calmdrill

A Sandpiper Technology product

Twelve incident drill scenarios

Reliability, security and continuity drills, written by people who have held the pager. Each one is a complete exercise file. This page shows what your team sees at the start. The rest stays with the Game Master until the debrief.

Five reliability, two continuity and five security scenarios.

Scenario index

Every scenario runs in all three modes: Team, Solo on-call and Leadership. Difficulty is out of four. Choose a title to go to its record.

Scenario index
CodeScenarioTypeDifficultyRuns forBest for
CD-⁠01The 02:14 CertificateReliabilityDifficulty 2 of 435–50 minFirst drill for any team. On-call practice. Anyone who has ever said ‘cert-manager handles that’.
CD-⁠02Friday FlagReliabilityDifficulty 3 of 440–55 minTeams who ship behind feature flags, believe that makes every change reversible, and have a launch date on the wall.
CD-⁠03Region GreyReliability, continuityDifficulty 4 of 450–70 minTeams with a DR region they’ve never really failed over to, and a BCP that says ‘RPO 1 hour’ without saying how.
CD-⁠04The Restore That Wasn’tContinuityDifficulty 3 of 445–60 minTeams who say ‘we have backups’ but whose last restore test lives in a ticket rather than a calendar.
CD-⁠05Somebody Else’s OutageReliabilityDifficulty 2 of 435–50 minAny team with a synchronous third-party call in a critical path, or that has said ‘it’s their outage, nothing we can do’.
CD-⁠06The Quiet CorruptionReliabilityDifficulty 3 of 445–60 minTeams who own money-shaped data and whose dashboards stay green while the numbers are wrong.
CD-⁠07Keys in the WildSecurityDifficulty 3 of 445–60 minAWS teams with an IAM user older than their CTO, and anyone who believes ‘AWS quarantined the key, so we’re fine’.
CD-⁠08The Friendly AdminSecurityDifficulty 4 of 450–75 minSecurity, IT and leadership together, at any company that sends invoices or is paid by bank transfer.
CD-⁠09Poisoned PackageSecurityDifficulty 4 of 450–75 minFront-end, platform and security engineers together, especially teams who think ‘we use a lockfile, so we’re safe’.
CD-⁠10The Open DoorSecurityDifficulty 3 of 450–75 minExec teams, security leads and counsel who must make a breach-notification call on half the facts, best run in Leadership mode.
CD-⁠11Nobody HomeContinuityDifficulty 3 of 445–60 minTeams that put everything behind SSO, and the platform and security leads who own break-glass: the credentials are in the safe, right?
CD-⁠12The Helpful AgentSecurityDifficulty 4 of 445–60 minAny organisation that has given an AI assistant tools: security, platform and support leads, and the exec who signed off ‘v2’.

What a scenario file holds

Every file has the same nine sections, in the same order. Your team hears the first. The Game Master works from the other eight and keeps them back until the debrief, as a human exercise controller would.

Each record below prints the first section in full and counts the rest.

The sections of a scenario file
SectionWho reads itWhat it does
Player briefingYour teamSets the scene and delivers the first message. Read out or pasted as it stands.
Hidden truthGame MasterWhat is really happening, and when, plus the tempting but risky moves it lets you make, with their consequences. Fixed, so every answer the Game Master gives agrees with it.
SignalsGame MasterWhat logs, dashboards and commands show when players look. The right place shows the real clue. The wrong place shows normal-looking data.
Inject timelineGame MasterMessages from colleagues, customers and leadership, each with a simulated time and a condition.
Hint ladderGame MasterGraded hints, one rung at a time, given only when the team asks. Each one is logged and the report counts them.
Rubric indicatorsGame MasterWhat good looks like in this scenario for each of the six scored dimensions.
Debrief questionsGame MasterAsked after the reveal, to turn what happened into actions.
Evidence mappingGame MasterCareful wording for the report’s evidence section, which never claims compliance.
Adapting to your stackGame MasterHow to re-skin the drill to your own services and tools while keeping the same failure and objectives.

CD-⁠01The 02:14 Certificate

TypeReliability
Difficulty 2 of 4
Runs for35–50 minutes
ModesTeam, Solo on-call, Leadership

What it tests

  1. Recognise and declare a partial, growing outage quickly
  2. Separate a tempting red herring (a recent deploy) from the evidence
  3. Find a certificate chain failure in an estate that “auto-renews everything”
  4. Handle a break-glass access problem when the one person who knows is unavailable
  5. Keep customers and Enterprise accounts informed while impact grows

Player briefing

It’s 02:19 UTC on a Tuesday at Harbourline. You’re on call.

