Hidden-failure debrief
After a short timer, malware is re-enabled and the team only learns why during debrief.
Scenario Lab
Some lessons need more than a slide. This scenario turns incident response into a physical team challenge using a former military-base-style airsoft arena as the map.
The team must contain the breach, protect backups, search the logs, remove persistence, remove malware, block command-and-control, restore from backup and only then reconnect.
Interactive map
The map does not require hover. Labels are buttons, the explainer updates beside the image, and the full sequence is written out below.
Required sequence
Get the order wrong and the scenario may still appear to work, until the debrief explains why the malware came back, the backup became suspect, or the attacker route stayed open.
Facilitator debrief
The main player copy keeps pressure on the task. The debrief explains the failure states after the team has made decisions.
After a short timer, malware is re-enabled and the team only learns why during debrief.
Backup integrity is marked compromised or suspect.
Scenario can reinfect or fail at go-live.
Outside-world connection creates recurrence and triggers failed scenario state.
They may attack the wrong target or miss the CnC/watchdog clue.
Use the whitepaper as the concept note, then talk to everwished about shaping the exercise around your incident response reality.