A branching, choose-your-path tabletop built for a consumer products contract manufacturer. Six shared injects establish the crisis, then the room's own decision — pay the ransom, or refuse it — sends the exercise down one of two independent, fully-scripted paths. Neither one lets anyone off easy.
Every detail below is fictional — specific enough to feel real in the room, and generic enough to map onto almost any manufacturer that makes products under someone else's name.
A contract manufacturer headquartered in Ohio with two additional plants in North Carolina and Texas, producing private-label personal care, home care, and baby care products for four retail and specialty brand clients under exclusive manufacturing and non-disclosure agreements. ~900 employees, $310M in annual revenue, three of four production lines running at or near capacity.
Fairhaven doesn't sell a single product under its own name. Its entire value to its clients is that it can be trusted with their formulations, their production schedules, and their reputations — which is exactly what a ransomware crew is counting on.
Six injects, delivered over the first 33 hours, that every player experiences regardless of what the room ultimately decides. This phase ends with the decision that splits the exercise in two.
Automated monitoring at the Ohio plant fires dozens of alerts for mass file-renaming activity across file servers. On the plant floor, several manufacturing execution system (MES) terminals reboot into a screen no one recognizes.
The CISO confirms encryption across the ERP, MES, the lab information management system (LIMS, which holds every formulation record), and shared drives at Ohio HQ. The North Carolina and Texas plants were isolated in time — but the formulation vault's backup sync job was mid-run when the attack hit, so the last clean snapshot is already 30 hours old.
A ransom note attributed to "BlackHarvest" demands $4.6M in Monero within 96 hours. It claims 410GB was exfiltrated, including R&D formulation files, client contracts, and internal email, with publication threatened on the group's leak site if unpaid.
All Ohio lines are down. A 60,000-unit TinyRoots baby wash order tied to a retailer back-to-school promotion is due to ship in five days. The contract carries a $50,000-per-day penalty after a three-day grace period.
Legal confirms all four master service agreements require client notification within 24 hours of any incident affecting "confidentiality of formulation IP or continuity of supply." Lumière Beauty's agreement separately requires notice to its outside PR firm — meaning Fairhaven doesn't control the pace of who finds out next.
Outside counsel, forensics, and the insurer's ransom negotiator each bring a different recommendation to the table: forensics won't guarantee full decryption even if the ransom is paid; the negotiator cites roughly 60% delivery reliability for this threat group; general counsel flags possible sanctions exposure in the payment itself. The board has the floor, and has to decide.
From here, the facilitator runs one of two fully independent scripts depending on what the room chose in Inject 6. Toggle between them below to see how each one unfolds — in a live session, players only ever see the one they earned.
The board authorizes payment. The cyber insurer's crypto intermediary screens the wallet address for OFAC sanctions exposure, clears it, and sends $4.6M in Monero.
A decryption tool arrives and works. ERP and email come back clean. The MES and LIMS decryption stalls around 40% complete; several thousand files — including current-batch quality records — return corrupted or zero-byte.
QA discovers the corrupted LIMS files include the batch records for a TinyRoots baby wash lot already sitting in the warehouse, ready to ship. Without those records, Fairhaven can no longer prove the lot passed quality testing before the attack.
A new contact from BlackHarvest arrives through a different channel: the original payment only covered decryption, they say, not deletion of the stolen data. They want $1.9M more within 48 hours, or they publish Lumière Beauty's unreleased spring line and internal client correspondence.
Coverage counsel for the cyber insurer notes the policy's ransom-payment sublimit is nearly exhausted by the first payment, and is not yet willing to confirm a second extortion payment would be covered at all.
A sample appears on the leak site: three pages that look like a genuine Lumière Beauty formulation spec sheet, watermarked "full release in 96 hours." A trade reporter emails Fairhaven's general inbox asking for comment.
Lumière Beauty's general counsel sends formal written notice that Fairhaven is in material breach of the agreement's confidentiality provisions, reserves the right to terminate and pursue damages, and demands a same-day call with Fairhaven's CEO.
General counsel and the CFO argue against paying again — "we make ourselves a repeat customer." The board chair, focused on saving the Lumière relationship, argues there's no real alternative. Separately, an engineer flags that the corrupted MES data likely affects two other clients' current production runs — not yet disclosed to anyone.
Twelve hours remain before BlackHarvest's stated deadline to publish the full Lumière data set. The board has to decide, a second time, whether to pay — already knowing the first payment didn't resolve the incident.
Regardless of the second payment decision, forensics finds a persistent backdoor BlackHarvest planted during its original dwell time in the network. The environment may already be compromised again — payment was never going to be the thing that ended this.
Leadership declines to pay. The FBI's regional cyber squad is formally engaged, and the incident response team pivots fully to recovery from backup as the primary path forward.
Restoration from the immutable cyber vault begins. Ohio's ERP and file shares come back on schedule — but the most recent clean snapshot of the LIMS formulation database is the one taken 30 hours before the attack. Anything done in that window isn't coming back from backup.
IT discovers the North Carolina plant's local backup appliance — supporting the Solene Fragrance Co. line — was on the same domain and was encrypted before it could be isolated. There is no offsite copy: that appliance was excluded from the cyber vault's replication scope eight months earlier, during a cost-cutting review.
Solene, per contract, retains a copy of its own final approved formulations — but not the production parameters Fairhaven had customized for its own equipment. The line can restart, but only after re-validating the process from scratch.
Angered by the refusal, BlackHarvest publishes a "proof pack" on its leak site: internal emails and a partial client list that names all four of Fairhaven's brand clients directly, stating the full formulation data will follow "since they chose not to protect their customers."
A regional business publication runs the leak as a story, naming Lumière Beauty, TinyRoots, Northwood Home, and Solene Fragrance Co. Two of the four brands' social accounts are immediately flooded with consumer questions about product safety.
Northwood Home invokes its contractual right to a third-party security audit before allowing shipments to resume, and wants it to start within five business days — pushing Fairhaven's restart timeline for that line out by at least two more weeks.
With three of four lines still down on day five and no firm restart date for two of them, the CFO reports Fairhaven is close to breaching a revenue-linked covenant on its revolving credit facility. The bank's relationship manager has asked for an update.
An anonymous post on an industry forum, claiming to be from a current employee, alleges Fairhaven knew about the backup gap for months and didn't fix it. A reporter forwards the post to Fairhaven's comms lead and asks if it's true — with the leak site's threatened full release still 24 hours out.
The recovery lead reports that even with systems restored, manually re-entering five days of missed production, QC, and shipping transactions to reconcile with physical inventory will take operations another ten days.
The two paths are built to converge on the same hard questions, arrived at from opposite directions.
The full Fairhaven scenario — every inject, both paths, and the debrief questions — is available as a print-ready PDF you can share with your own team or board. Enter your email and we'll take you straight to the download.
The Fairhaven exercise is a sample — built to show how a ransomware simulation can branch on the decision that actually matters, and stay uncomfortable in both directions. A simulation built for your organization starts with your systems, your contracts, and your clients.
Exercises often require access to crisis plans, escalation structures, and vulnerabilities. That material is handled in confidence, and NDAs are available on request.
Talk to us about a custom simulation →