Scenarios library
Framework-aligned scenarios, ready to run.
13 scenarios across 9 frameworks, authored by people who've sat on the auditor side of the table. Pick one, try it in the demo, or bring it to your next exercise.
What's in a scenario
Not a Word doc. A session-ready, framework-tagged, decision-scored package.
- A tuned narrative
- A threat your buyer recognizes — county ransomware, FFIEC wire fraud, hospital EHR outage, SMB BEC — written in the language of that environment.
- Three constrained decisions
- Injects arrive with a time box and a bounded option set. Atlas captures what your team picks, time-stamps it, and scores it against your plan.
- Framework crosswalk
- Every scenario ships mapped to a primary framework plus every other one it touches. NIST CSF 2.0, HSEEP, FFIEC, HIPAA, PCI, CJIS, CMMC — crosswalks land in the AAR, not a separate spreadsheet.
- HSEEP-conformant AAR
- The artifact at the end is identical in structure to the one a $50K consulting engagement produces. PDF and DOCX. Forward it to your auditor, examiner, or carrier.
Showing 13 of 13 scenarios
- Data Exfiltration / Insider-AdjacentAdvanced
CUI Exfiltration on the Eve of CMMC L2 Assessment — DIB Scenario
A defense-industrial-base subcontractor finds CUI staged for exfil 11 days before its CMMC Level 2 C3PAO assessment. Walk DFARS 7012 72-hour reporting, NIST SP 800-171 R2 incident response, and the assessment-impact decision under live regulatory pressure.
- CMMC IR.L2-3.6.3
- NIST SP 800-171 R2 §3.6
- DFARS 252.204-7012
- DoD CIO 72-hour reporting
- RansomwareAdvanced
County Election Systems — Ransomware 14 Days Before the General
Your county BoE's ePollbook vendor reports a confirmed ransomware encryption event 14 days before the November general election. Walk the room through containment, COOP activation, and public communication under HSEEP.
- NIST 800-84
- FEMA HSEEP
- CISA CTEPs
- NIST CSF 2.0
- RansomwareAdvanced
Municipal Court Records — Ransomware Under CJIS
Encrypted court records two weeks before a high-profile trial calendar. Walk the response under CJIS v6.0 notification and chain-of-custody requirements.
- CJIS v6.0
- NIST CSF 2.0
- FEMA HSEEP
- Payments Fraud / ACH OriginationAdvanced
ACH Payments-Rail Fraud — The Originator Your Examiner Calls First
An originating depository financial institution discovers a batch of fraudulent ACH credits already settled to mule accounts at a downstream bank. Walk the NACHA Rule 2.5 reversal sequence, the FFIEC IR chain, and the FinCEN SAR clock under live financial pressure.
- FFIEC IT Handbook
- FFIEC CAT
- NACHA Operating Rules
- NYDFS 23 NYCRR §500
- Business Email Compromise / Wire FraudIntermediate
FFIEC Wire Fraud — The Examiner's Favorite FI Tabletop
A community bank's wire room authorizes a $2.3M outbound after a spoofed CEO thread. Walk the FFIEC IT Handbook IR sequence, hit the NYDFS 72-hour clock, and produce the evidence packet your examiner asks for.
- FFIEC IT Handbook
- FFIEC CAT
- NCUA ACET
- NYDFS 23 NYCRR §500
- Vendor OutageAdvanced
Hospital EHR Outage — HIPAA Contingency Plan Test
Your EHR vendor takes a regional outage during a Friday-night ED surge. Walk the HIPAA §164.308 contingency plan and document the test for your next OCR audit.
- HIPAA §164.308
- NIST CSF 2.0
- NIST 800-84
- RansomwareIntermediate
K-12 District — Student Information System Ransomware
A ransomware event encrypts the SIS one week before report cards. Run the response under FERPA, state DOE notification rules, and parent communication constraints.
- NIST CSF 2.0
- FEMA HSEEP
- CISA CTEPs
- RansomwareIntermediate
MSP Client Ransomware — Multi-Tenant Blast Radius
A ransomware event at one of your managed clients turns out to share a tenant boundary with three others. Walk the partner playbook for containment, customer comms, and cross-tenant notification.
- NIST CSF 2.0
- NIST 800-84
- SOC 2 CC7.4/CC7.5
- Supply-Chain Compromise / RMMAdvanced
RMM Supply-Chain Compromise — Your Vendor Is the Threat Actor
Your remote monitoring & management vendor publishes a CVE confirming an authenticated update mechanism was abused. Atlas walks your team through the cross-tenant blast radius, customer comms, and the compensating-control story your insurers and auditors want to hear.
- NIST CSF 2.0
- NIST 800-161r1
- SOC 2 CC7.4/CC7.5
- CIS Controls v8 IG2
- Data ExposureIntro
Donor PII Exposure — Non-Profit Cyber-Grant Reporting
A misconfigured S3 bucket exposes 11 years of donor records. Walk the response under non-profit cyber-grant reporting requirements and donor trust constraints.
- NIST CSF 2.0
- Business Email CompromiseIntro
Wire Fraud via BEC — The Auditor's Favorite SMB Scenario
A finance lead authorizes a $187K wire to a 'new vendor' after a CEO email thread that turns out to be a BEC. Run the response your SOC 2 / cyber-insurance underwriter wants documented.
- SOC 2 CC7.4/CC7.5
- HIPAA §164.308
- FFIEC
- PCI 12.10
Your file server starts encrypting on a Sunday night. No regulator is calling, but your cyber-insurance carrier wants documented evidence of a tested IR plan at renewal. Run the exercise that produces it.
- NIST CSF 2.0
- CIS Controls v8 IG1
- Cyber-insurance evidence
- OT / ICS IntrusionAdvanced
Municipal Water — OT Intrusion in the SCADA Network
An anomalous setpoint change is detected in the water-treatment SCADA. Walk the IT/OT coordination, public-health threshold decisions, and EPA notification under the Water Sector annex.
- NIST CSF 2.0
- FEMA HSEEP
- CISA CTEPs
Don't see what you need?
Request a custom scenario.
We build custom scenarios for design partners, Financial Institutions, and enterprise tiers. Tell us the threat model, the framework you're graded on, and the environment — we'll ship a session-ready scenario with crosswalks and sample AAR inside two weeks.
Custom scenarios include a free revision round and are yours to re-run year over year.
Try any scenario in the 90-second demo.
Pick a default for your segment, or swap to one of the 10+ scenarios in the library.