Your phone goes off:

FromPagerDuty
ViaPage
Message

[TRIGGERED] auth-svc: login_success_rate < 80% for 5m (currently 71%)

You open Datadog on your laptop. The login success rate was a steady 99.6% all evening. At about 02:14 it started dropping. There are no other pages yet. Slack is quiet: most of the company is asleep in London and Lisbon.

What do you do first?

Team mode: whoever holds the pager is the first responder. Everyone else is “asleep” until paged. The Game Master will tell you when they pick up.

Held by the controllerCounted from the scenario file. Players never see it, and none of it is on this page.
Hidden truthOne, fixed, revealed at the debrief
Injects13, timed or conditional, from T+00:00 to T+01:15
Hint ladder4 steps, given on request
Scored on6 dimensions, with indicators for this scenario
Debrief questions6
Your own stackNotes for re-skinning it to your services
Best for
First drill for any team. On-call practice. Anyone who has ever said ‘cert-manager handles that’.
Included in
The free Starter pack, and every paid edition

Designed to support evidence for

SOC 2
A1.2, A1.3, CC7.4, CC7.5
ISO 27001
A.5.24, A.5.26, A.5.27, A.5.30
NIST CSF 2.0
Respond (RS), Recover (RC)
Your own process
Incident process

Note: Your auditor decides whether an exercise meets a particular requirement.

Download the starter pack, freeRun the 5-minute version

Back to the index

CD-⁠02Friday Flag

TypeReliability
Difficulty 3 of 4
Runs for40–55 minutes
ModesTeam, Solo on-call, Leadership

What it tests

  1. Diagnose creeping database contention and trace it to its real source, not the most recent visible change
  2. Stop a background job properly (Kubernetes Job, GitOps controller and the query already running in the database)
  3. Assess honestly whether a rollback is safe before doing it, and recognise a one-way door
  4. Hold the line on safety against launch and marketing pressure, and give leadership an honest answer
  5. Make a sensible weekend plan instead of “fixing forward” at 17:30 on a Friday

Player briefing

It’s 15:20 UTC (16:20 in London) on Friday 9 October at Harbourline. You’re on call. Half the company is mentally on the weekend already.

Your phone goes off:

FromPagerDuty
ViaPage
Message

[TRIGGERED] invoice-svc: 5xx rate > 2% for 10m (currently 3.4%)

In Datadog, invoice-svc p99 latency has been climbing gently all afternoon: about 350 ms at lunchtime, 5.6 s now. The errors are mostly timeouts. Nothing is fully down; people are saving and sending invoices, just slowly, and some attempts fail.

A few things happened today, and they’re all in Slack:

  • 13:58 UTC: invoice-svc v4.18.0 was synced by Argo CD. It’s the Forecast 2 release, with a database migration, all behind the forecast-2 feature flag.
  • 14:30 UTC: the forecast-2 flag was rolled out to 10% of organisations in LaunchDarkly, as a “soft launch” for Monday’s analyst briefing.
  • The public launch of Forecast 2 is Thursday 29 October, three weeks away. Marketing has been counting down for a month.

What do you do first?

Team mode: it’s a working afternoon, so everyone is reachable on Slack, though some people are about to log off. The Game Master plays anyone not in the room.

Held by the controllerCounted from the scenario file. Players never see it, and none of it is on this page.
Hidden truthOne, fixed, revealed at the debrief
Injects13, timed or conditional, from T+00:00 to T+00:50
Hint ladder4 steps, given on request
Scored on6 dimensions, with indicators for this scenario
Debrief questions6
Your own stackNotes for re-skinning it to your services
Best for
Teams who ship behind feature flags, believe that makes every change reversible, and have a launch date on the wall.
Included in
The Kit, Pro and Practitioner editions

Designed to support evidence for

SOC 2
CC8.1, CC7.4, CC7.5, A1.1
ISO 27001
A.8.32, A.5.24, A.5.26, A.5.27, A.8.6
NIST CSF 2.0
Respond (RS), Recover (RC)
Your own process
Incident and change process

Note: Your auditor decides whether an exercise meets a particular requirement.

