Phishing and Executive Impersonation Response
An urgent request impersonates an executive or business partner. Participants decide how to verify it, hold transfers or information sharing, and report it.
Practical exercises use scenarios to help participants understand situations, make decisions appropriate to their roles, and check whether organizational response procedures work.
Participants make role-specific decisions using realistic information and time pressure. Findings help improve organizational procedures and training plans.
Experience one incident from multiple roles, then compare the exercise with actual workplace procedures.
An urgent request impersonates an executive or business partner. Participants decide how to verify it, hold transfers or information sharing, and report it.
A potentially infected device and service outage appear. Review isolation, reporting, evidence preservation, continuity, and recovery priorities.
Sensitive information appears to have reached the wrong recipient. Practice containment, impact scoping, and appropriate internal reporting.
Unusual login alerts and user reports arrive. Check account protection, session blocking, log review, and actions to prevent further harm.
Adjust exercise difficulty and decision points to your environment and participants.
Define participants, learning goals, roles, and decision authority.
Provide information in stages through email, user reports, logs, and media inquiries.
Record choices, decision rationale, reporting timing, and collaboration across roles.
Share effective actions and missed procedures, then define training and policy improvements.
Review the time taken at each stage, from recognizing a threat to reporting, isolation, and decisions.
Check required actions such as verification, containment, evidence preservation, and internal reporting.
Identify operational improvements such as role confusion, reporting gaps, and approval delays.