DefenStory
SCENARIO-BASED PRACTICE

Build Response Skills
for Real Threats through practical exercises.

Practical exercises use scenarios to help participants understand situations, make decisions appropriate to their roles, and check whether organizational response procedures work.

Security staff and employees reviewing an attack scenario together
PRACTICE TO PREPARE

Experience the situation and check whether response procedures work.

Participants make role-specific decisions using realistic information and time pressure. Findings help improve organizational procedures and training plans.

Situational AwarenessRole-Based DecisionsOrganizational Feedback

Recommended Exercise Scenarios

Experience one incident from multiple roles, then compare the exercise with actual workplace procedures.

01

Phishing and Executive Impersonation Response

An urgent request impersonates an executive or business partner. Participants decide how to verify it, hold transfers or information sharing, and report it.

02

Initial Ransomware Response

A potentially infected device and service outage appear. Review isolation, reporting, evidence preservation, continuity, and recovery priorities.

03

Misdirected Personal Data and Data Breaches

Sensitive information appears to have reached the wrong recipient. Practice containment, impact scoping, and appropriate internal reporting.

04

Account Takeover and Unusual Logins

Unusual login alerts and user reports arrive. Check account protection, session blocking, log review, and actions to prevent further harm.

How Exercises Work

Adjust exercise difficulty and decision points to your environment and participants.

Set Goals and Roles

Define participants, learning goals, roles, and decision authority.

Introduce the Scenario

Provide information in stages through email, user reports, logs, and media inquiries.

Observe Decisions and Actions

Record choices, decision rationale, reporting timing, and collaboration across roles.

Connect Feedback to Improvement

Share effective actions and missed procedures, then define training and policy improvements.

What Exercise Results Show

◷

Response Time

Review the time taken at each stage, from recognizing a threat to reporting, isolation, and decisions.

✓

Completion of Required Actions

Check required actions such as verification, containment, evidence preservation, and internal reporting.

↗

Coordination of Roles and Procedures

Identify operational improvements such as role confusion, reporting gaps, and approval delays.

Exercises take place in a safe learning environment and do not involve attacks on or unauthorized access to real systems.