Back to the index

CD-⁠03Region Grey

TypeReliability, continuity
Difficulty 4 of 4
Runs for50–70 minutes
ModesTeam, Solo on-call, Leadership

What it tests

  1. Recognise a grey failure (partial, intermittent, ‘everything is green’) and gather evidence to localise it
  2. Decide between evacuating an Availability Zone and failing over to another region, with RPO and RTO made explicit
  3. Execute a zonal evacuation safely: database failover, capacity, disruption budgets and AZ-bound storage
  4. Resist pressure to act on the most dramatic option, and on unverified signals of spread
  5. Keep customers, Enterprise accounts and leadership informed while the cloud provider is still silent

Player briefing

It’s 10:40 UTC (11:40 in London) on Wednesday 21 October at Harbourline. A normal, busy weekday morning. You’re on call.

Your phone goes off:

FromPagerDuty
ViaPage
Message

[TRIGGERED] api-gateway: p99 latency > 2s for 10m (currently 3.9s)

In Datadog, api-gateway p99 latency has been drifting upwards since about 10:20. The median is barely changed (190 ms against a usual 140 ms). The 5xx rate is 2.9%, up from the usual 0.1%. There have been no deploys since yesterday afternoon. Every dashboard tile is amber rather than red. The AWS Health Dashboard says “No recent issues”.

Harbourline runs in eu-west-2 (London) across three Availability Zones, with a warm standby in eu-west-1 (Ireland).

What do you do first?

Team mode: it’s working hours, so everyone is reachable. The Game Master plays anyone not in the room.

Held by the controllerCounted from the scenario file. Players never see it, and none of it is on this page.
Hidden truthOne, fixed, revealed at the debrief
Injects15, timed or conditional, from T+00:00 to T+02:10
Hint ladder4 steps, given on request
Scored on6 dimensions, with indicators for this scenario
Debrief questions6
Your own stackNotes for re-skinning it to your services
Best for
Teams with a DR region they’ve never really failed over to, and a BCP that says ‘RPO 1 hour’ without saying how.
Included in
The Kit, Pro and Practitioner editions

Designed to support evidence for

SOC 2
A1.2, A1.3, CC7.4, CC7.5, CC9.1
ISO 27001
A.5.29, A.5.30, A.8.14, A.5.24, A.5.26
NIST CSF 2.0
Respond (RS), Recover (RC)
DORA
Art. 11–12 (if in scope)
Your own process
BCP and incident process

Note: Your auditor decides whether an exercise meets a particular requirement.

Back to the index

CD-⁠04The Restore That Wasn’t

TypeContinuity
Difficulty 3 of 4
Runs for45–60 minutes
ModesTeam, Solo on-call, Leadership

What it tests

  1. Recognise silent data loss and establish its exact scope and start time from evidence
  2. Contain further divergence while recovery runs
  3. Know what point-in-time recovery really gives you (a new cluster, not an undo button) and plan around it
  4. Choose between swapping, restore-and-merge, application-level repair and read-only mode, with RPO and RTO made explicit
  5. Verify data integrity before declaring recovery, and handle processor obligations to affected customers

Player briefing

It’s 09:41 UTC on Thursday 12 November at Harbourline. You’re on call.

Two things arrive almost together:

FromPagerDuty
ViaPage
Message

[TRIGGERED] invoice-svc: InvoiceIntegrityError > 50/min (currently 214/min)

FromPriya Nair (Head of Support)
ViaSlack
Channel#support
Message

Lisbon team has 19 tickets since half nine, all EU customers, all saying the same thing: lines have disappeared from their invoices. Some invoices are completely empty but still show the old total. What's going on?

In Sentry, the error is new today: InvoiceIntegrityError: sum(line_items) 0.00 != invoice.total 1,284.00 (invoice 38,114,207). Viewing a PDF, sending, or editing an affected invoice fails. The app is otherwise up and fast. invoice-svc v4.21.2 (a PDF font rendering change) was deployed at 08:50.

What do you do first?

Team mode: it’s working hours, so everyone is reachable. The Game Master plays anyone not in the room.

