Open cardosec

Case 392A76 · Famous breaches · L4 Advanced

Ransom note in billing

Practise as: Incident drill

Live alertYou are the CISO of a fuel pipeline operator. At 05:00 a control room worker finds a ransom note on an IT system; billing is encrypted and you cannot confirm whether OT networks are clean.

  1. 01 What happened?
  2. 02 What is the impact?
  3. 03 What do you do?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Safety first: decide whether to shut OT down proactively; you cannot prove the IT/OT boundary held
  2. Contain IT: isolate segments, disable remote access (VPN), reset privileged creds, engage IR and FBI/CISA
  3. Validate OT separately: check jump hosts, historians and firewall logs between IT and OT zones
  4. Business decisions: can you operate without billing and tracking? Plan manual restart and staged recovery
  5. Ransom decision involves legal, OFAC sanctions checks, insurer, and whether backups are intact

If the interviewer pushes back

  • What evidence would you need before telling the CEO it is safe to restart the pipeline?

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.