A written incident response plan is a good start. Whether it works is a different question, and you do not want to learn the answer during a real event. A tabletop exercise tests the plan in a conference room, with no systems at risk. For energy and industrial companies, the most valuable tabletop brings operations and IT people together, because that is where plans most often break down.
This script is designed for a small team and about ninety minutes. It uses a hypothetical scenario, so adjust the details to fit your environment.
Who should attend
- Plant or field operations manager and a lead operator or technician.
- IT lead or your managed IT provider.
- Controls or automation engineer.
- A senior executive with authority to make decisions.
- HR or communications, if you have them.
- Safety or compliance lead.
- Optionally, a representative from your insurer or legal counsel.
Appoint a facilitator who runs the scenario and a note taker who records decisions and gaps. The facilitator should not be the person who wrote the plan.
Ground rules
- No blame. The aim is to find gaps.
- Answer as you would on the real day, not as you wish you would.
- Use only the information you have in the scenario.
- Safety decisions always come first.
The scenario
Early on a weekday morning, an office employee reports that files on a shared drive have been renamed and a ransom note has appeared. Within the hour, an operator reports that the screens at a monitoring workstation are frozen. Operations is not sure whether the control system is affected.
The facilitator reveals new information in stages, called injects.
Inject one: first report
An employee reports locked files and a ransom note.
Questions:
- Who is the first person they call, and how do they reach them?
- Who decides to disconnect machines, and how?
- Who is told in the first fifteen minutes?
- Who protects the backups?
Inject two: operations is affected
A monitoring workstation in the control room is unresponsive. Operators cannot tell whether the process is still being controlled correctly.
Questions:
- Who decides whether to continue running, switch to manual, or shut down?
- Do operators have written manual procedures, and have they practiced them?
- How do we know the control network is isolated from the infected business network?
- Who is the single decision maker for operational safety?
Inject three: vendor and remote access
The attacker may have used a vendor remote connection. A vendor engineer calls offering to connect and help.
Questions:
- Do we allow the vendor to connect during an incident?
- How do we shut off all remote access, and who can do it at night?
- Who contacts each vendor, and what do we tell them?
Inject four: outside questions
A customer asks why a delivery is late. A local reporter calls. The attacker threatens to publish stolen data.
Questions:
- Who speaks for the company?
- What do we say to customers and to employees?
- Who do we notify: insurer, law enforcement, regulators, CISA, customers? When?
- Who decides about any contact with the attacker, and with whom do we consult?
Inject five: recovery
Backups exist, but the most recent copy of a key system is eight days old.
Questions:
- What can we restore, in what order?
- What data would be lost, and how do we recreate it?
- How do we confirm the restored systems are clean?
- When is it safe to reconnect the business network to the control network?
Wrap-up questions
- What surprised us?
- Where did we disagree?
- Which phone numbers, documents, or accounts did we not have at hand?
- What did we assume that might not be true?
After the exercise
- Within a week, write a short summary listing the gaps and recommended fixes.
- Assign each fix an owner and a due date.
- Update the incident response plan, contact lists, and manual procedures.
- Schedule the next exercise, ideally annually, with a different scenario.
- Keep the notes. They show diligence to insurers, customers, and regulators.
Variations
Try a scenario involving a compromised vendor laptop, a lost controller configuration, an insider mistake, or a power or communications failure combined with a cyber event. Rotating scenarios keep the exercise fresh.
Tips for success
- Keep the pace brisk, and do not let one question consume the whole session.
- Encourage operators to speak up. They know what will actually happen at the panel.
- Use real names and real phone numbers rather than roles alone.
Support from Ironfield Cyber
Ironfield Cyber can facilitate tabletop exercises for contractors and energy companies, tailored to your systems and operations, and help you turn the findings into an improved response plan. If you have never run one, we can help you design a first session.