Held by the controllerCounted from the scenario file. Players never see it, and none of it is on this page.
Hidden truthOne, fixed, revealed at the debrief
Injects14, timed or conditional, from T+00:00 to T+01:20
Hint ladder4 steps, given on request
Scored on6 dimensions, with indicators for this scenario
Debrief questions6
Your own stackNotes for re-skinning it to your services
Best for
Teams who say ‘we have backups’ but whose last restore test lives in a ticket rather than a calendar.
Included in
The Kit, Pro and Practitioner editions

Designed to support evidence for

SOC 2
A1.2, A1.3, CC7.4, CC7.5, CC6.3
ISO 27001
A.8.13, A.8.31, A.8.2, A.5.24, A.5.26, A.5.34
NIST CSF 2.0
Respond (RS), Recover (RC)
UK GDPR / EU GDPR
Art. 28 & 33 (processor duties, decision support only)
Your own process
BCP

Note: Your auditor decides whether an exercise meets a particular requirement.

Back to the index

CD-⁠05Somebody Else’s Outage

TypeReliability
Difficulty 2 of 4
Runs for35–50 minutes
ModesTeam, Solo on-call, Leadership

What it tests

  1. Recognise when a supplier’s partial outage has become your own outage, and take ownership of it
  2. Find and cut the coupling (synchronous calls, naive retries, shared thread pools) instead of waiting
  3. Understand retry storms and why a system can stay broken after the trigger goes away
  4. Quantify and clean up the side effects (duplicate emails, duplicate invoices, double payments)
  5. Communicate honestly about fault, without blaming a supplier publicly

Player briefing

It’s 09:47 UTC on Monday 2 November at Harbourline: the first working Monday of the month, traditionally Harbourline’s busiest invoicing morning. You’re on call.

Your phone goes off:

FromPagerDuty
ViaPage
Message

[TRIGGERED] api-gateway: 5xx rate > 5% for 3m (currently 18.2%)

In Datadog, api-gateway was fine at 09:30. From about 09:40 the 5xx rate climbed steeply. They’re almost all 504 Gateway Timeout, almost all from routes served by invoice-svc. Logins work. Payments are fine. But opening the invoice list, editing and sending invoices are slow or failing.

In #deploys, the only change this morning is notify-svc v2.9.1 at 09:35: new wording for payment-reminder emails.

What do you do first?

Team mode: it’s working hours, so everyone is reachable. The Game Master plays anyone not in the room.

Held by the controllerCounted from the scenario file. Players never see it, and none of it is on this page.
Hidden truthOne, fixed, revealed at the debrief
Injects12, timed or conditional, from T+00:00 to T+00:58
Hint ladder4 steps, given on request
Scored on6 dimensions, with indicators for this scenario
Debrief questions6
Your own stackNotes for re-skinning it to your services
Best for
Any team with a synchronous third-party call in a critical path, or that has said ‘it’s their outage, nothing we can do’.
Included in
The Kit, Pro and Practitioner editions

Designed to support evidence for

SOC 2
CC9.2, CC7.4, CC7.5, A1.1
ISO 27001
A.5.19, A.5.22, A.5.24, A.5.26, A.5.27, A.8.6
NIST CSF 2.0
Supply chain risk (GV.SC), Respond (RS), Recover (RC)
Your own process
Incident process

Note: Your auditor decides whether an exercise meets a particular requirement.

Back to the index

CD-⁠06The Quiet Corruption

TypeReliability
Difficulty 3 of 4
Runs for45–60 minutes
ModesTeam, Solo on-call, Leadership

What it tests

  1. Recognise a data-integrity incident that fires no alerts, and declare it as an incident rather than a support ticket
  2. Scope a slow-burn defect precisely: which invoices, which customers, which currencies, how much money, paid or unpaid
  3. Stop the bleeding in the right order, including work that is already queued
  4. Verify with a method that does not share the bug
  5. Correct legal documents properly (credit notes, not silent edits) and decide who to tell, and how

Player briefing

It’s 10:05 UTC on Friday 23 October (11:05 in London and Lisbon). Nothing is on fire. Every dashboard is green.

Priya Nair (Head of Support) drops this into #eng-invoicing and tags whoever is on call:

FromPriya
ViaSlack
Message

Escalating this one because it doesn't smell like user error. Accountant for an Irish customer (Kinsale Craft Distillers). Pasting her email:

"Dear Harbourline Support, I act for Kinsale Craft Distillers. Invoice HL-KCD-2026-0587 to their Cork wholesaler (billed in sterling, as it belongs to a UK group) shows net £10,000.00 and VAT at 23% of £1,729.28. 23% of £10,000 is £2,300.00. The euro VAT figure printed underneath (€1,994.33) is also wrong, and the rate shown, '1 GBP = 0.8671 EUR', is upside down. Three of my client's invoices this month are affected. Their Sep–Oct VAT return is due on 23 November and I need to know whether I can rely on any figure your system produces. Please treat this as urgent. Aoife Brennan ACA, Brennan & Lowry, Cork."

