Sample Scenario — Executive Ransomware Simulation

The Fairhaven Ransomware Exercise

A branching, choose-your-path tabletop built for a consumer products contract manufacturer. Six shared injects establish the crisis, then the room's own decision — pay the ransom, or refuse it — sends the exercise down one of two independent, fully-scripted paths. Neither one lets anyone off easy.

16injects per path
2diverging paths
6 dayssimulated timeline
3.5 hrstypical runtime

Fictional, but built to feel real in the room.

Every detail below is fictional — specific enough to feel real in the room, and generic enough to map onto almost any manufacturer that makes products under someone else's name.

Fairhaven Formulations

A contract manufacturer headquartered in Ohio with two additional plants in North Carolina and Texas, producing private-label personal care, home care, and baby care products for four retail and specialty brand clients under exclusive manufacturing and non-disclosure agreements. ~900 employees, $310M in annual revenue, three of four production lines running at or near capacity.

Fairhaven doesn't sell a single product under its own name. Its entire value to its clients is that it can be trusted with their formulations, their production schedules, and their reputations — which is exactly what a ransomware crew is counting on.

Lumière Beauty — prestige skincare, 22% of revenue
TinyRoots — baby care, FDA-monograph products
Northwood Home — household cleaning, big-box retail
Solene Fragrance Co. — fine fragrance, NC plant

The crisis everyone faces.

Six injects, delivered over the first 33 hours, that every player experiences regardless of what the room ultimately decides. This phase ends with the decision that splits the exercise in two.

DAY 0
02:14
INJECT 1Detection

Night-shift alerts, unfamiliar screens

Automated monitoring at the Ohio plant fires dozens of alerts for mass file-renaming activity across file servers. On the plant floor, several manufacturing execution system (MES) terminals reboot into a screen no one recognizes.

Tests: the 2 a.m. escalation chain — does the on-call analyst know who to wake up, and how fast?
06:45
INJECT 2Scoping

Confirmed: ransomware, and a backup gap nobody planned for

The CISO confirms encryption across the ERP, MES, the lab information management system (LIMS, which holds every formulation record), and shared drives at Ohio HQ. The North Carolina and Texas plants were isolated in time — but the formulation vault's backup sync job was mid-run when the attack hit, so the last clean snapshot is already 30 hours old.

Tests: whether the team understands scope and recovery-point gaps before anyone starts making promises.
08:30
INJECT 3Extortion

The note

A ransom note attributed to "BlackHarvest" demands $4.6M in Monero within 96 hours. It claims 410GB was exfiltrated, including R&D formulation files, client contracts, and internal email, with publication threatened on the group's leak site if unpaid.

Tests: how quickly legal and outside forensics get engaged to test the exfiltration claim, rather than taking it at face value.
11:00
INJECT 4Operations

A promotion, a penalty clause, and a shipment that isn't moving

All Ohio lines are down. A 60,000-unit TinyRoots baby wash order tied to a retailer back-to-school promotion is due to ship in five days. The contract carries a $50,000-per-day penalty after a three-day grace period.

Tests: prioritization under competing client commitments when there isn't enough capacity to protect all of them.
15:00
INJECT 5Client relations

Four clients, four clocks

Legal confirms all four master service agreements require client notification within 24 hours of any incident affecting "confidentiality of formulation IP or continuity of supply." Lumière Beauty's agreement separately requires notice to its outside PR firm — meaning Fairhaven doesn't control the pace of who finds out next.

Tests: notification sequencing and message discipline across simultaneous, contractually-obligated disclosures.
DAY 1
09:00
INJECT 6Decision point

Pay, or don't

Outside counsel, forensics, and the insurer's ransom negotiator each bring a different recommendation to the table: forensics won't guarantee full decryption even if the ransom is paid; the negotiator cites roughly 60% delivery reliability for this threat group; general counsel flags possible sanctions exposure in the payment itself. The board has the floor, and has to decide.

Tests: decision-making authority and speed under genuinely incomplete information — this is the fork.

The room decides. The exercise branches.

INJECTS 1–6 DECISION PATH A — PAY PATH B — REFUSE

From here, the facilitator runs one of two fully independent scripts depending on what the room chose in Inject 6. Toggle between them below to see how each one unfolds — in a live session, players only ever see the one they earned.

Path A — the board paysTen injects. Paying buys speed, not certainty — and it puts Fairhaven back at the table with the same attacker twice.
DAY 1
18:00
INJECT 7APayment

Wire sent

The board authorizes payment. The cyber insurer's crypto intermediary screens the wallet address for OFAC sanctions exposure, clears it, and sends $4.6M in Monero.

