Cyber Resilience Tabletop Exercise
Large-scale critical infrastructure tabletop combining technical incident response with governance-level decision simulation β co-facilitated with CMU and GW faculty for a hybrid OT/IT water treatment facility scenario.
This tabletop exercise was designed to stress-test both the technical incident response capability and the governance decision-making of participants simultaneously β a gap that most standard IR exercises fail to address.
The scenario places a fictional water utility under a coordinated cyberattack targeting both IT corporate infrastructure and OT SCADA systems, forcing participants to navigate conflicting priorities between operational continuity, public safety, regulatory reporting, and law enforcement coordination.
"Real incidents break at the seam between technical teams and decision-makers. This exercise was designed to find and stress that seam under realistic pressure."
- βIT team must contain without disrupting billing operations
- βLegal must assess breach notification requirements (state law + CISA)
- βOperations must decide: isolate OT (lose visibility) or maintain connectivity (accept risk)
- βLeadership must evaluate public disclosure timeline vs. ongoing investigation
- βExecutive decision required: notify public health authorities now or wait for confirmation?
- βFBI and CISA notification procedures activate
- βManual override protocols and OT playbook validation