| name | breach-simulation |
| title | Designing Breach Simulation Exercise |
| description | Designs and executes tabletop breach simulation exercises for testing organizational breach response capabilities. Covers scenario creation with realistic inject timelines, participant role assignment, communication testing across internal and external channels, decision-point evaluation, and after-action report generation. Keywords: tabletop exercise, breach simulation, incident response testing, scenario design, after-action report. |
| author | mukul975 |
| author_url | https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/breach-simulation |
| license | Apache-2.0 |
| version | 0.1.0 |
| execution_mode | open |
| jurisdiction | general |
| practice | data-protection |
| language | en |
Designing Breach Simulation Exercise
Overview
Breach simulation exercises (tabletop exercises) test an organization's ability to detect, respond to, and recover from a personal data breach without the consequences of an actual incident. A well-designed exercise validates the breach response plan, identifies gaps in procedures, communication, and decision-making, and builds institutional muscle memory. This skill covers the end-to-end design process from scenario creation through after-action reporting.
Exercise Design Framework
Exercise Types
| Type | Duration | Participants | Complexity | Purpose |
|---|
| Tabletop (discussion-based) | 2-4 hours | 8-15 senior stakeholders | Medium | Test decision-making, communication, and policy application |
| Functional exercise | 4-8 hours | 15-30 cross-functional team members | High | Test operational procedures and tool usage |
| Full-scale simulation | 1-3 days | Organization-wide (50+ participants) | Very high | Test end-to-end response including technical, legal, communications, and executive functions |
Recommended Exercise Cadence
| Exercise Type | Frequency | Audience |
|---|
| Tabletop | Semi-annually | Executive team, DPO, legal, communications, CISO |
| Functional | Annually | SOC, privacy team, IT operations, HR, customer service |
| Full-scale | Every 2 years | Organization-wide |
Scenario Design
Scenario 1: Ransomware Attack on Customer Database
Complexity: High
Duration: 3 hours
Primary objectives: Test Art. 33 72-hour notification decision-making, executive communication, and vendor coordination.
Background briefing (distributed 24 hours before exercise):
Stellar Payments Group processes payment transactions for 15,230 account holders across 18 EU member states and 12 US states. The production customer database is hosted on a PostgreSQL cluster in AWS eu-west-1. The DPO is Dr. Elena Vasquez. The CISO is Thomas Brenner. Mandiant is the retained incident response firm.
Inject timeline: