Back to scenarios
Red padlocks over streams of code, illustrating the Account Takeover: Containment & Response Microsimulation
Cyber & DataIndividual

Account Takeover: Containment & Response

At a glance

Account Takeover: Containment & Response is a simulation from iluminr in the Cyber & Data category for Technology & Security, Risk and Communications. It tests how your team protects customer data & identity, with indicative mapping to NYDFS Part 500, SEC Cyber Disclosure Rule and GLBA Safeguards Rule.

A suspected account compromise points to a data breach. Contain it, escalate it and coordinate across functions.

What it tests

  • Lock affected accounts or keep watching
  • Decide who needs to know, and when
  • Set the customer message

How you can run it

MicrosimulationPlay individually, with feedback on every decision.
Full-Scale SimulationExtend it across teams, functions and partners.
Expert-FacilitatedOur team designs and runs it with you.

Questions about Account Takeover: Containment & Response

What does Account Takeover: Containment & Response test?

Account Takeover: Containment & Response tests whether your team can lock affected accounts or keep watching, decide who needs to know, and when and set the customer message.

Who should take Account Takeover: Containment & Response?

Account Takeover: Containment & Response is designed for Technology & Security, Risk, Communications, Compliance and Legal.

Which regulations and standards does Account Takeover: Containment & Response support?

Account Takeover: Containment & Response supports testing expectations in NYDFS Part 500, SEC Cyber Disclosure Rule, GLBA Safeguards Rule, EU DORA, NIS2, APRA CPS 234, MAS TRM Guidelines, NIST CSF 2.0, EBA ICT & Security Risk Guidelines, ECB CROE, TIBER-EU, CBEST, APRA Intel-Led Cyber Testing, HKMA CFI, HKMA iCAST, RBI Cyber Security Framework, Singapore Cybersecurity Act, OSFI B-13, OSFI I-CRT, SAMA Cyber Security Framework, UAE Central Bank IS Regulation, UAE Information Assurance Standards, Israel INCD Cyber Methodology, ISO 27001, ISO 27035, NIST SP 800-61r3, NIST SP 800-53, CISA Cyber Storm, ENISA Cyber Europe, ISO 22398 and NIST SP 800-84. Mapping is indicative, so confirm scope against your own obligations.

Can Account Takeover: Containment & Response be run individually or as a team?

It is played individually, with feedback on every decision. It can also be extended into a team or full-scale simulation.

Can we customize Account Takeover: Containment & Response?

Yes. You can tailor the roles, plans, critical services, injects and objectives in the iluminr builder, or have our team customize it for you.

How do we get access to Account Takeover: Containment & Response?

Select Request Microsimulation. We'll set up access for you or facilitate it with your team.

Related scenarios

Phone call in the dark, illustrating the Bracing for Impact: Communications Test MicrosimulationCyber & DataBracing for Impact: Communications TestTest your organization's ability to send timely Emergency Notifications in response to a sophisticated, self-learning malware threat that targets critical infrastructure.Code on a dark screen, illustrating the Data Breach: Major Leak MicrosimulationCyber & DataData Breach: Major LeakA massive data breach has struck some of the world’s largest organizations, including your own, leading to the potential compromise of sensitive personal information. The breach has exposed the names, phone numbers, and addresses of millions of customers, raising immediate concerns about privacy, identity theft, and the security of your data handling practices.Code on a dark screen, illustrating the Extortion: Ransomware Invasion MicrosimulationCyber & DataExtortion: Ransomware InvasionAddress a widespread ransomware attack demanding cryptocurrency payments, focusing on stakeholder communication and restoring operational control.