Industrial Control Systems Ransomware Tabletop Simulation Script
Facilitate a high-impact operational technology cybersecurity risk simulation for factory plant leaders.
Use this template to conduct an OT/ICS cyber-physical risk simulation drill with plant managers, automation engineers, and executive risk committees. It produces a fully orchestrated tabletop exercise facilitation script.
Role: Industrial Cybersecurity & Operational Technology (OT) Risk Governance Principal
Context
- Manufacturing automation framework: {{scada_system_type}}
- Simulated attack vector: {{threat_vector}}
- High-risk target cell or facility: {{target_production_unit}}
- Financial loss per hour of plant outage: {{downtime_cost_per_hour}}
- Active cyber-physical incident team: {{incident_response_team}}
- Fallback operational regime: {{failover_protocol}}
Task
Create a comprehensive tabletop facilitation script that guides cross-functional manufacturing and IT/OT risk leaders through a live-action simulation of a ransomware or malicious shutdown event targeting shop-floor control systems.
Method
- Establish the scenario baseline: regular operational metrics disrupted by anomalous {{threat_vector}} indicators.
- Script Facilitator Inject 1 (The Detection): Initial HMI anomalies across {{target_production_unit}} and telemetry blackout.
- Script Facilitator Inject 2 (The Dilemma): Physical safety alarms triggered vs. enterprise ransomware demand escalation.
- Design targeted pressure questions for {{incident_response_team}} concerning air-gap severance vs. automated downtime costs.
- Script Facilitator Inject 3 (The Cascade): Compromise of {{scada_system_type}} preventing safe automated shutdown.
- Guide participants through testing the manual feasibility and human risk of {{failover_protocol}}.
- Frame economic trade-offs based on accumulating losses at {{downtime_cost_per_hour}}.
- Script the debriefing sequence to isolate operational vulnerabilities and gap-remediation commitments.
Constraints
- MUST format as a facilitator guide containing timed injects, spoken prompts, expected answers, and tension triggers.
- MUST NOT allow purely IT solutions; force evaluation of physical machinery safety, pneumatic valves, and PLC controls.
- Include explicit participant reaction benchmarks for each inject stage.
- Ensure clear distinction between facilitator spoken dialogue, scenario inject text, and observer scoring rubrics.
Output format
- Phase 1: Scenario Setup & Inject 1 Dialogue (200 words, including facilitator prompt)
- Phase 2: Escalation Inject 2 & Technical Decision Prompts (250 words)
- Phase 3: Critical Operations Failover & Risk Dilemma Inject (250 words)
- Phase 4: Facilitator Debrief Script & Capability Gap Scorecard (150 words)
Self-review
- Check that the tension between cyber isolation and physical plant safety is maintained throughout.
- Ensure financial stakes using {{downtime_cost_per_hour}} are explicitly brought into the crisis decision points.
- Validate that all 6 input variables are logically woven into the tabletop narrative.
Explicit role, a named task, and discrete steps the model can follow.
Background, inputs and variables the model needs before it starts.
Hard boundaries — what the model must and must not do.
A named, field-level shape for the response.
Ordered work items that force analysis before an answer.
Length and structure that travel across frontier models.
Signal density — instruction weight without padding.
Documented variables so the scaffold adapts to new inputs.
Quality bar, assumptions and behaviour when inputs are thin.
How much real usage the template has behind it.