Skip to content

Talk-through drill

30 min read

Talk-through drill: supply-chain ransomware

Running this as a session

With a class: read each part aloud, pause at the Discuss prompts, and let students argue it out. Recast "your workplace" as a business they know.

As staff training: run it over a lunch break, no projector needed. Rate your readiness one to five at the start, and again at the end.

What this is

This is a talk-through drill, known in the security field as a tabletop exercise (TTX): a talk-through, not a test. Nobody touches a real computer and nothing here is graded. You read a short story, you stop at each turning point, and you decide out loud, or on paper, what you would actually do. The value is in the thinking and the discussion, not in getting a "right" answer. There is no clock counting your mistakes.

The names and the company are invented. Any resemblance to a real business is coincidence.

Lab

How to run this.

If you are alone: read each part, then write your decision down before you read the next part. Do not peek ahead. Writing it first keeps you honest with yourself.

If you are in a group: read each inject aloud, give everyone about two minutes to think, then discuss before moving on.

Before you begin, rate your confidence from 1 to 5: how ready would your own workplace be if this happened? Write the number down now. You will rate it again at the end. Plan for about 30 minutes.

The setup

Planora sh.p.k. is a small architecture and interior-design studio in a mid-size Albanian town. Six people work there. They keep all their drawings, client plans, and contracts on one shared drive that every machine can reach, because everyone needs to open everyone else's files.

Planora does not have its own IT person. Instead they pay a small outside firm to look after their computers. That firm logs in from a distance, using a remote-maintenance tool, to install updates and fix problems. Planora trusts them completely. That trust is exactly what this exercise is about.

Meet the small response team, the people who will have to decide things this week. Ilir owns the studio and signs off on money and big calls. Besa runs the office and is the one who talks to the outside IT firm. Genti is the youngest draftsman, the one everybody calls when a screen does something strange.

Inject 1, Monday

Monday morning, two things happen at once. Genti's design software shows a pop-up: "A new version is ready. Update now." At the same time, Besa gets a short message from the outside IT firm saying they will do routine remote maintenance this week and may push some updates to the machines. Both look completely normal. Updates are good, everyone knows you are supposed to install them, and the IT firm always does this kind of work.

Discuss:

  • An update you should install and an update that has been tampered with can look identical on screen. How would you tell a real one from a poisoned one before you click?
  • The message says the IT firm will "push some updates." Does that message, by itself, prove it really came from them?
  • If you decided to hold off and check first, who would you check with, and how would you reach them?

Inject 2, Tuesday

Tuesday afternoon a message arrives that looks like it is from the IT firm. It says a maintenance session needs to start right away and asks Besa to approve the remote connection and confirm the login details for the maintenance account. The tone is friendly but a little urgent, "so we can finish before end of day." Besa is busy and the request looks routine.

Discuss:

  • Before approving anything, how would you verify that this request is genuinely from your IT firm? Name the exact separate, trusted channel you would use, not a reply to the same message.
  • The maintenance account can reach every machine in the studio. Should logging into it require multi-factor authentication (MFA)? What changes for the attacker if it does?
  • "Urgent, before end of day" is doing a lot of work in that message. How does time pressure change the way people make security decisions, and how do you slow it down?

Inject 3, Wednesday

By Wednesday the remote-maintenance tool has run. On the surface everything is fine. But Genti notices two odd things while cleaning up his desktop. There is a new account on his machine that nobody remembers creating, and the shared drive was busy in the middle of the night, long after everyone had gone home. He is not sure it means anything. It could be nothing. It could be the IT firm working late.

Discuss:

  • A new account and after-hours activity: is this "probably nothing" or a warning sign? What would move it from one to the other in your mind?
  • The tool you trust is the tool the intruder is now using. When a trusted channel is the thing being abused, what can you actually still rely on?
  • What is the smallest, safest first step here, before anyone panics and before anyone deletes anything?

Inject 4, Thursday

Thursday morning nobody can open the shared drive. Files that were plain drawings and contracts yesterday now have strange new endings and will not open. A short text file has appeared in every folder. It says the files have been locked with encryption and that a key to unlock them will be provided in return for a large sum. This is ransomware, and it arrived through the maintenance tool the studio trusted, not through anyone opening a bad email attachment.

Discuss:

  • The first real question is not "do we pay." It is "do we have backups, and has anyone ever tested that they actually restore?" How confident are you in the answer for your own workplace?
  • If a backup exists but was connected to the same shared drive, could the ransomware have reached it too? What kind of backup survives an attack like this?
  • What do you stop doing in the first ten minutes, and what do you avoid doing that might make things worse?

Inject 5, Friday

By Friday the studio has to face the wider picture. Client plans and contracts are locked. Someone raises the idea of quietly paying the large sum to make it all go away. Ilir wants to know their obligations: this was a real security incident, so who outside the studio needs to be told, and does the law expect them to report it. Besa remembers that Albania has a national cyber authority, and that reporting is not just paperwork, it can bring help and it warns others who use the same IT firm.

Discuss:

  • Paying the large sum is tempting because it feels fast. What are the reasons it can fail you, and what does paying do to the next victim?
  • How and when would you report this to the national cyber authority, and what would you want to have written down before you call?
  • The same IT firm serves other businesses. Do you have any responsibility to warn beyond your own walls, and how would that change what you tell people?

Debrief

Walk back through the week and notice that each stop was really a lesson in disguise.

Monday, the two updates, was the patching and trust dilemma. Updates keep you safe and updates can carry the attack. The point is not to stop patching. It is to know where a real update should come from.

Tuesday, the urgent approval request, was about verifying a vendor through a separate, trusted channel and about protecting powerful accounts with multi-factor authentication (MFA). Notice that this looked nothing like classic phishing sent to a whole staff, and nothing like a business email compromise (BEC) chasing a payment. It leaned on a relationship you already trusted, which is what makes a supply-chain attack hard to spot.

Wednesday, the new account and the after-hours activity, was about noticing weak signals and about the hard truth that the tool you trust can be turned against you. That is the vulnerability at the heart of every supply-chain story.

Thursday, the locked files, was ransomware and encryption used as a weapon. The whole outcome came down to one boring question asked long before the bad day: do backups exist, and have they been tested by actually restoring from them.

Friday was about responsibility beyond your own office: reporting to the national cyber authority, thinking twice before paying a large sum, and warning others who share your supplier.

Now rate your confidence from 1 to 5 again. If the number moved, notice which inject moved it, and make that the first thing you fix at work on Monday.

Found something unclear, outdated or improvable? Suggest an improvement

shënim: ky material u krijua në kuadër të projektit 'U.S. Cybersecurity Leadership in AI for Albania', financuar nga departamenti i shtetit i shteteve të bashkuara. mendimet, gjetjet dhe përfundimet e paraqitura këtu janë të autorit(ëve) dhe nuk pasqyrojnë domosdoshmërisht ato të departamentit të shtetit të shteteve të bashkuara.

Disclaimer: This material was created on behalf of the 'U.S. Cybersecurity Leadership in AI for Albania' project, funded by the United States Department of State. The opinions, findings, and conclusions stated herein are those of the author(s) and do not necessarily reflect those of the United States Department of State.

Disclaimer