The library
10 scenarios, written not generated.
101 timed updates in total, each one written by hand and reviewed. Every legal deadline is cited by article; anything a scenario invents for the sake of the exercise says so on its face. Pick the one that matches how your organization actually holds money, data and its own public voice.
Ransomware
01 / 10
The shared drive is gone
A Monday morning starts with nobody able to open a file. By the end of the hour the room has to decide who can authorize pulling systems offline, what it tells staff, and whether beneficiary data is in scope.
- Who it is for
- General NGO
- Shape
- 60 min · 10 updates
- In the room
- Incident Lead · IT / Systems · Communications · Finance · Programs · Data Protection
- Covers
- Identify · Contain · Recover · Remove the cause · LessonsTechnical · Decide · Communicate · Comply · Protect
Business email compromise / payment fraud
02 / 10
The bank details changed
A supplier payment has already gone to the wrong account, and the email that asked for it came from a real address. The room has to move money, mailboxes and a donor relationship at the same time.
- Who it is for
- General NGO
- Shape
- 60 min · 9 updates
- In the room
- Incident Lead · Finance · IT / Systems · Communications / Fundraising · Programs · Data Protection
- Covers
- Identify · Contain · Remove the cause · Recover · LessonsDecide · Technical · Comply · Protect · Communicate
Device seizure or loss with beneficiary data
03 / 10
The laptop didn't come back
A field officer is stopped at a checkpoint and her laptop is taken. It holds a beneficiary registration list. The room has to think about named people before it thinks about compliance.
- Who it is for
- Field operations / protection programming
- Shape
- 60 min · 9 updates
- In the room
- Incident Lead · Safeguarding / Protection · Programs / Field Coordination · ICT Focal Point · Safety & Security · Communications / Donor Relations
- Covers
- Identify · Contain · Recover · LessonsDecide · Protect · Technical · Comply · Communicate
Cloud account takeover
04 / 10
Someone else is signing in as the Director
An overnight login from a country you do not work in turns out to be genuine, and the account it belongs to can approve payments and read everything. The room has to lock a Country Director out of her own organization before it can find out what the intruder already has.
- Who it is for
- Cloud-first country office
- Shape
- 60 min · 11 updates
- In the room
- Incident Lead · IT / Systems · Finance · Communications · Programs · Data Protection
- Covers
- Identify · Contain · Remove the cause · Recover · LessonsTechnical · Decide · Protect · Comply · Communicate
Departing-staff insider access
05 / 10
She left on Friday. Her access didn't.
A finance officer who resigned three weeks ago is still signing in, and a donor and beneficiary list has moved to a personal account. The room has to separate theft from sloppiness, and decide what it is willing to say about a former colleague.
- Who it is for
- General NGO
- Shape
- 60 min · 10 updates
- In the room
- Incident Lead · People / HR · Finance · IT / Systems · Communications / Fundraising · Data Protection
- Covers
- Identify · Contain · Recover · Remove the cause · LessonsTechnical · Decide · Protect · Comply · Communicate
Vendor or implementing-partner breach
06 / 10
Our data, their breach
The company that hosts your beneficiary database was breached eight days ago and has just told you, in one paragraph. The room has to work out what it is answerable for when the failure happened somewhere else, and how to press a supplier it has no leverage over.
- Who it is for
- General NGO / data held by third parties
- Shape
- 60 min · 10 updates
- In the room
- Incident Lead · Programs · Data & Evaluation · IT / Systems · Data Protection · Grants / Contracts
- Covers
- Identify · Contain · Remove the cause · Recover · LessonsComply · Decide · Technical · Communicate · Protect
Messaging account compromise
07 / 10
That message isn't from the Director
The Country Director's WhatsApp is answering messages she never sent, in the groups that coordinate field movements and partner payments. The room has to warn several hundred people on a channel it no longer controls, before someone tells the account where a convoy is.
- Who it is for
- Field operations coordinated over WhatsApp
- Shape
- 60 min · 10 updates
- In the room
- Incident Lead · Safety & Security · ICT Focal Point · Programs · Communications · Safeguarding / Data Protection
- Covers
- Identify · Contain · Remove the cause · Recover · LessonsCommunicate · Technical · Protect · Decide · Comply
Mobile-money and payment-list fraud
08 / 10
The transfers went to the wrong phones
A cash-transfer run has paid 260 households and 41 of the numbers are not theirs. The room has to halt a payment channel that people are already queuing for, on the day they were promised money, and work out that the list was changed from inside.
- Who it is for
- Cash and voucher assistance
- Shape
- 60 min · 10 updates
- In the room
- Incident Lead · Finance · Cash & Voucher Assistance · ICT Focal Point · Safeguarding / Data Protection · Communications / Donor Relations
- Covers
- Identify · Contain · Recover · Remove the cause · LessonsTechnical · Decide · Protect · Comply · Communicate
Public platform and social account takeover
09 / 10
Someone else is speaking as you
Your main social account is posting, your website footer is pointing somewhere it shouldn't, and community members are already replying to both. The room has to take back its own voice, warn the people who trust it, and decide what it says publicly while it still does not know how this happened.
- Who it is for
- Organizations with a public website, social channels and a community that trusts them
- Shape
- 60 min · 11 updates
- In the room
- Incident Lead · Brand & Communications · Community & User Support · Engineering · Finance · Data Protection & Legal
- Covers
- Identify · Contain · Remove the cause · Recover · LessonsCommunicate · Technical · Protect · Decide · Comply
Accidental disclosure of personal data
10 / 10
It went to the wrong list
A beneficiary list left the building by accident, to forty-seven people who should never have had it, and two of them have already replied to everyone. There is no attacker to blame and no system to shut down — only a notification clock that has already started and a colleague who is certain she has ended her career.
- Who it is for
- Any organization holding personal data about the people it serves
- Shape
- 60 min · 11 updates
- In the room
- Incident Lead · Programs · Data Protection · IT / Systems · Communications / Fundraising · People / HR
- Covers
- Identify · Contain · Recover · Remove the cause · LessonsProtect · Technical · Comply · Decide · Communicate
Where to start
The right first drill depends on your organization, not on an average.
If you move money
Donor invoice fraud, then mobile-money fraud if you make field payments. Both start with a payment nobody questioned.
If you hold data about people
Accidental disclosure first — the most common real incident is a mistake, not an attacker — then device loss if staff carry data.
If you have a public voice
Public platform takeover. Your community watching it happen live is a different drill from anything internal.