Is this a one-off? What do I tell her?

Datadog shows no errors, no latency change, normal invoice volumes. No pages have fired this week.

What do you do first?

Team mode: the on-call engineer and Priya are active. Everyone else is at their desks and reachable on Slack within a few minutes: it’s a normal working Friday.

Held by the controllerCounted from the scenario file. Players never see it, and none of it is on this page.
Hidden truthOne, fixed, revealed at the debrief
Injects15, timed or conditional, from T+00:00 to T+01:10
Hint ladder4 steps, given on request
Scored on6 dimensions, with indicators for this scenario
Debrief questions6
Your own stackNotes for re-skinning it to your services
Best for
Teams who own money-shaped data and whose dashboards stay green while the numbers are wrong.
Included in
The Kit, Pro and Practitioner editions

Designed to support evidence for

SOC 2
PI1.3, PI1.4, PI1.5, CC7.4, CC7.5, CC8.1
ISO 27001
A.5.24, A.5.26, A.5.27, A.8.29, A.8.32
NIST CSF 2.0
Respond (RS), Recover (RC)
Your own process
Incident process

Note: Your auditor decides whether an exercise meets a particular requirement.

Back to the index

CD-⁠07Keys in the Wild

TypeSecurity
Difficulty 3 of 4
Runs for45–60 minutes
ModesTeam, Solo on-call, Leadership

What it tests

  1. Contain a leaked long-lived AWS access key in the right order, including credentials and footholds created from it
  2. Find attacker persistence beyond the obvious (second keys, new users, scheduled functions, session tokens)
  3. Preserve evidence while containing, and use CloudTrail to establish what was actually accessed
  4. Make a personal-data breach assessment under uncertainty, with counsel, and record when the organisation became aware
  5. Handle the contractor, the cost and the legitimate workload that depended on the key

Player briefing

It’s 13:20 UTC on Wednesday 14 October. You’re the security on-call this week.

Two things land within three minutes of each other.

FromAWS
ViaEmail
Toaws-security@harbourline.io
Time (UTC)13:14
Message

Action required: your AWS access key AKIA…QXWD for IAM user svc-exports-sync in account 418273659021 was found publicly available at https://github.com/mduarte-dev/pdf-invoice-renderer/blob/9c1e4b7/test/.env.integration. We have attached the AWSCompromisedKeyQuarantineV3 policy to the user. Please rotate the key and review your account for unauthorised activity.

FromPagerDuty
ViaPage
Time (UTC)13:17
Message

[TRIGGERED] GuardDuty HIGH · Persistence:IAMUser/AnomalousBehavior · account 418273659021 (harbourline-prod) · eu-west-2

harbourline/pdf-invoice-renderer is Harbourline’s small open-source PDF library. mduarte-dev is not a Harbourline account.

What do you do first?

Team mode: the security on-call holds the pager. Platform (Tom Becker, Leo Park) and the CTO are in the office and reachable in a few minutes. Anyone else: ask.

Held by the controllerCounted from the scenario file. Players never see it, and none of it is on this page.
Hidden truthOne, fixed, revealed at the debrief
Injects16, timed or conditional, from T+00:00 to T+01:05
Hint ladder4 steps, given on request
Scored on6 dimensions, with indicators for this scenario
Debrief questions6
Your own stackNotes for re-skinning it to your services
Best for
AWS teams with an IAM user older than their CTO, and anyone who believes ‘AWS quarantined the key, so we’re fine’.
Included in
The Kit, Pro and Practitioner editions

Designed to support evidence for

SOC 2
CC6.1, CC6.2, CC6.3, CC7.2, CC7.3, CC7.4, CC7.5
ISO 27001
A.5.17, A.5.19, A.5.24–A.5.28, A.8.15, A.8.16
UK GDPR
Art. 33–34 (process)
NIST CSF 2.0
Detect (DE), Respond (RS), Recover (RC)
Your own process
Incident process

Note: Your auditor decides whether an exercise meets a particular requirement.

