Table 3.

Scenario types

Scenario typeDetails
Phishing-led ransomware propagationSimulates a phishing compromise followed by lateral movement and ransomware deployment, resulting in data encryption and extortion. Primary risk vectors include social engineering and endpoint compromise
Insider data exfiltrationModels an insider using removable media or personal cloud storage to exfiltrate sensitive data. Risk vectors include insider misuse and unauthorised data access
Public-cloud misconfigurationEmulates exposure of personally identifiable information (PII) because of misconfigured access controls, such as open AWS S3 buckets. Risk vectors include misconfiguration and poor cloud governance
Credential leakageReplicates unauthorised access via credentials exposed in public code repositories or compromised CI/CD pipelines. Risk vectors include credential theft and supply chain exposure
Source(s): Authors’ own work

or Create an Account

Close Modal
Close Modal