Malware & Monsters

Large Group Session

Malware & Monsters

Something Has Gone Wrong

You Have Been Called In

Your organisation is under attack.

You do not have the full picture yet.

Your job is to get it.

Three Teams. One Incident.

How This Session Works

You have been divided into three specialist teams.

Each team receives different evidence.

No team has the complete picture. That is deliberate.

Your Incident Commander synthesizes across all three teams.

Your Teams

Three Lenses on the Same Incident

ALPHA Forensics

What happened at the system level – processes, files, artifacts, timelines.

BRAVO Network & Infrastructure

How it moved, what it touched, where it came from, where it is going.

CHARLIE Business Impact

What it means for operations, stakeholders, and decisions under pressure.

The Incident Commander

One Person. One Job.

The IC does not join a team.

The IC listens to all three teams, connects the threads, and makes decisions when the teams disagree.

The IC is not expected to know more than the teams.

The IC is expected to integrate what the teams know.

How a Round Works

The Same Pattern, Every Round

%%{init: {
  "theme": "base",
  "themeVariables": {
    "primaryColor": "#f8f9fa",
    "primaryTextColor": "#2c3e50",
    "primaryBorderColor": "#dee2e6",
    "lineColor": "#2c3e50",
    "fontFamily": "\"Source Sans Pro\", sans-serif",
    "fontSize": "15px"
  }
}}%%
flowchart LR
    E["Open your\nenvelope"] --> A["Analyse\nas a team"]
    A --> B["Team Lead\nbriefs the IC"]
    B --> I["IC synthesizes\nacross all teams"]
    I --> N["Next round\nenvelope"]

    classDef step fill:#f8f9fa,stroke:#dee2e6,color:#2c3e50,font-weight:bold
    classDef ic   fill:#2c3e50,stroke:#2c3e50,color:#ffffff,font-weight:bold

    class E,A,B,N step
    class I ic

%%{init: {
  "theme": "base",
  "themeVariables": {
    "primaryColor": "#f8f9fa",
    "primaryTextColor": "#2c3e50",
    "primaryBorderColor": "#dee2e6",
    "lineColor": "#2c3e50",
    "fontFamily": "\"Source Sans Pro\", sans-serif",
    "fontSize": "15px"
  }
}}%%
flowchart LR
    E["Open your\nenvelope"] --> A["Analyse\nas a team"]
    A --> B["Team Lead\nbriefs the IC"]
    B --> I["IC synthesizes\nacross all teams"]
    I --> N["Next round\nenvelope"]

    classDef step fill:#f8f9fa,stroke:#dee2e6,color:#2c3e50,font-weight:bold
    classDef ic   fill:#2c3e50,stroke:#2c3e50,color:#ffffff,font-weight:bold

    class E,A,B,N step
    class I ic

The Rules

Five Things That Make This Work

  1. Your evidence stays at your table. Do not show cards to other teams.

  2. When the timer ends, analysis ends. The cross-team briefing starts immediately.

  3. Team Leads brief the IC. Not the other way round. The IC listens first.

  4. The IC’s call is the call. Voice disagreement once, then commit.

  5. You will not have all the answers. That is fine. Neither does anyone else.

Dice (If Your IM Chooses)

Optional – Not Every Session Uses Them

From Round 3, the IC may roll a d20 when calling a response.

Helps your roll:

  • Teams correctly identified the threat: +2
  • All 3 teams fully briefed the IC: +1
  • All 3 teams agreed on a recommendation: roll 2 dice, take the higher

Hurts your roll:

  • Wrong response for what you are facing: -2
  • IC called before all teams had briefed: -1
  • Time pressure: -1 to -2

Your IM will confirm whether dice are in play before Round 3.

What You Are Trying to Achieve

The Objective

By the end of this session, your three teams and your IC should be able to answer three questions:

What is happening?

How did it get here?

What do we do about it?

Not all teams will answer all three questions. The IC is responsible for the final synthesis.

A Few Minutes Before You Start

Check In With Your Team

  • Who is your Team Lead?
  • Does everyone know which team they are on?
  • Has the IC been briefed?

You have 2 minutes.

The scenario begins when the envelopes are distributed.

Ready.