Back to the index

CD-⁠08The Friendly Admin

TypeSecurity
Difficulty 4 of 4
Runs for50–75 minutes
ModesTeam, Solo on-call, Leadership

What it tests

  1. Contain a compromised privileged identity completely: sessions, factors, OAuth grants, delegated access, mail rules and any admin footholds
  2. Recognise that locking the user out is not the same as locking the attacker out
  3. Run payment-diversion fraud response with finance and customers while the facts are still moving
  4. Warn customers through channels the attacker doesn’t control, and decide how widely to warn
  5. Handle the personal-data angle with counsel, and fix the help-desk and admin-rights causes without blame

Player briefing

It’s 09:20 UTC on Tuesday 13 October (10:20 in London). Normal working morning; Forecast 2 launch prep is everywhere.

Priya Nair posts in #security:

FromPriya
ViaSlack
Message

Need someone from security now please. Jonas (account manager for Fenwick & Rowe Solicitors, Enterprise) just had their finance manager on the phone. They got an email from accounts@harbourline.io at 07:58, replying in their real renewal thread, saying we've changed banks, with a PDF letter on our letterhead and new account details. She rang to double-check before paying the £64,800 renewal. Jonas says we haven't changed banks. Screenshot attached. The email is genuinely from our domain; their IT says it passed all the checks.

The screenshot shows a reply to an October thread about invoice INV-HL-2026-3381, signed “Harbourline Accounts Receivable”, attaching Harbourline – Change of Bank Details – Oct 2026.pdf.

What do you do first?

Team mode: players are Harbourline staff in the office or remote. Callum Reid (IT and workplace) is at a dental appointment until about 10:00 UTC. Everyone else: ask.

Held by the controllerCounted from the scenario file. Players never see it, and none of it is on this page.
Hidden truthOne, fixed, revealed at the debrief
Injects14, timed or conditional, from T+00:00 to T+01:10
Hint ladder4 steps, given on request
Scored on6 dimensions, with indicators for this scenario
Debrief questions6
Your own stackNotes for re-skinning it to your services
Best for
Security, IT and leadership together, at any company that sends invoices or is paid by bank transfer.
Included in
The Kit, Pro and Practitioner editions

Designed to support evidence for

SOC 2
CC2.3, CC6.1, CC6.2, CC6.3, CC7.3, CC7.4, CC7.5
ISO 27001
A.5.15–A.5.18, A.5.24–A.5.27, A.6.3, A.8.2
UK GDPR
Art. 33–34 (process)
NIST CSF 2.0
Identity and access (PR.AA), Respond (RS), Recover (RC)
Your own process
Incident process

Note: Your auditor decides whether an exercise meets a particular requirement.

Back to the index

CD-⁠09Poisoned Package

TypeSecurity
Difficulty 4 of 4
Runs for50–75 minutes
ModesTeam, Solo on-call, Leadership

What it tests

  1. Scope a supply-chain compromise precisely: which builds ran the bad version, when, and with which secrets in reach
  2. Rotate secrets in the right order, without re-exposing new secrets to a still-poisoned pipeline
  3. Decide with evidence whether production artefacts are tainted, and rebuild from a known-good state
  4. Check what the attacker actually did with each stolen credential, especially edge (DNS/WAF) changes
  5. Carry customer, legal and leadership obligations when the second-order impact lands on customers

Player briefing

It’s 09:05 UTC on Tuesday 20 October. Normal working morning.

Ines Carvalho (Security Lead) posts in #security:

FromInes
ViaSlack
Message

Heads-up, possibly nothing. A GitHub advisory went out at 08:10: css-var-hoist 2.3.4 is malicious. It has a postinstall script that steals environment variables, and npm has pulled the version. It's a transitive dependency of web-app via vite-plugin-brand-icons. I just checked main: our lockfile has 2.3.4. Also, #alerts-ci has three "new external destination from ci namespace" warnings from last night and this morning that nobody looked at. Who's around?

web-app builds run on Harbourline’s self-hosted GitHub Actions runners (ephemeral pods on EKS). Production web-app was last deployed at 07:58 this morning.

What do you do first?

Team mode: everyone is at work. Tom Becker (Platform) and Leo Park (SRE) are reachable immediately; Marcus Hale (CTO) is in a meeting until 09:30. Rachel Moss (counsel) is on a flight from New York.

