Case 392A76 · Famous breaches · L4 Advanced
Ransom note in billing
Practise as: Incident drill
Live alertYou are the CISO of a fuel pipeline operator. At 05:00 a control room worker finds a ransom note on an IT system; billing is encrypted and you cannot confirm whether OT networks are clean.
- 01 What happened?
- 02 What is the impact?
- 03 What do you do?
What a strong answer covers
Try it out loud first. Then check yourself:
- Safety first: decide whether to shut OT down proactively; you cannot prove the IT/OT boundary held
- Contain IT: isolate segments, disable remote access (VPN), reset privileged creds, engage IR and FBI/CISA
- Validate OT separately: check jump hosts, historians and firewall logs between IT and OT zones
- Business decisions: can you operate without billing and tracking? Plan manual restart and staged recovery
- Ransom decision involves legal, OFAC sanctions checks, insurer, and whether backups are intact
If the interviewer pushes back
- What evidence would you need before telling the CEO it is safe to restart the pipeline?
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.