a shared-dependency concentration risk that belongs to everyone and no one.

Grounded in · Colonial Pipeline ransomware incident (May 2021): the operator of a major U.S. refined-products pipeline proactively took its mainline offline following a cyber incident on its business systems, and over the following days the precautionary shutdown triggered regional fuel shortages, panic buying, gas stations running dry, airlines adding fuel stops and adjusting schedules, and a federal regional emergency declaration to ease fuel transport — a cross-sector cascade driven by a single midstream operator that thousands of dependent organizations neither owned nor controlled.

Every scenario above runs against a model of your facility.

Pick one, seat your team, and leave with a scored after-action report and tracked corrective actions.