Held by the controllerCounted from the scenario file. Players never see it, and none of it is on this page.
Hidden truthOne, fixed, revealed at the debrief
Injects13, timed or conditional, from T+00:00 to T+01:10
Hint ladder4 steps, given on request
Scored on6 dimensions, with indicators for this scenario
Debrief questions6
Your own stackNotes for re-skinning it to your services
Best for
Front-end, platform and security engineers together, especially teams who think ‘we use a lockfile, so we’re safe’.
Included in
The Kit, Pro and Practitioner editions

Designed to support evidence for

SOC 2
CC6.1, CC7.1, CC7.3, CC7.4, CC7.5, CC8.1, CC9.2
ISO 27001
A.5.19, A.5.21, A.5.24–A.5.28, A.8.8, A.8.25, A.8.32
NIST SP 800-218 (SSDF)
PS, PW, RV
NIST CSF 2.0
Supply chain risk (GV.SC), Respond (RS), Recover (RC)
Your own process
Incident process

Note: Your auditor decides whether an exercise meets a particular requirement.

Back to the index

CD-⁠10The Open Door

TypeSecurity
Difficulty 3 of 4
Runs for50–75 minutes
ModesTeam, Solo on-call, Leadership

What it tests

  1. Contain an exposure without destroying the evidence needed to scope it
  2. Separate “was exposed” from “was actually accessed”, using access logs, and state how confident you are
  3. Make and record a notification decision with counsel, including the processor’s duty to tell controller customers without undue delay
  4. Treat a good-faith security researcher as an ally, not a threat
  5. Give the press an honest statement that matches what customers are being told
  6. Keep CEO-level decisions owned, timed and written down across several days

Player briefing

It’s Wednesday 7 October 2026, 15:10 UTC (16:10 in London). Forecast 2 launches in three weeks.

Ines Carvalho (Security Lead) has pulled you into a call and pasted this into #security. It arrived at security@harbourline.io six minutes ago:

FromKit Laurence (independent security researcher)
ViaEmail
SubjectCustomer invoices publicly accessible via share.harbourline.io
Message

Hi, while looking at something unrelated I found that https://share.harbourline.io/sitemap.xml lists what look like tens of thousands of invoice share links. The ones I opened (38, sorry, I stopped once I was sure) show a customer's invoice with no login: names, addresses, amounts and, on several, the payee's sort code and account number. The links seem to last 30 days and I think the tokens might be guessable. Three example URLs below. I haven't shared this with anyone. I'd like to publish a write-up once it's fixed. Is 30 days reasonable? Please confirm you've received this.
— Kit

Ines says: “I haven’t clicked anything yet. Harbourline has a security.txt pointing at this inbox, but no bug bounty and no safe-harbour wording. Where do we start?”

Leadership mode: you are the exec team. Ines and Marcus will do or delegate the technical work you ask for and report back. Team mode: you are the responders; leadership will come to you.

Held by the controllerCounted from the scenario file. Players never see it, and none of it is on this page.
Hidden truthOne, fixed, revealed at the debrief
Injects18, timed or conditional, from T+00:00 to T+48:10
Hint ladder4 steps, given on request
Scored on6 dimensions, with indicators for this scenario
Debrief questions7
Your own stackNotes for re-skinning it to your services
Best for
Exec teams, security leads and counsel who must make a breach-notification call on half the facts, best run in Leadership mode.
Included in
The Kit, Pro and Practitioner editions

Designed to support evidence for

SOC 2
CC7.3, CC7.4, CC7.5, CC2.3 (P6.6 if Privacy is in scope)
ISO 27001
A.5.24–A.5.28, A.5.34
UK GDPR
Art. 28, 33, 34 breach-assessment process
NIST CSF 2.0
Respond (RS), Recover (RC)
Your own process
Incident process

Note: Your auditor decides whether an exercise meets a particular requirement.

Back to the index

CD-⁠11Nobody Home

TypeContinuity
Difficulty 3 of 4
Runs for45–60 minutes
ModesTeam, Solo on-call, Leadership

What it tests

  1. Keep running an ordinary SEV2 when your identity provider is down and most tools won’t let you in
  2. Work out quickly who can still reach what, and for how long
  3. Refuse shortcuts that trade a short-term fix for a long-term security problem (shared logins, forgotten admin keys)
  4. Establish out-of-band communication and decision authority without the wiki, the org chart or half of Slack
  5. Test whether the break-glass arrangements actually work, and who is allowed to use them

Player briefing

It’s Monday 9 November 2026, 14:20 UTC. You’re on call.

