Tabletop Exercise CISO-PRACTSIE

For facilitator materials, please refer to: Workshop Facilitator Materials

Phase 1: Shutdown of the Main System by Ransomware

JNSA Architects, Inc. develops and operates PC online games. 01. Company Overview: - Company name: JNSA Architects, Inc. - Annual revenue: JPY 3.4 billion - Employees: 170 - Main business: PC online game development and operation - Main system: GanGan system: a visually enhanced role-playing game 2M users, 100K paying, JPY 2B revenue last year, AWS Japan region - Corporate culture: No prior incident response experience. Tends to view security incidents optimistically. Cultural divide between founding members and those with a banking background. 02. Incident: - The GanGan system, the company's main source of revenue, has been shut down by ransomware. - Based on last year's figures, a GanGan system outage represents an opportunity loss of JPY 5.5 million/day. - Situation: - The main game service, the GanGan system, has gone down, and what appears to be a ransomware extortion message is being displayed. - Summary of the extortion message: - The system is under the control of the hacker group "Condor" - Data on the system's storage has been encrypted by "Condor" - To decrypt it, 1 BTC (approx. JPY 10 million) must be paid within 3 days via Bitcoin - Background: - Yesterday, an employee working from home was infected with ransomware. - Since there was no intranet connection via VPN or similar, and the main files were stored on online storage, it was decided to handle this by wiping the PC rather than paying the ransom. 03. Reports from each department - Report from the GanGan team: - In-game points held by users total approximately JPY 1.5 billion. - Report from the Operations team: - The GanGan system has been compromised and the data encrypted; operations cannot continue. - A backup from one week ago is available, but a restore has never been performed. - Based on the data volume, the restore is estimated to take about 5 days. - A snapshot (backup) of the program from one month ago is available. - Report from the Development team: - The source code is intact, but there is no backup of the dataset (characters, images, etc.). - Rebuilding the system from scratch would take 3-4 months, delaying the release of the new game by 6 months. - Report from the Support desk: - Many complaints are coming in and the phone lines are overwhelmed. - Email responses also cannot keep up; please do something. - Numerous inquiries about large-scale leaks of personal information and credit card data. - Report from PR: - Inquiries are flooding in. Disclosure to users and media is needed. - Information from CSIRT: - This group has a reputation for restoring systems if the ransom is paid.
Mission: - Respond to each question from the CISO's perspective regarding the ransomware damage. - When responding, evaluate impact/severity based on the "Business Risk Evaluation Criteria," considering the perspectives of customers, operations, and finance. - Note: there is no single correct answer for the Status Report.

Incident Detail Report: Total Shutdown of the GanGan System Due to Ransomware

0. Overview


0.1 Requests to Management


Ransom payment:

1. GanGan System Overview



2. Incident Overview

  • Detected: 7/23 12:17


3. Impact Assessment on Information Assets

Credit card information, etc.: Required
Severity
Likelihood

Customer confidential information: Required
Severity
Likelihood

Company confidential information: Required
Severity
Likelihood

Authentication credentials: Required
Severity
Likelihood

4. Anticipated Secondary Damage


5. Response Structure (RACI Chart)

Management:
Business division executive:
CISO:
CSIRT:
IT/Systems:
PR:
Legal/IP:
HR:
General staff:

6. External Response


Outside counsel:
Forensics specialist firm:
Security (incident response firm):
Insurance company:
Payment gateway provider:
Certified public accountant:

7. External Notification and Reporting Plan

[A: Immediate / B: After facts are confirmed / C: After finalized / D: Not required / E: On hold]

Mandatory contacts

Personal Information Protection Commission:
Regulatory authority (MIC / METI):
Police (cybercrime investigation):
Financial Services Agency:
GDPR / CCPA:
Labor Bureau:
Center for Security Trade Control:

Business partners & users

Payment gateway provider:
Advertising client:
Main bank:
Users (affected parties):

Media & PR

Company website / company social media:
General media:

8. Financial Damage and Cost Projections



9. Compliance and Social Impact




10. User-Facing Countermeasures (Workarounds)



11. Additional Notes


Select Content to Load
    Be sure to click "Register" before clicking the consult button. ✓ Registered
    * Input will be reflected on members' screens ✓ Updated
    Evaluation Results
    (History — Phase / )
    Consulting...
    The AI is generating the evaluation. Please wait.