The library

10 scenarios, written not generated.

101 timed updates in total, each one written by hand and reviewed. Every legal deadline is cited by article; anything a scenario invents for the sake of the exercise says so on its face. Pick the one that matches how your organization actually holds money, data and its own public voice.

  1. Ransomware

    01 / 10

    The shared drive is gone

    A Monday morning starts with nobody able to open a file. By the end of the hour the room has to decide who can authorize pulling systems offline, what it tells staff, and whether beneficiary data is in scope.

    Who it is for
    General NGO
    Shape
    60 min · 10 updates
    In the room
    Incident Lead · IT / Systems · Communications · Finance · Programs · Data Protection
    Covers
    Identify · Contain · Recover · Remove the cause · LessonsTechnical · Decide · Communicate · Comply · Protect
  2. Business email compromise / payment fraud

    02 / 10

    The bank details changed

    A supplier payment has already gone to the wrong account, and the email that asked for it came from a real address. The room has to move money, mailboxes and a donor relationship at the same time.

    Who it is for
    General NGO
    Shape
    60 min · 9 updates
    In the room
    Incident Lead · Finance · IT / Systems · Communications / Fundraising · Programs · Data Protection
    Covers
    Identify · Contain · Remove the cause · Recover · LessonsDecide · Technical · Comply · Protect · Communicate
  3. Device seizure or loss with beneficiary data

    03 / 10

    The laptop didn't come back

    A field officer is stopped at a checkpoint and her laptop is taken. It holds a beneficiary registration list. The room has to think about named people before it thinks about compliance.

    Who it is for
    Field operations / protection programming
    Shape
    60 min · 9 updates
    In the room
    Incident Lead · Safeguarding / Protection · Programs / Field Coordination · ICT Focal Point · Safety & Security · Communications / Donor Relations
    Covers
    Identify · Contain · Recover · LessonsDecide · Protect · Technical · Comply · Communicate
  4. Cloud account takeover

    04 / 10

    Someone else is signing in as the Director

    An overnight login from a country you do not work in turns out to be genuine, and the account it belongs to can approve payments and read everything. The room has to lock a Country Director out of her own organization before it can find out what the intruder already has.

    Who it is for
    Cloud-first country office
    Shape
    60 min · 11 updates
    In the room
    Incident Lead · IT / Systems · Finance · Communications · Programs · Data Protection
    Covers
    Identify · Contain · Remove the cause · Recover · LessonsTechnical · Decide · Protect · Comply · Communicate
  5. Departing-staff insider access

    05 / 10

    She left on Friday. Her access didn't.

    A finance officer who resigned three weeks ago is still signing in, and a donor and beneficiary list has moved to a personal account. The room has to separate theft from sloppiness, and decide what it is willing to say about a former colleague.

    Who it is for
    General NGO
    Shape
    60 min · 10 updates
    In the room
    Incident Lead · People / HR · Finance · IT / Systems · Communications / Fundraising · Data Protection
    Covers
    Identify · Contain · Recover · Remove the cause · LessonsTechnical · Decide · Protect · Comply · Communicate
  6. Vendor or implementing-partner breach

    06 / 10

    Our data, their breach

    The company that hosts your beneficiary database was breached eight days ago and has just told you, in one paragraph. The room has to work out what it is answerable for when the failure happened somewhere else, and how to press a supplier it has no leverage over.

    Who it is for
    General NGO / data held by third parties
    Shape
    60 min · 10 updates
    In the room
    Incident Lead · Programs · Data & Evaluation · IT / Systems · Data Protection · Grants / Contracts
    Covers
    Identify · Contain · Remove the cause · Recover · LessonsComply · Decide · Technical · Communicate · Protect
  7. Messaging account compromise

    07 / 10

    That message isn't from the Director

    The Country Director's WhatsApp is answering messages she never sent, in the groups that coordinate field movements and partner payments. The room has to warn several hundred people on a channel it no longer controls, before someone tells the account where a convoy is.

    Who it is for
    Field operations coordinated over WhatsApp
    Shape
    60 min · 10 updates
    In the room
    Incident Lead · Safety & Security · ICT Focal Point · Programs · Communications · Safeguarding / Data Protection
    Covers
    Identify · Contain · Remove the cause · Recover · LessonsCommunicate · Technical · Protect · Decide · Comply
  8. Mobile-money and payment-list fraud

    08 / 10

    The transfers went to the wrong phones

    A cash-transfer run has paid 260 households and 41 of the numbers are not theirs. The room has to halt a payment channel that people are already queuing for, on the day they were promised money, and work out that the list was changed from inside.

    Who it is for
    Cash and voucher assistance
    Shape
    60 min · 10 updates
    In the room
    Incident Lead · Finance · Cash & Voucher Assistance · ICT Focal Point · Safeguarding / Data Protection · Communications / Donor Relations
    Covers
    Identify · Contain · Recover · Remove the cause · LessonsTechnical · Decide · Protect · Comply · Communicate
  9. Public platform and social account takeover

    09 / 10

    Someone else is speaking as you

    Your main social account is posting, your website footer is pointing somewhere it shouldn't, and community members are already replying to both. The room has to take back its own voice, warn the people who trust it, and decide what it says publicly while it still does not know how this happened.

    Who it is for
    Organizations with a public website, social channels and a community that trusts them
    Shape
    60 min · 11 updates
    In the room
    Incident Lead · Brand & Communications · Community & User Support · Engineering · Finance · Data Protection & Legal
    Covers
    Identify · Contain · Remove the cause · Recover · LessonsCommunicate · Technical · Protect · Decide · Comply
  10. Accidental disclosure of personal data

    10 / 10

    It went to the wrong list

    A beneficiary list left the building by accident, to forty-seven people who should never have had it, and two of them have already replied to everyone. There is no attacker to blame and no system to shut down — only a notification clock that has already started and a colleague who is certain she has ended her career.

    Who it is for
    Any organization holding personal data about the people it serves
    Shape
    60 min · 11 updates
    In the room
    Incident Lead · Programs · Data Protection · IT / Systems · Communications / Fundraising · People / HR
    Covers
    Identify · Contain · Recover · Remove the cause · LessonsProtect · Technical · Comply · Decide · Communicate

Where to start

The right first drill depends on your organization, not on an average.

If you move money

Donor invoice fraud, then mobile-money fraud if you make field payments. Both start with a payment nobody questioned.

If you hold data about people

Accidental disclosure first — the most common real incident is a mistake, not an attacker — then device loss if staff carry data.

If you have a public voice

Public platform takeover. Your community watching it happen live is a different drill from anything internal.