A public-portfolio tabletop exercise pack and incident response playbook library covering 10 scenarios across 5 industries and 5 jurisdictions, built around 5 threat-based IR playbooks.
This library is designed so a small security team could run any scenario with no modification, and so the same operational playbook can be applied across very different regulatory regimes — which is the central design idea: playbooks are organised by threat type, not industry, and each carries jurisdiction-specific regulatory annexes. See DESIGN.md for the full design rationale.
- Read the master facilitator guide once — it applies to every scenario.
- Pick a scenario from the table below. Read its
scenario-brief.mdandfacilitator-addendum.mdahead of the session; saveinject-cards.mdfor the facilitator only. - Run the linked playbook's structure as the basis for how the response should unfold, and use the jurisdiction annex relevant to the scenario.
- Complete the after-action report template within 48 hours of the exercise.
| Industry | Company | Jurisdiction | Scenario | Playbook |
|---|---|---|---|---|
| Healthcare | Khanyisa Health Group | South Africa (POPIA) | Ransomware | Ransomware |
| Healthcare | Khanyisa Health Group | South Africa (POPIA) | Data Exfiltration | Data Exfiltration / Breach |
| Aviation | Al Falah Airways | UAE (GCAA/ICAO) | OT / Critical Systems Disruption | OT / Cyber-Physical Systems |
| Aviation | Al Falah Airways | UAE/GDPR | Passenger Data Breach | Data Exfiltration / Breach |
| Banking | Brindlewood Bank plc | UK (FCA/ICO) | BEC / Wire Fraud | BEC / Payment Fraud |
| Banking | Brindlewood Bank plc | UK (FCA/ICO) | Ransomware | Ransomware |
| Education | Mornington Cross University | Australia (NDB) | Data Exfiltration | Data Exfiltration / Breach |
| Education | Mornington Cross University | Australia (NDB) | Ransomware | Ransomware |
| Shopping Mall | Cobalt Ridge Retail Properties | USA (PCI-DSS) | POS / Payment Card Breach | Payment Card / POS |
| Shopping Mall | Cobalt Ridge Retail Properties | USA | Cyber-Physical Convergence | OT / Cyber-Physical Systems |
| Playbook | Jurisdiction Annexes |
|---|---|
| Ransomware | South Africa (POPIA), UK (FCA/ICO), Australia (Privacy Act/NDB) |
| Data Exfiltration / Breach | South Africa (POPIA), Australia (NDB), UAE/GDPR |
| BEC / Payment Fraud | UK (FCA, SWIFT CSCF, Action Fraud) |
| OT / Cyber-Physical Systems | UAE (GCAA/ICAO), USA (life-safety systems) |
| Payment Card / POS Compromise | USA (PCI-DSS, state breach laws) |
scenarios/<industry-threat>/
scenario-brief.md # company profile, initial indicator, escalation structure
inject-cards.md # timed escalations — facilitator only, don't share in advance
facilitator-addendum.md # scenario-specific probing questions and failure modes
playbooks/<threat-type>.md # roles, step-by-step response, decision trees, comms
# templates, evidence checklist, jurisdiction annexes
templates/
facilitator-guide.md # generic methodology for running any scenario
after-action-report-template.md # reusable AAR structure
All companies, scenarios, and individuals referenced in this library are fictional. Regulatory frameworks (POPIA, UK FCA/ICO, GDPR, Australia's NDB scheme, PCI-DSS, ICAO/GCAA) are real and described to the best of the author's understanding for educational/training purposes — always verify current regulatory requirements with qualified legal counsel before relying on this material operationally.
MIT — see LICENSE.