Skip to content
Obfuscation Hub
Lab Intermediate

Respond to a Compromised Vendor Account

A tabletop exercise: your managed service provider reports that one of their technician accounts — with admin rights in your environment — was compromised. Work the first four hours, decision by decision.

Estimated time

60–90 minutes (solo) · 90–120 minutes (team tabletop)

Required tools

  • Pen and paper or a shared document
  • Optional: the Toolkit incident-response checklist alongside

Skills practiced

  • Containment decision-making
  • Third-party incident coordination
  • Evidence preservation
  • Stakeholder communication

Scenario

Meridian Physical Therapy Group (a fictional 12-clinic healthcare practice, ~200 staff) outsources IT to Cedarline Managed Services (also fictional). Cedarline technicians hold administrator accounts in Meridian’s Microsoft 365 tenant and remote-management (RMM) agent access to every workstation.

At 08:40 on a Tuesday, Meridian’s operations director receives a call from Cedarline’s service manager:

“We identified unauthorized access to one of our technician accounts overnight. We’ve disabled it on our side. We’re still determining which customer environments the account touched. We’ll update you by end of day.”

You are Meridian’s operations director (or play the roles across a team). Meridian has no internal IT staff — which is precisely why this exercise exists. Work the injects in order; do not read ahead.

Objectives

  • Practice containment decisions when the compromised party is also your IT department.
  • Balance business continuity against access cutoff for a healthcare operation.
  • Preserve evidence and establish a decision log under time pressure.
  • Draft honest stakeholder communications before all facts are known.

Inject 1 — 08:40: The call

Cedarline has told you what they know. You have 20 minutes before your morning leadership huddle.

Tasks: Write down (a) the five questions you ask Cedarline before hanging up, (b) who inside Meridian you inform immediately and what you say, (c) the single decision you must make right now — and make it: does Cedarline’s remaining access stay on while they investigate?

Inject 2 — 09:30: The complication

Your cyber-insurance policy, you now recall, requires notification “without undue delay” and use of approved incident-response counsel for events involving potential access to patient data. The RMM agent on every workstation could, in principle, access systems that store scheduling information and clinical notes. Nothing confirms patient data was touched.

Tasks: (a) Decide who you notify now versus later: insurer, counsel, practice leadership, clinic managers, patients — and record the reasoning. (b) Start a decision log: time, decision, decider, basis. Backfill Inject 1. (c) List what you ask Cedarline to preserve (sign-in logs, RMM session recordings, ticket history) — in writing, this time.

Inject 3 — 11:15: The finding

Cedarline reports: the compromised account authenticated to Meridian’s M365 tenant twice overnight, from an unfamiliar network, and viewed the admin portal. No mailbox access, no data export, and no RMM sessions are observed so far. They recommend resetting all Meridian admin credentials and rotating the RMM deployment.

Tasks: (a) Cedarline performing those resets means the possibly-compromised channel fixes itself — is that acceptable? What verification or independent party would you want? (b) Define what “confirmed contained” would mean here, concretely. (c) Decide what the 13:00 message to clinic managers says — write its three sentences.

Inject 4 — Day 5: The aftermath

Containment held; investigation found no patient-data access. Cedarline’s post-incident report attributes the compromise to a phished technician credential that was not protected by MFA — for a firm that requires MFA of its clients.

Tasks: (a) Write the five questions for the vendor-review meeting. (b) Using the vendor security questionnaire as a prompt, list the contractual and technical changes Meridian should require to continue the relationship. (c) Note the two internal changes Meridian owes itself regardless of Cedarline’s answers.

Expected deliverables

  • A four-inject decision log with times, deciders, and reasoning
  • The preservation request list from Inject 2
  • The clinic-manager communication from Inject 3
  • A vendor-remediation requirements list from Inject 4

Reflection questions

  • Where did you feel the tension between continuity and containment most sharply? Who should hold that decision in real life — and is that written down anywhere at your organization?
  • What information did you want at 08:40 that only a pre-existing vendor-access inventory could have provided?
  • If Cedarline had gone unreachable at Inject 2, what could Meridian have actually done alone? What does that answer imply?
  • Which notification (insurer, counsel, patients) carried the most uncertainty, and what would have reduced it?

Optional advanced challenge

Rewrite the scenario’s worst gap: draft the one-page “vendor incident annex” Meridian should attach to its incident-response plan — contacts on both sides, unilateral cutoff capability and its business cost, preservation asks, and the pre-named decision-maker. Compare it against our third-party privileged access analysis.

Defensive and ethical use

This is a fictional tabletop for authorized preparedness training. It contains no techniques for compromising systems and must not be used to simulate attacks against environments without explicit authorization.