Your phone goes off:

FromPagerDuty
ViaPage
Message

[TRIGGERED] auth-svc: token_refresh_error_rate > 10% for 15m (currently 57%)

You acknowledge it in the PagerDuty app and open Datadog on your laptop. Instead of the dashboard you get Harbourline’s Okta sign-in page. You enter your details, approve the push and get “Something went wrong. Please try again later.” The second attempt spins for thirty seconds and gives the same error.

Slack still works on your laptop. #support has two new messages about customers “getting kicked out”.

What do you do first?

Team mode: whoever holds the pager is the first responder. Everyone else can be reached only through channels the Game Master confirms actually work for them.

Held by the controllerCounted from the scenario file. Players never see it, and none of it is on this page.
Hidden truthOne, fixed, revealed at the debrief
Injects20, timed or conditional, from T+00:00 to T+02:20
Hint ladder4 steps, given on request
Scored on6 dimensions, with indicators for this scenario
Debrief questions7
Your own stackNotes for re-skinning it to your services
Best for
Teams that put everything behind SSO, and the platform and security leads who own break-glass: the credentials are in the safe, right?
Included in
The Kit, Pro and Practitioner editions

Designed to support evidence for

SOC 2
CC7.4, CC7.5, CC9.1, A1.2, A1.3, CC6.1
ISO 27001
A.5.24, A.5.26, A.5.29, A.5.30, A.8.2
NIST CSF 2.0
Respond (RS), Recover (RC)
DORA
Art. 11 (if applicable)
Your own process
Incident process

Note: Your auditor decides whether an exercise meets a particular requirement.

Back to the index

CD-⁠12The Helpful Agent

TypeSecurity
Difficulty 4 of 4
Runs for45–60 minutes
ModesTeam, Solo on-call, Leadership

What it tests

  1. Recognise an indirect prompt injection as a security incident, not an AI quirk
  2. Contain an AI agent quickly: disable tools, revoke its credentials, block the egress path
  3. Preserve prompts, tool calls and egress logs as evidence before anything is cleaned up
  4. Scope from logs, separating what was in reach, what was read and what left, instead of asking the model
  5. Rotate what leaked, decide on customer and regulator notification with counsel, and set conditions for turning the tools back on

Player briefing

It’s Tuesday 17 November 2026, 11:05 UTC.

Three weeks ago Harbourline shipped Harbour Helper v2. The internal AI assistant used by Support and Engineering can now read support tickets, search the internal wiki, create Jira issues, and fetch URLs (“so it can summarise links customers send us”). Support uses it on almost every ticket.

A message lands in #support-internal:

FromJas Kaur (Support, Tier 2)
ViaMessage
Message

Bit odd. I asked Harbour Helper to summarise ticket #88213 and suggest a reply. It says it's "known issue E-4471, tracked in PLAT-3318, recommend setting to Pending". But our export errors are all EXP- codes, there's no E-4471 that I can find, and PLAT-3318 was created by Harbour Helper at 10:47, a few seconds after I asked. Also the little tools badge says "Used 8 tools" just for a summary? Am I overthinking this?

What do you do?

Held by the controllerCounted from the scenario file. Players never see it, and none of it is on this page.
Hidden truthOne, fixed, revealed at the debrief
Injects13, timed or conditional, from T+00:00 to T+01:40
Hint ladder4 steps, given on request
Scored on6 dimensions, with indicators for this scenario
Debrief questions7
Your own stackNotes for re-skinning it to your services
Best for
Any organisation that has given an AI assistant tools: security, platform and support leads, and the exec who signed off ‘v2’.
Included in
The Kit, Pro and Practitioner editions

Designed to support evidence for

SOC 2
CC7.2, CC7.3, CC7.4, CC6.1, CC6.6
ISO 27001
A.5.24–A.5.28, A.8.12, A.8.16
OWASP Top 10 for LLM Applications 2025
LLM01, LLM02, LLM06
NIST AI RMF
Manage
UK GDPR
Art. 33, 34 breach-assessment process
Your own process
Incident process

Note: Your auditor decides whether an exercise meets a particular requirement.

Back to the index

Green sheet. The order copy. For whoever holds the budget.

All twelve are in the Kit

$149 once, for your whole organisation, with as many drills as you like. Pro and Practitioner include all twelve too. CD-⁠01 is free in the starter pack.