Tests: whether the paperwork — insurer coordination, legal sign-off, sanctions screening — gets done properly under time pressure, not skipped in the rush to act.
DAY 2
10:00
INJECT 8ARecovery

The key works — mostly

A decryption tool arrives and works. ERP and email come back clean. The MES and LIMS decryption stalls around 40% complete; several thousand files — including current-batch quality records — return corrupted or zero-byte.

Tests: resetting expectations in real time when "we paid" doesn't mean "we're whole."
16:00
INJECT 9AQuality / regulatory

A lot with no paper trail

QA discovers the corrupted LIMS files include the batch records for a TinyRoots baby wash lot already sitting in the warehouse, ready to ship. Without those records, Fairhaven can no longer prove the lot passed quality testing before the attack.

Tests: whether the team will hold, re-test, or knowingly ship a lot on trust — with a baby-care client and a regulator both a phone call away.
DAY 3
09:00
INJECT 10ADouble extortion

"We kept a copy, for insurance"

A new contact from BlackHarvest arrives through a different channel: the original payment only covered decryption, they say, not deletion of the stolen data. They want $1.9M more within 48 hours, or they publish Lumière Beauty's unreleased spring line and internal client correspondence.

Tests: the room's ability to reframe a decision it thought was already made, with sunk cost now working against clear thinking.
13:00
INJECT 11AInsurance

The sublimit problem

Coverage counsel for the cyber insurer notes the policy's ransom-payment sublimit is nearly exhausted by the first payment, and is not yet willing to confirm a second extortion payment would be covered at all.

Tests: financial literacy under pressure — does the team know its own policy well enough to negotiate from a position of fact, not hope?
DAY 4
08:00
INJECT 12AMedia

Three pages, watermarked "sample"

A sample appears on the leak site: three pages that look like a genuine Lumière Beauty formulation spec sheet, watermarked "full release in 96 hours." A trade reporter emails Fairhaven's general inbox asking for comment.

Tests: the line between disciplined "no comment" and stonewalling a legitimate press inquiry.
15:00
INJECT 13AClient relations

Fairhaven's biggest client calls its lawyers

Lumière Beauty's general counsel sends formal written notice that Fairhaven is in material breach of the agreement's confidentiality provisions, reserves the right to terminate and pursue damages, and demands a same-day call with Fairhaven's CEO.

Tests: executive-to-executive crisis management with 22% of company revenue on the line.
DAY 5
10:00
INJECT 14AInternal conflict

The room splits

General counsel and the CFO argue against paying again — "we make ourselves a repeat customer." The board chair, focused on saving the Lumière relationship, argues there's no real alternative. Separately, an engineer flags that the corrupted MES data likely affects two other clients' current production runs — not yet disclosed to anyone.

Tests: whether disagreement among leaders produces a decision or produces paralysis, right when the room needs to move.
17:00
INJECT 15ADecision point

Twelve hours on the clock, again

Twelve hours remain before BlackHarvest's stated deadline to publish the full Lumière data set. The board has to decide, a second time, whether to pay — already knowing the first payment didn't resolve the incident.

Tests: whether the room repeats its earlier reasoning or has actually learned something from days 1 through 5.
DAY 6
09:00
INJECT 16ARemediation

The door they never closed

Regardless of the second payment decision, forensics finds a persistent backdoor BlackHarvest planted during its original dwell time in the network. The environment may already be compromised again — payment was never going to be the thing that ended this.

Tests: whether the team can separate the relief of "the immediate demand is handled" from the harder, longer work of actually re-architecting trust in the environment.
Path B — the board refusesTen injects. Refusing to pay protects the company's principle and its wallet — and exposes exactly how much the backup strategy was never actually tested end to end.
DAY 1
18:00
INJECT 7BLaw enforcement

The board says no

Leadership declines to pay. The FBI's regional cyber squad is formally engaged, and the incident response team pivots fully to recovery from backup as the primary path forward.

Tests: law enforcement engagement protocol, and whether the team can explain "why we said no" clearly to employees and clients alike.
DAY 2
09:00
INJECT 8BRecovery

Thirty hours of work that no longer exists

Restoration from the immutable cyber vault begins. Ohio's ERP and file shares come back on schedule — but the most recent clean snapshot of the LIMS formulation database is the one taken 30 hours before the attack. Anything done in that window isn't coming back from backup.

