Back to scenarios
Phone call in the dark, illustrating the Vished: Customer & Regulatory Impacts Microsimulation
Cyber & DataTeam

Vished: Customer & Regulatory Impacts

At a glance

Vished: Customer & Regulatory Impacts is a simulation from iluminr in the Cyber & Data category for Technology & Security, Risk and Compliance. It tests how your team protects online & mobile banking, with indicative mapping to NYDFS Part 500, SEC Cyber Disclosure Rule and GLBA Safeguards Rule.

A convincing voice-phishing call gives attackers a foothold, with consequences for customers and regulators. Assess the incident, identify the critical business functions at risk, and work through your regulatory obligations.

What it tests

  • Test incident assessment capabilities.
  • Demonstrate awareness of critical business functions.
  • Confirm understanding of regulatory requirements.

How you can run it

MicrosimulationRun as a team in a shared event room.
Full-Scale SimulationExtend it across teams, functions and partners.
Expert-FacilitatedOur team designs and runs it with you.

Questions about Vished: Customer & Regulatory Impacts

What does Vished: Customer & Regulatory Impacts test?

Vished: Customer & Regulatory Impacts tests whether your team can test incident assessment capabilities, demonstrate awareness of critical business functions and confirm understanding of regulatory requirements.

Who should take Vished: Customer & Regulatory Impacts?

Vished: Customer & Regulatory Impacts is designed for Technology & Security, Risk, Compliance, Legal, Communications and Executive & Board.

Which regulations and standards does Vished: Customer & Regulatory Impacts support?

Vished: Customer & Regulatory Impacts supports testing expectations in NYDFS Part 500, SEC Cyber Disclosure Rule, GLBA Safeguards Rule, EU DORA, NIS2, APRA CPS 234, MAS TRM Guidelines, NIST CSF 2.0, EBA ICT & Security Risk Guidelines, ECB CROE, TIBER-EU, CBEST, APRA Intel-Led Cyber Testing, HKMA CFI, HKMA iCAST, RBI Cyber Security Framework, Singapore Cybersecurity Act, OSFI B-13, OSFI I-CRT, SAMA Cyber Security Framework, UAE Central Bank IS Regulation, UAE Information Assurance Standards, Israel INCD Cyber Methodology, ISO 27001, ISO 27035, NIST SP 800-61r3, NIST SP 800-53, CISA Cyber Storm, ENISA Cyber Europe, ISO 22398 and NIST SP 800-84. Mapping is indicative, so confirm scope against your own obligations.

Can Vished: Customer & Regulatory Impacts be run individually or as a team?

It runs as a team exercise in a shared event room. It can also be extended into a full-scale simulation across teams and partners.

Can we customize Vished: Customer & Regulatory Impacts?

Yes. You can tailor the roles, plans, critical services, injects and objectives in the iluminr builder, or have our team customize it for you.

How do we get access to Vished: Customer & Regulatory Impacts?

Request it from this page. If you are an iluminr customer, we will set up access in your account. If not, we will contact you and either provide access or facilitate it for you.

Related scenarios

Phone call in the dark, illustrating the Bracing for Impact: Communications Test MicrosimulationCyber & DataBracing for Impact: Communications TestTest your organization's ability to send timely Emergency Notifications in response to a sophisticated, self-learning malware threat that targets critical infrastructure.Code on a dark screen, illustrating the Data Breach: Major Leak MicrosimulationCyber & DataData Breach: Major LeakA massive data breach has struck some of the world’s largest organizations, including your own, leading to the potential compromise of sensitive personal information. The breach has exposed the names, phone numbers, and addresses of millions of customers, raising immediate concerns about privacy, identity theft, and the security of your data handling practices.Code on a dark screen, illustrating the Extortion: Ransomware Invasion MicrosimulationCyber & DataExtortion: Ransomware InvasionAddress a widespread ransomware attack demanding cryptocurrency payments, focusing on stakeholder communication and restoring operational control.