NEW
Font size
WorksheetsUnited Bank for Africa - Tabletop Exercise
Total questions: 13
Worksheet time: 14mins
Scenario Overview
Several employees report being locked out of their workstations. A ransom note appears on their screens demanding $3 million in Bitcoin within 72 hours.
The attackers claim to have exfiltrated customer data, including financial records and personally identifiable information (PII).
The bank’s online services and mobile app are intermittently unavailable, and ATM transactions begin to fail.
Exercise Phases and Injects
Phase 1 – Detection and Initial Response
Inject 1: IT operations report that over 40% of endpoints are encrypted.
Inject 2: The SOC identifies the ransomware variant as “LockBit 3.0.”
Discussion Points:
1. How will you activate the incident response plan?
a) Wait for full confirmation from IT before acting
b) Immediately convene the incident response team and activate the incident response plan
c) Notify all staff to shut down their systems immediately without coordination
d) Escalate only to the CIO and await further direction
2. Who makes the call to shut down affected systems or the network?
a) The Board of Directors
b) The Chief Information Security Officer (CISO) in consultation with the board of directors and senior executives
c) Any IT staff member noticing the issue
d) The external managed service provider
3. How do you verify the extent of data exfiltration?
a) Assume all data is stolen
b) Wait for attackers to release data proof
c) Engage the forensics team to analyze network traffic and logs for data exfiltration evidence
d) Contact the regulator to confirm data loss
Phase 2 – Communication and Escalation
Inject 3: A journalist emails the communications team claiming they received a leaked sample of customer data from the attackers.
Inject 4: The regulator (e.g., CBN or FDIC) requests an urgent report on the incident.
Discussion Points:
4. What is your communication strategy (internal/external)?
a) Silence until the attack is fully resolved
b) Publicly deny the incident immediately
c) Allow employees to post clarifications on social media
d) Coordinate internal updates and prepare approved external communication guided by legal and compliance teams
5. What message do you give to customers and the media?
a) Acknowledge the incident, assure investigation and customer protection steps
b) Downplay the incident to avoid panic
c) Share all technical details publicly
d) Redirect media to IT for responses
6. How do you handle disclosure to regulators and law enforcement?
a) Delay reporting until the ransom deadline
b) Promptly report the incident in line with legal and regulatory requirements
c) Report only after customer data is confirmed leaked
d) Only disclose if compelled by the regulator
Phase 3 – Business Impact
Inject 5: Online banking remains unavailable for over 8 hours.
Inject 6: The attackers release 10,000 customer records on the dark web as proof.
Discussion Points:
7. What is your stance on ransom payment?
a) Immediately pay to restore operations
b) Evaluate payment only after consulting law enforcement, legal counsel, and considering regulatory and ethical implications
c) Refuse payment under all circumstances
d) Let IT decide based on system downtime
8. How do you maintain critical banking operations and customer confidence?
a) Use alternative channels like manual processing and communication hotlines to support customers
b) Wait for full system restoration before any response
c) Focus only on recovering systems
d) Blame service providers for the downtime
9. What are your legal and regulatory obligations at this stage?
a) Wait for attackers to release more data before acting
b) Keep the matter confidential to protect reputation
c) Notify affected customers and regulators as per data breach laws
d) Issue a statement denying responsibility
Phase 4 – Recovery and Lessons Learned
Inject 7: Backups are found to be partially corrupted.
Inject 8: Customers begin withdrawing funds in mass due to panic.
Discussion Points:
10. How do you restore systems securely?
a) Restore from the most recent clean backups and validate system integrity before going live
b) Reconnect encrypted systems to the network immediately
c) Pay the ransom for the decryption key without verification
d) Ignore corrupted backups and start rebuilding systems manually
11. How do you communicate service restoration and prevent reputational damage?
a) Blame the attackers publicly
b) Avoid communication to prevent panic
c) Announce “business as usual” even if systems are unstable
d) Provide transparent updates on restoration progress and customer protection measures
12. What policy or control gaps could have possibly contributed to this incident?
a) Lack of tested backup and incident response procedures
b) Overreliance on third-party vendors for cybersecurity
c) Insufficient employee awareness and phishing defenses
d) All of the above
13. How can the board ensure accountability after the incident?
a) Demand immediate resignations
b) Commission a post-incident review and ensure lessons are integrated into enterprise risk management
c) Reduce IT budget
d) Keep the incident confidential permanently