Tests: whether "we have backups" gets treated as a finish line or correctly understood as a recovery-point gap with real consequences.
14:00
INJECT 9BRoot cause

The appliance that was cut from scope

IT discovers the North Carolina plant's local backup appliance — supporting the Solene Fragrance Co. line — was on the same domain and was encrypted before it could be isolated. There is no offsite copy: that appliance was excluded from the cyber vault's replication scope eight months earlier, during a cost-cutting review.

Tests: whether the team can absorb a previously-known, previously-accepted gap becoming today's emergency, without the conversation collapsing into blame.
DAY 3
08:00
INJECT 10BClient dependency

The client has the formula. Not the process.

Solene, per contract, retains a copy of its own final approved formulations — but not the production parameters Fairhaven had customized for its own equipment. The line can restart, but only after re-validating the process from scratch.

Tests: creative recovery thinking that reaches beyond internal IT — to clients, contracts, and paper trails outside the four walls.
15:00
INJECT 11BRetaliation

BlackHarvest posts anyway

Angered by the refusal, BlackHarvest publishes a "proof pack" on its leak site: internal emails and a partial client list that names all four of Fairhaven's brand clients directly, stating the full formulation data will follow "since they chose not to protect their customers."

Tests: crisis communications when the attacker, not the company, controls the timing and framing of disclosure.
DAY 4
09:00
INJECT 12BMedia

The story runs with names in it

A regional business publication runs the leak as a story, naming Lumière Beauty, TinyRoots, Northwood Home, and Solene Fragrance Co. Two of the four brands' social accounts are immediately flooded with consumer questions about product safety.

Tests: co-messaging across four separate brand comms teams who did not ask to be part of this story.
13:00
INJECT 13BClient relations

Trust has conditions now

Northwood Home invokes its contractual right to a third-party security audit before allowing shipments to resume, and wants it to start within five business days — pushing Fairhaven's restart timeline for that line out by at least two more weeks.

Tests: the gap between "we're technically ready to restart" and what it actually takes to earn a client's trust back.
DAY 5
10:00
INJECT 14BFinance

The bank wants a call

With three of four lines still down on day five and no firm restart date for two of them, the CFO reports Fairhaven is close to breaching a revenue-linked covenant on its revolving credit facility. The bank's relationship manager has asked for an update.

Tests: whether the operational recovery plan is connected to the balance sheet, or running on a separate track from it.
16:00
INJECT 15BDecision point

"They knew, and did nothing"

An anonymous post on an industry forum, claiming to be from a current employee, alleges Fairhaven knew about the backup gap for months and didn't fix it. A reporter forwards the post to Fairhaven's comms lead and asks if it's true — with the leak site's threatened full release still 24 hours out.

Tests: truthful, controlled public response under a disclosure clock, with an insider-risk problem layered on top and no ransom decision left to fall back on.
DAY 6
09:00
INJECT 16BOperations

Systems up. Business not caught up.

The recovery lead reports that even with systems restored, manually re-entering five days of missed production, QC, and shipping transactions to reconcile with physical inventory will take operations another ten days.

Tests: the difference between technical recovery and operational recovery — a distinction most exercises never reach because they stop the moment the screens come back on.

What the debrief surfaces.

The two paths are built to converge on the same hard questions, arrived at from opposite directions.

If the room paid

  • Did anyone document why paying was defensible before the wire went out, or only after?
  • Who owns the decision to pay a second time — and does that authority actually sit where the org chart says it does?
  • Was the insurance policy understood well enough, in advance, to know its limits before hitting them mid-crisis?

If the room refused

  • Was the backup strategy ever actually tested end to end, or only assumed to work?
  • Who had visibility into the scope exclusion made eight months earlier, and why didn't it get revisited?
  • How is "systems restored" being reported upward — as the end of the crisis, or as the start of the recovery?
Fairhaven Formulations, BlackHarvest, and all named brand clients in this scenario are fictional and created for exercise purposes only.

Want this as a PDF?

The full Fairhaven scenario — every inject, both paths, and the debrief questions — is available as a print-ready PDF you can share with your own team or board. Enter your email and we'll take you straight to the download.

This is one scenario. Yours would be built around your business.

The Fairhaven exercise is a sample — built to show how a ransomware simulation can branch on the decision that actually matters, and stay uncomfortable in both directions. A simulation built for your organization starts with your systems, your contracts, and your clients.

Confidential by design

Exercises often require access to crisis plans, escalation structures, and vulnerabilities. That material is handled in confidence, and NDAs are available on request.

Talk to us about a custom simulation →